The Cyber Questions Your Clients and Auditors Will Ask

July 19, 2026  |  Technology

cyber questions
by:admin July 19, 2026 0 Comments

Can Your Firm Prove It’s Secure?

Something has changed for financial firms over the past few years, and it arrived quietly.

Clients — particularly institutional ones — have started asking how their data is protected. Not casually over coffee, but in writing, through questionnaires that expect specific answers. Insurers have moved in the same direction: cyber coverage that once required a signature now requires evidence of particular controls, and renewals ask whether those controls remain in place.

For a Jackson accounting or advisory firm, this creates a straightforward question. If someone asked tomorrow, could you answer with documentation rather than reassurance?

Most firms can’t. Not because they’re insecure, but because nobody ever asked them to prove it before.

The questions actually being asked

These are the areas that appear consistently across client questionnaires, insurance applications, and audit inquiries. Reading them as a checklist is more useful than reading them as a warning.

Is Multi-Factor Authentication enforced across the firm? Not available, not enabled for some — enforced, on email, remote access, and every cloud application. This has become close to a baseline requirement rather than a best practice, and it’s the question asked most consistently. Note that partial answers tend to be treated as negative ones.

How is client data encrypted, at rest and in transit? Both matter, and they’re different problems. Data sitting on a laptop that leaves the office is a distinct exposure from data moving between your systems and a client portal.

When were backups last tested? Note the precise wording. Not whether backups exist — whether recovery has been verified, and on what date. This question specifically catches firms whose backups run nightly and have never been restored.

Who has access to client data, and how is that reviewed? Access accumulates as staff change roles and seasonal help comes and goes. A firm that can demonstrate a periodic review is in a substantially stronger position than one that can’t.

How are staff trained, and how often? Human error remains the leading cause of incidents, and questionnaires increasingly ask for training records and frequency rather than a yes or no.

What is your incident response plan? If something happened tonight, who gets called, in what order, and what gets communicated to clients and when?

How are systems patched and monitored? Patch compliance is an unusually revealing metric. It indicates whether security is actively maintained or merely installed once.

Do you have a written information security plan? For tax professionals in particular, this is not optional. The IRS requires it, and its absence is straightforward to identify.

Why this matters more than it first appears

The instinctive reaction is that this is administrative burden layered onto an already demanding practice. It’s worth considering the other reading.

Coverage depends on it. Cyber insurance claims have been reduced or denied where firms attested to controls they didn’t actually have in place. The application is a legal document, and the attestation is made by whoever signs it. Firms occasionally discover at claim time that a box was ticked based on an assumption nobody verified.

Client acquisition depends on it. Institutional clients and larger businesses increasingly won’t engage a firm that can’t complete their security questionnaire satisfactorily. Being unable to answer removes you from consideration before any conversation about your actual capability takes place — which is a difficult way to lose work.

Regulatory expectations are rising. Financial services firms face growing obligations around safeguarding client information, and the direction of travel is firmly toward more documentation rather than less.

It’s a genuine differentiator. In a relationship business, being able to tell a client exactly how their financial data is protected — with evidence attached — is a real advantage in a market where most competitors would struggle to produce anything.

Consider two responses to the same questionnaire. One firm writes that it takes security seriously and uses strong passwords. Another states that MFA is enforced firm-wide, backups were tested on a specific date with documented results, staff complete training quarterly with completion records, and all systems are continuously monitored — and attaches the documentation.

The second firm wins that engagement. Increasingly, the first never reaches the conversation.

What it takes to answer confidently

The reassuring part is that answering these questions well requires a fairly standard set of controls, implemented properly and kept current. There’s nothing exotic on this list.

  • Multi-Factor Authentication everywhere, with no exceptions for partners or principals. Those accounts have the broadest access and are targeted specifically.
  • Endpoint detection and response, watching for suspicious behavior rather than only recognizing known threats.
  • Email threat filtering and DNS security, stopping the messages that begin most incidents. This matters particularly for firms handling wire instructions, where a single convincing message can redirect a substantial transfer.
  • Automated patch management, holding compliance consistently high without depending on anyone’s memory or availability.
  • Monitored, verified backups with off-site replication and scheduled recovery testing — so the answer to “when did you last test?” is a date rather than a shrug.
  • Continuous monitoring across every device, producing records that demonstrate ongoing oversight rather than a one-time setup.
  • Documented training, delivered regularly, with completion recorded.
  • A written incident response plan, prepared in advance, because nobody makes good decisions about notification and communication at seven in the morning on a bad day.

