CPAmerica ADVANTAGE News From Your Accounting Association
May 2022 IN THIS ISSUE: ► Cybersecurity as a journey, not a destination ► Preferred Provider Spotlight - MindBridge ► Member Services - LMS launch ► Member News ► CPAmerica Insights - Grace Horvath
Cybersecurity as a journey, not a destination Cybersecurity services provided by Frankel Zacharia & Gray, Gray & Gray
It is probably no surprise that the cybersecurity industry has changed exponentially in recent years. With ransomware attacks on the rise and individuals’ personal data being held hostage, an attack can compromise your business in many ways, aside from merely shutting you down. Frankel Zacharia has been serving clients’ cybersecurity needs since 2008 and IT director, Tim Weidman has seen firsthand the changes in the industry and the attackers. “When an incident occurred, it used to be that if you had a backup, you could simply restore it,” said Weidman. “And if you didn’t have a backup, you could pay a couple hundred dollars and get your files back. That doesn’t happen anymore, most ransomware won’t give you your data back for less than $1 million.” Weidman explained that the ransomware actors now not only steal your files, but also use them to blackmail and extort the company, the employees, their families and more. In this new world, your company’s goal should no longer be to prevent an attack from taking place, but rather to make attacks happen less often, make them do less damage and to allow the company to recover faster. Weidman says that if you’re not putting in place new cybersecurity controls each year, you may be leaving yourself and your company vulnerable.
Don’t miss our Member Sharing Call: Cybersecurity Insurance Coverage on May 25, 2022 at 4pm ET, register online at tinyurl.com/4pe6yjpn
These industry changes are exactly why the Gray, Gray & Gray team decided to make cybersecurity a priority and a service they wanted to offer to their clients.
“As part of our ‘power of more’ rebranding, we wanted to do more for our clients,” said Gray, Gray & Gray partner and chief operating officer, Hank Wolfson. “In meeting with our top clients, it became apparent that there was a desperate need for cybersecurity education, training and ensuring that the right protective safeguards are in place.” In adding this consulting service to their firm, Gray, Gray & Gray partnered with their long-time client, GraVoc Associates to develop a plan that best served their clients. This partnership provides the technological skills and resources to deliver a full slate of cybersecurity services, including multi-layered defense, end-point protection, secure backup, remote monitoring, employee training and testing, and compliance services to ensure clients are meeting the requirements of state, federal and international data security laws. “Our services are designed around being a better partner to our clients, with the goal of short- and long-term action plans for cybersecurity strategy going forward,” said Nathaniel Gravel, GraVoc cybersecurity consultant. If your company wants to refresh their own cybersecurity policies, Weidman recommends working off of a cybersecurity insurance requirement checklist, this will give your firm a good jumping off point to know what measures need to be in place to secure your firm. If you are interested in learning more about Frankel Zacharia’s cybersecurity services, please contact Tim Weidman at tweidman@ fzacpa.com. If you would like to learn more about Gray, Gray & Gray’s cybersecurity offerings, please contact Hank Wolfson at hwolfson@ gggllp.com. For a complete list of firms that provide these services, please contact Amy Azoulay at aazoulay@cpamerica.org.
Member Services: New learning management system (LMS) for members coming soon through partnership with Prolaera CPAmerica is pleased to announce the rollout of our new learning management system (LMS) through a partnership with Prolaera. This new partnership will expand and enrich CPAmerica’s current CPE offerings and online learning experience for members starting in early June. The CPAmerica team underwent a rigorous process to select the LMS provider offering the best platform for their members. The last several months were spent reviewing requests for proposal (RFPs), attending product demonstrations and conducting interviews with members. “We are excited to support members’ needs for training and CPE with our new LMS,” said CPAmerica president, Grace Horvath. “The post-pandemic workplace has made staff training and development even more challenging, and our partnership with Prolaera will further enhance the essential resources and benefits of membership.” CPAmerica’s LMS will provide members with access to a robust CPE compliance tracking tool, comprehensive reporting and an extensive catalog of top-rated CPE, all in one centralized location. “Prolaera’s vision perfectly aligns with CPAmerica’s goals to empower members with a modern learning and development platform that simplifies CPE management at its core,” added Prolaera founder, Evan Hiner. “We see numerous opportunities in our partnership with CPAmerica and their members to enhance their human capital at this time of rapid change in the industry.”
The LMS launch will commence with a complimentary webinar for members on the new platform June 15 at 3pm EST, featuring transformational leader and highly regarded industry speaker, Kimberly Ellison-Taylor, CPA, CGMA, CISA.
SAVE THE DATE Complimentary LMS Launch Webinar featuring Kimberly Ellison-Taylor, CPA, CGMA, CISA June 15, 2022 | 3pm ET Registration information coming June 1st!
