the 7 categories of cybersecurity solutions firms need

how important are wisp and employee awareness? just ask the irs or the ftc. 

by donny shimamoto, cpa, citp, cgma
on cybersecurity for accountants
center for accounting transformation

historically, finding cybersecurity solutions “right-sized” for the small and mid-sized business space was difficult. most of the technologies were expensive and difficult to implement, and their price points weren’t reasonable for organizations with under 25 people. it’s only been within the last five years that we’ve seen solutions mature and evolve enough to be delivered via the cloud at a price point that makes sense for smaller organizations.

more: how hacker-proof is your firm?donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

to check if your policy addresses all of the requirements, take our cybersecurity compliance self-assessment for tax practitioners at: improvetheworld.net/cyberselfassessfortaxbook

with the covid-19 pandemic and the adoption of remote work increased cybersecurity threats, the cybersecurity industry has stepped up and made solutions much more affordable and easier to implement. these solutions still require some technical knowledge to install, but there is much less maintenance, and they now make economic sense even for sole practitioners. read more →

understanding the full cost of a data breach

indirect costs often have a much greater impact—especially for smaller firms.

by donny shimamoto
cybersecurity for accountants

generally, when there is unauthorized access to personally identifiable information (pii), a data breach is considered to have happened. originally pii was only defined as:

more:  how hacker-proof is your firm? | unleashing the power of technology: transforming accountants into trusted advisors | future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

  • a first name or initial and last name, along with:
    • social security number (ssn)
    • driver’s license number
    • credit or debit card number
    • financial account number with access code (e.g., a bank account number and pin)
  • personal health information (also known as phi)

however, due to the increasing sensitivity of the public to privacy concerns and resulting legislative actions, the following is also often considered to be part of pii: [i]

read more →

adrian hong: necessity can make you an expert

innovation insights: trial by fire may not be fun, but it can make you a pro.

subscribe to 卡塔尔世界杯常规比赛时间 podcasts anywhere: applegooglespotifyiheartdeezer, amazon music and audibleplayer fmaudacygaana (india), and boomplay (africa).

innovation insights
with donny shimamoto

center for accounting transformation

adrian hong’s journey into the realm of environmental, social, and governmental (esg) reporting has been nothing short of inspiring. as the founder of hong consulting, llc, his dedication to assisting companies with esg reporting stems from a rich tapestry of experiences, all pointing to one common thread – the desire to help.

center for accounting transformation
center for accounting transformation

more: blake oliver: why tax work yearns to be free |private equity explodes in u.k. | brannon poe: the status quo must go  |  accounting nerds, unlock your super powers  | private equity vs. the cpa firm partnershipthe fintech flood: accounting will never be the same  |  think small to think big with matt wilkinson | your sales tax headaches are only just beginning | when financial statements go extinct with corey schmidt  |  can geraldine carter save accountants from themselves? |  re-inventing accounting with tyler anderson |  turning client service into new revenue

see also: deloitte develops audit technology for smaller firms

goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

after building a formidable reputation in auditing within public accounting and lending his skills to the financial accounting standards board for refining external taxonomy, life had other plans. hong returned to his roots in hawaii to steer the helm of his family’s venture, island plastic bags.

read more →

irs and ftc cybersecurity expectations of tax practitioners

your tools for a cybersecurity compliance check-up.

by donny shimamoto
cybersecurity for accountants

in august 2019, the irs published its list of “security six” steps to protect taxpayer information.[i] these described the six “basic protections” that it expects tax prepares to utilize.

more:  how hacker-proof is your firm? | unleashing the power of technology: transforming accountants into trusted advisors | future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

these include:

read more →

cybersecurity exemptions for orgs with less than 5,000 clients

you may be off the hook, but not out of the woods.

by donny shimamoto

management consulting company aon described an exemption for some of the ftc requirements for firms that handle the personal identifiable information (pii) of less than 5,000 consumers.[i]

the safeguards rule provides an exception from certain requirements if the covered financial institution maintains customer information concerning fewer than 5,000 consumers. a consumer is defined in section 314.2(b)(1) of the safeguards rule as “an individual who obtains or has obtained a financial product or service from the financial institution that is used primarily for personal, family, or household purposes, or that individual’s legal representative.”

more:  how hacker-proof is your firm? | unleashing the power of technology: transforming accountants into trusted advisors | future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

essentially if you handle less than 5,000 social security numbers, then it would appear that you can take advantage of this exemption. aon went on to report that if you fall under this exemption, then you do not need to address the following requirements:

read more →

safe harbor compliance reduces risk of fines and penalties

protect your clients–and your firm–by being proactive.

by donny shimamoto, cpa, citp, cgma

in the last few years, we’re starting to see state legislatures and attorney generals recognizing that tax practitioners are trying to protect their clients. they are formalizing this recognition with changes to regulations or laws to include “safe harbor” provisions that limit or eliminate the fines and penalties for tax practitioners who take proactive action to manage their cybersecurity risks.

more:  how hacker-proof is your firm? | unleashing the power of technology: transforming accountants into trusted advisors | future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

as of december 2022, the following states have some type of safe harbor provision in place:

in contrast, states like california and colorado are taking the opposite approach and penalizing organizations that have data breaches.[iv]

read more →

unleashing the power of technology: transforming accountants into trusted advisors



the smartest route to advisory:
join the survey. get the roadmap

imagine the possibilities.

