<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.cpate.ch/index.php?action=history&amp;feed=atom&amp;title=ATL272</id>
	<title>ATL272 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.cpate.ch/index.php?action=history&amp;feed=atom&amp;title=ATL272"/>
	<link rel="alternate" type="text/html" href="https://wiki.cpate.ch/index.php?title=ATL272&amp;action=history"/>
	<updated>2026-09-07T07:43:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wiki.cpate.ch/index.php?title=ATL272&amp;diff=318&amp;oldid=prev</id>
		<title>Bftcpa606: Created page with &quot;= ATL272 - The Gathering Storm =  &#039;&#039;&#039;Episode:&#039;&#039;&#039; ATL272&lt;br&gt; &#039;&#039;&#039;Title:&#039;&#039;&#039; &#039;&#039;The Gathering Storm&#039;&#039;&lt;br&gt; &#039;&#039;&#039;Hosts:&#039;&#039;&#039; Randy Johnston and Brian F. Tankersley, CPA.CITP, CGMA&lt;br&gt; &#039;&#039;&#039;Podcast:&#039;&#039;&#039; Accounting Technology Lab, brought to you by CPA Practice Advisor  == Promotional Hook ==  AI is making cyberattacks faster, cheaper, and more scalable at exactly the time many accounting firms are carrying too much technical debt. ATL272 examines what firms should do before that combin...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.cpate.ch/index.php?title=ATL272&amp;diff=318&amp;oldid=prev"/>
		<updated>2026-08-21T16:49:42Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;= ATL272 - The Gathering Storm =  &amp;#039;&amp;#039;&amp;#039;Episode:&amp;#039;&amp;#039;&amp;#039; ATL272&amp;lt;br&amp;gt; &amp;#039;&amp;#039;&amp;#039;Title:&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;The Gathering Storm&amp;#039;&amp;#039;&amp;lt;br&amp;gt; &amp;#039;&amp;#039;&amp;#039;Hosts:&amp;#039;&amp;#039;&amp;#039; Randy Johnston and Brian F. Tankersley, CPA.CITP, CGMA&amp;lt;br&amp;gt; &amp;#039;&amp;#039;&amp;#039;Podcast:&amp;#039;&amp;#039;&amp;#039; Accounting Technology Lab, brought to you by CPA Practice Advisor  == Promotional Hook ==  AI is making cyberattacks faster, cheaper, and more scalable at exactly the time many accounting firms are carrying too much technical debt. ATL272 examines what firms should do before that combin...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= ATL272 - The Gathering Storm =&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Episode:&amp;#039;&amp;#039;&amp;#039; ATL272&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Title:&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;The Gathering Storm&amp;#039;&amp;#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hosts:&amp;#039;&amp;#039;&amp;#039; Randy Johnston and Brian F. Tankersley, CPA.CITP, CGMA&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Podcast:&amp;#039;&amp;#039;&amp;#039; Accounting Technology Lab, brought to you by CPA Practice Advisor&lt;br /&gt;
&lt;br /&gt;
== Promotional Hook ==&lt;br /&gt;
&lt;br /&gt;
AI is making cyberattacks faster, cheaper, and more scalable at exactly the time many accounting firms are carrying too much technical debt. ATL272 examines what firms should do before that combination turns into a very expensive problem.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;Quote timestamps come from the supplied SRT transcript and should correspond to the video if the audio and video edits are identical.&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== Episode Summary ==&lt;br /&gt;
&lt;br /&gt;
In ATL272, “The Gathering Storm,” Randy Johnston and Brian Tankersley argue that AI is changing cybersecurity faster than many accounting firms are changing their defenses. The issue is not simply smarter phishing or more malware. AI can automate reconnaissance, vulnerability discovery, exploit development, credential testing, and lateral movement at machine speed, while open-weight models and falling token costs may make those capabilities cheaper and more widely available. That matters especially for CPA firms because they hold an unusually valuable combination of tax data, identity information, client credentials, banking access, payment authority, and long-retained documents.&lt;br /&gt;
&lt;br /&gt;
The hosts also point to a dangerous mismatch: attackers are getting faster while many firms still rely on home-grade routers, unsupported operating systems, aging hardware, and definition-based security tools. Human error remains a major weakness, when convincing phishing messages land during stressful periods.&lt;br /&gt;
&lt;br /&gt;
