MTS Consulting Group, Inc.
Cyber Liability Knowledge Center
Series: Building Business Resilience
The Quick Answer
An accounting or tax firm does not need to solve every cybersecurity problem in the first 90 days.
A better approach is to divide the work into three 30-day phases:
Days 1-30: Create Clarity
Understand the business, establish ownership, gather evidence, and identify the risks that matter most.
Days 31-60: Reduce Priority Risk
Address a small number of meaningful gaps, verify important safeguards, and document leadership decisions.
Days 61-90: Build the System
Test recovery assumptions, establish recurring reviews, create a forward-looking roadmap, and make Cyber Liability management part of normal business operations.
The objective is not to reach "perfect security" in three months.
It is to move from:
Assumption → Evidence → Priority → Decision → Improvement
At MTS Consulting Group, that is what reducing Cyber Liability should look like.
Create Clarity Before Action.

The objective is not to reach "perfect security" in three months.
It is to move from:
Assumption → Evidence → Priority → Decision → Improvement
At MTS Consulting Group, that is what reducing Cyber Liability should look like.
Create Clarity Before Action.
Why 90 Days?
Cybersecurity projects often fail for one of two reasons.
The first is doing too little.
Leadership knows there are risks but never creates a plan.
The second is trying to do everything at once.
A security review produces:
- 42 findings
- 19 recommendations
- 11 tools
- Five projects
- A giant spreadsheet
- A large budget request
Leadership becomes overwhelmed.
Nothing meaningful changes.
A 90-day roadmap gives the organization enough time to make real progress while keeping the work manageable.
The structure creates urgency without panic.
It creates accountability without pretending every issue is an emergency.
And it gives leadership enough time to learn before making expensive decisions.
That reflects the MTS principle:
Teach Before We Act.
The First Rule: Do Not Start by Buying Technology
This may be the most important rule in the entire 90-day plan.
Do not begin with:
"Which security product should we buy?"
Begin with:
"What are we trying to protect, what does the evidence tell us, and what risk matters most?"
The organization may eventually need:
- New security controls
- Different technology
- Additional monitoring
- Recovery improvements
- Training
- Process changes
- Vendor changes
But those decisions should follow evidence.
Not fear.
Not a product demo.
Not an assumption.
Clarity first. Technology second.
The MTS 90-Day Cyber Liability Roadmap
The roadmap has three phases.
Phase 1: Days 1-30: CREATE CLARITY
Understand the organization and establish the facts.
Phase 2: Days 31-60: REDUCE PRIORITY RISK
Act on the few issues that matter most.
Phase 3: Days 61-90: BUILD THE SYSTEM
Make improvement repeatable rather than one-time.
The organization should emerge from Day 90 with:
- Clearer ownership
- Better evidence
- Fewer assumptions
- Documented decisions
- Improved safeguards
- Better recovery understanding
- A prioritized roadmap for what happens next
Not perfection.
Progress.
PHASE 1: DAYS 1-30: CREATE CLARITY
The first month should be about understanding before changing.
Leadership needs a baseline.
Step 1: Identify What the Business Depends On
Begin with the business.
Not the firewall.
For an accounting or tax firm, identify the systems and services that would create real disruption if they became unavailable.
Examples might include:
- Tax preparation software
- Accounting applications
- Microsoft 365
- Client portals
- File storage
- Payroll systems
- Internet connectivity
- Remote access
- Phone systems
- Critical cloud services
- Third-party vendors
Then ask:
"How long could we realistically operate without each one?"
Not every system deserves the same recovery priority.
That matters later.
Step 2: Identify the Information That Matters Most
Technology supports information.
Leadership should understand what sensitive information the firm possesses and where it moves.
For example:
- Taxpayer information
- Social Security numbers
- Financial statements
- Payroll information
- Banking information
- Employee information
- Authentication credentials
- Client business records
Then examine the information lifecycle.
How does it arrive?
Portal?
Email?
Paper?
Cloud application?
Where is it stored?
Who can access it?
How is it transmitted?
How long is it retained?
How is it eventually removed or destroyed?
This begins exposing where Cyber Liability lives.
Step 3: Define Ownership
One of the most common causes of hidden risk is unclear responsibility.
Leadership assumes:
"The IT company handles that."
The IT provider assumes:
"The client owns that."
A vendor assumes:
"The MSP handles that."
Nobody is intentionally ignoring the issue.
Ownership was simply never made clear.
For every meaningful responsibility, identify:
Owner
Who is responsible for making sure it happens?
Implementer
Who performs the work?
Verifier
Who confirms it actually occurred?
