<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.cpate.ch/index.php?action=history&amp;feed=atom&amp;title=ATL271</id>
	<title>ATL271 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.cpate.ch/index.php?action=history&amp;feed=atom&amp;title=ATL271"/>
	<link rel="alternate" type="text/html" href="https://wiki.cpate.ch/index.php?title=ATL271&amp;action=history"/>
	<updated>2026-09-07T07:43:22Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wiki.cpate.ch/index.php?title=ATL271&amp;diff=313&amp;oldid=prev</id>
		<title>Bftcpa606 at 23:12, 18 August 2026</title>
		<link rel="alternate" type="text/html" href="https://wiki.cpate.ch/index.php?title=ATL271&amp;diff=313&amp;oldid=prev"/>
		<updated>2026-08-18T23:12:49Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 23:12, 18 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[File:ATL271.jpg|thumb|ATL271: Why Your WISP Is Essential in 2026]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= ATL271 - Why Your WISP Is Essential in 2026 =&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= ATL271 - Why Your WISP Is Essential in 2026 =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-311:rev-313:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Bftcpa606</name></author>
	</entry>
	<entry>
		<id>https://wiki.cpate.ch/index.php?title=ATL271&amp;diff=311&amp;oldid=prev</id>
		<title>Bftcpa606: Created page with &quot;= ATL271 - Why Your WISP Is Essential in 2026 =  &#039;&#039;&#039;Accounting Technology Lab&#039;&#039;&#039;&lt;br /&gt; &#039;&#039;&#039;Hosts:&#039;&#039;&#039; Randy Johnston and Brian F. Tankersley, CPA.CITP, CGMA&lt;br /&gt; &#039;&#039;&#039;Presented by:&#039;&#039;&#039; CPA Practice Advisor&lt;br /&gt; &#039;&#039;&#039;Episode length:&#039;&#039;&#039; Approximately 25 minutes  == Episode Summary ==  In ATL271, “Why Your WISP Is Essential in 2026,” Randy Johnston and Brian Tankersley explain why a written information security plan is no longer a compliance document that can sit on a shelf....&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.cpate.ch/index.php?title=ATL271&amp;diff=311&amp;oldid=prev"/>
		<updated>2026-08-18T23:11:10Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;= ATL271 - Why Your WISP Is Essential in 2026 =  &amp;#039;&amp;#039;&amp;#039;Accounting Technology Lab&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt; &amp;#039;&amp;#039;&amp;#039;Hosts:&amp;#039;&amp;#039;&amp;#039; Randy Johnston and Brian F. Tankersley, CPA.CITP, CGMA&amp;lt;br /&amp;gt; &amp;#039;&amp;#039;&amp;#039;Presented by:&amp;#039;&amp;#039;&amp;#039; CPA Practice Advisor&amp;lt;br /&amp;gt; &amp;#039;&amp;#039;&amp;#039;Episode length:&amp;#039;&amp;#039;&amp;#039; Approximately 25 minutes  == Episode Summary ==  In ATL271, “Why Your WISP Is Essential in 2026,” Randy Johnston and Brian Tankersley explain why a written information security plan is no longer a compliance document that can sit on a shelf....&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= ATL271 - Why Your WISP Is Essential in 2026 =&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Accounting Technology Lab&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hosts:&amp;#039;&amp;#039;&amp;#039; Randy Johnston and Brian F. Tankersley, CPA.CITP, CGMA&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Presented by:&amp;#039;&amp;#039;&amp;#039; CPA Practice Advisor&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Episode length:&amp;#039;&amp;#039;&amp;#039; Approximately 25 minutes&lt;br /&gt;
&lt;br /&gt;
== Episode Summary ==&lt;br /&gt;
&lt;br /&gt;
In ATL271, “Why Your WISP Is Essential in 2026,” Randy Johnston and Brian Tankersley explain why a written information security plan is no longer a compliance document that can sit on a shelf. Accounting firms hold concentrated stores of tax, financial, identity, and sometimes health information, making them attractive targets for phishing, credential theft, ransomware, fraudulent wire instructions, and AI-enhanced attacks. The hosts walk through the overlapping expectations of the IRS, FTC Safeguards Rule, and HIPAA, including written policies, multi-factor authentication, encryption, logging, incident response, training, governance, vendor oversight, and regular risk assessment. They emphasize that penalties can be severe, but the larger business risk may be client loss, reputational damage, litigation, and disruption during tax season. The episode also highlights practical governance: assign accountability, review the WISP regularly, connect security spending to risk, and report results to leadership. Randy and Brian close with five high-impact controls—MFA, full-disk encryption, tested backups, a written incident response plan, and vendor security questionnaires—plus a recurring calendar for log reviews, backup restores, phishing simulations, vulnerability scans, training, patching, and annual WISP updates. Their message: security is an operating discipline, not paperwork. For firms of every size, preparation now is cheaper than recovery.&lt;br /&gt;