Their recommendation is practical: harden systems now, eliminate unsupported technology, rehearse incident response, shorten detection-to-containment time, test backup restores, inventory every AI tool and agent in the firm, map where client data goes, inspect audit trails, and maintain control of firm data. The takeaway is caution without panic: this is not “Terminator and Skynet,” but waiting for certainty is not a cybersecurity strategy.&lt;br /&gt;
&lt;br /&gt;
== Pull Quotes ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Time&lt;br /&gt;
! Speaker&lt;br /&gt;
! Quote&lt;br /&gt;
|-&lt;br /&gt;
| 00:01:07&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “We want you to start being proactive now on protecting your businesses.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:02:32&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “I think that security is going through a similar transition right now.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:04:47&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “The time to first attack after a vulnerability is exposed is well below an hour now.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:07:02&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “We have pretty much the dream identity theft set of data.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:11:58&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “We are trying to have you think about how you stand up your defenses and how the attackers are trying to defeat your defenses or guardrails.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:16:59&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “You really need to step up your cybersecurity posture now, because we’re going into a very bad neighborhood with very scary things going on.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:17:35&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “The attackers’ tools are actually dropping in cost very rapidly.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:18:17&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “When these things are out, they’re out, and there’s no real coming back.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:20:17&lt;br /&gt;
| Brian Tankersley&lt;br /&gt;
| “We have cheaper attacks, we have more targets. We have the machine speed shrinking the response time.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:21:09&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “It’s not Terminator and Skynet at this point.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:22:27&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “Get the fundamentals right, including testing the backups.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:23:33&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “If you’re waiting for things to be certain, that ain’t going to happen.”&lt;br /&gt;
|-&lt;br /&gt;
| 00:25:12&lt;br /&gt;
| Randy Johnston&lt;br /&gt;
| “Pollyanna Randy is suggesting that you may well have some really ugly conditions in front of you, and I’m trying to keep you out of the storm.”&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Suggested Short-Video Clips ===&lt;br /&gt;
&lt;br /&gt;
The strongest clips for Shorts/Reels are &amp;#039;&amp;#039;&amp;#039;00:16:59&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;00:20:17&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;00:22:27&amp;#039;&amp;#039;&amp;#039;, and &amp;#039;&amp;#039;&amp;#039;00:25:12&amp;#039;&amp;#039;&amp;#039;. The final quote is particularly useful because it ties directly to the episode title.&lt;br /&gt;
&lt;br /&gt;
== Social Media Posts ==&lt;br /&gt;
&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;AI isn’t just making attackers smarter. It’s making them faster, cheaper, and able to work in parallel.&amp;#039;&amp;#039;&amp;#039; ATL272 asks the question every accounting firm should be asking: Is your cybersecurity posture keeping up? #AccountingTech #Cybersecurity #AI&lt;br /&gt;
