September 01, 2024

Top Cybersecurity Tactics for CPAs in the Digital Age

By Stacey Howard

While navigating digital transformation, the world positions the accounting profession in its crosshairs. Many CPAs and accounting firms are sitting on a treasure trove of sensitive data and are becoming prime targets for cybercriminals.

Technology has introduced innovative measures for streamlining processes and enhancing the efficiency of CPA firms. However, everything that glitters is not gold.

According to IBM's Cost of a Data Breach report, firms investing in cybersecurity now are saving an average cost of $4.45 million/data breach, a 15% increase over the past three years.

These advancements also open up the accounting profession to novel risks. Consequently, cybersecurity solutions have become imperative for CPAs to safeguard their businesses and clients.

The Rise of Digital Transformation in Accounting

CPAs and accounting firms are actively reshaping themselves through digital transformation. They are embracing advanced tools and technologies such as artificial intelligence (AI), machine learning and automation. These innovative measures enhance efficiency and empower CPAs and accountants to transition their focus from mere data crunching to high-value services. This shift includes strategic financial planning and risk management, even business advisory services.

Technology has revolutionized the accounting profession; however, it introduces new challenges – notably cybersecurity threats – that demand immediate attention.

Why Hackers Are Targeting CPAs

In recent years, we have witnessed a shift in focus among hackers. They no longer concentrate solely on the prominent, headline-making targets associated with previous breaches. Instead, their attention extends to smaller and less conspicuous victims.

Emerging patterns suggest that certain financial cybersecurity criminals might even circumvent launching ransomware attacks against larger organizations. This will help to prevent national political or law enforcement responses – as Sherry Bambrick, Senior Underwriter for the AICPA Member Insurance Programs, asserts. This is an evolving strategy carrying significant implications for CPAs.

Bambrick stated: "Hackers find CPA firms particularly attractive because these entities essentially aggregate financial and personal identifiable information (PII) data. The escalating emphasis on smaller organizations, along with the vast amount of PII potentially held by a firm, significantly amplifies the risk they encounter."

Hackers target CPA firms not only for their access to client funds but also due to the assumption that mid-size and smaller firms lack robust information security strategies. These assumptions are born from a misguided belief held by their leaders that they're too small to be targeted.

What Are the Best Cybersecurity Practices for CPAs?

Let’s tap into some of the cybersecurity practices to stay ahead in the competitive market.

1. Proactively Detect Risks. CPAs must proactively detect risks and vulnerabilities and protect against breaches or "active" concerns such as phishing and ransomware. They need to put measures in place for this.

Moreover, these protective strategies should address the technology involved and its users. Comprehensive security is a shared responsibility where both digital systems and human factors intersect in all their complex intricacies. How you can go about it:

  • Use risk assessments for a health check of your business;
  • Implement zero trust factor that aims to protect the network and security infrastructure;
  • Watch for advanced persistent threats (APTs) and monitor endpoints by using tools such as endpoint detection response (EDR); and
  • Use software like MetricStream IT and cyber risk management software for risk identification.

2. Conduct Training and Build a Secure Culture. CPA firm owners should conduct security awareness training that includes real-world exercises. In particular, realistic and challenging phishing simulations should be implemented. To reinforce best practices, adeptly blend teaching with engaging activities.

Construct a firm emphasizing a "culture of security," focusing on data governance and management. Remember that the business side – not just the IT and risk management divisions – must provide robust input for this initiative. CPAs can run cybersecurity governance and risk management programs using voluntary framework, which can include the risk assessment.

For instance, the National Institute of Standards and Technology (NSIT) includes the following five continuous functions:

  • Identify: Develop an organizational understanding of managing cybersecurity risk to systems, people, assets, data, and capabilities.
  • Protect: Proactively implement appropriate safeguards to ensure the delivery of critical services. By doing so, you can take control of your cybersecurity landscape.
  • Detect: Identify the occurrence of a cybersecurity event.
  • Respond: Take action regarding a detected cybersecurity incident.
  • Recover: Maintain resilience plans and restore any capabilities or services that were impaired by a cybersecurity incident.

3. Emphasize Self-Awareness Practice. Remind your employees to cultivate self-awareness, a crucial practice in today's digital landscape. Taking a moment before responding or acting upon suspicious emails can often mark the turning point; it is usually half the battle won.

To illustrate this concept, urge them to evaluate dubious URLs for anomalies and validate the sender's identity through another trusted method – perhaps by placing an essential phone call.

4. Implement Multi-Factor Authentication and Restrict Online Sharing. All access points require more than just a password to join the network, so utilize multi-factor authentication. Implementing confirmation via text messages, phone calls or fingerprints, despite its minimal effort, can significantly enhance a firm's security.

You should push employees to restrict the online sharing of work-related information, as potential attackers can leverage this practice for social engineering schemes. It will effectively mitigate cyber criminals' ammunition by refraining from incorporating details such as client or colleague names in personal social media posts.

