You run a firm. Maybe accounting, maybe law, maybe engineering, architecture, wealth management, or consulting. A prospective client sends over their standard vendor questionnaire before signing, and buried on page three is a section titled “Information Security.” It asks who your security contact is, whether you encrypt client data at rest, how long you keep files, and what your incident response plan says. You read it twice, then go looking for someone in the office who might know.

That moment is happening to professional services firms across Denton County and the wider DFW area right now, and it is not going away. The pattern is always the same three facts stacked on top of each other. Your actual product is trust, because clients hire you for judgment they cannot verify themselves. Your actual risk is client data, because almost nothing you hold belongs to you. And your budget is real, meaning finite, meaning you cannot solve this by buying everything. Getting the order right on those three is the whole game.

Quick note: this is general information, not legal, tax, or insurance advice. Your obligations depend on your profession, your licensing body, and your clients. Talk to your own attorney, CPA, or agent about what applies to you.

Trust Became a Technical Question When Nobody Was Looking

Thirty years ago, a client evaluating your firm looked at your credentials, your references, and your office. Those still matter. What changed is that part of the trust evaluation moved into a questionnaire your prospect’s risk team wrote, and your answers get compared against other firms’ answers.

The practical consequence is that “we have a guy who handles the computers” has become a competitive disadvantage. Not because it is dangerous, though sometimes it is, but because it produces no documentation. When the questionnaire arrives, firms that answer in an afternoon look serious and firms that need three weeks look like a risk. The work is mostly writing down what you already do.

Your Risk Is Their Data, Not Yours

This is the part that trips up firm owners. If a manufacturer gets breached, it is largely their own problem. If your firm gets breached, you have exposed hundreds of other people’s tax returns, deal terms, or litigation strategy. The blast radius is not your firm. It is your entire client list, and every one of them has a lawyer.

That asymmetry is why professional services firms are attractive targets. One firm holds concentrated, high-value information from many organizations. In its 2025 Data Breach Investigations Report, Verizon found that third party involvement in breaches had doubled to 30 percent of cases. You are somebody else’s third party.

Worth remembering that the cloud is just someone else’s computer. Moving client files to a well-run cloud platform usually beats a server in the closet, but it does not transfer responsibility. The provider secures the building. You still control who has the keys, and that is where nearly every real incident starts.

The Rules That Probably Already Apply to You

Most firm owners assume security regulation happens to hospitals and banks. Depending on your practice, you may already be covered and not know it.

  • Tax and accounting practices sit under the FTC Safeguards Rule. The Federal Trade Commission’s own business guidance lists tax preparation firms and non-SEC-registered investment advisers among the “financial institutions” covered. The rule requires a written security program, a designated qualified individual to run it, a risk assessment, multi-factor authentication, encryption, staff training, service provider oversight, and a written incident response plan. Multi-factor authentication, or MFA, means a second proof of identity beyond a password.
  • Law firms answer to their own confidentiality duty. American Bar Association Model Rule 1.6(c) states that “a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.” That is an ethics obligation, and states adopt their own versions.
  • Everyone else gets governed by contract. No regulator means client agreements instead, and those increasingly carry security terms, breach notification timelines, and audit rights a partner signed without reading closely.
  • Your cyber liability policy is a rulebook too. Many policies condition coverage on controls you attested to at application. Ask your agent what you actually promised.

What Actually Moves the Needle on a Real Budget

A short list of unglamorous controls covers most of the realistic risk, and they are affordable at ten people or a hundred. Do these before anything with a dashboard.

  1. MFA on every account, no partner exemptions. Email, file storage, practice management, banking, remote access. The account with the most access is the one attackers want, and it usually got a waiver.
  2. A password manager for the whole firm. An encrypted vault that generates a unique password per site. It ends password reuse, which is how somebody else’s breach becomes yours.
  3. Backups you have actually restored from. Including cloud file storage and email, which most firms wrongly assume the provider backs up for them. A backup nobody has tested is a theory.
  4. Real offboarding. When someone leaves, access ends the same day, across every system, including the ones they signed up for on a credit card. Write the checklist once.
  5. A written retention and destruction schedule. Decide how long you keep closed matters, then follow it. Data you do not hold cannot leak. When drives and laptops retire, physical destruction closes the loop. Harrison Ward Technology runs a Pure Leverage DCV71 hard drive crusher at roughly nine drives a minute, meeting recognized destruction standards, with a record of what was destroyed.
  6. Fifteen minutes of training, twice a year. Focused on wire fraud and fake invoice requests, because that is where firms lose actual money.

Where Firms Waste Money

The most common overspend is buying sophisticated monitoring before fixing basic access control. That is installing cameras while leaving the door unlocked. Second is paying for overlapping subscriptions nobody cancelled, which is why an annual software inventory tends to fund the rest of the program.

On artificial intelligence, the advice here is specific. Treat it like a junior staff member. It drafts, it summarizes, it never signs anything, and a licensed human reviews the output before it reaches a client. Keep client data out of consumer AI tools that train on what you type. IBM’s 2025 Cost of a Data Breach Report found unsanctioned AI use added roughly 670,000 US dollars to the average breach cost. And AI is the dumbest it will ever be today, so build the review process now.

The Bottom Line

Professional services firms do not need enterprise security. They need a short list of controls genuinely in place, written down in language a client’s risk team can read, and reviewed once a year. That protects the client data you hold and answers the questionnaire that decides whether you get the engagement. Same work, two payoffs. Again, this is general information rather than legal, tax, or insurance advice, so confirm your obligations with your own attorney, CPA, or agent.

If you would like help turning what your firm already does into something you can hand a client, reach out to Harrison Ward Technology. We work with firms in Lewisville, Flower Mound, Highland Village, Frisco, and across Denton County, and we are happy to start with the questionnaire on your desk.


Sources

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).