Decision Maker
Who decides what happens when a gap is identified?
Those roles may be different.
That is okay.
The important thing is that they are visible.
Step 4: Get Independent Evidence
This is an appropriate point to use the Independent Cyber Risk Assessment introduced in Chapter 9.
The assessment used through MTS is performed by an independent security partner and is designed to provide an outside, credential-free perspective.
The goal is not to replace the existing technology provider.
It is to test assumptions.
Leadership should begin asking:
- What do we believe is protected?
- What can actually be observed?
- Where does the evidence support our assumptions?
- Where does the evidence suggest further investigation?
Independent evidence can confirm that things are working well.
That is valuable.
It can also identify uncertainty.
That is valuable too.
Step 5: Apply the Four Areas of Cyber Liability
Do not leave findings in technical language.
Translate them.
For each significant issue, consider:
Business & Operational Risk
Could this prevent the firm from operating or serving clients?
Legal Risk
Could this create responsibilities requiring qualified professional guidance?
Regulatory Risk
Could this affect responsibilities expected of the firm?
Reputational Risk
Could this damage client or stakeholder trust?
A vulnerability means more when leadership understands what it could mean to the business.
See the Whole Risk.
Step 6: Choose the Top Three Priorities
Do not attempt to address every finding.
Start with three.
Ask:
Which issue could create the greatest business disruption?
Which assumption is most important to verify?
Which improvement could meaningfully reduce risk now?
The exact priorities will differ by firm.
For one organization, they might be:
- Verify recovery capability.
- Correct privileged-access problems.
- Remove unmanaged or unnecessary vendor access.
For another:
- Expand MFA.
- Improve employee onboarding and offboarding.
- Correct backup coverage.
The number is intentional.
Three priorities are manageable.
Thirty usually are not.
What Should Exist by Day 30?
At the end of the first month, leadership should have:
- A list of critical business systems
- A basic picture of sensitive information
- Clearer responsibility ownership
- Independent or other credible evidence
- Identified assumptions
- A view of Cyber Liability across four areas
- Three priority issues
- A record of what will happen next
That is meaningful progress.
No giant transformation project required.
Days 1-30: Create Clarity
Create six connected stages:
UNDERSTAND THE BUSINESS → IDENTIFY CRITICAL SYSTEMS & DATA → DEFINE OWNERSHIP → GATHER EVIDENCE → SEE THE WHOLE RISK → SELECT 3 PRIORITIES
Month 1 is about knowing what is true before deciding what to change.

PHASE 2: DAYS 31-60: REDUCE PRIORITY RISK
Now the organization begins acting on what it learned.
This is where many firms make another mistake.
They convert every finding into a technology purchase.
That is unnecessary.
A risk can sometimes be reduced by:
- Changing a process
- Removing access
- Updating documentation
- Correcting a configuration
- Teaching employees
- Testing recovery
- Assigning ownership
- Eliminating an unused system
- Reviewing a vendor
The solution should follow the problem.
Step 7: Verify the Critical Safeguards
Pick the safeguards leadership depends on most.
Then ask:
"Can we prove these are working?"
Examples include:
Multifactor Authentication
Where is it enabled?
Where isn't it?
What exceptions remain?
Endpoint Protection
Which systems are actively reporting?
Are any devices missing?
Backup
What is being protected?
Recovery
What has actually been restored in a test?
Employee Access
Does every employee have only the access they need?
Former Employee Access
Can the organization prove access was removed?
Vendor Access
Who still has access and why?
This is the difference between:
Having controls
and
having confidence in controls.
Step 8: Fix the High-Value Gaps
The first improvements should focus on meaningful risk reduction.
A useful question is:
"Which action gives us the most meaningful reduction in exposure relative to the time, cost, and disruption involved?"
That prevents security work from becoming a competition to see who can buy the most tools.
Sometimes a relatively small change produces significant value.
Examples might include:
- Removing an unnecessary administrator account
- Enabling MFA on a critical system
- Correcting an exposed service
- Removing dormant vendor access
- Fixing a failed backup process
- Updating an outdated system
- Improving employee offboarding
Specificity matters.
Step 9: Document Every Leadership Decision
Not every recommendation will be approved.
That is normal.
Leadership may choose:
Accept
Proceed now.
Defer
Acknowledge the issue but intentionally schedule it later.
Decline
Understand the recommendation but consciously choose not to proceed.
Investigate
Gather more evidence before deciding.
The important thing is that the issue does not disappear.
For significant decisions, document:
- What was identified
- What evidence exists
- Why it matters
- What was recommended
- What leadership decided
- Who owns the next step
- When it will be reviewed again
Documentation is protection.
