
If your accounting or tax firm experienced a cyber incident tomorrow, would your leadership team know what to do first?
Not what you assume would happen.
Not what someone thinks is written in a policy somewhere.
What would actually happen?
For accounting and tax firms, cyber preparedness isn't just an IT issue. Your ability to serve clients depends on email, tax software, client portals, cloud applications, document management systems, internet access, and third-party providers.
If one of those systems becomes unavailable—especially during busy season—the problem can quickly move from the IT department to the leadership table.
And the consequences can extend beyond downtime.
There may be business, legal, regulatory, operational, insurance, and reputational consequences. Together, these are part of your firm's cyber liability exposure.
You don't need to be a cybersecurity expert to begin preparing for them.
You can start with 15 minutes, the right people, and five questions.
1. If Our Firm Stopped Operating Tomorrow, What Would We Restore First?
This sounds like an easy question.
Try asking it around the leadership table.
If your technology suddenly became unavailable, what would your firm need first?
Email?
Tax preparation software?
Microsoft 365?
Your document management system?
Client portals?
E-file capabilities?
Phones?
Internet access?
A critical cloud application?
The answer will depend on how your firm operates. It may also change throughout the year.
During tax season, for example, a system that could be unavailable for several hours in July might create a much bigger problem in March.
The purpose of this question isn't to build a complete disaster recovery plan in 15 minutes.
It's to find out whether everyone agrees on what is most important.
If five people give five different answers, you've discovered something useful.
Your recovery priorities need more clarity.
2. Who Makes Decisions During a Cyber Incident or Business Disruption?
When something goes wrong, your firm will need more than technical help.
It will need decisions.
Who contacts your IT provider?
Who determines whether employees should continue working?
Who communicates with clients?
Who contacts your cyber insurance carrier?
Who decides when legal counsel or other outside advisors should become involved?
Who communicates with critical software providers or vendors?
And who has the authority to make those decisions?
These responsibilities are much easier to discuss on a normal Tuesday than during a cyber incident.
You won't be able to predict every situation. You don't need to.
What matters is knowing who is responsible for what and where the decision-making process begins.
3. How Would We Communicate If Our Normal Systems Were Unavailable?
Most firms rely heavily on email and cloud-based communication.
But what happens if those systems are unavailable?
Or worse, what happens if email is part of the incident and shouldn't be trusted?
Your firm needs another way to communicate with leadership, employees, critical vendors, and other important contacts.
The solution doesn't have to be complicated.
It does need to be:
- Known.
- Documented.
- Accessible.
- Tested.
- Usable when your normal systems aren't available.
Think about where your emergency information is stored, too.
If the only copy of your incident response plan or emergency contact list is sitting on a network you can't access, you may not have the information when you need it most.
That's the difference between assuming you're prepared and having evidence that you're prepared.
Cyber liability isn't about panic. It's about proof.
4. What Is Our Firm's Biggest Operational Dependency?
Every accounting and tax firm has dependencies.
Some are obvious. Others work so quietly in the background that nobody thinks much about them—until they're gone.
Your biggest dependency might be a software platform.
It might be your internet connection.
A cloud provider.
A key employee.
An outside technology provider.
A third-party vendor.
Or an integration connecting two critical systems.
Ask your leadership team:
What single failure would create the greatest disruption to our ability to serve clients?
Then go one step further:
What happens if we don't have it for a day? Three days? A week?
This is where cybersecurity becomes a business conversation.
The question isn't simply whether a particular application could go down.
It's what happens to the firm when it does.
Could employees continue working?
Could you access the information needed to serve clients?
Could deadlines still be met?
Would sensitive client information be affected?
Would you have insurance, legal, regulatory, or contractual responsibilities?
Would a third-party failure create a problem you hadn't planned for?
Would you be able to explain what happened—and what protections were already in place?
Looking at the whole risk helps leadership decide what deserves attention first.
Compliance may tell you whether you've met a requirement. Cyber liability asks what happens to the business when something goes wrong.
Both matter. They just answer different questions.
5. If a Cyber Incident Happened Tomorrow, What Would We Wish We Had Prepared Today?
This may be the most useful question in the entire meeting.
Imagine it's tomorrow morning.
Your systems are unavailable.
An employee clicked something they shouldn't have.
Someone's credentials were stolen.
A vendor experienced a security incident.
Or your team simply can't access the systems needed to work.
What would you wish you already had?
Maybe it's:
- An up-to-date emergency contact list.
