Archive for category: Blog Posts

Prep for a Secure Firm: A Cybersecurity Awareness Month Checklist

 

We asked our security team what they would tell an investment or professional firm to fix first. 

None of it requires new software, a budget cycle or an outside consultant. Every recommendation below is finishable in an afternoon by whoever already administers your systems, and each one comes from what we find repeatedly when we take over environments at law, CPA and investment firms across Dallas-Fort Worth.

October is Cybersecurity Awareness Month, which makes it a convenient time to work through them. The recommendations hold the rest of the year too.

What Do Security Experts Recommend for an Investment or Professional Firm?

An investment or professional firm should use Cybersecurity Awareness Month to fix the small number of things that actually cause breaches at firms like theirs: unenforced multifactor authentication, accounts belonging to people who left, mailbox forwarding rules nobody is alerted on, and backups that have never been restored. Awareness training is worth running, but it does not change the environment. These four recommendations do.

Cybersecurity Awareness Month is run each October by the Cybersecurity and Infrastructure Security Agency. Its baseline for individuals covers phishing, strong passwords, multifactor authentication, and updates. For organizations, it adds logging, backups, encryption, and incident response planning. Everything below maps to one of those.

Recommendation One: Fix Identity Before Anything Else

Identity is the layer everything else sits on. If it is wrong, nothing above it holds.

  • Enforce multifactor authentication with no exceptions. The exceptions are usually partners, and partners are the accounts attackers want. “Almost everyone” is not enforced.
  • Switch off legacy authentication. It is the quiet way around MFA. If it is still enabled anywhere in your tenant, your MFA is optional.
  • Find the accounts belonging to people who left. Pull a report of every account with no sign-in in ninety days. In almost every environment we inherit, at least one still has elevated access.
  • Separate privileged accounts from daily-use ones. Nobody should be reading email from an account that can change tenant settings.

Recommendation Two: Make Email Compromise Visible

Email is where the money actually leaves. Business email compromise remains among the costliest categories of cybercrime in the FBI IC3 annual reports, year after year.

  • Turn on alerting for mailbox forwarding rules. Compromise almost always announces itself through a quietly created forward. Alert on rule creation, external forwarding and new delegate permissions. This is the single highest-value hour on the whole list: it turns a months-long compromise into a same-day one.
  • Audit delegate access on partner and executive mailboxes. Delegates accumulate over years and are almost never removed.
  • Check DMARC and DKIM on every domain you own, not just the primary one. Firms routinely protect the main domain and leave the old one wide open for spoofing.
  • Agree one rule for sensitive material. Matters involving personal financial data, health information or sealed filings go through a portal, not an attachment. Then make the secure path the easy one, because controls people route around are not controls.

Recommendation Three: Prove You Can Recover

This is the recommendation that produces the most uncomfortable answer, which is why it is worth acting on.

  • Run an actual restore. Not a backup check. A restore. Write down the date and what broke, because something always does.
  • Know your recovery order. If everything went down tonight, which system comes back first? For most firms it is the document system and time and billing, not email, and most firms have never said so out loud.
  • Test that you can reach people. If your email is the thing that is down, how does the firm coordinate? A phone tree written on paper is not old-fashioned, it is a control.

A backup job reporting success is a claim. A completed restore is evidence. The difference matters the week you need it, and it matters every time a client asks.

Recommendation Four: Be Able to Show Your Work

The first three change the environment. This one lets you prove it, which is increasingly what clients want.

  • Write the incident response plan down. One page naming who decides, who calls the client and within how many days beats a sophisticated plan that does not exist.
  • Build the evidence pack once. A current inventory of systems holding client data, your last restore date, your access review records, a subcontractor list, training completion records. Assemble it once and every future request becomes a mapping exercise.
  • Ask your IT provider for their own security documentation. You are expected to oversee them. If they cannot produce it for you, they will not produce it when a client asks either.