Our cybersecurity services implement these as a coordinated layer, and our managed IT services keep them monitored, current, and documented — which is the part that converts controls into answers you can actually give.

The documentation problem, specifically

There’s a distinction worth drawing out, because it trips up firms that are genuinely well protected.

Having a control and being able to evidence a control are different things. A firm might have excellent backups running to a well-designed off-site system, tested informally when someone needed a file recovered — and still be unable to answer a questionnaire, because nothing was recorded.

This is why the documentation tends to arrive as a by-product of the right arrangement rather than as separate work. Monitoring produces logs. Scheduled backup testing produces reports. Managed patching produces compliance figures. Training platforms produce completion records. A firm running these properly can assemble a response in an afternoon.

A firm without them faces a scramble, usually at the least convenient moment — during a client’s due diligence review, or in the days after an incident when attention is needed elsewhere.

The threat that costs financial firms the most

Questionnaires focus on controls, but it’s worth naming the specific attack that takes the most money from accounting and advisory firms — because it isn’t ransomware.

It’s business email compromise, and it works like this. Someone enters credentials on a convincing replica of a Microsoft 365 login page. Nothing visible happens. The attacker now has access to a real mailbox and typically does nothing dramatic for weeks.

Instead, they read. They learn which clients have transactions pending, how the firm communicates, who authorizes payments, and how the principals write. Some create quiet mail rules so their activity stays hidden from the account’s actual owner.

Then, at a well-chosen moment — a closing, a distribution, a large invoice — they send a message from that legitimate account requesting a change to payment details. Because it originates from a real address within a real conversation, it passes every technical check that exists.

For financial firms this is particularly dangerous, because the amounts involved are larger and the requests are entirely plausible. A message about redirecting a client distribution doesn’t look unusual coming from an advisor’s genuine mailbox.

Two controls stop most of this. MFA prevents the initial account access in the overwhelming majority of cases. And a verification procedure — confirming any payment change by phone, using a number already on file rather than one supplied in the email — catches what gets through. That second control costs nothing and is worth building into the firm’s standard practice regardless of anything else on this page.

What we typically find

Assessments across accounting and advisory practices surface a consistent pattern:

  • MFA enabled selectively, often not on the accounts with the broadest access
  • Backups never restored, running successfully for years without verification
  • Patch compliance between 55% and 70%, with third-party applications lagging furthest
  • Seasonal staff accounts still active, sometimes years after those individuals finished
  • No written information security plan, despite the IRS requirement for tax professionals
  • No incident response plan, meaning the first decisions get made under pressure
  • Client documents exchanged by email attachment, rather than through a secure portal

None of this reflects poorly on the firms involved. It reflects a business that grew while nobody’s job description included security documentation.

A note for smaller Gold Country firms

Firms in Jackson and the surrounding Amador County communities sometimes assume this scrutiny applies primarily to larger organizations. In practice, the questionnaire a client sends doesn’t scale down for firm size, and neither does the insurer’s application.

There’s a practical difficulty specific to the region as well. Access to specialist IT support is thinner here than in Sacramento, and firms frequently end up relying on a general computer vendor for security work that requires a different discipline entirely. That vendor may be perfectly capable at what they do — but maintaining a documented security program is not the same job as fixing computers, and it’s unfair to expect it of someone who was never engaged for it.

That gap is usually the reason a genuinely capable firm finds itself unable to answer basic questions about its own controls.

Where to start

Begin with an honest inventory. Take the eight questions above, walk through them with whoever manages your technology, and note which you could answer today with evidence attached.

The gaps that surface are almost always closable, and generally less expensive than firms expect. What’s costly is discovering them during an insurance claim, a client’s due diligence review, or the week after an incident.

RJ PRO Tech Group works with financial and accounting firms across the Gold Country to build security you can document — verified backups, monitored systems, and support that’s genuinely reachable when you need it.

Schedule a complimentary IT assessment for your Jackson firm.

Categories:

Get Access To Your Free White Papers

Enter your details and we’ll take you straight to the download page.