
5 Ways AI Can Support Disaster Preparedness Planning at Your Firm
Most accounting firms know they should have a disaster recovery plan. But few have one that is current, tested and complete. That is not always
October is Cybersecurity Awareness Month, and it is a good time to take stock of what your firm actually knows versus what it thinks it knows when it comes to cybersecurity. Not all of the advice out there is accurate. Some has circulated for so long that it has taken on a life of its own and gets repeated until it sounds like fact, even when it is outdated or wrong.
When bad advice goes unchallenged, it creates blind spots. And blind spots are exactly what cybercriminals look for. Accounting firms are increasingly in their crosshairs because client financial data, tax filings and e-transfer access make them a uniquely valuable target.
The good news is that these gaps are simple to close once you know where they are. Here are six myths we hear from firm leadership regularly, along with the truth behind each one.
There is no such thing as a firm too small for an opportunistic cybercriminal. It does not matter if you are a sole practitioner or a firm with a dozen staff. If you have exposed accounts or vulnerable systems, bad actors will take advantage of it. An accounting firm offers something particularly valuable: client SINs, banking details and direct access to filings and refunds.
Fact: Hackers choose targets based on opportunity, not size.
It is 4:17 on a Friday afternoon. A bookkeeper receives an email that appears to be from a partner at the firm: “Can you update the banking information on this client’s file before you leave?” The name is right, the tone sounds familiar, and with everyone trying to wrap up the week, the easiest thing to do is simply respond. There is only one problem: the partner never sent it.
The days of obvious phishing emails full of typos are gone. Today’s messages are polished, personalized and often built specifically around a real client or a real filing deadline. Instead of depending on individual detection alone, your team needs to think about sender behavior. Ask whether the supposed sender would:
If anything seems off, verify by phone using a number you already have on file, especially during tax season, when your team is moving fast enough that a convincing request is easy to wave through.
Fact: A convincing email can still be a scam, and the busier your season, the more likely someone is to miss it.
Multi-factor authentication is important, but it is not invulnerable. Hackers use MFA fatigue to their advantage, counting on staff approving requests out of habit or annoyance. “Prompt bombing” floods a phone with requests in hopes someone approves access just to make it stop, and that access can reach your accounting software, client portals or e-filing systems just as easily as email.
Fact: MFA should be part of a broader security strategy, not the whole strategy.
Ask yourself: if your firm was hit with a ransomware attack in the middle of filing season, could you restore client files? How long would it take, and what happens to returns with a deadline in the meantime?
We have covered this one in depth before, because it is a myth that costs firms more than almost any other: an untested backup is not something you can rely on during an incident, and tax season is not the time to find out yours does not work.
Fact: Having backups is not the same as being able to recover.
Your IT provider can put strong protections in place, but they cannot stop every bad click, rushed reply or split-second call. Cybersecurity decisions happen every day, across every role at the firm, from the front desk to the partners’ offices. It takes only one bad click on a fraudulent banking-update request to open the door to a serious loss.
Telling staff to simply “be careful” is not a plan. Every team member should know who to contact, how to verify a request and how to report something that looks wrong, especially before client funds move. When leadership normalizes verification instead of treating it as a delay, staff speak up before a situation becomes a crisis.
Fact: Training your team to pause and verify strengthens your firm’s cybersecurity more than any single tool.
It is Tuesday morning during filing season. Several staff members suddenly cannot access client files. Many firms discover in that moment that nobody has answered the basic questions:
Do not rely on memory in the moment. Have an incident response plan, and make sure it accounts for the deadlines your firm cannot miss.
Fact: Your recovery plan should not debut during an incident.
Cybersecurity Awareness Month is about making sure the assumptions guiding your firm’s decisions are correct. Myths are comfortable. They let you feel covered without having to dig deeper. But cybersecurity gaps rarely come from a missing product or procedure. They come from believing you have already got it handled when you do not.
If any of these myths sound familiar, it is time to take a closer look at where your firm actually stands.
Schedule a Free Discovery Call and we will help you separate what is protecting your firm from what is only giving you peace of mind. Or call us at 1-833-231-6182.

Most accounting firms know they should have a disaster recovery plan. But few have one that is current, tested and complete. That is not always

If you are like most practice owners, you are always looking for ways to save time. New software, AI tools and productivity systems all promise

There is something impressive about how well families execute the back-to-school season. Backpacks are ready, bedtimes are adjusted and the route to school is planned