Four Things Worth Telling Your Team

Everything above is administrator work. This part is for everyone else, and it is short enough to paste into a firm-wide email.

  • Length beats complexity on passwords. A long passphrase you can remember is stronger than a short one with symbols bolted on, and far stronger than the same password reused on twelve sites. The one that matters most is the password on your email, because that is the account that resets all the others. We wrote more on this in password security for DFW investment and professional firms.
  • Use a password manager, and stop trying to remember them. Reuse is the actual risk. When a breach elsewhere exposes a password you also use at work, attackers try it against your firm within hours. Credential stuffing at that scale is routine, as the 16 billion credential leak made obvious.
  • Approve nothing you did not start. If a multifactor prompt appears and you were not signing in, that means someone already has your password. Deny it and report it the same hour. Attackers rely on people approving a prompt to make it stop.
  • Urgency plus a change of payment details is the tell. Almost every successful attack on a professional firm involves a message that is urgent, plausible, and asks for money to move or credentials to be entered. Slow down, and confirm it on a number you already had, never the one in the message.

None of that is new advice. It is on this list because it still works, and because the firms we onboard are rarely breached by anything cleverer.

The Best Self-Test We Know

If you want a harder version of all of the above, borrow the instrument your clients already use: a client security questionnaire.

Take a blank one and answer it honestly as a firm. Better still, hand it to someone who did not build the environment and ask them to answer from evidence alone. Whatever they cannot find is what a client will not be able to verify either.

We covered how these work, what reviewers are really testing, and the answers that quietly lose engagements in our guide to client security questionnaires.

What We Actually Find

None of this is theoretical. Across onboarding engagements with investment and professional firms, the same findings come up:

Multifactor authentication not enforced, legacy authentication still enabled, and stale directory accounts still live. A three-office CPA firm whose server backup jobs had been failing repeatedly across multiple years, with client financial data exposed the entire time, because the jobs reported and nobody read the reports. A wealth management firm where a business email compromise redirected a client payment to a fraudulent account.

Not one of those is exotic. No zero-day, no sophisticated adversary. Every item is a known problem with a known fix, sitting unaddressed because nobody owned it. That is what a month of focused attention is actually for.

Who Owns This After October?

The honest limitation of any checklist is that it is a moment in time. Working through these four fixes what is broken today and does nothing about what changes in March, when someone joins, a vendor is swapped, or a client sends a questionnaire with a question nobody has considered.

Security at a professional firm is a standing function, not a project. Most firms between ten and a hundred and fifty people cannot justify a full-time chief information security officer, and hiring one is rarely the right answer anyway. What they need is the function: someone accountable for the risk register, the policies, the evidence pack, the vendor reviews and the board-level reporting, on a schedule rather than in a panic.

That is what a vCISO is. Senior security direction without the hire, sized to a firm rather than an enterprise. For firms in the Legacy and Preston corridors, our vCISO practice in Plano covers exactly this, and for family offices and investment firms, we run a dedicated version with the regulatory overlay built in.

If October leaves you with a list of things nobody owns, that is the gap a vCISO closes.

Want these run for you? We do this as a security assessment for investment and professional firms, and you get the findings whether or not you engage us. Call (888) 352-4832 or book one.

Frisco, Plano and Irving

Frisco firms are typically newer and cloud-native, so the identity work is usually quick and the evidence work is the hard one: good controls, thin documentation. DKBinnovative is headquartered in Frisco, and our Managed IT Frisco team runs this work locally, while our Managed IT Frisco practice for financial and professional firms handles the compliance layer on top.

Plano holds the region’s most established practices, which means the identity work takes longer: legacy authentication, file servers and permission structures that predate anyone currently working there. Our Managed IT Plano team does most of these untanglings, and our Managed IT Plano security practice handles what the audit turns up.

Irving and Las Colinas firms are usually already being asked. The corridor’s corporate tenant base runs real vendor due diligence, so the evidence work tends to arrive uninvited. Our Managed IT Irving practice works from 7301 State Hwy 161, and our Managed IT Irving team handles the evidence side.