Step 10: Close the Scope Gaps
Chapter 3 and Chapter 10 both addressed scope.
The 90-day plan is a good time to resolve it.
Leadership should be able to identify:
What the Technology Provider Owns
What Leadership Owns
What Employees Own
What Vendors Own
What the Independent Security Partner Does
Where Legal or Other Professional Guidance May Be Needed
The objective is not for one organization to own everything.
It is to eliminate:
"I thought somebody else handled that."
That sentence has created enough Cyber Liability already.
Step 11: Improve Employee Understanding
Security training should not simply produce a certificate.
It should change behavior.
During Days 31-60, focus education on issues employees are likely to face.
For accounting and tax firms, examples might include:
- Suspicious client attachments
- Fake tax documents
- Credential theft
- MFA fatigue
- Urgent payment-change requests
- Fake messages from firm leadership
- Improper use of personal storage
- AI tools receiving sensitive client information
- Requests to bypass approved processes
Employees do not need to become cybersecurity professionals.
They need enough understanding to recognize when they should stop and ask.
That is Teach Before We Act applied internally.
What Should Exist by Day 60?
By the end of the second month, leadership should be able to point to tangible improvement.
Examples include:
- Priority technical gaps corrected
- Important safeguards verified
- Unnecessary access removed
- Leadership decisions documented
- Responsibilities clarified
- Employee education reinforced
- Open issues assigned to owners
- Deferred issues given review dates
The organization should be able to say:
"We know more than we knew 30 days ago, and several meaningful risks are now lower."
That is progress.
PHASE 3: DAYS 61-90: BUILD THE SYSTEM
The third month is what separates a security project from a Cyber Liability management system.
If the organization stops after fixing the first few issues, the environment will slowly change again.
Employees change.
Vendors change.
Technology changes.
Applications change.
AI changes workflows.
Business priorities change.
Risk returns.
The purpose of Days 61-90 is to make Cyber Liability management repeatable.
Step 12: Test Recovery
One of the highest-value questions leadership can ask is:
"Can we recover?"
Not:
"Do we have backups?"
Actually recover.
Choose a meaningful system or dataset and test.
Record:
- What was restored
- How long it took
- What failed
- What dependencies appeared
- What leadership expected
- Whether reality matched the expectation
If leadership believes recovery will take four hours but testing shows twelve, the backup did not necessarily fail.
The assumption failed.
That is valuable information.
Step 13: Review the Technology Lifecycle
Cyber Liability includes aging technology.
During Days 61-90, look forward.
Which technology may require attention during the next:
12 Months
24 Months
36 Months
Consider:
- Workstations
- Servers
- Network equipment
- Operating systems
- Major software platforms
- Legacy applications
- Security products
- Cloud services
Leadership should not discover predictable lifecycle expenses through emergency proposals.
A roadmap converts:
"Why do we suddenly need this?"
into:
"We knew this was coming."
Step 14: Review Vendors and Third Parties
Accounting firms frequently depend on third-party providers.
Examples might include:
- Tax software companies
- Payroll platforms
- Cloud providers
- Document portals
- Banks
- Web providers
- Outsourced consultants
- Technology vendors
- Other professional partners
Ask:
- What access do they have?
- Who owns the relationship?
- Is the access still necessary?
- What data do they receive?
- What happens if their service becomes unavailable?
- Who removes access when the relationship ends?
The vendor may own its technology.
Leadership still owns the decision to depend on it.
Step 15: Establish the Leadership Review Cadence
Cyber Liability should become part of leadership operations.
Not an annual surprise.
The exact cadence will depend on the firm, but the review should answer questions such as:
What changed?
What evidence did we collect?
What incidents or patterns occurred?
What risks remain open?
What progress did we make?
What are the next one to three priorities?
What decisions does leadership need to make?
That is different from reviewing ticket volume.
Leadership meetings should produce decisions.
Step 16: Create the Cyber Liability Roadmap
Day 90 should not end with:
"Great. We're done."
It should end with a roadmap.
A practical roadmap can include four categories.
NOW
Issues requiring current action.
NEXT
Items planned during the next quarter.
LATER
Longer-term investments or improvements.
MONITOR
Issues that do not currently require action but should remain visible.
This helps leadership manage competing priorities without pretending everything must happen immediately.
Step 17: Reassess the Four Cyber Liability Areas
After 90 days, return to the four areas.
Business & Operational
Are operations more resilient?
Legal
Are responsibilities clearer and evidence easier to produce when appropriate professionals need it?
