
Brian O'Connell, President
This week, a reader left a comment on our QuickSend blog post. He said he didn’t think we needed to worry about the security of email.
He wrote,
“I know that you say email is not secure, but the chances of your competitors setting up an intercept for your email are so small that it’s kind of silly, especially if you use a reputable mail client (even gmail works) and a browser with encryption.”
In this post, I want to explain why our focus on security for our CPA websites is anything but silly.
In fact, it keeps our clients safe from a security breach that could ruin their practice – as well as saving them from a $100,000 fine.
Defining the Threat
Do you really need to worry that Ed Smith’s firm down the street is going to intercept your email?
Here’s what Bob Rayl, our Chief Technology Officer, said about that question, in reponse to the above comment:
“Our primary goal is to make it as easy as possible for accountants and tax professionals to protect their clients.
“We’re not overly concerned with an accountant’s competitor intercepting e-mails; we’re much more concerned with people who would use sensitive information (social security numbers, account numbers, etc.) for nefarious means — of which there’s been no shortage lately, judging by the disturbingly large (and growing) number of people out there whose machines have been compromised for just such purposes.”
Yes, “intercepting email” sounds like such a remote possibility that it’s not even worth considering. But, in fact, the threat lies in the potential for your computer to be hacked – not by your competitors, necessarily, but by “professional” hackers – for the prized information you have stored in your email attachments.
Why Password Protection Is Not Enough
Bob explains why – unfortunately – protecting your emails with a password falls short of the mark:
“If you’re sending files via e-mail, they can be cracked, even if you’re password protecting the file.
“A large portion of firms out there have been using passwords such as their clients’ social security numbers, zip codes, or a combination of the two. A simple script can ‘brute-force’ the password in a matter of minutes in the case of a 9-digit number such as a social security number. It’s a matter of seconds for smaller passwords such as zip codes.”
Simply put – if a hacker wants the information in an email attachment, he can probably get it.
Federal Regulations Mandate High Security
Even if we decided that we did not need to protect our clients against the possibility of hacking, we would still be obligated to tell them that email is not secure.
Why? Because of the Gramm-Leach-Bliley Act (GLBA) of 1999. All tax, accounting, and CPA firms, regardless of size, must comply with the GLBA, also known as the Financial Services Modernization Act of 1999.
The GLBA was enacted to protect consumers’ private financial information. It governs the collection and disclosure of clients’ financial information by CPAs, accountants, and tax preparers.
A single violation of the Gramm-Leach-Bliley Act carries a fine of up to $100,000 for each violation, and key officers may be fined up to $10,000 per violation.
If we don’t protect your data according to the regulations, your firm is in serious jeopardy.
Our Client Portal Keeps You Fully Protected
If email is not an option for transmitting financial information, what can you use to exchange documents with your clients?
Our secure Client Portal.
When you use our Client Portal, your clients’ data is 100% encrypted. This virtually eliminates the legal liability associated with data breaches. In fact, your Client Portal has very detailed Audit Trails that help prove that information hasn’t been leaked.
Furthermore, our Client Portal is proteceted by 14 layers of security. Other Client Portal vendors provide only 5 or 6 layers.
QuickSend and SecureReceive, our time-saving features that allow you and your clients to quickly exchange files without having to click in to the Portal interface, uses the very same highly secure technology.
Using these tools keeps you fully compliant with the regulations and as protected as possible.
We Welcome the Comment
I’m delighted that a reader questioned why our security is so high. I know it’s a topic with a lot of technical details, and explaining it can get a little dry.
But it boils down to this: providing our clients with the highest level of security is paramount at CPA Site Solutions.
If you have any questions about our secure Client Portal, QuickSend, SecureReceive, or anything else, give us a call at 1-800-896-4500, or email support@cpasitesolutions.com.