Frequently Asked Questions

What should an investment or professional firm do for Cybersecurity Awareness Month?

Fix the small number of things that actually cause breaches at firms like yours: unenforced multifactor authentication, accounts belonging to people who left, mailbox forwarding rules nobody is alerted on, and backups that have never been restored. Awareness training is worth running, but it does not change the environment.

When is Cybersecurity Awareness Month?

Every October, run by the Cybersecurity and Infrastructure Security Agency. Its baseline covers phishing, strong passwords, multifactor authentication and updates, with logging, backups, encryption and incident response added for organizations.

What is the single highest-value security fix for a small firm?

Alerting on mailbox forwarding rules. Business email compromise almost always announces itself through a quietly created forward, and alerting on rule creation turns a months-long compromise into a same-day one. It takes about an hour to configure.

How do we know whether our backups actually work?

Run a restore. A backup job reporting success is a claim; a completed restore is evidence. Note the date and what broke during it, because clients increasingly ask for exactly that.

Do we need a CISO, or is a vCISO enough?

For most investment and professional firms between ten and a hundred and fifty people, a vCISO is the right size. You get the function that matters, meaning the risk register, policies, evidence pack, vendor reviews and board reporting on a schedule, without carrying a full-time executive salary. A full-time CISO starts making sense at a scale most DFW investment and professional firms have not reached.

What if we already have an IT provider?

Then most of this is their job, and the useful move is to ask. Send them the four recommendations and ask which are already in place, which are not, and why. A good provider answers with specifics and dates. A provider who treats the questions as an inconvenience has told you something worth knowing.

Working With DKBinnovative

We have supported investment and professional firms across Dallas-Fort Worth since 2004, which is 22 years, currently spanning 2,632+ end users across 55+ companies with a 78% first-call resolution rate and 98.14% client satisfaction. We standardize on Microsoft Azure and Microsoft 365, and deploy Hatz.AI where firms need governed AI that keeps client material inside their own tenant.

If October is the month you finally get security attention at your firm, spend it on the four recommendations above. If you would rather we ran them for you, that is a security assessment.

Call (888) 352-4832 or book an assessment.

Related reading: The Professional Firm Tech Stack · IT Support for Law & Accounting Firms · Reg S-P Is Now in Force · Investment & Professional Firms

External references: CISA Cybersecurity Awareness Month, FBI IC3 annual reports, NIST Cybersecurity Framework.

The Professional Firm Tech Stack: What’s In It, and What We Find When We Take One Over

 

The Professional Firm Tech Stack: What's In It, and What We Find When We Take One Over

Most firms can name every product they run. Far fewer can say which one authenticates against which, who reviews the permissions, or when a restore was last tested end to end.

That second set of questions is the one that decides how a firm’s week goes. Technology in a professional practice rarely fails inside a product. It fails in the space between two of them, and that space tends to belong to nobody.

The document system has to authenticate against something. The billing platform has to be backed up in a way you can actually restore. The email tenant has to be the same tenant the practice management tool trusts. Get any one of those joins wrong and the symptom surfaces somewhere else entirely, which is why they sit unfixed for years.

So this is the stack layer by layer: what these firms run, what we find when we inherit one, and what a working version looks like. The findings below are drawn from our own engagements, including a five-year engagement with a three-office North Texas CPA firm and a business email compromise at a wealth management firm.

DKBinnovative technician monitoring the tech stack of a DFW professional services firm
Seven layers. Almost everything that goes wrong happens between two of them.

What Software Do Most Law Firms Use?

Most law firms run a practice management platform such as Clio, MyCase or Actionstep for matters, time and billing, a document management system such as iManage or NetDocuments, Microsoft 365 for email and files, a legal research tool such as Westlaw or LexisNexis, and an e-signature service. The software is rarely the problem. The problem is that these products are usually bought separately, at different times, by different people, and nobody owns how they fit together.

