Managed IT and Cybersecurity for Columbus Professional Services Firms
Your firm runs on two things clients never see: a mailbox and a document store. Both hold confidential client material, and both are reachable from the internet. The requirements that cover them come from licensing bodies and from federal regulators, and they hold whatever an IT budget happens to include. For a practice that prepares tax returns for compensation, one of those duties is already written law, whether or not the document exists.
Which practices need a Written Information Security Plan?
Paid preparers, and the IRS puts the question in front of them every year. Form W-12, the PTIN application and renewal, carries line 11, Data Security Responsibilities, where the applicant checks a box next to this statement: “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.” The law behind that sentence is the Gramm-Leach-Bliley Act, which directs the Federal Trade Commission to set safeguard rules for companies the law defines as financial institutions. The rule reaches an accountant or other tax preparation service that is in the business of completing income tax returns (16 CFR 314.2(h)(2)(viii)), and the IRS says the same thing in plainer terms in its own guidance every filing season: a written data security plan is required by law. For a practice that does not prepare returns, whether the rule reaches it at all turns on that definition, which is worth confirming against 16 CFR 314.2(h) rather than assuming in either direction.
The plan is a program the firm has to keep running. The FTC Safeguards Rule requires a covered firm to designate a Qualified Individual to oversee the program, to base it on a risk assessment, to encrypt customer information in transit over external networks and at rest, to require multi-factor authentication for anyone accessing any information system, to train staff, to oversee the service providers who touch that data, and to keep a written incident response plan. The rule does allow narrow alternatives. Compensating controls are permitted where encryption is genuinely infeasible, and reasonably equivalent or stronger controls can stand in place of multi-factor authentication, but only where the Qualified Individual reviews and approves them in writing (16 CFR 314.4(c)). Those read as documented exceptions rather than defaults.
Since May 2024 the rule also requires notice to the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving the unencrypted customer information of at least 500 consumers. How the rule defines that event is worth reading before anyone assumes an incident sits outside it: unauthorized access to unencrypted customer information is presumed to be unauthorized acquisition unless the institution holds reliable evidence showing acquisition did not happen and could not reasonably have happened (16 CFR 314.2(m)). The burden runs toward reporting, so “we never saw the data leave” is not by itself an answer. Size does not lift the rule either. Below a consumer threshold it trims a short list of provisions and nothing more (16 CFR 314.6), which the first FAQ below covers.
What does Ohio’s ethics rule require a law firm to do about client data?
Ohio Rule of Professional Conduct 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information related to the representation of a client. The rule’s commentary is the part worth reading twice: unauthorized access is not automatically a violation where reasonable efforts were made, and reasonableness is judged on factors the commentary lists, including the sensitivity of the information, how likely disclosure was without additional safeguards, and the cost and difficulty of those safeguards.
That standard rewards firms that write things down. A practice that can show what it evaluated, what it put in place, and why it drew the line where it did is in a very different position than one reconstructing its reasoning after an incident. Separately, and as national guidance rather than Ohio law, the American Bar Association’s Formal Opinion 483 is generally read to require notifying a current client when a breach involves, or is substantially likely to involve, material client confidential information. The opinion sets its own definitions and limits, including how it treats former clients and incidents where nothing appears to have been taken. Read Opinion 483 itself, or take it to your ethics counsel, rather than relying on a summary. Either way, retention is worth treating as a security decision rather than a storage one: data a firm no longer holds is data nobody has to explain.
How does email compromise turn into a wire loss at a professional firm?
The pattern is consistent. An attacker gets into one mailbox, usually with a reused password and nothing but that password in the way, then reads quietly for weeks. They learn how your firm words a closing, who signs off on a disbursement, and which clients are mid-transaction. Then they send payment instructions that look exactly like yours, in your thread, at the moment everyone expects wire details to arrive.
The FBI’s Internet Crime Complaint Center recorded just over $3 billion in business email compromise losses across 24,768 complaints in 2025, second only to investment fraud among every crime type it tracks, with a further $275 million reported under real estate. Firms that hold client funds, run trust or escrow accounts, or sit in the middle of someone else’s transaction are exactly what this is built for. The controls that break the pattern are unglamorous: multi-factor authentication with no exceptions, alerting on mailbox rule changes and silent auto-forwarding, detection for lookalike domains, and a written callback procedure to a previously known number before any change to payment instructions is honored.
What does proving your firm enforces those controls actually look like?
The renewal application is where all of this turns into a yes-or-no question. Cyber insurance questionnaires for professional firms now ask whether multi-factor authentication is enforced, whether mailbox forwarding and rule changes are monitored, whether staff have completed security awareness training, and whether backups have been tested by restoring them. What an underwriter does with those answers is their side of the table, and not ours to speak to. What an IT provider can tell you is whether each answer survives someone asking for the artifact behind it: an exported policy, a coverage report measured against a current user list, a dated restore record. Most firms answer from memory, and memory is generous. The exception list is where the honest answer usually turns out to be qualified, and on a professional firm’s tenant the accounts sitting on that list tend to be the ones with the most authority over money.
