How Often Should Accounting Firms in Los Angeles Perform Security Risk Assessments and IT Audits?

For most accounting firms, a comprehensive security risk assessment should be performed at least once a year, with additional reviews whenever significant business, technology, or cybersecurity changes occur.
Examples include:
- Office relocations or expansions
- Mergers or acquisitions
- Cloud migrations
- Microsoft 365 security changes
- Adoption of AI tools such as Microsoft Copilot
- Cybersecurity incidents
- Changes in cyber insurance requirements
- Implementation of new accounting software
Routine assessments help leadership identify emerging risks before they become business disruptions.
For accounting firms throughout Los Angeles County and Greater Los Angeles, where sensitive financial information and strict client expectations are part of daily operations, cybersecurity assessments should be viewed as an ongoing governance process rather than a compliance checkbox.
Why Risk Assessments Matter More Than Ever
Cyber threats evolve continuously.
A cybersecurity strategy that was appropriate two years ago may no longer provide adequate protection today.
Meanwhile, accounting firms are constantly changing.
Examples include:
- Hiring new employees.
- Supporting hybrid work.
- Migrating to Microsoft 365.
- Implementing secure client portals.
- Adding AI-powered productivity tools.
- Expanding into additional office locations.
Every business change also changes your technology risk profile.
Without regular assessments, vulnerabilities often remain undiscovered until after an incident occurs.
Why This Matters
You cannot reduce risks that you haven’t identified.
Security assessments provide leadership with the visibility needed to prioritize technology investments based on actual business risk rather than assumptions.
Security Risk Assessment vs. IT Audit
These terms are often used interchangeably, but they serve different purposes.
Understanding the distinction helps firms choose the right type of review.
| Security Risk Assessment | IT Audit |
|---|---|
| Identifies cybersecurity risks | Evaluates operational effectiveness |
| Focuses on future threats | Reviews current controls |
| Prioritizes improvements | Verifies compliance with policies |
| Supports strategic planning | Supports governance and accountability |
| Ongoing risk management | Point-in-time evaluation |
Most accounting firms benefit from performing both on a regular basis.
Rather than replacing one another, they work together to strengthen cybersecurity, operational resilience, and executive oversight.
Why This Difference Matters
- A security assessment answers: “Where are we vulnerable?”
- An IT audit answers: “Are our processes working as intended?”
Together, they provide leadership with a more complete understanding of the firm’s technology environment.
The Six Areas Every Security Risk Assessment Should Review
An effective assessment evaluates more than firewalls and antivirus software.
It should examine the entire technology environment from both a business and cybersecurity perspective.
Area #1 — Identity and Access Management
Most successful cyberattacks begin by compromising user identities rather than devices.
Every assessment should review:
- Multi-Factor Authentication (MFA)
- Microsoft 365 identities
- Administrator accounts
- Password policies
- Conditional Access
- Privileged access
- Account lifecycle management
Executive Planning Tip
Identity protection should always be one of the highest-priority sections of a security assessment because it directly affects every user and every cloud service within the organization.
Decision Table
| Assessment Question | Healthy Environment | Warning Sign |
|---|---|---|
| Is MFA enabled for every user? | Yes | Only administrators use MFA |
| Are inactive accounts removed promptly? | Yes | Former employee accounts remain active |
| Are administrator privileges limited? | Yes | Multiple users have unnecessary administrative rights |
Area #2 — Endpoint Security and Device Management
Every laptop, desktop, and mobile device connected to your firm’s network represents a potential entry point for cybercriminals.
As accounting firms expand hybrid work arrangements and support employees across multiple locations, endpoint security becomes increasingly important.
A comprehensive assessment should evaluate:
- Endpoint Detection and Response (EDR)
- Antivirus effectiveness
- Operating system patch levels
- Device encryption
- Local administrator privileges
- Mobile device management (MDM)
- Hardware lifecycle status
- Remote wipe capabilities
Why This Matters
Even the strongest firewall cannot protect a compromised laptop used outside the office. Every endpoint should receive the same level of protection regardless of where employees work.
Area #3 — Microsoft 365 and Cloud Security
Microsoft 365 is often the most critical business platform within an accounting firm.