What Software Do Most Accounting and RIA Firms Use?

Accounting firms typically run tax preparation software such as UltraTax, Lacerte or ProSystem fx, QuickBooks for client bookkeeping, a document portal for client exchange, and Microsoft 365. RIAs run a portfolio accounting or performance reporting platform, a CRM such as Redtail or Wealthbox, a custodian portal, and Microsoft 365. In both cases the line-of-business application is the one nobody can lose access to, and it is usually the one with the weakest integration story.

The Seven Layers, and What We Find in Each

The order below is deliberate. It runs from the layer everything else depends on to the layer most firms buy first.

1. Identity

What it is: Microsoft Entra ID or on-premises Active Directory, usually both, deciding who is allowed into everything above it.

What we find: At the CPA firm, multifactor authentication was not enforced, legacy authentication was still enabled, and stale Active Directory accounts were still live. In a separate post-acquisition engagement, a compromised Microsoft 365 account had been in use by an attacker for more than a year, quietly provisioning Azure virtual machines to run phishing campaigns and generating over $10,000 in fraudulent cloud charges before anyone noticed.

What good looks like: MFA enforced with no exceptions, legacy authentication disabled outright, and quarterly account hygiene that actually removes departed staff. At the CPA firm we run that review every quarter and reset privileged passwords as part of it.

2. Email

What it is: Microsoft 365 in nearly every DFW professional firm we see, and the single most attacked surface in the stack.

What we find: The CPA firm had logged 150+ Microsoft 365 and Outlook disruptions consuming over 200 hours of support time before we arrived. Separately, a wealth management firm suffered a business email compromise that redirected a client payment to a fraudulent account. Email is where the money actually leaves, and the FBI IC3 annual reports put business email compromise among the costliest categories of cybercrime year after year.

What good looks like: DMARC and DKIM deployed across every domain the firm owns, not just the primary one, plus alerting on mailbox forwarding rules and delegate changes. Those two rules catch most BEC in hours rather than months.

3. Document management

What it is: iManage, NetDocuments, SharePoint, or a file server somebody has been meaning to retire since 2019.

What we find: Permissions that grew by accretion. A folder opened up for one project in 2021 and never closed. For litigation practices the more serious finding is a legal hold that cannot be applied reliably because the same matter exists in two systems.

What good looks like: One authoritative repository, permissions reviewed on a schedule rather than on request, and preservation that a custodian cannot override.

4. The line-of-business application

What it is: Practice management, tax software, portfolio accounting. The thing the firm cannot work without.

What we find: This is the layer most IT providers quietly decline to support. The application gets treated as the software vendor’s territory, so tickets are forwarded rather than resolved, and the firm ends up managing that relationship itself during the weeks it can least afford to.

What good looks like: Your provider holds genuine competence in the specific platform you run, and owns the problem rather than routing it onward. Faults get diagnosed and fixed in-house, paired with proactive update management so the same issue stops recurring.

5. Backup and recovery

What it is: The layer everyone assumes is fine.

What we find: The most alarming finding in five years of that CPA engagement: server backup jobs had been failing repeatedly across multiple years, with client financial data exposed the entire time and no durable fix. The jobs reported. Nobody read the reports.

What good looks like: Azure Backup with daily restore points, continuous monitoring of the jobs themselves, and a restore you have actually performed. A green backup status is a claim. A completed restore is evidence.

6. Endpoint and network

What it is: Laptops, the office network, and whatever is filtering traffic.

What we find: At the CPA firm we detected live active threats already present on endpoints during onboarding. Not historical indicators. Active. At the wealth management firm, containing the compromised account took ten minutes, but auditing all 20 endpoints to confirm the blast radius took five hours, and that only worked because there was tooling to audit with.

What good looks like: EDR with 24/7 monitoring behind it, DNS-layer filtering, and network segmentation. We run SentinelOne and Cisco Umbrella, on Meraki infrastructure with VLAN segmentation where the firm has its own network. CISA Cyber Essentials is a reasonable baseline to measure yours against.