Regulatory
Are expected safeguards and responsibilities better understood and supported by evidence?
Reputational
Is leadership better prepared to protect client trust?
The objective is not a perfect score.
It is movement.
The First 90 Days of Reducing Cyber Liability

ASSUMPTION → EVIDENCE → PRIORITY → DECISION → IMPROVEMENT
90 days will not eliminate Cyber Liability. It can create a much stronger way to manage it.
Why the First 90 Days Should Not Be a Tool-Deployment Marathon
Security vendors can make the first 90 days sound like a deployment schedule.
Day 10: Install product.
Day 20: Add product.
Day 30: Upgrade firewall.
Day 45: Add another platform.
Day 60: Deploy more licenses.
That may be appropriate in some situations.
But it should not be the structure of the strategy.
The MTS sequence is different:
Understand
Verify
Prioritize
Decide
Implement
Measure
The technology exists to support that process.
The technology is not the process.
What Should Leadership Measure?
Do not measure progress only by the number of security products installed.
Look for outcomes.
For example:
Fewer Unknowns
Leadership can answer questions it could not answer 90 days earlier.
Clearer Ownership
Important responsibilities have named owners.
Better Evidence
Critical controls can be demonstrated.
Lower Priority Risk
Meaningful exposures have been corrected or reduced.
Better Recovery Understanding
Leadership knows what recovery looks like.
Documented Decisions
Accepted, deferred, declined, and investigated risks have records.
Better Roadmap Visibility
Leadership knows what is coming next.
Those are meaningful indicators of maturity.
An Illustrative 30-Person Accounting Firm
Consider a 30-person accounting firm starting with reasonable protections.
It has:
- Managed IT
- MFA
- Endpoint protection
- Backups
- Security awareness training
- A written information-security plan
Leadership still has several questions.
Month 1
An Independent Cyber Risk Assessment and internal review identify three priorities:
- Vendor access needs review.
- Recovery expectations have never been tested.
- One important cloud service needs additional verification.
Leadership does not buy another product.
It assigns ownership and gathers evidence.
Month 2
The firm:
- Removes several unnecessary vendor accounts
- Verifies the cloud configuration
- Documents the outstanding recovery question
- Reinforces employee access procedures
Month 3
The firm performs a recovery exercise.
The recovery works, but takes six hours instead of leadership's assumed two.
That result is not a failure.
It is evidence.
Leadership can now decide whether six hours is acceptable or whether additional investment is justified.
At Day 90, the firm still has Cyber Liability.
But its leadership understands that liability much better.
That is the objective.
What If Your Firm Has Serious Problems on Day 1?
The roadmap is not a reason to delay urgent action.
If credible evidence reveals a serious active exposure, the organization may need to respond immediately.
Examples could include:
- An active compromise
- Known unauthorized access
- A critically exposed system
- A significant failure of an important protection
The roadmap provides structure.
It does not require leadership to wait until Day 31 because the calendar says so.
Guide Through the Storm means adapting to reality.
Prioritization always matters more than arbitrary dates.
What If Your Firm Is Already in Good Shape?
Excellent.
Then the 90-day plan becomes a verification and maturity exercise.
Perhaps the organization spends more time on:
- Recovery testing
- Vendor reviews
- Lifecycle planning
- Documentation
- Independent validation
- AI governance
- Strategic roadmap development
The purpose of the roadmap is not to prove every business has serious problems.
It is to create a disciplined process for finding out what is true.
The "Three Priorities" Rule
Throughout the 90 days, resist the urge to create long executive action lists.
A useful leadership discipline is:
What are the three things that matter most right now?
Those three may change.
Good.
Month 1 priorities may be resolved.
Month 2 introduces the next three.
That creates continuous improvement without overwhelming the organization.
The First 90 Days and the Independent Cyber Risk Assessment
The assessment from Chapter 9 fits naturally into Phase 1.
Remember the division of responsibilities:
The Independent Security Partner
Performs the Independent Cyber Risk Assessment.
MTS
Helps leadership interpret findings, connect them to Cyber Liability, prioritize next actions, and coordinate appropriate technology work when invited.
Leadership
Makes the business decisions.
That separation is intentional.
It strengthens the evidence process.
It also reinforces an important MTS principle:
Confidence, not dependency.
A 90-Day Leadership Checklist
By Day 90, leadership should be able to answer these ten questions.
- What are the three systems our business depends on most?
- What sensitive information would create the most exposure?
- Who owns our major technology and Cyber Liability responsibilities?
- What independent evidence have we reviewed?
- What are our three highest-priority risks?
