Free Site Registration


Data Breaches a Worry at CPA Firms Too

Print
Email
Reprints
New York (August 19, 2009)

The news this week about the massive hacking and identity theft of credit card data should raise concerns at CPA firms about how good a job they’re doing at protecting client information.

A Miami computer hacker named Albert Gonzalez has been indicted for collaborating with two Russian accomplices to steal the information on more than 130 million credit and debit card accounts. Gonzalez apparently had been detained back in 2003 for his previous activities, but the feds released him after he worked as an informant to help them build a case against a group of fellow hackers. Unbeknownst to them, he simply relocated to Florida and went back to his old ways, enabling him to throw a $75,000 party to celebrate his own birthday.

While Gonzalez was mainly targeting retailers like TJ Maxx, 7-Eleven, and Hannaford, and payment processors like Heartland Payment Systems, accounting firms should still sit up and take notice. Companies can set up all kinds of elaborate security systems and still fall prey to hackers. Accounting firms too have a fiduciary duty to safeguard the security of their clients’ data, and it’s all too easy for the information to fall into the wrong hands.

Advertisement

One danger has been the increasing trend toward Web-based access of accounting data. While the systems make it much more convenient for accountants to work remotely, they also expose the information to many more potential touch points than they had previously gone through, as well as more opportunities to access the data surreptitiously. The Wall Street Journal’s account of the Gonzalez case mentions the explosion in cases of wire fraud in recent years as wire transfers are increasingly conducted over the Internet.

The same can be said of accounting. The trend toward cloud-based computing, with its exploitation of whatever servers and resources happen to be available in the “cloud,” could eventually spell trouble. Of course, data is still hackable even from a stand-alone computer not connected to a network. Just insert a writeable CD or a USB drive. But by adding Internet access to the accounting system, that system becomes that much more vulnerable. Simple password protection is not going to deter an experienced hacker.

The Federal Trade Commission has thrice delayed the implementation of a so-called “Red Flags Rule” that requires creditors and financial institutions to adopt written identity theft prevention programs, giving them more time to put those safeguards in place. So far, it hasn’t been easy, especially for small businesses that provide credit to customers, and the new deadline is November 1 of this year. The AICPA has asked the FTC to exempt CPAs from certain provisions of the Red Flags Rule.

“We are concerned with the potentially broad application of the Red Flags Rule to the accounting profession, and do not believe that there is any reasonably foreseeable risk of identity theft when CPA clients are billed for services rendered,” AICPA president and CEO Barry Melancon wrote to the FTC earlier this month.

He argued that the burdens associated with the rule’s requirements outweigh the risks. The AICPA is asking state CPA societies to also write to the FTC and ask for the exemption.

Even if the exemption is granted, CPA firms will still need to do a better job of safeguarding their clients’ personal information. The risks are all too real, and for many people all too financially damaging.

0 Comments

Be the first to comment on this post using the section below.

Add Your Comments...

Already Registered?

If you have already registered to Accounting Today, please use the form below to login. When completed you will immeditely be directed to post a comment.

 

Advertisement
Advertisement

What's New at Grant Thornton

May 14, 2012

CEO Stephen Chipman talks about his firm's new brand focus on growth, and its recent M&A activity.

Advertisement

SLIDE SHOW

Top 10 Payroll Mistakes Companies Make

May 14, 2012

Keeping your clients from running afoul of IRS rules around payroll taxes will help them avoid stiff penalties.

10 Years of the Top 100 Firms

May 6, 2012

Tracking trends at the biggest firms in the U.S.

Best Accounting Firm Taglines

April 27, 2012

Our favorite slogans from around the profession.

Favorite Busy Season Activities

April 10, 2012

LinkedIn Accounting members share the best methods to bust stress and boost morale.

The Best Places to Be an Accountant 2012

March 27, 2012

From our 2012 Regional Leaders list, we rank the best parts of the country to operate an accounting firm.

More Wacky Tax Deductions

March 26, 2012

LinkedIn members point out some weird tax deductions their clients have suggested.

7 Tax-Free Benefits for Employees

April 15, 2012

Employee rewards Uncle Sam can't touch.

Advertisement
Advertisement
Advertisement