7. Monitoring and advisory

What it is: Whether anyone is watching, and whether anyone is planning.

What we find: A fully reactive break-fix model with no patch management schedule, no tax-season planning and no technology roadmap. Decisions made at the moment of failure, by whoever was in the room.

What good looks like: Continuous monitoring, a patch calendar that knows what month it is, and quarterly vCIO reviews. For the CPA firm that meant pausing non-critical updates during peak filing periods, which is a scheduling decision rather than a technical one, and it is the sort of thing only a provider who understands the practice will think to do.

Curious what we would find in yours? The assessment covers all seven layers and takes a few weeks. Call (888) 352-4832 or book one.

DKBinnovative engineer checking backup and network infrastructure at a professional firm
Backup and endpoint: the two layers everyone assumes are fine.

The Pattern Underneath All of It

Read those findings together and one thing connects them. Not a single item on the list is exotic. There is no zero-day, no sophisticated adversary, no failure of technology.

Backups failing for years. MFA not turned on. Legacy authentication left enabled. Accounts belonging to people who left. A forwarding rule nobody alerted on. Every one of these is a known problem with a known fix, sitting unaddressed because the stack had no owner.

That is the actual finding after five years and 1,256 tickets at one firm: professional firms do not usually fail because they bought the wrong software. They fail because seven layers were assembled by different people over a decade and nobody was responsible for the whole.

What a Working Stack Looks Like

The same CPA firm, after the work: backups modernized onto Azure with daily restore points and monitored continuously. MFA enforced firm-wide, legacy authentication eliminated, active endpoint threats contained through EDR. Quarterly Active Directory hygiene across all three offices. DMARC and DKIM across every domain. A patch schedule that pauses during tax season. Quarterly vCIO reviews replacing decisions made in a panic.

The numbers underneath that: 1,256 tickets resolved over five years, 2,164+ hours of support for 52 staff across three offices, more than 65% resolved same-day or next-day, and average resolution under one day. Through five tax seasons, without disrupting one of them.

That is the whole argument. Not better software. The same software, owned properly.

How to Audit Your Own Stack This Week

You do not need us to do the first pass. Seven questions, one per layer, and you can ask them all in an afternoon.

  1. Identity. Is MFA enforced on every account with no exceptions, and is legacy authentication disabled? Ask for it in writing.
  2. Email. Does anything alert when a mailbox forwarding rule is created?
  3. Documents. Who reviewed folder permissions last, and when?
  4. Line-of-business app. When your tax or practice management software breaks, does your IT provider fix it or forward it?
  5. Backup. What is the date of the last completed restore test, and what broke during it?
  6. Endpoint. Is there EDR, and is a human watching it outside business hours?
  7. Advisory. When did someone last show you a technology roadmap you had not asked for?

Any question you cannot answer is a layer without an owner. That is the finding, and you just produced it yourself. If you want a framework to hang the answers on, the NIST Cybersecurity Framework maps cleanly onto these seven layers.

Frisco, Plano and Irving

Plano firms tend to have the deepest layers and the oldest ones. Established practices carry file servers, legacy authentication and permission structures that predate anyone currently working there. The CPA engagement above is the North Texas pattern exactly. Our Managed IT Plano team does most of these untanglings, and our Managed IT Plano security practice handles what the audit turns up.

Frisco firms are typically newer and cloud-native, which moves the problem rather than removing it. The stack is cleaner but governance is thinner: fewer legacy servers, more unmanaged SaaS bought by whoever needed it. DKBinnovative is headquartered in Frisco, and our Managed IT Frisco team sees this pattern constantly, while our Managed IT Frisco practice for financial and professional firms covers the compliance layer that sits on top of it.

Irving and Las Colinas firms get audited by their own clients. The corridor’s corporate tenant base runs vendor due diligence that asks about exactly these seven layers, which means a Las Colinas firm often discovers its gaps through someone else’s security questionnaire. Our Managed IT Irving practice works from 7301 State Hwy 161, and our Managed IT Irving team handles the evidence side.