- A tested backup and restore process.
- A documented incident response plan.
- Clearly assigned leadership responsibilities.
- Your cyber insurance information.
- A current list of critical vendors.
- Important information available somewhere offline.
- Evidence showing which cybersecurity protections are in place.
- A documented order for restoring critical systems.
Don't debate every item during the meeting.
Write them down.
Those answers give you the beginning of a practical preparedness list based on how your firm actually operates.
Why Is Cyber Preparedness Important for Accounting and Tax Firms?
Accounting and tax professionals are trusted with information that is deeply important to their clients.
Financial records. Tax information. Identification data. Business information. Payroll information. Documents clients expect their accounting professionals to protect.
But protecting that information isn't solely about installing cybersecurity tools.
Your firm's cyber risk is spread across its people, technology, client information, operations, and third-party systems.
That makes cyber preparedness a leadership responsibility as much as a technology responsibility.
The goal isn't for firm leaders to become cybersecurity experts.
The goal is to understand enough to make responsible decisions.
That means being able to answer four basic questions:
Where do we stand?
What matters most?
What should we do next?
What evidence do we have that supports our answer?
When those answers are clear, cybersecurity becomes much easier to manage as a business risk.
What Should Accounting Firm Leaders Know About Cyber Liability?
Cyber liability is bigger than a cybersecurity checklist.
It is the potential business, legal, regulatory, operational, insurance, and reputational exposure created when cybersecurity responsibilities aren't adequately addressed.
For an accounting or tax firm, that exposure can involve:
- Sensitive client information.
- Business interruption.
- Cyber insurance.
- Employee actions.
- Legal and regulatory responsibilities.
- Third-party vendors.
- Technology systems.
- Client relationships.
- Professional reputation.
This doesn't mean your firm must eliminate every possible risk.
No organization can.
Responsible preparedness means understanding the risks you carry, determining which ones deserve attention, making informed decisions about them, and keeping evidence of the protections and processes you have put in place.
You don't have to become a cybersecurity expert to remain the responsible professional your clients already trust.
How Do You Know Where Your Firm Has Cybersecurity Gaps?
Go back through the answers from your 15-minute meeting.
Listen for phrases such as:
“I think…”
“We should…”
“Someone probably has that…”
“Our IT provider handles it…”
“I'm pretty sure…”
Those phrases don't automatically mean something is wrong.
They identify places where you may have an assumption instead of evidence.
That's useful information.
For each one, ask:
How do we know?
Maybe the answer is a document.
Maybe it's a configuration report.
Maybe it's the result of a backup restore test.
Maybe it's a written responsibility.
Maybe it's an assessment.
Maybe it's a conversation you still need to have with your technology provider, insurance professional, attorney, or another advisor.
You aren't trying to find someone to blame.
You're turning uncertainty into something you can evaluate.
That's how a useful cyber preparedness conversation should work.
Put This 15-Minute Cyber Preparedness Meeting on Your Calendar
You don't need to wait for a ransomware incident, insurance renewal, client security questionnaire, or busy-season outage to find out whether your leadership team is prepared.
Set aside 15 minutes.
Bring together the people responsible for leadership, operations, technology, and client communication.
Ask these five questions:
- If our business stopped operating tomorrow, what would we restore first?
- Who is responsible for decisions during a disruption?
- How would we communicate if our normal tools were unavailable?
- What is our biggest operational dependency?
- If a disruption happened tomorrow, what would we wish we had prepared today?
Write down the answers.
Then separate what you know from what you assume.
Where you have evidence, document it.
Where you have uncertainty, identify the next question that needs to be answered.
You may discover you're better prepared than you thought.
You may also uncover a few gaps.
Either result is useful because now you have something every leadership team needs before making a decision:
Clarity.
Not Sure What Your Answers Mean?
If your 15-minute conversation leaves you with more questions than answers, you don't have to sort through them alone.
MTS Consulting Group helps accounting and tax firm leaders understand where they stand, identify the cyber liability risks that matter to their business, and make informed decisions based on evidence rather than assumptions.
We believe you shouldn't have to become a technology or cybersecurity expert to make responsible decisions about protecting your clients and your firm.
That's our role as a Beacon in the Cyber Storm—helping you see the path more clearly before the crisis hits.
Schedule a Discovery Call with MTS Consulting Group.
It's a conversation, not a sales pitch. You can ask questions, learn how we approach cyber risk, and determine whether MTS is the right fit for your firm.