Each of the controls above is a setting someone has to configure, and each one is set up differently. Enforced multi-factor authentication means it is not technically possible to sign in without the second factor, with every exclusion written down, dated and owned by a named person. Mailbox rule and auto-forward alerting means a new rule raises an alert somewhere a human is obligated to look, instead of surfacing weeks later when a client asks why nobody answered. Lookalike-domain detection means someone is watching for registrations that swap a character in your firm’s domain, so the first one you see is not the one already sitting in a client’s payment thread. And the callback procedure has to live inside the disbursement workflow itself: a specific step, a number you already had on file rather than the one in the email, and a person who performs it. A rule that exists only in a partner’s head is not something anyone can evidence. Alerts also need somewhere to land. Under a signed agreement, first response on an issue raised with us is targeted at one hour for a P1, meaning the whole company is down or disrupted, which is covered around the clock, and at two hours for a P2 or four hours for a P3 during business hours, Monday to Friday, 8:00AM to 5:00PM Eastern. Those are first-response targets. They are not fix times.
Evidencing is separate work from configuring, and it is the half that decays. A coverage report is only true against the device and user list it was run from, so it gets re-run rather than re-sent. A restore test counts as evidence only when it records the date, the systems and the outcome. Training completion is a roster with names and dates on it. Exceptions need a review date, and for a tax practice, where an account runs something else in place of multi-factor authentication, the Safeguards Rule allows that only where the firm’s Qualified Individual reviews and approves the reasonably equivalent or stronger control in writing (16 CFR 314.4(c)). Managed IT and cloud IT services cover the tenant side of the configuration work: enforcement, and the alerting on mailbox rules and forwarding. The callback step sits inside your own disbursement workflow rather than in IT, and it still has to be written down before anyone can evidence it. Virtual CISO and compliance work covers the rest: a gap analysis that finds what is missing, evidence tracking so the artifacts exist before anyone asks for them, and control maintenance between renewals so the file is not rebuilt from scratch every year. Start while the renewal is still months out, because closing a real gap takes longer than editing an answer.
What does Ohio’s cybersecurity safe harbor actually protect against?
Start by assuming a breach reaches the firm. Of the more than 1,400 ransomware complaints the FBI received in 2025 from businesses outside the sixteen critical infrastructure sectors, legal services was the most reported industry at 18 percent, with consulting services at 7 percent. Ohio then adds a lever federal law does not. Ohio Revised Code Chapter 1354, often called the Ohio Data Protection Act, took effect in 2018 and was among the first state cybersecurity safe harbor statutes in the country. It provides an affirmative defense to tort claims alleging that a failure to implement reasonable information security controls led to a breach. Raising it requires creating, maintaining and complying with a written cybersecurity program that reasonably conforms to one of the frameworks the statute recognizes in ORC 1354.03. Those frameworks include the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, the CIS Critical Security Controls and the ISO/IEC 27000 family, with separate routes for entities already regulated under HIPAA or Title V of the Gramm-Leach-Bliley Act. For an accounting firm that is the same work the FTC Safeguards Rule already requires, provided it is documented and actually followed.
The part firms miss is that the program has to stay current. When a listed framework publishes a final revision, the statute allows one year from the publication date stated in the revision to reasonably conform to it, and an amended law on one of the regulated routes carries the same one-year clock (ORC 1354.03(A)(2) and (B)(2)). That is not hypothetical. NIST published Cybersecurity Framework 2.0 in February 2024, so a program still written to the version the statute originally named is past its year. Where a framework mapping has not been revisited since the program was written, whether the defense still stands is a question for counsel.
What the defense does and does not do is worth being precise about. It is a shield against tort claims brought under Ohio law or in Ohio courts (ORC 1354.02(D)), not against contract claims, not against federal enforcement, and not against the notification duty. Chapter 1354 also creates no private right of action of its own, class actions included (ORC 1354.04). Its reach then depends on how the program is built: it can be written to protect personal information alone, or to protect personal information together with “restricted information,” a second category defined at ORC 1354.01(E), and the broader program earns the broader defense (ORC 1354.02(A)(2) and (D)(2)). Both categories are keyed to information about an identifiable individual whose exposure creates a material risk of identity theft or fraud, and Ohio’s definition of personal information in particular is narrower than most firms assume. The account-number prong, for instance, counts only when the credentials that would open the account come with it. Read ORC 1349.19(A)(7) and ORC 1354.01(E) before deciding which client material a program should cover.
Notice runs on its own track, and the safe harbor does not touch it. ORC 1349.19 requires notice to affected Ohio residents in the most expedient time possible and no later than 45 days following discovery of the breach or notification of it, once unencrypted computerized personal information has been accessed and acquired without authorization in a way that causes, or is reasonably believed to cause, a material risk of identity theft or other fraud to those residents. The section also carries qualifications and exceptions, including a delay for the legitimate needs of law enforcement, and different handling for entities already covered by certain federal notification regimes. Read ORC 1349.19 directly. One companion duty is easy to miss: where a single occurrence requires notice to more than 1,000 Ohio residents, the statute also requires notifying the nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution and content of those notices (ORC 1349.19(G)). All of which puts a premium on knowing what was actually accessed.