Frequently Asked Questions

What software do most law firms use?

Most law firms run a practice management platform such as Clio, MyCase or Actionstep, a document management system such as iManage or NetDocuments, Microsoft 365 for email and files, a legal research tool such as Westlaw or LexisNexis, and an e-signature service. The software is rarely the problem. The problem is that these products are bought separately, at different times, and nobody owns how they fit together.

What software do accounting and RIA firms use?

Accounting firms typically run tax software such as UltraTax, Lacerte or ProSystem fx, QuickBooks, a client document portal and Microsoft 365. RIAs run portfolio accounting or performance reporting, a CRM such as Redtail or Wealthbox, a custodian portal and Microsoft 365. The line-of-business application is the one nobody can lose access to and usually the one with the weakest integration story.

What is the most common IT problem you find at professional firms?

Backups that have been failing without anyone noticing. In one five-year CPA engagement, server backup jobs had failed repeatedly across multiple years with client financial data exposed the whole time. The jobs reported their failures. Nobody was reading the reports.

Should our IT provider support our practice management or tax software?

Yes, and many will not. Generalist providers treat line-of-business applications as the vendor’s responsibility, which is technically correct and useless during filing season. Ask a prospective provider directly whether they hold application-level competence in the specific platform you run.

How long does a stack assessment take?

A few weeks to assess all seven layers and produce findings. If remediation is needed, full onboarding for a professional firm typically runs 45 to 90 days depending on how much legacy infrastructure is involved.

Do we need to replace our software to fix these problems?

Almost never. Nearly every finding in this article was resolved on the software the firm already owned. The fix is ownership of the whole stack, not replacement of the parts.

Working With DKBinnovative

We have supported professional firms across Dallas-Fort Worth since 2004, which is 22 years, currently spanning 2,632+ end users across 55+ companies with a 78% first-call resolution rate and 98.14% client satisfaction. We standardize on Microsoft Azure and Microsoft 365, and deploy Hatz.AI where firms need governed AI that keeps client material inside their own tenant.

Call (888) 352-4832 or book an assessment.

Related reading: Case study: multi-office CPA firm · Case study: financial services crisis in 24 hours · Investment & Professional Firms · Managed IT for Law Firms · Managed IT for Accounting & CPA Firms

External references: Microsoft Entra MFA, Exchange Online basic authentication deprecation, FBI IC3 annual reports, CISA Cyber Essentials, NIST Cybersecurity Framework.

Client Security Questionnaires: What DFW Professional Firms Are Being Asked

 

Client Security Questionnaires: What DFW Professional Firms Are Being Asked

A client security questionnaire is now a routine part of winning professional services work in Dallas-Fort Worth, and the firms that lose on it usually lose for answering badly rather than for being insecure.

It arrives as a spreadsheet attached to an otherwise friendly email. Forty questions, sometimes three hundred. Your client’s procurement or compliance team needs it back in two weeks. Nobody at your firm has seen most of these terms before, and the engagement is worth more than anything else in the pipeline.

This is the newest pressure on professional firms, and it is not going away. It is a direct consequence of regulation flowing downhill: covered institutions are required to oversee their service providers, so they oversee you.

This guide covers what these questionnaires are actually testing, which answers quietly disqualify a firm, and how to get to a position where the next one takes an afternoon instead of a fortnight.

DKBinnovative engineer completing a client security questionnaire for a DFW professional firm
We complete these as a standard deliverable, not a favour.

What Is a Client Security Questionnaire and Why Are Firms Receiving Them?

A client security questionnaire is a structured assessment a client sends to verify that your firm protects their data adequately before or during an engagement. Professional firms receive them because regulations like SEC Regulation S-P and the GLBA Safeguards Rule require covered institutions to oversee their service providers, and your firm is a service provider. The questionnaire is how that obligation gets discharged on paper.