A security assessment should verify that cloud services are configured securely and aligned with the firm’s governance policies.
Review areas should include:
- Multi-Factor Authentication (MFA)
- Conditional Access
- Microsoft Defender
- SharePoint permissions
- OneDrive sharing
- Microsoft Teams governance
- Data Loss Prevention (DLP)
- External collaboration
- Identity monitoring
Executive Planning Tip
Do not assume default Microsoft 365 settings provide adequate protection. Security should be reviewed regularly as new features, licensing options, and business requirements evolve.
Area #4 — Network Infrastructure and Perimeter Security
Although many workloads have moved to the cloud, network infrastructure remains essential to daily operations.
A security assessment should evaluate:
- Firewall configuration
- Secure remote access
- Wireless network security
- Guest network separation
- VPN policies
- Internet redundancy
- Network segmentation
- Firmware updates
Decision Table
| Assessment Question | Healthy Environment | Warning Sign |
|---|---|---|
| Is the firewall actively managed? | Yes, with regular rule reviews | Configuration has not been reviewed in years |
| Is guest Wi-Fi isolated? | Completely separated from business systems | Guests share the production network |
| Is remote access secured? | VPN or Zero Trust with MFA | Direct exposure to the internet |
Area #5 — Backup and Business Continuity
Cybersecurity and business continuity are closely connected.
Even well-protected firms should prepare for hardware failures, ransomware, or other unexpected disruptions.
A risk assessment should verify:
- Backup frequency
- Backup retention
- Off-site or immutable storage
- Backup monitoring
- Restore testing
- Recovery Time Objectives (RTO)
- Recovery Point Objectives (RPO)
- Business continuity documentation
Why This Matters
The question is no longer, “Do we have backups?”
It is, “How quickly can we resume serving clients if something goes wrong?”
Area #6 — Employee Awareness and Security Culture
Technology alone cannot eliminate cyber risk.
Employees remain one of the most important components of a firm’s cybersecurity strategy.
An effective assessment should review:
- Security awareness training
- Phishing simulations
- Acceptable use policies
- Password management practices
- AI usage guidelines
- Incident reporting procedures
- Remote work security practices
Organizations with well-trained employees often identify suspicious activity sooner and recover more effectively from security incidents.
Key Insight
Cybersecurity is strongest when technology, processes, and people work together.
Cybersecurity Maturity Model
Every accounting firm is at a different stage of cybersecurity maturity.
Use the following framework to evaluate your current position.
| Level | Characteristics |
|---|---|
| Reactive | Limited security controls, inconsistent documentation, assessments performed only after incidents. |
| Protected | Core security technologies deployed, annual assessments performed, documented policies in place. |
| Managed | Regular assessments, executive reporting, governance, Microsoft 365 optimization, employee training. |
| Resilient | Continuous improvement, Zero Trust principles, AI governance, business continuity integration, strategic oversight. |
Cybersecurity maturity should improve steadily over time rather than through isolated technology purchases.
Annual Security Assessment Timeline
The following schedule provides an example of how accounting firms can maintain continuous visibility into technology risks.
| Quarter | Recommended Activities |
|---|---|
| Q1 | Comprehensive security risk assessment, technology inventory review, identity audit |
| Q2 | Microsoft 365 security review, vulnerability scanning, employee security awareness training |
| Q3 | Backup restoration testing, disaster recovery exercise, endpoint review |
| Q4 | Executive cybersecurity review, budget planning, technology roadmap updates, AI governance review |
This cadence helps organizations identify emerging risks before they affect operations.
Risk Prioritization Framework
Not every vulnerability presents the same level of business risk.
Security assessments should classify findings according to business impact.
| Risk Level | Recommended Response |
|---|---|
| Critical | Immediate remediation (24–72 hours) |
| High | Address within 30 days |
| Medium | Include in the next scheduled improvement cycle |
| Low | Monitor and review during future assessments |
Prioritizing findings helps leadership allocate resources effectively while addressing the most significant risks first.
Executive Assessment Checklist
Use this checklist during your next technology review.