SPECIAL THANK YOU TO OUR 2022 STRATEGIC EVENT SPONSOR
McGuire Sponsel is built for the CPA industry by acting as an extension of your firm. We value the CPA/client relationship and our service is unmatched in the industry. Your clients are not just a number to McGuire Sponsel but rather, an important relationship. Our team is committed to providing first-class service with integrity in a way that helps partner firms bring value to their clients.
For more, visit www.mcguiresponsel.com
CPAmerica Advantage | News From Your Accounting Association | MAY 2022 | 2
Member News Harper & Whitfield, P.C., CPAS advances team member to principal Harper & Whitfield P.C., a certified public accounting firm with has announced the advancement of Rebecca B. Zappone, CPA, MST, of Plymouth, CT to principal of the firm. Harper & Whitfield is fortunate to have Zappone join the leadership team and continue as an integral part of its forwardRebecca Zappone thinking and success for years to come. The firm recognizes the dedication and hard work that Zappone has consistently demonstrated, while providing excellent client service, managing the completion of numerous important internal administrative projects, and serving as a go-to resource throughout the firm. Zappone has more than 25 years of professional accounting experience, specializing in tax planning and compliance for individuals and closely held businesses. She represents clients in IRS and state income tax audits and other matters and facilitates staff training. The firm named Zappone a manager in 2008 and promoted her to director in 2018.
Matthews, Cutrer & Lindsay announce new audit manager Matthews, Cutrer & Lindsay, P.A. (MC&L), is excited to announce the newest addition to their team, Chery Lacey, CPA, who will be serving as one of the firm’s auditing managers. Lacey comes from a background of 25 years in audit management in Jackson, Miss. “We are so thankful to have Chery Lacey join our team,” shareholder Matt Freeland, Chery Lacey CPA said. “At MC&L, we pride ourselves on collaboration and professionalism with and for our clients, and Chery’s background is exemplary of both of those qualities.” With over 35 years of experience in the industry, Lacey specializes in overseeing auditing for governmental, nonprofit, and commercial entities. She will also help with tax preparation for nonprofit and commercial operations for MC&L.
Whalen & Co. CPAs announces new hire and promotion WhalenCPAs is proud to welcome a new audit service staff member, Vincent Meszaro. Meszaro brings to the team five years of financial and audit experience in
a range of industries. They are also excited to announce a new promotion. Brittany Engell, CPA, has been promoted to senior staff of accounting services. Engell joined the team in 2020 and has been an integral part of the Whalen team.
VonLehman announces new full-time hire VonLehman CPA & Advisory Firm is excited to announce that Taylor Jolly has officially joined the team as a full-time audit staff accountant! Jolly has been with the firm since December 2018, working as an audit co-op. She just completed her master’s program and will be graduating from Thomas More University on May 14th. When asked why Jolly decided to stay Taylor Jolly at VonLehman she said, “I chose to stay at VL because of the culture and environment of the firm. I love how everyone knows everyone, as well as the flexibility the firm gives everyone so that they’re able to live a balanced lifestyle. I am super excited to start my career here at VL!”
GRF partner appointed to AICPA women’s committee GRF CPAs & Advisors partner, Amy Boland, CPA has been appointed to a one-year term on the Association of International Certified Professional Accountants (AICPA) Women’s Initiatives Executive Committee (WIEC). The committee’s mission is to promote and support the success of women to advance the profession together. Boland joins other distinguished WIEC members from the accounting industry who work closely with AICPA staff to produce Amy Boland necessary and appropriate resources, as well as prepare for speaking engagements on the subject around the country. Committee members are dedicated to executing the Women’s Initiatives Executive Committee mission and vision and spreading the message for the need for women’s initiatives.
Harper & Pearson Company, P.C. celebrates its 60th anniversary Harper & Pearson Company, PC was founded 60 years ago, their three founders Bruce Harper, Fred Pearson and JB Lee decided to start their own CPA firm in Houston, Texas. Their success over the years is a tribute to their vision – helping
clients. They are proud to be celebrating this milestone anniversary!
Harper & Pearson Company, P.C., independently owned is a Houston-based, full-service accounting and consulting firm established in 1962 on a foundation of commitment to technical quality and dedication to client service. Their experienced professionals provide a comprehensive array of audit, tax, and consulting services to a diverse client base that includes a variety of businesses and high-net worth individuals. With a staff of approximately seventy professionals, our Firm is large enough to provide topnotch expertise and extensive resources and remain faithful to our tenet of personalized service.
Wallace Plese + Dreher managing partner recognized Wallace Plese + Dreher congratulates managing partner, Randy G. Brammer, CPA, CCIFP on his recognition and inclusion in People & Projects to Know (PTK) in Commercial Real Estate 2022. PTK highlighted 118 people involved in commercial real estate development, transactions, and professional services. In addition to accountants, Randy Brammer architects, attorneys, brokers, engineers, and general contractors were featured.
