PS ProTech(305) 699-5652

Compliance support

The rules your firm answers to, handled

Regulators, insurers and clients all ask how you protect information. We put the controls in place, write the documentation and keep the evidence, so you have an answer ready.

By profession

What applies to your firm

The rules professional firms are most often asked about. Find yours.

  • Accounting and CPA firms
    FTC Safeguards Rule
    A written information security program, a named person in charge of it, a risk assessment, multi-factor authentication, encryption, staff training and oversight of vendors.
    IRS data security guidance
    A written information security plan for anyone preparing returns, as set out in IRS Publications 4557 and 5708.
  • Tax preparers
    IRS written information security plan
    Every paid preparer is expected to have one, and the PTIN renewal asks you to confirm your data security responsibilities.
    FTC Safeguards Rule
    The same federal rule that covers accountants, including reporting certain breaches to the FTC.
  • Financial advisers
    SEC Regulation S-P
    Written policies to protect client records, an incident response program, and notice to clients after a breach of their information.
    State rules and the FTC Safeguards Rule
    State-registered advisers answer to their state regulator and to the federal Safeguards Rule.
  • Law firms
    Florida Bar rules of professional conduct
    Reasonable efforts to prevent unauthorized access to client information, and competence in the technology you use to handle it.
    ABA ethics opinions
    Guidance on securing client communications and on a lawyer's obligations after a breach.
  • Real estate and title firms
    FTC Safeguards Rule
    Settlement and closing services fall under it, with the same written program and controls as other financial businesses.
    ALTA Best Practices
    The title industry's own standard, which underwriters expect: a written privacy and information security program and controls on escrow funds.
  • Insurance agencies
    State insurance privacy and safeguards rules
    Agencies are expected to protect policyholders' financial and health information, under state rules that apply the Gramm-Leach-Bliley Act to insurance.
    Carrier requirements
    The carriers you write for set their own security terms in their agency agreements.
  • Consultancies
    Client security questionnaires
    Larger clients ask outside firms to describe and prove their security before sharing data or system access.
    Contract terms
    Security and breach-notice clauses in your client agreements, which become your obligations once signed.
  • Architecture and engineering firms
    Client and owner requirements
    Security questionnaires and contract clauses from clients, especially on public, healthcare and corporate projects.
    Professional liability insurers
    Questions about backups, access controls and how project files are protected.

Every firm

What applies whatever your profession

  • Florida Information Protection Act

    Reasonable measures to protect personal information, notice to affected people generally within 30 days of a breach, and a report to the Attorney General's office when 500 or more Floridians are affected.

  • Cyber insurance applications

    Your answers form part of the policy. Insurers ask about multi-factor authentication, EDR, backups, training and payment verification, and expect them to be true.

  • Client security questionnaires

    More clients now ask their professional advisers to prove how information is protected before they hand it over.

General information, not legal advice. The rules that apply to your firm depend on the work you do, the data you hold and where your clients are.

How we help

From a rule on paper to proof in your hands

  1. 1

    Work out what applies

    We go through your profession, your clients and your contracts, and list the rules and requests you actually face. Where a question is a legal one, we say so and point you to your counsel.

  2. 2

    Put the controls in place

    Most of these rules ask for the same things: multi-factor authentication, encryption, protected devices, tested backups, trained staff. We set them up and keep them running.

  3. 3

    Write it down

    We prepare your written information security plan and the policies behind it, in plain language that describes what your firm really does, and keep them current.

  4. 4

    Keep the evidence

    Reports that show each control is switched on, ready for an insurance renewal, a client questionnaire or a regulator's question.

Straight answers

What we don't do

Compliance is an area where vendors overpromise. Here is where our part ends.

  • We don't give legal advice. Whether your firm meets a legal obligation is a question for your counsel.
  • We don't certify firms as compliant, and we'd be wary of any IT provider that says it can.
  • We don't do defense contract work such as CMMC. That needs a specialist, and we'll tell you if you need one.

Questions

What firms ask

Can you make our firm compliant?

We can put the technical controls in place, write the documentation and give you the evidence. Whether that meets a particular legal obligation is a judgment for you and your counsel, which is why we call this compliance support.

We're a small firm. Do these rules really apply to us?

Often, yes. The FTC Safeguards Rule and the IRS guidance apply to tax and accounting practices of any size, though some requirements are lighter for firms holding information on fewer than 5,000 people. Florida's breach notification law applies to every business that holds personal information.

What is a written information security plan?

A document that sets out what information your firm holds, the risks to it, the safeguards you use, who is responsible, and what you do if something goes wrong. Several of the rules on this page require one.

Which plan includes this?

Compliance reporting, a written security plan kept current, and help with questionnaires and insurance forms are part of the Secure plan. On other plans, a written security plan can be prepared as a one-time project.

See what it costs for your firm.

Build a plan in two minutes. No call required.