# CPA firms don&amp;#039;t just hold data. They hold &amp;#039;&amp;#039;&amp;#039;identity information, tax records, bank details, credentials, payment authority, and access to client systems.&amp;#039;&amp;#039;&amp;#039; That makes accounting firms unusually attractive cyber targets. ATL272: &amp;#039;&amp;#039;The Gathering Storm.&amp;#039;&amp;#039;&lt;br /&gt;
# Your incident response plan isn&amp;#039;t a compliance document to put on a shelf. &amp;#039;&amp;#039;&amp;#039;It&amp;#039;s a fire drill. Rehearse it before you need it.&amp;#039;&amp;#039;&amp;#039; #CPA #Cybersecurity&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Backups don&amp;#039;t count until you&amp;#039;ve tested the restore.&amp;#039;&amp;#039;&amp;#039; One of the simplest recommendations in ATL272 may also be one of the most important.&lt;br /&gt;
# The cyber response window is shrinking. When attackers operate at machine speed, &amp;#039;&amp;#039;&amp;#039;“we&amp;#039;ll patch it next week” becomes a business risk.&amp;#039;&amp;#039;&amp;#039; ATL272 examines why.&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Technical debt is becoming security debt.&amp;#039;&amp;#039;&amp;#039; Unsupported operating systems, aging hardware, and consumer-grade network equipment become much bigger liabilities when attacks can be automated.&lt;br /&gt;
# Open-weight AI changes the economics of cybersecurity. Powerful capabilities can become &amp;#039;&amp;#039;&amp;#039;cheaper, portable, replicable, and difficult to contain once they&amp;#039;re released.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# Security that works is largely invisible. Security that fails can stop the business. That&amp;#039;s why cybersecurity spending is difficult to appreciate—&amp;#039;&amp;#039;&amp;#039;right up until the moment you desperately wish you had spent it.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# AI may make phishing better, but the human layer hasn&amp;#039;t disappeared. A convincing message delivered to a tired, distracted professional can defeat a lot of expensive technology.&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Inventory your AI stack.&amp;#039;&amp;#039;&amp;#039; Which applications and agents touch client data? Where does the data go? What do your audit trails show? Who controls that information afterward? ATL272 gets into the governance questions behind the AI boom.&lt;br /&gt;
# If your cybersecurity strategy begins and ends with traditional antivirus, &amp;#039;&amp;#039;&amp;#039;the game has changed.&amp;#039;&amp;#039;&amp;#039; ATL272 looks at why accounting firms need more proactive detection, response, and containment.&lt;br /&gt;
# Tax season is a terrible time to discover that your router, server, operating system, or other critical infrastructure is unsupported. &amp;#039;&amp;#039;&amp;#039;Fix the boring infrastructure before the storm arrives.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# “&amp;#039;&amp;#039;&amp;#039;We have cheaper attacks, we have more targets. We have the machine speed shrinking the response time.&amp;#039;&amp;#039;&amp;#039;” That&amp;#039;s the cybersecurity business problem behind ATL272.&lt;br /&gt;
# “&amp;#039;&amp;#039;&amp;#039;Get the fundamentals right, including testing the backups.&amp;#039;&amp;#039;&amp;#039;” Sophisticated AI security tools won&amp;#039;t compensate for sloppy cybersecurity basics.&lt;br /&gt;
# “&amp;#039;&amp;#039;&amp;#039;If you&amp;#039;re waiting for things to be certain, that ain&amp;#039;t going to happen.&amp;#039;&amp;#039;&amp;#039;” Cybersecurity decisions rarely arrive with perfect information. Waiting is still a decision.&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Not Skynet. Still serious.&amp;#039;&amp;#039;&amp;#039; ATL272 avoids the science-fiction answer and focuses on the operational problem: AI is reducing the cost and increasing the speed of cyberattacks.&lt;br /&gt;
# Accounting firms sit at the intersection of &amp;#039;&amp;#039;&amp;#039;money movement, identity data, tax records, and client-system credentials.&amp;#039;&amp;#039;&amp;#039; That&amp;#039;s a high-value target whether we like it or not.&lt;br /&gt;
# There&amp;#039;s a governance problem hiding inside the cybersecurity problem: &amp;#039;&amp;#039;&amp;#039;Which AI vendors can access your client data, what happens to it, and can you prove it?&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# A cybersecurity policy isn&amp;#039;t resilience. &amp;#039;&amp;#039;&amp;#039;Rehearsed incident response, tested backups, supported systems, useful audit trails, and controlled data flows are resilience.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# &amp;#039;&amp;#039;The Gathering Storm&amp;#039;&amp;#039; is a warning, not a prediction of doom. Use the time you have now to &amp;#039;&amp;#039;&amp;#039;harden, patch, rehearse, test, inventory, and govern.&amp;#039;&amp;#039;&amp;#039; ATL272 from the Accounting Technology Lab. #CPA #AccountingTechnology #Cybersecurity&lt;br /&gt;
&lt;br /&gt;