Identity & Access
☐ MFA enabled for all users
☐ Conditional Access configured
☐ Administrative privileges reviewed
☐ Dormant accounts removed
Devices
☐ Endpoint Detection and Response (EDR)
☐ Device encryption
☐ Patch compliance
☐ Hardware lifecycle review
Microsoft 365
☐ Defender configuration reviewed
☐ SharePoint permissions audited
☐ OneDrive sharing evaluated
☐ Teams governance documented
Business Continuity
☐ Backup restoration tested
☐ Disaster recovery plan reviewed
☐ Business continuity documentation updated
☐ Recovery objectives validated
Governance
☐ Annual security assessment completed
☐ Employee security awareness training delivered
☐ Executive cybersecurity report reviewed
☐ Technology roadmap updated
Common Findings During Security Assessments
Many accounting firms discover similar issues during routine assessments.
Common findings include:
- Legacy User Accounts
- Former employees or contractors retain unnecessary access to Microsoft 365 or business applications.
- Excessive Administrative Privileges
- Too many users have elevated permissions, increasing organizational risk.
- Outdated Hardware
- Aging workstations, servers, or networking equipment no longer receive security updates or support.
- Overly Broad File Sharing
- SharePoint, OneDrive, or Teams permissions have expanded over time without periodic review.
- Inconsistent Documentation
- Policies, recovery procedures, and asset inventories have not been updated to reflect current operations.
Cost Expectations
Security risk assessments vary based on firm size, infrastructure complexity, and the scope of the review.
For accounting firms with 20–100 employees, assessments may be performed as:
- A standalone cybersecurity engagement.
- An annual governance review.
- Part of a Managed IT Services agreement.
- A cyber insurance readiness assessment.
Organizations should focus less on the cost of the assessment itself and more on the value of identifying security gaps before they result in operational disruption or financial loss.
“The most effective security assessments don’t simply identify vulnerabilities. They help leadership make informed decisions about which risks matter most and how to reduce them over time.”
Why Security Assessments Matter in Los Angeles
Accounting firms across Los Angeles County and Greater Los Angeles operate in an environment where cyber threats, client expectations, and technology requirements continue to evolve.
Regular security risk assessments help firms maintain visibility into their technology environment while supporting strategic planning, operational resilience, and responsible growth. Rather than treating cybersecurity as an annual project, successful firms integrate assessments into their ongoing business planning and governance processes.
Real-World Planning Scenario
How an Annual Security Assessment Helped a Los Angeles Accounting Firm Identify Hidden Risks
A growing accounting firm in Los Angeles County had steadily invested in technology over several years. The firm had implemented Microsoft 365, enabled Multi-Factor Authentication (MFA), adopted secure client portals, and worked with a Managed IT Services Provider that monitored its systems around the clock.
Leadership assumed the firm’s cybersecurity posture was strong.
During its annual security risk assessment, however, several opportunities for improvement were identified, not because the technology had failed, but because the business had evolved.
The assessment revealed:
- Former employees still had inactive Microsoft 365 accounts that had not been fully removed.
- SharePoint permissions had expanded as new departments and client projects were added.
- Several laptops were approaching end-of-support and no longer aligned with the firm’s hardware lifecycle plan.
- Backup monitoring was functioning correctly, but restoration testing had not been performed recently.
- Cybersecurity awareness training had not been repeated since the previous year.
- AI usage guidelines had not been established despite employees beginning to experiment with generative AI tools.
None of these findings represented an active security incident. However, each represented an opportunity to reduce future risk.
Following the assessment, leadership prioritized remediation over the next two quarters as part of its broader technology roadmap.
The result was a stronger governance process, improved visibility into the firm’s technology environment, and greater confidence that security investments aligned with business priorities.
This example illustrates an important principle: the value of a security assessment lies in identifying manageable risks before they become operational problems.
Executive Decision Framework
Use the following framework to determine the right cadence for cybersecurity reviews within your accounting firm.
If Your Firm Has Never Completed a Formal Security Assessment
Begin with a comprehensive baseline review.
Recommended priorities include:
- Asset inventory
- Identity and access review
- Microsoft 365 assessment
- Backup verification
- Firewall and network review
- Executive risk report
If You Completed an Assessment More Than 12 Months Ago
Technology and cyber threats have likely changed.
Recommended next steps:
- Perform a new security risk assessment.