&lt;br /&gt;
== Key Takeaways ==&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;A WISP should be an operating system for security—not shelfware.&amp;#039;&amp;#039;&amp;#039; It needs ownership, periodic review, documented changes, and executive oversight.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Accounting firms are unusually attractive targets&amp;#039;&amp;#039;&amp;#039; because they aggregate tax, financial, identity, payroll, and other confidential information.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Credential theft and phishing remain central risks,&amp;#039;&amp;#039;&amp;#039; while AI is making fraudulent messages and attacks more convincing.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Vendor management belongs inside the security program.&amp;#039;&amp;#039;&amp;#039; Cloud applications, hosting companies, MSPs, AI services, and other third parties expand the firm&amp;#039;s attack surface.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Incident response must be planned before the incident.&amp;#039;&amp;#039;&amp;#039; Firms should understand regulatory notification obligations, internal responsibilities, legal resources, and PR response.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Security has a recurring calendar.&amp;#039;&amp;#039;&amp;#039; Log reviews, backup restores, phishing tests, vulnerability scanning, access reviews, training, patching, and WISP updates need assigned frequencies and owners.&lt;br /&gt;
&lt;br /&gt;
== Catchy Quotes ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Approx. Time&lt;br /&gt;
! Speaker&lt;br /&gt;
! Quote&lt;br /&gt;
|-&lt;br /&gt;
| 02:04&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “The firms get hit because you and I are the Fort Knox of confidential data.”&lt;br /&gt;
|-&lt;br /&gt;
| 03:33&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “The bad guys are getting better faster than the good guys are getting better.”&lt;br /&gt;
|-&lt;br /&gt;
| 07:40&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “Anything that touches client data is a death sentence for a hard drive in my office.”&lt;br /&gt;
|-&lt;br /&gt;
| 12:10&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “If you don&amp;#039;t have an adequate WISP, you&amp;#039;re in violation of the FTC safeguards rule.”&lt;br /&gt;
|-&lt;br /&gt;
| 18:20&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “You&amp;#039;ve got risk on any provider.”&lt;br /&gt;
|-&lt;br /&gt;
| 18:42&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “As soon as you know something&amp;#039;s happened, the clock is ticking.”&lt;br /&gt;
|-&lt;br /&gt;
| 23:11&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “Multi-factor authentication, full disk encryption, tested backup strategies, written incident response plans, vendor security questionnaires.”&lt;br /&gt;
|-&lt;br /&gt;
| 24:55&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “Make sure that you&amp;#039;ve got your WISP … pulled out, dusted off, and updated for this year&amp;#039;s regulations.”&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;Note: Timestamps are approximate where the quote occurs inside a longer timestamped speaker segment in the transcript.&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== Social Media Posts ==&lt;br /&gt;
&lt;br /&gt;
# Your WISP isn&amp;#039;t supposed to be the PDF nobody has opened since last year. In ATL271, Randy Johnston and Brian Tankersley explain why cybersecurity governance has become an operating requirement for accounting firms. #WISP #Cybersecurity #AccountingTechnology&lt;br /&gt;
# Accounting firms may not look like Fort Knox—but they often hold Fort Knox quantities of confidential data. Tax records. Payroll. Bank information. Identity data. That&amp;#039;s exactly why attackers care. ATL271 tackles the risk. #CPA #Cybersecurity&lt;br /&gt;
# Phishing emails aren&amp;#039;t getting worse. They&amp;#039;re getting &amp;#039;&amp;#039;&amp;#039;better&amp;#039;&amp;#039;&amp;#039;—and AI is helping the bad guys improve faster. ATL271 looks at what CPA firms should be doing about it now. #AI #Phishing #InfoSec&lt;br /&gt;
# A written information security plan isn&amp;#039;t just a compliance exercise. It&amp;#039;s the playbook your firm needs when somebody clicks the wrong link at 4:45 Friday afternoon. Listen to ATL271. #WISP #IncidentResponse&lt;br /&gt;
# MFA. Encryption. Tested backups. Incident response. Vendor questionnaires. Five controls that can materially improve an accounting firm&amp;#039;s security posture—and they&amp;#039;re all discussed in ATL271. #Cybersecurity #CPAfirm&lt;br /&gt;
# Your firm&amp;#039;s security perimeter doesn&amp;#039;t stop at the office door. It includes every SaaS vendor, MSP, cloud provider, AI platform, remote employee, and third party touching client information. ATL271 digs into vendor risk. #VendorRisk #AccountingTech&lt;br /&gt;
# Buying a WISP template isn&amp;#039;t the same thing as managing information security. Randy Johnston and Brian Tankersley explain why governance, accountability, testing, and periodic updates matter in ATL271. #Governance #WISP&lt;br /&gt;
# Who owns cybersecurity at your firm? Who approves changes? Who reviews the logs? Who reports problems to leadership? If the answer is “I&amp;#039;m not sure,” ATL271 belongs on your playlist. #CyberGovernance #CPA&lt;br /&gt;
# A backup isn&amp;#039;t really a backup until you&amp;#039;ve restored it. ATL271 recommends making backup restoration testing part of your recurring security calendar. That&amp;#039;s boring—right up until the day it saves the firm. #Backup #Ransomware&lt;br /&gt;
# Cybersecurity isn&amp;#039;t an annual checkbox. Access logs, terminated users, phishing tests, vulnerability scans, MFA coverage, patching, training, and backups all operate on different schedules. ATL271 explains the cadence. #InfoSec&lt;br /&gt;
# The uncomfortable truth about a breach isn&amp;#039;t just the remediation bill. It&amp;#039;s clients asking, “Why should I still trust you?” ATL271 examines the compliance &amp;#039;&amp;#039;&amp;#039;and reputational&amp;#039;&amp;#039;&amp;#039; stakes of information security. #RiskManagement #CPAfirm&lt;br /&gt;
# What happens after an incident can be every bit as important as what happened before it. Legal counsel, regulatory notification, communications, documentation, and PR belong in the response plan. ATL271 explains why. #IncidentResponse&lt;br /&gt;
# The shiny new accounting app may solve a workflow problem—and create a vendor-risk problem. ATL271 makes the case for asking security questions before sensitive client data goes into somebody else&amp;#039;s system. #AccountingTech #VendorManagement&lt;br /&gt;
# Your terminated employee shouldn&amp;#039;t still be able to log in six months later. ATL271 recommends regularly confirming that departed users actually lost access. Simple control. Serious consequences if you skip it. #AccessControl #Cybersecurity&lt;br /&gt;
# Security awareness training on Day One isn&amp;#039;t bureaucracy. It&amp;#039;s part of onboarding someone who is about to receive access to some of your clients&amp;#039; most sensitive information. ATL271 explains the governance behind the practice. #SecurityAwareness&lt;br /&gt;
# Accounting firms have spent years adopting cloud systems. The next maturity step is managing the &amp;#039;&amp;#039;&amp;#039;governance&amp;#039;&amp;#039;&amp;#039; around those systems: access, logging, vendors, policies, responsibilities, and incident response. ATL271 tackles the issue. #CloudSecurity #CPA&lt;br /&gt;
# “We&amp;#039;ve never had a breach” is not a cybersecurity strategy. Neither is “our IT guy handles that.” ATL271 explains why firm leadership has a role in WISP governance and security oversight. #CyberRisk #Leadership&lt;br /&gt;
# AI is changing both sides of cybersecurity. Firms can use better tools—but attackers also get better tools. ATL271 looks at why yesterday&amp;#039;s WISP may not adequately address today&amp;#039;s threat environment. #AIsecurity #WISP&lt;br /&gt;
# Before you recycle an old laptop, copier, scanner, drive, or network device, ask a better question: &amp;#039;&amp;#039;&amp;#039;What client data touched this device?&amp;#039;&amp;#039;&amp;#039; ATL271 discusses secure disposal as part of the security lifecycle. #DataSecurity #Privacy&lt;br /&gt;
# Pull out the WISP. Dust it off. Read it. Test it. Assign owners. Update it. Then make sure what the document says is what the firm actually does. That&amp;#039;s the central message of ATL271: &amp;#039;&amp;#039;Why Your WISP Is Essential in 2026.&amp;#039;&amp;#039; #AccountingTechnologyLab #Cybersecurity&lt;br /&gt;
&lt;br /&gt;
