-
The Outdated WISP Problem Hiding in Many CPA Firms
A Written Information Security Plan may satisfy the question “do we have one?” But if it no longer reflects your people, systems, vendors and workflows, it may not help when…
-
AI Governance for CPA Firms: Closing the Gaps Your Current Policies Don’t Cover
Most CPA firms already have policies for data security, acceptable use, vendor management, incident response and client confidentiality. Many also have a Written Information Security Plan, or WISP, that outlines…
-
SOC 2 Type II vs. ISO 27001 for MSPs: What Actually Matters Across the CIA Triad
If your CPA firm is evaluating a managed service provider for IT-as-a-Service, security is usually the headline. But it is not the full story. For firms handling client financial data,…
-
Advisory: Apache Log4j Vulnerability Log4j zero-day vulnerability AKA Log4Shell (CVE-2021-44228)
What is the Log4j vulnerability? On December 9, a remote code execution (RCE) vulnerability was identified in Java logging library Apache Log4j, which is a ubiquitous software component used throughout…




