Most financial firms in Cameron Park have someone they call. A person who’s good with computers, responsive enough, reasonably priced, and has been handling things for years. When a printer stops working or someone’s laptop won’t start, they sort it out.
Nothing about that arrangement is wrong. The problem is that it was built to answer a question that has changed.
Ten years ago, the question was “who fixes it when something breaks?” Today, for a firm holding client financial data, the questions arriving are different ones. Can you demonstrate that Multi-Factor Authentication is enforced? When were your backups last tested? What’s your incident response plan? These come from insurers, from institutional clients, and increasingly from regulators — and they aren’t questions a computer guy was ever engaged to answer.
The gap nobody planned
It’s worth being clear that this isn’t a criticism of the person currently handling your technology. It’s a description of two different jobs that happen to involve the same equipment.
Break-fix work is reactive by design and by contract. Something fails, you call, someone comes, it gets repaired, you pay. The model works reasonably well for the problems it was built for, and it has the virtue of being simple to understand.
What it structurally cannot do is maintain a security posture. There’s nobody watching the network during the weeks an attacker typically spends inside one before triggering anything. There’s nobody confirming that last night’s backup would actually restore. There’s nobody tracking patch compliance across every workstation, or noticing that a control drifted out of effectiveness three months ago.
None of that is neglect. It’s simply outside the arrangement. You cannot call someone about a problem you don’t know you have.
What changed for financial firms specifically
Three shifts have arrived more or less together, and they’ve moved faster than most small firms have noticed.
Cyber insurance became conditional. Coverage that once required a signature now requires evidence of particular controls. Applications ask directly about MFA, backup testing, endpoint protection, and monitoring. More significantly, the application is a legal document, and claims have been reduced or denied where a firm attested to controls it didn’t actually have in place. Firms occasionally discover at claim time that someone ticked a box based on a reasonable assumption nobody had verified.
Clients started asking. Institutional clients and larger businesses now send security questionnaires to the professionals handling their money. Some require evidence before engagement. A firm that can’t complete the questionnaire satisfactorily is removed from consideration before any conversation about capability takes place — which is a difficult way to lose work you’d otherwise have won.
Regulatory expectations tightened. Financial services firms face growing obligations around safeguarding client information, and the direction of travel is firmly toward documentation. For tax professionals, the IRS requirement for a written information security plan is explicit and its absence is straightforward to identify.
The common thread is that all three ask you to demonstrate something rather than simply assert it. That’s the shift a break-fix arrangement was never designed to accommodate.
The threat that takes the most money
Ransomware gets the attention, but for accounting and advisory firms the costlier attack is quieter.
It starts with a fake login page. Someone enters their Microsoft 365 credentials, nothing visible happens, and an attacker now has legitimate access to a real mailbox. They don’t act immediately. Instead they read — learning which clients have transactions pending, how the firm communicates, who authorises payments, how the principals write. Some create mail rules so their activity stays hidden from the account’s actual owner.
Then, at a well-chosen moment, they send a message from that genuine address requesting a change to payment or wire instructions. Because it originates from a real account inside a real conversation, it passes every technical check that exists.
For financial firms this is particularly dangerous, because the amounts are larger and the requests are entirely plausible. A message about redirecting a client distribution doesn’t look unusual coming from an advisor’s actual mailbox.
Two controls stop most of it. Multi-Factor Authentication prevents the initial account access in the overwhelming majority of cases. And a verification habit — confirming any payment change by phone, using a number already on file rather than one supplied in the email — catches what gets through. The second costs nothing and is worth adopting regardless of anything else.
What proactive actually means
The word gets used loosely enough to have lost meaning, so it’s worth being concrete about the difference.
Proactive means every workstation, server, and network device is monitored continuously, so a failing drive or a filling disk gets addressed before anyone experiences an outage. It means patches are applied automatically and compliance is measured, rather than assumed. It means backups are verified daily, replicated somewhere ransomware on your network cannot reach, and tested quarterly with a written result.
It means security controls are maintained rather than installed — because MFA coverage drifts as staff join and leave, filtering rules need updating, and a control nobody reviews stops being effective within months.
And it means the documentation exists as a by-product. Monitoring produces logs. Scheduled testing produces reports. Managed patching produces compliance figures. When a client’s questionnaire arrives or an insurer asks, the answer is assembled in an afternoon rather than scrambled for over a week.
Firms often assume managed IT costs more than break-fix. Sometimes it does, in direct invoicing. The comparison is more interesting when you include what break-fix doesn’t cover.
A break-fix arrangement bills for the repair. It doesn’t bill for the four hours three staff members lost while waiting for the repair, or the client work that slipped, or the evening someone spent catching up. Those costs are real and land in the same business, they simply arrive as lost capacity rather than an invoice.
Then there’s the incident that doesn’t happen. Prevention is invisible by nature, which makes it easy to undervalue — but a firm that avoids one significant incident over three years has already justified the difference several times over, before counting the recovered hours.
The genuine advantage, mentioned most often by the firms we work with, is predictability. A fixed monthly cost is something you can budget around. Surprise invoices arriving after emergencies are not, and they tend to arrive during the periods when the firm can least absorb them.
What we typically find
Assessments across accounting and advisory practices surface a consistent pattern. MFA is usually enabled for some people rather than enforced for everyone, and often not on the accounts with the broadest access. Backups have been running successfully for years without anyone attempting a restore. Patch compliance sits somewhere between 55% and 70%, with third-party applications lagging furthest behind. Seasonal staff accounts remain active long after those individuals finished. And there is generally no written incident response plan, meaning the first decisions get made under pressure.
None of this reflects poorly on the firms involved. It reflects a practice that grew while nobody’s job description included security documentation.
Where to start
You don’t need a technical background to establish where your firm stands. Ask whoever currently handles your technology when the last actual restore test happened and what date it was. Ask whether MFA is enforced on every account with no exceptions. Ask who would be called, in what order, if something happened tonight.
Vague answers to those three questions tell you most of what you need to know — and every gap they reveal is closable, generally within weeks and for less than firms expect.
RJ PRO Tech Group works with financial and accounting firms across El Dorado County to build technology that’s reliable, secure, and documented, with a Help Desk that answers in minutes rather than days.