Understanding that origin changes how you read the document. It is not your client doubting you. It is your client creating a record that they performed diligence, because someone will eventually ask them to produce it.

Why the Volume Jumped This Year

Three rules push these downstream, and you do not need to know them in detail. You just need to know that your client is being asked, so they are asking you.

  • SEC Regulation S-P. Both compliance dates passed this year, which is why the volume jumped. Covered firms must oversee their service providers, and you are one. More in what Reg S-P now requires firms to evidence.
  • The GLBA Safeguards Rule. Accounting and tax practices count as financial institutions under it, with IRS Publication 4557 as the yardstick.
  • ABA Model Rules 5.1 and 5.3. Law firms must supervise their storage vendors, so corporate clients ask outside counsel to prove it.

The practical effect is a chain. Your client is asked by their regulator. They ask you. You should be asking your IT provider. Firms that cannot complete the third link tend to discover it at the worst moment.

DKBinnovative team reviewing security questionnaire evidence for a professional services firm
Build the evidence pack once. Every later questionnaire is a mapping exercise.

What the Questionnaire Is Really Testing

Most questionnaires draw on a small number of standard instruments: the Standardized Information Gathering (SIG) questionnaire, the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire, or a bespoke form built from the NIST Cybersecurity Framework or the CIS Critical Security Controls.

Whatever the format, they cluster into six things:

  1. Access control. Who can reach client data, how they authenticate, and how access is removed when someone leaves.
  2. Encryption. Data at rest and in transit, and whether you can say which systems are covered.
  3. Incident response. Whether a written plan exists, who owns it, and how fast you would notify them.
  4. Backup and recovery. Not whether you back up. Whether you have restored, and when.
  5. Subcontractors. Who else touches their data, including your IT provider and any offshore support.
  6. Training and governance. Whether staff are trained, and whether anyone reviews any of this on a schedule.

Have a questionnaire sitting on your desk right now? We complete these for client firms as a standard deliverable, and we will review one with you at no cost. Call (888) 352-4832 or send it over.

Turn a Thin Answer Into an October Project

If a questionnaire has landed and you already know which rows are weak, give the gaps a deadline. October is Cybersecurity Awareness Month, which makes it an easy window to get the work scheduled.

We have written the four-week version we run at professional firms: identity, email, recovery, then evidence, with every item finishable in an afternoon. See Prep for a Secure Firm.

The Answers That Quietly Lose Engagements

Reviewers are rarely looking for perfection. They are looking for signals that a firm has thought about this before today. These are the responses that read badly.

What firms write How it reads Better
“Yes” with no detail, across every row Nobody verified any of this Yes, plus the mechanism and who owns it
“We use a firewall and antivirus” Stopped paying attention around 2015 Name the identity controls; that is where breaches start now
“Our IT company handles that” The firm has outsourced its own accountability Name the provider, the control, and your oversight of them
“N/A” on incident response No plan exists A short written plan is better than a sophisticated absent one
Backups described, restore never mentioned Untested backups Give the date of your last successful restore test
Leaving subcontractor questions blank Either hiding something or does not know A current vendor list with owners and review dates

The single most common disqualifier is inconsistency. A firm claims annual access reviews in one row and cannot name who performs them in another. Reviewers notice, because catching that is the job.

How to Answer Well

Build the evidence pack once

Nearly every questionnaire asks for the same underlying facts. Assemble them once and maintain them: a current network and data inventory, your written incident response plan or WISP, the date of your last restore test, your access review records, a subcontractor list, and your training completion records. After that, each new questionnaire is a mapping exercise.

Never overstate

A questionnaire response is a representation to a client, and in a regulated relationship it can end up in front of an examiner. If a control is partial, say it is partial and give the remediation date. Reviewers accept gaps with plans far more readily than they accept claims that collapse under a follow-up question.

Answer the subcontractor questions honestly

Your IT provider is a subcontractor with access to client data. