← All Compliance Insights

CPA & Accounting

Too Small to Need a Security Program? What Real Cases Show Small Firms

“We're a small firm.”

For CPA and accounting practices, that can sound like a reasonable explanation for why the firm does not have a formal security program. There may be no internal IT department. No security officer. No compliance staff. No full-time cybersecurity specialist.

But the firm's size does not make the information it holds less valuable. A ten-person accounting practice may still maintain Social Security numbers, tax returns, financial statements, payroll information, bank-account information, identity documents and login credentials for hundreds or thousands of people. Real incidents involving small firms demonstrate why headcount is a poor measure of cybersecurity exposure.

Brazee & Huban: One Office, About a Dozen Employees

Brazee & Huban is especially relevant to small CPA firms because it was a single-location practice with roughly a dozen employees. The Massachusetts firm provided services including tax preparation, bookkeeping, payroll and wealth management and had just over ten employees.

According to its breach notification, the firm discovered that an unauthorized actor had accessed its systems around November 17, 2023. Client notification began on February 20, 2024—roughly three months later.

The incident affected more than 1,000 individuals, including 746 Massachusetts residents.

No published regulatory penalty is identified in the available breach record; the significance of the case is the size of the firm and the scale of the exposure.

ONE LOCATION.
ROUGHLY A DOZEN EMPLOYEES.
MORE THAN 1,000 PEOPLE AFFECTED.

That is much closer to the operating profile of many independent CPA firms than the large companies that dominate cybersecurity headlines.

Small Firm Does Not Mean Small Data Exposure

A firm's cybersecurity exposure is driven less by its number of employees than by factors such as:

  • how many clients it serves;
  • what information it maintains about those clients;
  • how long that information is retained;
  • how many tax years are stored electronically;
  • whether payroll or bookkeeping services are provided;
  • whether employees work remotely;
  • how the firm exchanges documents with clients;
  • which cloud platforms and third-party vendors have access to information; and
  • how administrator and employee accounts are protected.

A twelve-person CPA firm can therefore have a much larger data footprint than its headcount suggests. One employee account may provide access to information belonging to hundreds of clients. One administrative account may reach multiple systems. One compromised mailbox may contain years of tax documents and client communications.

The attacker does not need the firm to have 500 employees.

The attacker needs one useful path to valuable information.

Wojeski: Still a Small Firm, but Large Enough for Enforcement

Wojeski & Company CPAs provides another perspective. The New York accounting firm had roughly 35 to 40 employees and provided audit, tax and consulting services. After a ransomware incident in 2023 and a separate unauthorized-access event in 2024, personal information belonging to more than 4,700 people was exposed.

The New York Attorney General ultimately reached a settlement requiring $60,000 in penalties plus a substantial security-program overhaul. The required measures included a comprehensive information-security program, encryption, stronger access controls, vulnerability management, an incident-response plan and employee cybersecurity training.

A firm with fewer than 50 employees was not too small for an Attorney General investigation.

Once the settlement was reached, the firm was required to implement a formal security program.

What Happens When a CPA Firm Doesn't Maintain a Real Security Program?

Regulators Do Not Reserve Written Security Programs for Large Companies

TradeSource, Inc. was not an accounting firm, but its Massachusetts enforcement case illustrates the same principle. Following a phishing-related breach affecting more than 3,000 Massachusetts residents, the Attorney General found that the company did not have a Written Information Security Plan in place before or during the incident. The resulting settlement included $230,000 in penalties, a requirement to create and maintain a WISP, an independent third-party assessment and continuing employee security training.

The lesson is not that every small company without a perfect security program will face a six-figure penalty. The lesson is that small organizational size does not make formal security obligations disappear.

The Small-Firm Problem Is Usually Resources, Not Relevance

There is a legitimate challenge here. A 12-person CPA firm cannot reasonably build the same internal security organization as a national accounting firm. It probably should not try.

The smaller firm may not need:

  • a full-time CISO;
  • an internal security operations center;
  • a dedicated compliance department;
  • several cybersecurity engineers; or
  • an enterprise-sized governance bureaucracy.

But that does not mean it needs no program. It means the program has to be designed differently.

A small firm's security program can still identify:

  • who is responsible for overseeing security;
  • where sensitive information resides;
  • what the firm's important risks are;
  • what safeguards are appropriate;
  • how multifactor authentication and privileged access are managed;
  • how endpoints and networks are protected;
  • how backups are maintained and tested;
  • how employees are trained;
  • how vendors are evaluated;
  • what happens when an incident occurs;
  • how breach-notification responsibilities are escalated; and
  • how the firm documents that these activities are actually occurring.

None of those requires a Fortune 500 security department. They require ownership, planning, appropriate technology and a repeatable process.

A WISP Should Be Proportional—Not Optional

This is one reason a generic downloaded WISP is a poor solution for a small CPA firm. A 10-person firm and a 500-person organization should not have identical security programs.

Their systems, staffing, risks and available resources are different. But a useful Written Information Security Plan can scale those requirements to the actual organization.

What Does a CPA Firm's WISP Actually Need to Include?

The goal is not to make the small firm look like a large enterprise. The goal is to make the firm's security practices deliberate rather than accidental.

Small Firms May Actually Have Less Margin for Error

A larger organization may have internal counsel, a communications department, cybersecurity personnel, insurance specialists and multiple technical teams available when an incident occurs. A small CPA firm may have the managing partner, an office administrator and an outside IT provider.

If ransomware appears Monday morning, those same people may suddenly be expected to coordinate:

  • technical containment;
  • forensic investigation;
  • legal counsel;
  • cyber-insurance notification;
  • client communications;
  • breach-notification analysis;
  • payroll and business continuity; and
  • restoration of normal operations.

That is exactly why planning beforehand matters.

A small organization may have fewer resources available during an incident, not fewer responsibilities.

Start With a Program That Fits the Firm You Actually Have

Small CPA firms should not copy enterprise security programs simply to check boxes. They should identify what sensitive information they hold, understand their actual environment, prioritize the risks that matter and implement safeguards appropriate to the business. The result should be a security program that the firm can realistically maintain.

Not a binder that nobody reads.

Not a policy template describing controls the firm does not actually use.

And not a plan to figure everything out after an incident occurs.

How GO InfoTek Can Help

GO InfoTek works specifically with small and midsize CPA and accounting firms that need a structured security and compliance program without building an internal cybersecurity department. That can include:

  • security risk assessment;
  • Written Information Security Plan development and maintenance;
  • implementation and review of technical safeguards;
  • FTC Safeguards Rule support;
  • IRS Publication 4557 security planning;
  • employee security-awareness training;
  • vulnerability management;
  • incident-response and breach-notification planning;
  • vendor-security oversight;
  • policy and documentation development; and
  • ongoing vCISO support.

The objective is not to turn a 12-person accounting firm into a large enterprise. It is to build a security program appropriate for a 12-person accounting firm—and make sure it actually works.

Because small firm and small risk are not the same thing.

This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.

Sources and Further Reading

A practical next step

Discuss Your Environment with GO InfoTek

Start with the systems, safeguards, documentation and questions your organization has today.

Schedule a Conversation