- Review Microsoft 365 security settings.
- Validate backup restoration procedures.
- Reassess user access and permissions.
- Update the technology roadmap.
If Your Firm Recently Expanded or Changed Technology
Business changes often introduce new risks.
Review:
- New office locations
- Hybrid work policies
- Cloud migrations
- Accounting software integrations
- AI platform adoption
- Third-party vendor access
If Your Firm Performs Annual Reviews
Shift from periodic reviews to continuous governance.
Focus on:
- Quarterly executive security reporting
- Ongoing vulnerability management
- Security awareness training
- Technology roadmap updates
- Business continuity exercises
- AI governance reviews
Boardroom Questions Every Managing Partner Should Ask
Technology governance should not be delegated entirely to IT.
Leadership should regularly ask:
- What are our five highest cybersecurity risks today?
- Have those risks changed since our last assessment?
- Which recommendations remain unresolved?
- When were our backups last restored successfully?
- Are former employees’ accounts removed promptly?
- What new cyber risks have emerged since last year?
- How are AI tools affecting our security posture?
- Which technology investments should we prioritize next?
If these questions cannot be answered confidently, your firm may benefit from a comprehensive security assessment.
Conclusion
Cybersecurity is not something that can be addressed once and forgotten.
As accounting firms adopt cloud platforms, expand hybrid work, strengthen Microsoft 365 security, and explore AI-powered productivity tools, their technology environment and the risks associated with it, continues to evolve.
For firms throughout Los Angeles County and Greater Los Angeles, regular security risk assessments and IT audits provide leadership with the information needed to make informed technology decisions, prioritize investments, and reduce operational risk.
Rather than waiting for an incident to expose vulnerabilities, proactive assessments help transform cybersecurity from a reactive technical function into an ongoing business governance process.
The goal is not to eliminate every risk. It is to understand the risks that matter most and manage them effectively over time.
When was your accounting firm’s last comprehensive cybersecurity assessment?
Fothion helps accounting firms throughout Los Angeles County and Greater Los Angeles evaluate their technology environment, identify cybersecurity risks, and develop practical remediation roadmaps aligned with business objectives.
A comprehensive security assessment provides executive leadership with the visibility needed to prioritize investments, strengthen resilience, and support long-term operational success.
Book a 30-minute call with Fothion: https://www.fothion.com/schedule-a-phone-call/
- Frequently Asked Questions
- How often should an accounting firm perform a security risk assessment?
- Most accounting firms should complete a comprehensive security risk assessment at least once a year. Additional assessments are recommended following significant business changes, technology upgrades, mergers, cybersecurity incidents, or changes in cyber insurance requirements.
- What is the difference between a vulnerability scan and a security risk assessment?
- A vulnerability scan identifies known technical weaknesses in systems and software. A security risk assessment takes a broader view by evaluating people, processes, technology, governance, and business impact to prioritize risk reduction.
- Does a security assessment include Microsoft 365?
- It should. Microsoft 365 is often the primary collaboration and communication platform within accounting firms, making identity protection, email security, permissions, and governance essential components of any comprehensive assessment.
- Should small and mid-sized accounting firms perform annual assessments?
- Yes. Cybercriminals frequently target organizations of all sizes. Annual assessments help firms identify evolving risks and make informed decisions about cybersecurity investments regardless of company size.
- Can a Managed IT Services Provider perform a security assessment?
- Many Managed IT Services Providers offer security assessments as part of their services or as a standalone engagement. Firms should understand the scope of the assessment, how findings are prioritized, and whether remediation guidance is included.
- What should leadership expect after a security assessment?
- Leadership should receive a clear executive summary, prioritized recommendations, an explanation of business impact, and a practical remediation roadmap rather than only technical findings.
- How long does a security assessment typically take?
- The timeline depends on the firm’s size, infrastructure, and assessment scope. For many accounting firms with 20–100 employees, assessments can be completed over several days to a few weeks, followed by an executive review of findings and recommendations.
- Does a security assessment help with cyber insurance or client security questionnaires?
- Yes. While every insurer and client has different requirements, maintaining a regular assessment program and documenting remediation efforts can help demonstrate a proactive approach to cybersecurity governance.
Leave a Comment