== Companies, Products, and Services Mentioned ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
! Company / Service&lt;br /&gt;
! Products or Context Mentioned&lt;br /&gt;
! X&lt;br /&gt;
! Facebook&lt;br /&gt;
! LinkedIn&lt;br /&gt;
! Instagram&lt;br /&gt;
|-&lt;br /&gt;
| CPA Practice Advisor&lt;br /&gt;
| Publisher/sponsor of Accounting Technology Lab&lt;br /&gt;
| @cpapracadvisor&lt;br /&gt;
| CPA Practice Advisor&lt;br /&gt;
| CPA Practice Advisor&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|-&lt;br /&gt;
| OpenAI&lt;br /&gt;
| ChatGPT; GPT models; GPT 5.2&lt;br /&gt;
| @OpenAI; @ChatGPTapp&lt;br /&gt;
| @OpenAI&lt;br /&gt;
| OpenAI&lt;br /&gt;
| @openai; @chatgpt&lt;br /&gt;
|-&lt;br /&gt;
| Hugging Face&lt;br /&gt;
| AI model hosting/community platform&lt;br /&gt;
| @huggingface&lt;br /&gt;
| Not verified&lt;br /&gt;
| Hugging Face&lt;br /&gt;
| Not verified&lt;br /&gt;
|-&lt;br /&gt;
| Anthropic&lt;br /&gt;
| Claude; Claude Code; Mythos; Fable; Project Glasswing referenced&lt;br /&gt;
| @AnthropicAI; @claudeai&lt;br /&gt;
| Not verified&lt;br /&gt;
| Anthropic&lt;br /&gt;
| Not verified&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft&lt;br /&gt;
| Vulnerability patching; operating systems; security&lt;br /&gt;
| @Microsoft&lt;br /&gt;
| Microsoft&lt;br /&gt;
| Microsoft&lt;br /&gt;
| @microsoft&lt;br /&gt;
|-&lt;br /&gt;
| Ubiquiti&lt;br /&gt;
| Networking/infrastructure equipment; rendered as “Ubiquity” in transcript&lt;br /&gt;
| @Ubiquiti&lt;br /&gt;
| Ubiquiti/UI&lt;br /&gt;
| Ubiquiti Inc.&lt;br /&gt;
| @ubiquiti&lt;br /&gt;
|-&lt;br /&gt;
| Cisco&lt;br /&gt;
| Networking/infrastructure vendor&lt;br /&gt;
| @Cisco&lt;br /&gt;
| Cisco&lt;br /&gt;
| Cisco&lt;br /&gt;
| @cisco&lt;br /&gt;
|-&lt;br /&gt;
| Google DeepMind&lt;br /&gt;
| Frontier AI/model-development discussion&lt;br /&gt;
| @GoogleDeepMind&lt;br /&gt;
| Google DeepMind&lt;br /&gt;
| Google DeepMind&lt;br /&gt;
| @googledeepmind&lt;br /&gt;
|-&lt;br /&gt;
| DeepSeek&lt;br /&gt;
| Open-model comparison&lt;br /&gt;
| @deepseek_ai&lt;br /&gt;
| No official account verified&lt;br /&gt;
| No official account verified&lt;br /&gt;
| No official account verified&lt;br /&gt;
|-&lt;br /&gt;
| Z.ai&lt;br /&gt;
| GLM models; GLM 5.2&lt;br /&gt;
| @Zai_org&lt;br /&gt;
| Not verified&lt;br /&gt;
| Z.ai&lt;br /&gt;
| Not verified&lt;br /&gt;
|-&lt;br /&gt;
| GitHub&lt;br /&gt;
| Distribution/hosting of open-source or open-weight material&lt;br /&gt;
| @github&lt;br /&gt;
| GitHub&lt;br /&gt;
| GitHub&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|-&lt;br /&gt;
| Reddit&lt;br /&gt;
| Distribution example for model weights/configurations&lt;br /&gt;
| @Reddit&lt;br /&gt;
| @reddit&lt;br /&gt;
| Reddit, Inc.&lt;br /&gt;
| @reddit&lt;br /&gt;
|-&lt;br /&gt;
| Yandex&lt;br /&gt;
| Example of another redistribution location&lt;br /&gt;
| @yandexcom&lt;br /&gt;
| Not independently verified&lt;br /&gt;
| Yandex&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|-&lt;br /&gt;
| BitTorrent&lt;br /&gt;
| Peer-to-peer distribution analogy&lt;br /&gt;
| @BitTorrent&lt;br /&gt;
| Not independently verified&lt;br /&gt;
| BitTorrent, Inc.&lt;br /&gt;
| Not independently verified&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Other Organizations, Technologies, and Regulatory Concepts Referenced ==&lt;br /&gt;
&lt;br /&gt;
* AICPA&lt;br /&gt;
* CPAmerica&lt;br /&gt;
* Stanford&lt;br /&gt;
* U.S. Department of Defense&lt;br /&gt;
* NSA&lt;br /&gt;
* GLBA&lt;br /&gt;
* Written Information Security Plans (WISPs)&lt;br /&gt;
* Model Context Protocol (MCP)&lt;br /&gt;
* CVEs&lt;br /&gt;
* Open-source/open-weight AI models&lt;br /&gt;
* AI agents&lt;br /&gt;
* Incident response&lt;br /&gt;
* Antivirus and endpoint security&lt;br /&gt;
* Backups and disaster recovery&lt;br /&gt;
* Routers and networking infrastructure&lt;br /&gt;
* Operating systems&lt;br /&gt;
* ACH and wire-transfer systems&lt;br /&gt;
&lt;br /&gt;
== Transcript Note ==&lt;br /&gt;
&lt;br /&gt;
One passage discussing an earlier state-linked AI campaign contains the phrase &amp;#039;&amp;#039;&amp;#039;“Pageantic coding tool.”&amp;#039;&amp;#039;&amp;#039; The supplied transcript does not establish that as a company or product name, so no entity has been inferred or added to the social-media table.&lt;/div&gt;</summary>
		<author><name>Bftcpa606</name></author>
	</entry>
</feed>