Wegner CPAs named a Top Workplace
Wegner CPAs has been named a Top Workplace by Wisconsin State Journal and Energage. Wegner was named a Top Workplace in the Madison, WI area and as a National Top Workplace. Headquartered in Madison, Wegner CPAs is a full-service accounting firm with offices in Baraboo, Janesville, Milwaukee, Reedsburg, New York, NY and Washington, D.C. Of their time with Wegner, one employee stated “I have the room to grow and am challenged, and still have the flexibility to adjust my schedule around my family life. I love the work I do, and Wegner encourages growth and a work life balance.”
CPAmerica Advantage | News From Your Accounting Association | MAY 2022 | 3
CPAmerica Insights Valuable lessons learned in cybersecurity “It’s not what happens to you, it’s how you react that matters.” - Epictetus I sat listening intently to a well-respected technology expert on pervasively increasing Grace Horvath, cybersecurity threats President during our January Large Firm Group Meeting. I wrote in my notes, “it’s not if, but when,” and made a note to check our insurance policies for cybersecurity insurance and ransomware coverage. The following week, our board met and we reviewed our annual enterprise risk management analysis. I reassured them that we had appropriate structures in place to mitigate the risks of a cybersecurity breach and business interruption. And then on January 31, we were hit. This experience cannot be summed up in this article. We have since recovered with some positive outcomes, but we still lost a lot of data and time. I would like to share some things I learned so that when, not if, this happens to you, you have an idea of what to expect. On the morning of January 31, an early riser staff member sent an email to our IT Department reporting no access to the remote desktop platform we have in place to accommodate anytime-anywhere work. (Note – that was our safeguard against business interruption.) This was not immediately alarming as you know from common experience that hiccups happen for no apparent reason, and your IT people tweak something and you move on. This time it was not fixing, and our nightmare began to unfold. I have known our IT director a long time, and this was the first I have seen a wrinkle in his composure when he said, “I’m pretty sure we’ve been hacked.” Our system had been completely breached. All systems were down, two of our backups had been wiped out and our third, locked out. (Note - that was our safeguard against data breach.) The ransom note was found buried deep within our directory ominously labeled, “If you want your stuff back, open this.” As in any case of shock, there is a time lapse for the enormity of the situation to sink in. My first thoughts were: how does this affect the members and our staff, and are they safe? Imagine doing
a spontaneous mental inventory of systems and data to assess the potential impact and damage of the situation. A call to our insurance connected us to the cybersecurity carrier who immediately engaged us with a team of cyber incident response specialists that included attorneys, digital forensics specialists, and negotiators. I learned an astounding amount during our daily calls that were conducted like a military defense response. Sometimes I felt like I was on a short-wave radio rather than a Teams call. We learned during our debriefings that our “threat actors” (TAs) are a newer, notorious group known for being erratic and difficult. Though our carrier stated current average ransom is $40,000, these guys wanted $800,000 for a “decryption key” to retrieve our files with no guarantee that our files would not be leaked and sold on the dark web. Reading the transcripts was surreal and sickening, as most of us have only seen such things in the movies. For not meeting deadlines, the TAs hurled threats of DDoS attacks (distributed denial-ofservice) which is the internet equivalent of a blitzkrieg to the website and contacting our members (which they did). With round-the-clock work and a dose of sheer luck, we were able to restore most of our backups which positioned us to not pay the ransom. We successfully survived ongoing DDoS attacks by employing multiple third parties to create protective barriers. Forensics finally concluded in March, unable to identify the exact point of breach. The best we could come to was either someone clicked on something or
Upcoming Event Dates Scan the QR code below for complete event information, a full list of events and to complete your registration.
there was a vulnerability created with software update. Regular communications and managing expectations for staff and members alike were key. Due to the sensitivity of a ransomware attack and all the unknowns, legal counsel reviewed all communications. The amount of information you do not have is glaring in these circumstances. The importance of the forensics investigation in getting yourself out of the dark and operational cannot be underestimated. Despite causing a dire situation, the sophistication of the TAs’ work is impressive. These people are brilliant opportunists and their operations run like a business, even referring to their “policies and procedures” during negotiations. As hard and as smart as we work to prevent cyberattacks, they will continue to successfully counter our efforts. I implore you, if have not recently done so, consider testing your systems, continually train your people, revisit your disaster recovery plans, and review your coverage. We will continue to share our lessons learned.
Contact us at: 7555 W. University Ave. Gainesville, FL 32607 (352) 727-4070 www.cpamerica.org
Follow us on social:
Send feedback and member firm news to: advantage@cpamerica.org
CPAmerica Advantage | News From Your Accounting Association | MAY 2022 | 4