5. Use VPN. A virtual private network (VPN) masks employees' identities, safeguarding their communications from potential attackers, a measure particularly crucial when they utilize public WiFi.

To scan and block malicious links, attachments or accounts – thus potentially intercepting and neutralizing malware from a corrupt link or attachment – requires the active tasks of installing and maintaining regular updates. Anti-virus/anti-phishing software is our tool for such critical operations.

6. Ensure Strict Control Over Data Sharing. When engaging with third-party providers, exercise stringent control measures like incorporating indemnification clauses or stipulating that the provider maintains cyber insurance in its service agreement for potential breaches on a third-party platform.

7. Plan Ahead for Any Data Breach. You must create a robust security and breach response plan that can be quickly implemented in the event of an issue. Furthermore, it is imperative to revisit and update this plan regularly. This practice helps ensure its effectiveness against the ever-evolving risk landscape.

Bottom Line

Integrating AI in accounting services not only augments cybersecurity defenses but also empowers firms to navigate the complexities of modern digital landscapes with confidence. See how at this link.

The evolution of digital transformation in accounting necessitates a paramount focus on cybersecurity. As cyber threats continue to advance, CPA firms must actively enhance their security measures. This is crucial for both protecting sensitive data and ensuring compliance with industry regulations.

About the Author: Stacey Howard is an accomplished blogger with over a decade of experience in the field of accounting and bookkeeping. With her extensive knowledge and expertise, she has been working as an accountant at a leading business process management firm Accounting To Taxes. Throughout her career, she has developed a passion for sharing valuable insights and information on various accounting industries through her engaging and informative write-ups. Her contributions to the accounting community have been widely recognized, making her a sought-after expert in the field.

 

Thanks to the Sponsors of Today's CPA Magazine

This content was made possible by the sponsors of this issue of Today's CPA Magazine: 

Accounting Biz Brokers

Accounting Practice Sales

CPA Charge

Goodman Financial

Poe Group Advisors

 


  • SECURE Act 2.0

    SECURE 2.0 and the One Big Beautiful Bill Act

    This article provides a snapshot of the key provisions of the One Big Beautiful Bill Act and retirement provisions in SECURE 2.0. Together, these laws are reshaping retirement planning through new compliance requirements and expanded advisory opportunities, with changes taking effect in 2026 and beyond that call for proactive guidance for clients and employers.
    View Article
  • CPE: Share Repurchases - Playing in the Big Leagues

    Stock buybacks have grown from a once-restricted practice into a dominant way corporations return cash to shareholders. While they return more cash to shareholders than dividends, the financial-reporting and tax risks that large buybacks create must be managed – from negative equity and distorted ratios to rising excise-tax costs.
    View Article
    Tax
  • Volunteer

    Welcoming 2026 with Purpose and Possibility

    Stepping into 2026 brings a wave of opportunity for TXCPA members. This issue of Today’s CPA covers key updates like H.R. 1, SECURE 2.0 and retirement planning, plus insights on AI-driven tax compliance and IRS technology trends. Explore ways to grow, give back, and connect through TXCPA programs and events.
    View Article
  • IRS Use of Artificial Intelligence and Data Analytics to Modernize Operations

    The IRS is rapidly expanding its use of artificial intelligence and data analytics to modernize operations, reshaping compliance, enforcement and taxpayer interactions. From AI-powered chatbots that ease service demands to advanced analytics, the agency is harnessing technology to manage massive data volumes—while walking a careful line between efficiency, fairness and taxpayer trust.
    View Article
    IRS
  • Tax Services

    AI-Powered Tax Compliance, Part 1: How Machine Learning is Revolutionizing Sales and Use Tax

    Business Problem Solved: Companies can struggle to stay on top of complex, high-volume sales and use tax obligations, and this article shows how a hybrid rules-plus-machine-learning approach enables earlier detection, reduces manual review and ensures scalable, auditable compliance.
    View Article
  • Your TXCPA Calendar: Key Dates, Leadership Opportunities and CPE Ahead

    Plan your year with this snapshot of essential events, deadlines and learning opportunities for TXCPA members.
    View Article
    Volunteer
  • fraud

    The Vicious Cycle of Cheating in Accounting: From Students to Practitioners

    Cheating among accounting students and practitioners is increasing and threatens public trust in the profession. Research shows that unethical behavior in school often carries into professional practice. Stronger penalties and dedicated ethics education are needed to break this cycle and reinforce integrity as a core professional value.
    View Article
  • What’s Happening Around Texas - January-February 2026

    TXCPA members are making a big impact! During Accounting Opportunities Month and our annual Month of Service, 68 volunteers reached over 3,000 students and supported local charities across Texas. From hosting career workshops and networking events to packing meals and donating toys, chapters showed the power of giving back.
    View Article
    volunteer for my chapter
  • Texas State Board of Public Accountancy

    Turning Challenges into Wins: How TXCPA Advocates for You

    TXCPA delivered major wins for Texas CPAs during the 2025 legislative session, strengthening the profession at a pivotal moment. New legislation expanded pathways to CPA licensure, modernized practice mobility for out-of-state CPAs and reinforced public protection. These successes highlight the growing impact of TXCPA’s advocacy and the critical role of the TXCPA PAC in safeguarding the CPA license.
    View Article
  • TXCPA Thanks Our 2025-2026 Professional Group Membership Program Participants!

