CPA firms

You're already paying for security you never turned on

Most of the CPA firms I talk to are already paying for security tools nobody ever switched on.

1 min readOriginally posted on LinkedIn

Most of the CPA firms I talk to are already paying for security tools nobody ever switched on.

Here's what I mean. Microsoft 365 Business Premium — the plan a lot of small firms are already sitting on — includes Defender for Office 365 Plan 1. That's Safe Links and Safe Attachments: every link and attachment gets checked at the moment someone clicks it, not just when it landed in the inbox.

It also includes Entra ID P1, which is what lets you say "nobody signs in from outside the country" or "an unmanaged laptop doesn't get client files." And full Intune, so a phone left in an Uber gets wiped before anyone opens it.

Microsoft ships reasonable defaults and leaves the stronger settings for you to turn on. Most firms never get to the second half of that sentence.

Two weeks out from the October 15 deadline is exactly when a firm can't afford to lose three days to a compromised mailbox. The damage isn't a ransom payment. It's the returns that don't get filed, the clients you have to call and explain it to, and the cyber renewal conversation waiting for you in the spring.

If you're on Business Premium, you already bought all of this. Worth asking whoever runs your IT which parts are actually on.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions