Compliance support
The rules your firm answers to, handled
Regulators, insurers and clients all ask how you protect information. We put the controls in place, write the documentation and keep the evidence, so you have an answer ready.
By profession
What applies to your firm
The rules professional firms are most often asked about. Find yours.
- Accounting and CPA firms
- FTC Safeguards Rule
- A written information security program, a named person in charge of it, a risk assessment, multi-factor authentication, encryption, staff training and oversight of vendors.
- IRS data security guidance
- A written information security plan for anyone preparing returns, as set out in IRS Publications 4557 and 5708.
- Tax preparers
- IRS written information security plan
- Every paid preparer is expected to have one, and the PTIN renewal asks you to confirm your data security responsibilities.
- FTC Safeguards Rule
- The same federal rule that covers accountants, including reporting certain breaches to the FTC.
- Financial advisers
- SEC Regulation S-P
- Written policies to protect client records, an incident response program, and notice to clients after a breach of their information.
- State rules and the FTC Safeguards Rule
- State-registered advisers answer to their state regulator and to the federal Safeguards Rule.
- Law firms
- Florida Bar rules of professional conduct
- Reasonable efforts to prevent unauthorized access to client information, and competence in the technology you use to handle it.
- ABA ethics opinions
- Guidance on securing client communications and on a lawyer's obligations after a breach.
- Real estate and title firms
- FTC Safeguards Rule
- Settlement and closing services fall under it, with the same written program and controls as other financial businesses.
- ALTA Best Practices
- The title industry's own standard, which underwriters expect: a written privacy and information security program and controls on escrow funds.
- Insurance agencies
- State insurance privacy and safeguards rules
- Agencies are expected to protect policyholders' financial and health information, under state rules that apply the Gramm-Leach-Bliley Act to insurance.
- Carrier requirements
- The carriers you write for set their own security terms in their agency agreements.
- Consultancies
- Client security questionnaires
- Larger clients ask outside firms to describe and prove their security before sharing data or system access.
- Contract terms
- Security and breach-notice clauses in your client agreements, which become your obligations once signed.
- Architecture and engineering firms
- Client and owner requirements
- Security questionnaires and contract clauses from clients, especially on public, healthcare and corporate projects.
- Professional liability insurers
- Questions about backups, access controls and how project files are protected.
Every firm
What applies whatever your profession
Florida Information Protection Act
Reasonable measures to protect personal information, notice to affected people generally within 30 days of a breach, and a report to the Attorney General's office when 500 or more Floridians are affected.
Cyber insurance applications
Your answers form part of the policy. Insurers ask about multi-factor authentication, EDR, backups, training and payment verification, and expect them to be true.
Client security questionnaires
More clients now ask their professional advisers to prove how information is protected before they hand it over.
General information, not legal advice. The rules that apply to your firm depend on the work you do, the data you hold and where your clients are.
How we help
From a rule on paper to proof in your hands
- 1
Work out what applies
We go through your profession, your clients and your contracts, and list the rules and requests you actually face. Where a question is a legal one, we say so and point you to your counsel.
- 2
Put the controls in place
Most of these rules ask for the same things: multi-factor authentication, encryption, protected devices, tested backups, trained staff. We set them up and keep them running.
- 3
Write it down
We prepare your written information security plan and the policies behind it, in plain language that describes what your firm really does, and keep them current.
- 4
Keep the evidence
Reports that show each control is switched on, ready for an insurance renewal, a client questionnaire or a regulator's question.
Straight answers
What we don't do
Compliance is an area where vendors overpromise. Here is where our part ends.
- We don't give legal advice. Whether your firm meets a legal obligation is a question for your counsel.
- We don't certify firms as compliant, and we'd be wary of any IT provider that says it can.
- We don't do defense contract work such as CMMC. That needs a specialist, and we'll tell you if you need one.
Questions
What firms ask
Can you make our firm compliant?
We can put the technical controls in place, write the documentation and give you the evidence. Whether that meets a particular legal obligation is a judgment for you and your counsel, which is why we call this compliance support.
We're a small firm. Do these rules really apply to us?
Often, yes. The FTC Safeguards Rule and the IRS guidance apply to tax and accounting practices of any size, though some requirements are lighter for firms holding information on fewer than 5,000 people. Florida's breach notification law applies to every business that holds personal information.
What is a written information security plan?
A document that sets out what information your firm holds, the risks to it, the safeguards you use, who is responsible, and what you do if something goes wrong. Several of the rules on this page require one.
Which plan includes this?
Compliance reporting, a written security plan kept current, and help with questionnaires and insurance forms are part of the Secure plan. On other plans, a written security plan can be prepared as a one-time project.
See what it costs for your firm.
Build a plan in two minutes. No call required.