    A big thank you to all the firms and organizations that joined or renewed with TXCPA’s Professional Group Membership program. To simplify renewals and maximize your team’s benefits, be sure to explore our group billing option.
    View Article
    Membership
  • TSBPA

    Steadfast Leadership: William Treacy’s 35 Years at the Texas State Board of Public Accountancy

    For three decades, William Treacy has led the Texas State Board of Public Accountancy with one guiding principle: protect the public. His tenure reflects a career defined by integrity, public service and steady leadership in a rapidly changing profession.
    View Article
  • Implications of Section 301 Tariff Actions

    Section 301 tariffs during President Trump’s first term were associated with reducing the U.S. trade deficit with China, though the overall deficit continued to grow. Data suggests tariffs shifted trade flows rather than curbing demand. For CPAs, these insights are key to assessing how renewed tariffs could impact trade patterns, costs and global tax planning.
    View Article
    Transfer pricing
  • Trusted Advisor

    Why Exit Planning Should Be on Every CPA Firm’s Radar

    Exit planning is quickly becoming a high-impact advisory opportunity for CPAs. While many business owners know they will eventually exit, few are truly prepared, and CPAs are ideally positioned to close that gap through trusted relationships and financial insight.
    View Article
  • Governance is Your Growth Engine: Build Value and Outrun Private Equity

    As private equity reshapes the accounting landscape and traditional partnership models strain under talent shortages and succession challenges, strong governance has become the real differentiator. By replacing ad hoc decision-making with clear roles, accountability, performance metrics and disciplined planning, firms can turn chaos into clarity and intention into execution.
    View Article
    Public practice
  • talent retention

    How Employee Resource Groups Can Drive Diversity in an Accounting Organization

    This article dives into how Employee Resource Groups (ERGs) help firms build cultures that attract, engage and retain people by turning inclusion into action. Firms that invest in ERGs create workplaces where employees are more engaged, loyal and likely to thrive.
    View Article
  • Take Note

    In this edition of Take Note: 2026 Midyear Leadership Council and Members Meeting; Support Through the Accountants Confidential Assistance Network (ACAN); CGMA® Designation; 2026 CPE Programs; TXCPA’s Career Center
    View Article
    TXCPA online learning
  • Classifieds

    The Classifieds section offers a centralized resource for practice sales, buyers seeking to purchase firms and specialized services. It helps members efficiently connect with opportunities tailored to their professional needs.
    View Article

CHAIR
Mohan Kuruvilla, Ph.D., CPA

PRESIDENT/CEO
Jodi Ann Ray, CAE, CCE, IOM

CHIEF OPERATING OFFICER
Melinda Bentley, CAE

EDITORIAL BOARD CHAIR
Jennifer Johnson, CPA

MANAGER, MARKETING AND COMMUNICATIONS
Peggy Foley
pfoley@tx.cpa

MANAGING EDITOR
DeLynn Deakins
ddeakins@tx.cpa

COLUMN EDITOR
Don Carpenter, MSAcc/CPA

DIGITAL MARKETING SPECIALIST
Wayne Hardin, CDMP, PCM®

CLASSIFIEDS
DeLynn Deakins

Texas Society of CPAs
14131 Midway Rd., Suite 850
Addison, TX 75001
972-687-8550
ddeakins@tx.cpa

 

Editorial Board
Derrick Bonyuet-Lee, CPA-Austin;
Aaron Borden, CPA-Dallas;
Don Carpenter, CPA-Central Texas;
Rhonda Fronk, CPA-Houston;
Aaron Harris, CPA-Dallas;
Baria Jaroudi, CPA-Houston;
Elle Kathryn Johnson, CPA-Houston;
Jennifer Johnson, CPA-Dallas;
Lucas LaChance, CPA-Dallas, CIA;
Nicholas Larson, CPA-Fort Worth;
Anne-Marie Lelkes, CPA-Corpus Christi;
Bryan Morgan, Jr, CPA-Austin;
Stephanie Morgan, CPA-East Texas;
Kamala Raghavan, CPA-Houston;
Amber Louise Rourke, CPA-Brazos Valley;
Shilpa Boggram Sathyamurthy, CPA-Houston, CA
Nikki Lee Shoemaker, CPA-East Texas, CGMA;
Natasha Winn, CPA-Houston.

CONTRIBUTORS
Melinda Bentley; Kenneth Besserman; Kristie Estrada; Holly McCauley; Craig Nauta; Kari Owen; John Ross; Lani Shepherd; April Twaddle; Patty Wyatt