Managed IT and Cybersecurity for Columbus Professional Services Firms
Your firm runs on two things clients never see: a mailbox and a document store. Both hold confidential client material, both are reachable from the internet, and both sit under duties that come from your licensing body and from federal regulators rather than from your IT budget. If your practice prepares tax returns for compensation, one of those duties is already written law, whether or not the document exists.
Does your tax practice need a Written Information Security Plan?
Yes, if you prepare returns for compensation, and the IRS puts the question in front of you every year. Form W-12, the PTIN application and renewal, carries line 11, Data Security Responsibilities, and you must check a box next to this statement: “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.” The law behind that sentence is the Gramm-Leach-Bliley Act, which directs the Federal Trade Commission to set safeguard rules for companies the law defines as financial institutions. The rule reaches an accountant or other tax preparation service that is in the business of completing income tax returns (16 CFR 314.2(h)(2)(viii)), and the IRS says the same thing in plainer terms in its own guidance every filing season: a written data security plan is required by law, not merely a good idea. If your practice does not prepare returns, whether the rule reaches you at all turns on that definition, which is worth confirming against 16 CFR 314.2(h) rather than assuming in either direction.
The plan is not a document you write once and file. The FTC Safeguards Rule requires you to designate a Qualified Individual to oversee the program, to base it on a risk assessment, to encrypt customer information in transit over external networks and at rest, to require multi-factor authentication for anyone accessing any information system, to train your staff, to oversee the service providers who touch that data, and to keep a written incident response plan. The rule does allow narrow alternatives — compensating controls where encryption is genuinely infeasible, and reasonably equivalent or stronger controls in place of multi-factor authentication — but only where your Qualified Individual reviews and approves them in writing (16 CFR 314.4(c)). Treat those as documented exceptions you can defend, not as defaults.
Since May 2024 the rule also requires you to notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving the unencrypted customer information of at least 500 consumers. Read how the rule defines that event before you assume you are clear of it: unauthorized access to unencrypted customer information is presumed to be unauthorized acquisition unless you hold reliable evidence showing acquisition did not happen and could not reasonably have happened (16 CFR 314.2(m)). The burden runs toward reporting, so “we never saw the data leave” is not by itself an answer. Being small does not lift the rule off you either. Below a consumer threshold it trims a short list of provisions and nothing more (16 CFR 314.6), which the first FAQ below covers.
What does Ohio’s ethics rule require a law firm to do about client data?
Ohio Rule of Professional Conduct 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information related to the representation of a client. The rule’s commentary is the part worth reading twice: unauthorized access is not automatically a violation if you made reasonable efforts, and reasonableness is judged on factors the commentary lists, including the sensitivity of the information, how likely disclosure was without additional safeguards, and the cost and difficulty of those safeguards.
That standard rewards firms that write things down. A practice that can show what it evaluated, what it put in place, and why it drew the line where it did is in a very different position than one reconstructing its reasoning after an incident. Separately, and as national guidance rather than Ohio law, the American Bar Association’s Formal Opinion 483 is generally read to require notifying a current client when a breach involves, or is substantially likely to involve, material client confidential information. The opinion sets its own definitions and limits — including how it treats former clients and incidents where nothing appears to have been taken — so read Opinion 483 itself, or take it to your ethics counsel, rather than relying on a summary. Either way, retention is worth treating as a security decision rather than a storage one: data you no longer hold is data you never have to explain.
How does email compromise turn into a wire loss at a professional firm?
The pattern is consistent. An attacker gets into one mailbox, usually with a reused password and nothing but that password in the way, then reads quietly for weeks. They learn how your firm words a closing, who signs off on a disbursement, and which clients are mid-transaction. Then they send payment instructions that look exactly like yours, in your thread, at the moment everyone expects wire details to arrive.
The FBI’s Internet Crime Complaint Center recorded $3,046,598,558 in business email compromise losses across 24,768 complaints in 2025, second only to investment fraud among every crime type it tracks, with a further $275 million reported under real estate. Firms that hold client funds, run trust or escrow accounts, or sit in the middle of someone else’s transaction are exactly what this is built for. The controls that break the pattern are unglamorous: multi-factor authentication with no exceptions, alerting on mailbox rule changes and silent auto-forwarding, detection for lookalike domains, and a written callback procedure to a previously known number before any change to payment instructions is honored.
What does Ohio’s cybersecurity safe harbor actually protect your firm from?
Start by assuming a breach reaches you. Of the more than 1,400 ransomware complaints the FBI received in 2025 from businesses outside the sixteen critical infrastructure sectors, legal services was the most reported industry at 18 percent, with consulting services at 7 percent. Ohio then gives you a lever federal law does not. Ohio Revised Code Chapter 1354, often called the Ohio Data Protection Act, took effect in 2018 and was among the first state cybersecurity safe harbor statutes in the country. It provides an affirmative defense to tort claims alleging that a failure to implement reasonable information security controls led to a breach. To raise it, you must create, maintain and comply with a written cybersecurity program that reasonably conforms to one of the frameworks the statute recognizes in ORC 1354.03 — among them the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, the CIS Critical Security Controls and the ISO/IEC 27000 family, with separate routes for entities already regulated under HIPAA or Title V of the Gramm-Leach-Bliley Act. For an accounting firm that is the same work the FTC Safeguards Rule already obliges you to do, provided it is documented and actually followed.