If you cannot say today which of those controls your firm has, that is the gap worth closing first. The Security Analysis is a paid, fully independent engagement at $349, mapped to 38 compliance frameworks, that produces a written picture of where your firm actually stands against them. It is deliberately not a sales call, and the findings are yours whether or not you ever hire anyone to act on them.
Start here
Find out where you actually stand
The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.
Questions we get asked
Does the Safeguards Rule exempt firms with fewer than 5,000 clients?
Only partly, and the exemption is far narrower than it sounds. Under 16 CFR 314.6, a financial institution that maintains customer information concerning fewer than five thousand consumers is excused from four specific items: the requirement that the risk assessment be written, the continuous monitoring or periodic penetration testing and vulnerability assessment regime, the written incident response plan, and the Qualified Individual’s regular written report to the governing body. Everything else applies in full, including encryption, multi-factor authentication, access controls, secure disposal, staff training, service provider oversight and FTC breach notification. The threshold also rewards careful counting, because the count is broader than a client list. The rule counts consumers whose information an institution maintains rather than engagements currently open, so former clients whose records are still held are in it, and 16 CFR 314.1(b) applies the part to all customer information in the institution’s possession, including consumer records another financial institution handed over, for people who were never its clients at all. Business-entity clients are not consumers under the rule, so a heavily commercial book can genuinely sit under the threshold, but that is worth confirming against 16 CFR 314.1(b), 314.2(b) and 314.6 rather than eyeballing it. TTS Cyber is not a law firm; this is not legal advice.
Can the Qualified Individual role be outsourced to an IT provider?
Yes. The Safeguards Rule allows the Qualified Individual to be employed by the covered firm, by an affiliate, or by a service provider (16 CFR 314.4(a)). Where an outside provider fills the role, three obligations follow: the firm retains responsibility for compliance, it must designate a senior member of its own personnel responsible for direction and oversight of that Qualified Individual, and it must require the provider to maintain an information security program that protects the firm in accordance with the rule. The arrangement buys expertise rather than moving accountability off the firm’s books. TTS Cyber’s Virtual CISO service is designed for that arrangement, with the firm keeping the internal oversight the rule requires. TTS Cyber is not a law firm; this is not legal advice.
What should we ask a practice management, document or cloud vendor before signing?
The Safeguards Rule already sets the shape of the answer, since it requires a covered firm to take reasonable steps to select providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess them based on the risk they present. In practice, ask where your data is stored and whether it is encrypted at rest, whether the vendor supports multi-factor authentication and single sign-on, what they commit to telling you after a security incident and on what timeline, whether they will identify their own subcontractors, and what happens to your data when the relationship ends. Get those answers into the contract rather than a sales email, because the rule places the contractual requirement on the financial institution rather than on the vendor. TTS Cyber is not a law firm; this is not legal advice.
How current does a cybersecurity program have to be for Ohio’s safe harbor?
Current enough to track the framework it names. Chapter 1354 protects a firm that creates, maintains and complies with a written program reasonably conforming to a listed framework, and when a listed framework publishes a final revision the statute allows one year from the publication date stated in that revision to reasonably conform to it (ORC 1354.03(A)(2), with the same one-year clock at (B)(2) for an amended law on one of the regulated routes). NIST published Cybersecurity Framework 2.0 in February 2024, so a program still written to the version the statute originally named is already past its year, and where a framework mapping has not been revisited since the document was written, whether the defense still stands is a question for counsel. Re-mapping to the current version of the named framework, with dated evidence that the program is actually followed, is the work that keeps it current. The limits hold either way: ORC 1354.02(D) reaches tort claims brought under Ohio law or in Ohio courts only, and ORC 1354.04 creates no private right of action. TTS Cyber is not a law firm; this is not legal advice.
When does a mailbox intrusion become an FTC-reportable event?
Sooner than most firms expect, and "we never saw the data leave" is not by itself the answer. Since May 2024 the FTC Safeguards Rule requires notifying the FTC as soon as possible and no later than 30 days after discovery of a notification event involving the unencrypted customer information of at least 500 consumers, and 16 CFR 314.2(m) presumes unauthorized access to unencrypted customer information to be unauthorized acquisition unless the institution holds reliable evidence showing acquisition did not happen and could not reasonably have happened. The burden runs toward reporting, so the questions to settle quickly are whose information sat in that mailbox, how many consumers it covers, and whether it was encrypted. Size does not lift this: the relief at 16 CFR 314.6 trims four specific provisions, and FTC breach notification is not one of them. TTS Cyber is not a law firm; this is not legal advice.
Primary sources
Read the rules yourself
Everything on this page rests on the text below. Where a section is named above, it is worth reading in the instrument rather than taking a summary for it, including this one.
Reference
Explained in full elsewhere on this site
Not legal advice
TTS Cyber is an IT and cybersecurity company, not a law firm, and nothing on this page is legal advice. This page summarises published rules and cites them so they can be read directly; where this page and the source differ, the source governs. Whether a particular rule reaches a particular business, and what it requires of that business, are legal questions for that business's own attorney.