== Products, Services, Companies, and Organizations Mentioned ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
! Company / Organization&lt;br /&gt;
! Product or Service Mentioned&lt;br /&gt;
! X&lt;br /&gt;
! Facebook&lt;br /&gt;
! LinkedIn&lt;br /&gt;
! Instagram&lt;br /&gt;
|-&lt;br /&gt;
| CPA Practice Advisor&lt;br /&gt;
| Accounting Technology Lab / media&lt;br /&gt;
| @cpapracadvisor&lt;br /&gt;
| CPA Practice Advisor&lt;br /&gt;
| CPA Practice Advisor&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|-&lt;br /&gt;
| YHB {{!}} CPAs &amp;amp; Consultants&lt;br /&gt;
| Firm security/vendor due-diligence example&lt;br /&gt;
| Not independently verified&lt;br /&gt;
| YHB {{!}} CPAs &amp;amp; Consultants&lt;br /&gt;
| YHB {{!}} CPAs &amp;amp; Consultants&lt;br /&gt;
| YHB {{!}} CPAs &amp;amp; Consultants&lt;br /&gt;
|-&lt;br /&gt;
| Mandiant / Google Cloud&lt;br /&gt;
| Cybersecurity / incident response&lt;br /&gt;
| @Mandiant&lt;br /&gt;
| Mandiant&lt;br /&gt;
| Mandiant (part of Google Cloud)&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|-&lt;br /&gt;
| Data Center Inc. (DCI)&lt;br /&gt;
| Bank core processing / technology&lt;br /&gt;
| Not independently verified&lt;br /&gt;
| Not independently verified&lt;br /&gt;
| DCI / datacenterinc&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|-&lt;br /&gt;
| Jack Henry&lt;br /&gt;
| Bank technology and processing&lt;br /&gt;
| @JH_Fintech&lt;br /&gt;
| JackHenryAssociates&lt;br /&gt;
| Jack Henry&lt;br /&gt;
| @jackhenry_fintech&lt;br /&gt;
|-&lt;br /&gt;
| Ubiquiti&lt;br /&gt;
| UniFi / Dream Machine networking and VPN hardware&lt;br /&gt;
| @Ubiquiti&lt;br /&gt;
| UIeverywhere&lt;br /&gt;
| Ubiquiti Inc.&lt;br /&gt;
| @ubiquiti*&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft&lt;br /&gt;
| BitLocker, Microsoft VPN, Copilot&lt;br /&gt;
| @Microsoft&lt;br /&gt;
| Microsoft&lt;br /&gt;
| Microsoft&lt;br /&gt;
| @microsoft*&lt;br /&gt;
|-&lt;br /&gt;
| Apple&lt;br /&gt;
| Device/full-disk encryption&lt;br /&gt;
| @Apple&lt;br /&gt;
| Apple&lt;br /&gt;
| Apple&lt;br /&gt;
| @apple*&lt;br /&gt;
|-&lt;br /&gt;
| Wolters Kluwer&lt;br /&gt;
| Professional tax/accounting technology provider&lt;br /&gt;
| Not listed in current corporate directory&lt;br /&gt;
| Wolters Kluwer&lt;br /&gt;
| Wolters Kluwer&lt;br /&gt;
| Wolters Kluwer&lt;br /&gt;
|-&lt;br /&gt;
| Thomson Reuters&lt;br /&gt;
| Professional tax/accounting technology provider&lt;br /&gt;
| Thomson Reuters&lt;br /&gt;
| thomsonreuters&lt;br /&gt;
| Thomson Reuters&lt;br /&gt;
| thomsonreuters&lt;br /&gt;
|-&lt;br /&gt;
| AICPA / AICPA &amp;amp; CIMA&lt;br /&gt;
| Professional association / §7216 discussions&lt;br /&gt;
| @AICPA&lt;br /&gt;
| AICPA&lt;br /&gt;
| AICPA&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;small&amp;gt;*Apparent account shown for identification; it was not verified to the same first-party standard during this research pass.&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Regulatory and Technical References Mentioned ==&lt;br /&gt;
&lt;br /&gt;
* Written Information Security Plan (WISP)&lt;br /&gt;
* IRS&lt;br /&gt;
* FTC&lt;br /&gt;
* HHS&lt;br /&gt;
* FTC Safeguards Rule&lt;br /&gt;
* Gramm-Leach-Bliley Act (GLBA)&lt;br /&gt;
* HIPAA&lt;br /&gt;
* IRC §7216&lt;br /&gt;
* IRS Publication 4557&lt;br /&gt;
* IRS Publication 5708&lt;br /&gt;
* IRS “Security Six”&lt;br /&gt;
* Multi-factor authentication (MFA)&lt;br /&gt;
* Encryption&lt;br /&gt;
* Firewalls&lt;br /&gt;
* VPNs&lt;br /&gt;
* Password managers&lt;br /&gt;
* Backup and restoration testing&lt;br /&gt;
* Vulnerability scanning&lt;br /&gt;
* Phishing simulation&lt;br /&gt;
* Incident response plans&lt;br /&gt;
* Business associate agreements (BAAs)&lt;br /&gt;
* Vendor security questionnaires&lt;br /&gt;
* Access logging and monitoring&lt;br /&gt;
* Secure equipment disposal&lt;br /&gt;
* Patch management&lt;br /&gt;
* Security awareness training&lt;br /&gt;
&lt;br /&gt;
== Suggested Hashtags ==&lt;br /&gt;
&lt;br /&gt;
#AccountingTechnologyLab #ATL271 #WISP #Cybersecurity #CPA #AccountingTechnology #DataSecurity #InfoSec #RiskManagement #VendorRisk #MFA #IncidentResponse #Ransomware #CyberGovernance&lt;/div&gt;</summary>
		<author><name>Bftcpa606</name></author>
	</entry>
</feed>