- Which critical safeguards have actually been verified?
- What risks have we accepted, deferred, declined, or investigated?
- Can we describe our recovery capability in realistic terms?
- What are the next 12 months of technology and risk priorities?
- When is our next leadership review?
If leadership can answer those questions clearly, the organization has made significant progress.
Frequently Asked Questions
Can an accounting firm eliminate Cyber Liability in 90 days?
No.
Cyber Liability changes as the organization, technology, employees, vendors, and threats change.
The first 90 days should create a stronger management system, not a false promise of zero risk.
What should happen in the first 30 days?
The first month should focus primarily on understanding the business, defining ownership, gathering evidence, identifying assumptions, seeing the whole risk, and selecting approximately three meaningful priorities.
Should we buy new security technology during the first month?
Possibly, if evidence supports an urgent need.
But buying tools should not be the default starting point.
Understand the risk first.
How many Cyber Liability issues should leadership work on at once?
There is no universal number, but MTS recommends beginning executive discussions with approximately one to three meaningful priorities rather than overwhelming leadership with dozens of findings.
Where does an Independent Cyber Risk Assessment fit?
It fits well in the first 30 days because it provides an outside source of evidence that can help test existing assumptions.
When used through MTS, the assessment itself is performed by an independent security partner.
Should our MSP perform all the work in the 90-day plan?
Not necessarily.
Responsibilities may involve:
- Leadership
- The technology provider
- The independent security partner
- Employees
- Vendors
- Legal counsel
- Other qualified professionals
The objective is clear ownership.
What should we do with a recommendation we cannot afford right now?
Understand it.
Document it.
Decide whether to accept, defer, decline, or investigate it.
If deferred, assign a review date.
A conscious business decision is different from allowing the recommendation to disappear.
When should we reassess Cyber Liability?
At minimum, leadership should establish a recurring review cadence.
Additional review may be appropriate when meaningful changes occur, such as:
- New offices
- Major staffing changes
- New applications
- Vendor changes
- Business acquisitions
- New AI usage
- Significant incidents
- Major infrastructure changes
Risk changes when the business changes.
The MTS Perspective
Cyber Liability should not be managed through fear.
It should not be managed through a stack of technology products.
And it should not be managed through a giant assessment that nobody reviews again.
A stronger model is:
Understand.
Gather evidence.
Prioritize.
Decide.
Document.
Improve.
Repeat.
The first 90 days establish that rhythm.
MTS's job is not to convince leadership that everything is an emergency.
Our job is to help leadership understand what is true, what matters, and what decision comes next.
Create Clarity Before Action.
Guide Through the Storm.
Teach Before We Act.
See the Whole Risk.
The goal is not perfect security.
The goal is a stronger organization that understands its risk and has a system for making better decisions.
Your Next Step
Do not create a 40-item Cyber Liability project list tomorrow.
Start with Day 1.
Schedule a leadership conversation.
Ask:
What does our business depend on most?
What are we currently assuming is protected?
What evidence do we have?
What are the three risks we should understand first?
Then document the answers.
That is enough to begin.
Clarity first. Progress second. Improvement over time.
MTS offers accounting and tax firms a Complimentary Independent Cyber Risk Assessment performed through an independent security partner.
It begins with 26 minutes.
No passwords.
No system credentials.
The assessment provides leadership with an outside perspective that can help shape the first 90 days.
You do not need to solve everything this week.
You need to know what should happen next.
Start Your First 90 Days With Independent Evidence.
Continue Through the Cyber Liability Knowledge Center
Start Here:
What Is Cyber Liability, and How Is It Different from Cybersecurity?
Previous Chapter:
How Should an Accounting Firm Choose a Technology Partner Who Understands Cyber Liability?
Next Chapter:
What Should Accounting Firm Leaders Ask About AI Before Employees Put Client Information Into It?
Related chapters:
- What Is Cyber Liability, and How Is It Different from Cybersecurity?
- What Are the Four Business Risks Every Accounting Firm Should Understand Before Investing in Cybersecurity?
- Why Doesn't Traditional IT Support Fully Address Cyber Liability?
- What Should Managed IT Actually Do to Reduce an Accounting Firm's Business Risk?
- Why Is Meeting the FTC Safeguards Rule Only the Starting Point for an Accounting Firm?
- What Should Tax Professionals Understand About IRS Publication 4557 Beyond the Checklist?
- How Does an Independent Cyber Risk Assessment Help Accounting Firm Leaders Make Better Decisions?
- How Should an Accounting Firm Choose a Technology Partner Who Understands Cyber Liability?
Explore MTS services:


