Skip to main content

Practical Advice for Preventing Organizational Data Breaches

-

Add to Calendar

Online

Online, OK 00000

Get Directions

2.00 Credits

Member Price $105

Non-Member Price $135

Overview

In an era where generative AI and deepfake technology have revolutionized the precision of social engineering, the risk profile for professional service firms has shifted dramatically. Financial practitioners are no longer just defending against generic “spam”; they are now targets of highly coordinated attacks designed to exploit the specific trust and authority inherent in the CPA-client relationship. This course breaks down the anatomy of a modern breach-from ransomware extortion to sophisticated supply chain vulnerabilities-and provides a practical roadmap for securing a small-to-mid-sized firm without an enterprise-level IT budget.

Moving beyond simple firewall conversations, participants will explore the transition to a “Zero Trust” environment and the implementation of high-security protocols like passkeys and FIDO2 authentication. We will examine the increased regulatory scrutiny from frameworks like GLBA, GDPR, and the FTC Safeguards Rule, emphasizing how these requirements translate into daily firm operations. Attendees will walk away with a concrete incident response plan for the critical first 24 hours of a suspected breach, ensuring they have the tools to mitigate damage, protect client confidentiality, and maintain the integrity of their practice.

Highlights

AI-Powered Threats: Defending Against Deepfakes and Precision Phishing, Ransomware Evolution: From Data Encryption to Exfiltration Extortion, Zero Trust for Small Firms: Practical Access Control Strategies, First Responders: Managing the Critical 24 Hours Post-Breach

Prerequisites

There are no prerequisites for this session.

Designed For

CPAs and firm owners managing security for small-to-mid-sized professional practices.

Objectives

Analyze how generative AI and deepfakes are utilized in modern social engineering attacks., Implement “Zero Trust” security principles to protect sensitive data in small firm environments., Evaluate organizational vulnerabilities within the software supply chain and third-party SaaS providers., Design a practical incident response plan for the first 24 hours of a breach., Utilize advanced authentication methods and encryption to meet evolving professional regulatory requirements.

Preparation

No advance preparation is required.

Leader(s):

Leader Bios

Stephen Yoss Jr., Stephen M. Yoss, Jr., CPA, MS is a ce, K2 Enterprises

Stephen M. Yoss, Jr., CPA, is the partner, and principal of Devmatics, LLC, a software development company that focuses on solving problems through the implementation of technology. Stephen has consulted with several companies on how to lower overhead, personnel and compliance costs by investing in technology and reengineering their business practices. He teaches his clients to embrace technology at every opportunity in order to increase efficiency and productivity.
Stephen began working with technology at age ten, and started his first IT company at age 13, designing web applications for local businesses. He has presented to thousands of practitioners nationwide on topics such as cloud computing, mobile technology, spreadsheet design and best practices, information security, identity theft prevention and many more.

Return to Top

Non-Member Price $135

Member Price $105