All professional firms
The 15-point security checklist for professional firms
· PS ProTech · 5 min read
You don't need a consultant to find out where your firm is exposed. You need an honest hour and the right questions. This checklist covers the fifteen things we look at first when we review a firm, in the order that matters.
Mark each one yes, partly or no. For every yes, ask how you know. "We have backups" is a belief. "We restored a file last month" is a fact.
Accounts and sign-in
1. Is multi-factor authentication on for every email account? Most breaches at professional firms start with a stolen email password. A second step at sign-in stops nearly all of them. No exceptions for partners. If you're unsure why it matters so much, read why multi-factor authentication is the first thing to fix.
2. Does every person have their own login? Shared logins for the practice management system or the accounting package mean you can't tell who opened what, and you can't remove one person's access without changing it for everyone.
3. Do you find out when a staff password appears in a breach? Passwords leak from other websites and get tried against yours. Dark web monitoring tells you when one of your firm's addresses turns up, so the password can be changed before it's used.
4. Is access removed the same day someone leaves? Not at the end of the month. Our same-day offboarding checklist lists every place access tends to linger.
Computers
5. Is every laptop encrypted? A lost encrypted laptop is an inconvenience. A lost unencrypted one may be a breach you have to report to every client on it.
6. Are updates installed within days? Attackers use known weaknesses in software that hasn't been updated. This is routine work that should happen without anyone thinking about it. See device monitoring and patching.
7. Does every computer have protection that watches behavior? Traditional antivirus looks for known bad files. Modern endpoint security also watches for what ransomware does, and that includes home computers used for work.
Email and money
8. Is email filtered before it reaches the inbox? AI now writes phishing emails with no spelling mistakes and the right names in them. Your staff can't be the only line of defense. Email security removes most of it before anyone sees it.
9. Do you confirm payment changes by phone? Any request to change bank details, or to send money somewhere new, gets a call back on a number you already hold. This one habit stops most payment fraud, including the kind that uses cloned voices.
10. Do staff get short, regular training? Ten minutes a quarter beats an hour once a year. Keep a record of who completed it, because clients and insurers ask. See security awareness training.
Recovery
11. Are your files and mailboxes backed up somewhere separate? Microsoft and Google keep their services running. They don't protect you from a deleted folder or an encrypted one. We explain the gap in does Microsoft 365 back up your data?
12. Have you restored something recently? A backup you haven't tested is a hope. Restore one file every quarter and write down that you did.
13. Is there a one-page plan for a bad day? Who to call, how to disconnect a machine, who decides about telling clients and your insurer. If the answer is "we'd figure it out," read the first hour of a ransomware attack.
Proof
14. Do you have a written security plan? Tax preparers are expected to have one, and every firm benefits from one. It's the document a client's security questionnaire is really asking about. Start with how to answer a client security questionnaire.
15. Do you have a rule for AI tools? Staff are already pasting text into chatbots to summarize and draft. Without a rule, some of that text is your clients' confidential information. See a policy for staff using AI tools.
How to run this at your firm
Going through the list alone gives you opinions. Going through it with the right people gives you facts.
Put three people in a room for an hour: a partner with authority to decide, whoever handles your IT, and whoever runs the office. Each knows something the others don't. The partner knows what clients have been promised. The IT person knows what's switched on. The office manager knows what happens in practice, such as which temp still has a login.
Ask for proof as you go. For each yes, have someone show it: the setting, the report, the dated document. This is where a comfortable yes turns into a partly.
Write down who owns each gap and a date to fix it. A list without names doesn't get done.
Repeat it every six months. New staff, new software and new habits open gaps that weren't there last time.
The evidence to keep
Each yes should leave something you can hand to a client or an insurer. Keep it in one folder.
- Sign-in: a report showing multi-factor authentication enforced for every account.
- Computers: an inventory showing encryption, update status and protection on each device.
- Training: who completed what, and when.
- Backups: the latest backup report and a note of your last restore test.
- Offboarding: a dated record for each person who left.
- Policies: your written security plan, your payment-change rule and your AI rule, each with a date and signatures.
That folder answers most of what's on a cyber insurance form, which we walk through in what cyber insurers ask.
Reading your score
- 12 or more yes answers, each with evidence: you're ahead of most firms your size. Close the remaining gaps and keep the evidence somewhere you can find it.
- 7 to 11: typical. The gaps are usually the unglamorous ones: offboarding, restore tests and written plans.
- 6 or fewer: start with items 1, 9 and 11. They cost little and remove the most risk.
Whatever the score, the items marked "partly" deserve the most attention. They're the ones a firm believes are handled.
Want a second pair of eyes?
We go through this list with firms in a free 30-minute IT and cybersecurity review. You'll come away knowing where your gaps are and what to fix first. If you'd like to see what it costs to have all fifteen handled for you, the plan builder shows the monthly price for your headcount.
