CironeFriedberg, LLP

Client Portal
Online Payment
Newsletter Signup
MENUMENU
  • About
  • Team
    • Partners/Principals
    • Managers
  • Services
    • Audit & Assurance
    • Client Accounting Services
    • Business Tax
    • Business Valuation
    • Individual Tax
    • Outsourced CFO/Controller
    • Accounting Advisory
    • Forensic & Litigation
  • Industries
  • Careers
  • Insights
  • Contact
  • ONLINE PAYMENT
  • NEWSLETTER SIGNUP
MENUMENU
  • About
  • Team
    • Partners/Principals
    • Managers
  • Services
    • Audit & Assurance
    • Client Accounting Services
    • Business Tax
    • Business Valuation
    • Individual Tax
    • Outsourced CFO/Controller
    • Accounting Advisory
    • Forensic & Litigation
  • Industries
  • Careers
  • Insights
  • Contact
  • ONLINE PAYMENT
  • NEWSLETTER SIGNUP

Cybersecurity: Essential for All Transactions

October 18, 2022 by Sandra Callanan CPA

man writing cyber security

Cybersecurity — especially data privacy — is one of the biggest problems facing businesses today. These security problems are compounded because every segment of every industry is affected differently, and each is subject to the risk factors peculiar to that segment. Grouping similar data together based on chosen parameters allows businesses to assess the privacy needs of each data segment they are holding. For example, the protections for public data don’t have to be as stringent as the protections for private data.

Protecting the privacy of the data with which they are entrusted is a universal business goal. The best way to get started is to answer the following questions:

  • What types of data does your business have (e.g., credit card information, health information, criminal history, biometrics)?
  • Which departments have access to that data?
  • Who are your data service providers and what are their credentials?
  • Which personnel can access the data?
  • What steps has your company taken to protect the data (e.g., encryption, back-up, internal controls)?

Federal and International Regulations

The United States has no federal law protecting data privacy. A number of states, however, are responding: at least 31 states have already established laws regulating the secure destruction or disposal of personal information. At least 12 states — Arkansas, California, Connecticut, Florida, Indiana, Maryland, Massachusetts, Nevada, Oregon, Rhode Island, Texas and Utah — have imposed broader data security requirements. Other states, including New York, are considering legislation.

California is a pioneer on the data privacy front. The California Consumer Privacy Act of 2018, which went into effect on January 1, 2020, is similar to the General Data Protection Regulation (GDPR). Companies that do business in California will be affected by this legislation.

At least some of the activity at the state level is in response to the European Union’s enactment of the GDPR. Any company doing business in a nation that has adopted the GDPR must comply with its consumer protections regarding data privacy. The GDPR covers many types of data, including the following:

  • Personally identifiable data (e.g., names, addresses, date of births, Social Security numbers)
  • Web-based data (e.g., user location, IP address, cookies, and RFID tags)
  • Health (HIPAA) and genetic data
  • Biometric data
  • Racial or ethnic data

The bottom line is that U.S. businesses operating in multiple jurisdictions must consider these categories, as well as any other categories pertinent to their industry, as they segment the data they are holding. Understanding the data they hold is essential to instituting the right level of privacy safeguards.

Three Steps to Securing Your Data

Understanding your data is the first step to securing data. The second step requires knowing the relevant laws and regulations your business must comply with.

The third step is to stay alert for any indications of a breach. The sad truth is that many data breaches go on for quite a while before they are discovered. The time lapse between hack and discovery allows hackers to continue accessing vulnerable data. That makes constant monitoring an important aspect of any data security program. Watching for the signs of a breach — such as an unanticipated spike in bandwidth usage — can indicate a problem.

By following these three steps, businesses can be sure they are doing their best to protect the data they and their data service providers hold.

Filed Under: Cybersecurity Tagged With: cybersecurity, encryption, fraud, internal controls, phishing, privacy

Cyberattacks Accelerate and Target Excel Users

February 24, 2022 by Teri Pough

Cyberattack

According to Check Point, in the last quarter of 2021 there were over 900 weekly cyber-attacks per organization recorded. In 2021, there was a 50% increase in overall attacks per week on corporate networks compared to the previous year.

The Journal of Accountancy recently published an article on the alarming rise in cyberattacks occurring in the last three months of 2021 related to Microsoft Excel. The article cited the Q4 2021 Threat Insights Report from HP Wolf Security, which detected a 588% rise in campaigns using malicious Microsoft Excel add-in (XLL) files intended to infect computer systems. This is particularly alarming, as this number reflects an increase compared only to the previous three months.

Cyberattacks using malicious add-in files were deployed through emails with .XLL attachments or links. When the recipient opened the attachment or link, they were prompted to install the Excel add-in. Just one click activated the malicious malware.

The Threat Insights Report recommends three steps each organization can take to protect themselves for these Excel attacks:

  1. Configure email gateway to block inbound emails containing XLL attachments
  2. Configure Microsoft Excel to permit add-ins only by trusted publishers
  3. Configure Microsoft Excel to disable add-ins

Cyberattacks can disrupt operations and put the finances and data of businesses at risk. For more information on this topic, see the reference links below.

If you need assistance or have any questions on the information in this article, please call your CironeFriedberg professional. You can reach us by phone at (203) 798-2721 (Bethel), (203) 366-5876 (Shelton), or (203) 359-1100 (Stamford) or email us at info@cironefriedberg.com.

 

Filed Under: Connecticut Businesses, Cybersecurity, Small Business Tagged With: cybersecurity

Have questions? Click here to connect with us!
  • About
  • Team
  • Industries
  • Careers
  • Insights
  • Contact
  • Privacy Policy

SERVICES

  • Audit & Assurance
  • Business Tax Services
  • Business Valuation
  • Individual Tax
  • Outsourced CFO/Controller
  • Forensic Litigation
  • Accounting Advisory
  • Client Accounting

Bethel, CT

24 Stony Hill Road
Bethel, CT 06801

Phone: 203-798-2721
Fax: 203-743-0280
Email Us

SHELTON, CT

6 Research Drive, Suite 450
Shelton, CT 06484

Phone: 203-366-5876
Fax: 203-366-1924
Email Us

Darien, CT

320 Boston Post Rd, Suite 180
Darien, CT 06820

Phone: 203-359-1100
Fax: 203-366-1924
Email Us

STAY CONNECTED

NEWSLETTER SIGNUP
follow us on facebook connect with us on linkedin
Member CPAmerica, Inc.

CironeFriedberg is an independently owned and operated member firm of CPAmerica, Inc., one of the largest associations of CPA firms in the United States. Through our affiliation, we have instant access to the expertise and resources of more than 2,800 professionals and more than 750 partners.

CironeFriedberg offers clients unique access to national and international markets through our membership in CPAmerica, an association of independent accounting firms that maintain the highest practice standards.


CironeFriedberg provides services in Fairfield and New Haven Counties in CT and Dutchess, Putnam, and Westchester Counties in NY
© 2023 CironeFriedberg, LLP
WEB DESIGN: WIETING DESIGN.COM
  • About
  • Team
    • Partners/Principals
    • Managers
  • Services
    • Audit & Assurance
    • Client Accounting Services
    • Business Tax
    • Business Valuation
    • Individual Tax
    • Outsourced CFO/Controller
    • Accounting Advisory
    • Forensic & Litigation
  • Industries
  • Careers
  • Insights
  • Contact
  • ONLINE PAYMENT
  • NEWSLETTER SIGNUP