by donny shimamoto, cpa, citp, cgma
the center for accounting transformation

in today’s rapidly evolving world, technology is revolutionizing the way we work and live. accountants and cpas are no exception.

more donny shimamoto:  how trusted advisors transform businesses | the future of accounting: a vision of trust, clarity, and hope | donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

we need to embrace the power of technology to enhance our services and better serve our clients as advisors. by leveraging technology and focusing on the complicated work that bots can’t do, accountants become trusted advisors, building deeper relationships and unlocking their full potential.

read more →

overcoming the five hurdles to advisory services

face these issues to achieve firm growth.

the smartest route to advisory:
join the survey. get the roadmap

by donny shimamoto, cpa, citp, cgma
the center for accounting transformation

are you tired of feeling overwhelmed and stuck in the compliance workload, unable to provide valuable insights to your clients? do you feel that your firm has the potential to grow and create a lasting impact, but capacity issues hinder your progress? 

more donny shimamoto:  how trusted advisors transform businesses | the future of accounting: a vision of trust, clarity, and hope | donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

you’re not alone. many accounting firms are struggling with the same challenges. but what if there was a way to break through these barriers and elevate your firm to new heights? read on to discover how to overcome the challenges associated with providing advisory services and transform your firm into a thriving, client-centered business.
read more →

how tax practitioners became cybersecurity risks

tax professionals are a hacker’s dream.  

by donny shimamoto, cpa, citp, cgma
on cybersecurity for accountants
center for accounting transformation

in 2015 the u.s. internal revenue service (irs) held its first security summit[i]. by creating a public-private partnership via the summit, the irs is seeking to protect more taxpayers and more tax dollars from tax-related identity theft.

more: how hacker-proof is your firm?donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

partners in the summit included the irs, state tax agencies and the private sector tax industry—for example, financial institutions, cybersecurity practitioners and tax practitioners.

the summit brought together people from the full value chain of tax compliance. taxpayers submit information to tax practitioners, who prepare the returns and submit them to the tax authorities.

read more →

why compliance still matters. but it’s not enough.

resistance is futile… and silly because it’s necessary for the profession.

the smartest route to advisory:
join the survey. get the roadmap

by donny shimamoto, cpa, citp, cgma
the center for accounting transformation

in the world of accounting, compliance work is often seen as the unglamorous side of the profession. but what if i told you that compliance is the heart and soul of accounting, the unsung hero that makes advisory work possible?

more donny shimamoto:  how trusted advisors transform businesses | the future of accounting: a vision of trust, clarity, and hope | donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

let’s explore the importance of compliance work in the accounting profession and why it’s time for us to stop minimizing its significance. read more →

how hacker-proof is your firm?

thieves always build a better mousetrap, so stay vigilant.

by donny shimamoto, cpa, citp, cgma
on cybersecurity for accountants

in 2018, fraudsters posed as tax authorities and state accounting and tax professional associations. these were simple phishing attacks trying to get tax practitioners’ email usernames and passwords, allowing fraudsters to obtain client contact information and perform email-based password resets for other systems.

more:  future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

the irs reported seeing threats specifically targeting preparers in illinois, iowa, new jersey and north carolina. additionally, the irs received reports tied to a canadian accounting association.[i]

read more →

it takes a village to stop cybercrime

we’re all in this together.//m.g005e.com/2021/11/09/russian-solarwinds-hackers-at-it-again/

by donny shimamoto, cpa, citp, cgma
on cybersecurity for accountants
center for accounting transformation

i’ve been warning accountants about the treasure trove of taxpayer information they are entrusted with since 2014. that was the first year i spoke at an aicpa conference about it risk management and the need to self-assess information security risks. every year since then, via numerous conference sessions and webinars, i’ve taught both non-techie accountants and it professionals about the cybersecurity jargon, key threats, how to understand the risks, and how various types of administrative and technical controls help mitigate those risks.

more:  donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

as quickly as cybersecurity practices mature, new threats, threat delivery vectors and other schemes arise. what many people don’t realize is that identity theft is a lucrative business. whether taxpayer identification (e.g., social security numbers), bank account information, credit card information or healthcare information—these records have value on the dark web. fraudsters will pay handsomely for this type of information.

read more →

how to transform your team into trusted advisors

woman ladder binoculars city view outlook vision success climb adobestock_57204649.jpegare you looking in the wrong place?

the smartest route to advisory:
join the survey. get the roadmap

or scan this:

launch survey

by donny shimamoto, cpa, citp, cgma
the center for accounting transformation

there’s a secret lurking in the depths of the public accounting world. a hidden treasure, a powerful weapon that can catapult your firm to new heights of success. it’s called “advisory services.” and yet, despite its immense potential, many firms are not yet experiencing its transformative power. why? because they’re looking in the wrong place.

more donny shimamoto:  how trusted advisors transform businesses | the future of accounting: a vision of trust, clarity, and hope | donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

the truth is, advisory services are not just about technical skills and compliance knowledge. it’s a whole different game. and if you want to play and win, you need to invest in your team’s development and give them the tools they need to become trusted advisors.
read more →