The part firms miss is that the program has to stay current. When a listed framework publishes a final revision, you have one year from the publication date stated in the revision to reasonably conform to it, and an amended law on one of the regulated routes carries the same one-year clock (ORC 1354.03(A)(2) and (B)(2)). That is not hypothetical. NIST published Cybersecurity Framework 2.0 in February 2024, so a program still written to the version the statute originally named is past its year. If nobody has revisited your framework mapping since the program was written, the defense you think you have may already be gone.
Understand what the defense does and does not do. It is a shield against tort claims brought under Ohio law or in Ohio courts (ORC 1354.02(D)), not against contract claims, not against federal enforcement, and not against your notification duty. Chapter 1354 also creates no private right of action of its own, class actions included (ORC 1354.04). Its reach then depends on a choice you make when you build the program: you can write it to protect personal information alone, or to protect personal information together with “restricted information,” a second category defined at ORC 1354.01(E), and the broader program earns the broader defense (ORC 1354.02(A)(2) and (D)(2)). Both categories are keyed to information about an identifiable individual whose exposure creates a material risk of identity theft or fraud, and Ohio’s definition of personal information in particular is narrower than most firms assume — the account-number prong, for instance, counts only when the credentials that would open the account come with it. Read ORC 1349.19(A)(7) and ORC 1354.01(E) before deciding which of your client material the program should cover, or ask us to walk your data through them.
Notice runs on its own track, and the safe harbor does not touch it. ORC 1349.19 requires notice to affected Ohio residents in the most expedient time possible and no later than 45 days following discovery of the breach or notification of it, once unencrypted computerized personal information has been accessed and acquired without authorization in a way that causes, or is reasonably believed to cause, a material risk of identity theft or other fraud to those residents. The section also carries qualifications and exceptions — including a delay for the legitimate needs of law enforcement, and different handling for entities already covered by certain federal notification regimes — so read ORC 1349.19, or ask us to walk your situation through it. One companion duty is easy to miss: if a single occurrence requires you to notify more than 1,000 Ohio residents, you must also notify the nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution and content of those notices (ORC 1349.19(G)). All of which means knowing what was accessed is not optional either.
If you cannot say today which of those controls your firm has, that is the gap worth closing first. The Security Analysis is a paid, fully independent engagement at $349, mapped to 38 compliance frameworks, that produces a written picture of where your firm actually stands against them. It is deliberately not a sales call, and the findings are yours whether or not you ever hire anyone to act on them.
Start here
Find out where you actually stand
The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.
Questions we get asked
Our firm has fewer than 5,000 clients. Are we exempt from the Safeguards Rule?
Only partly, and the exemption is far narrower than it sounds. Under 16 CFR 314.6, a financial institution that maintains customer information concerning fewer than five thousand consumers is excused from four specific items: the requirement that the risk assessment be written, the continuous monitoring or periodic penetration testing and vulnerability assessment regime, the written incident response plan, and the Qualified Individual’s regular written report to the governing body. Everything else applies in full, including encryption, multi-factor authentication, access controls, secure disposal, staff training, service provider oversight and FTC breach notification. Count the threshold carefully as well, because the count is broader than a client list. The rule counts consumers whose information you maintain rather than engagements you currently have open, so former clients whose records you still hold are in it, and 16 CFR 314.1(b) applies the part to all customer information in your possession — including consumer records another financial institution handed you, for people who were never your clients at all. Business-entity clients are not consumers under the rule, so a heavily commercial book can genuinely sit under the threshold, but confirm that against 16 CFR 314.1(b), 314.2(b) and 314.6 rather than eyeballing it.
Can we outsource the Qualified Individual role to our IT provider?
Yes. The Safeguards Rule allows the Qualified Individual to be employed by you, by an affiliate, or by a service provider (16 CFR 314.4(a)). If you use an outside provider, three obligations follow: your firm retains responsibility for compliance, you must designate a senior member of your own personnel responsible for direction and oversight of that Qualified Individual, and you must require the provider to maintain an information security program that protects you in accordance with the rule. It is a way to buy expertise you do not have on staff, not a way to move accountability off your books. TTS Cyber’s Virtual CISO service is designed for that arrangement, with your firm keeping the internal oversight the rule requires.
What should we ask a practice management, document or cloud vendor before signing?
The Safeguards Rule already sets the shape of the answer, since it requires you to take reasonable steps to select providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess them based on the risk they present. In practice, ask where your data is stored and whether it is encrypted at rest, whether the vendor supports multi-factor authentication and single sign-on, what they commit to telling you after a security incident and on what timeline, whether they will identify their own subcontractors, and what happens to your data when the relationship ends. Get those answers into the contract rather than a sales email, because the contractual requirement falls on you, not on them.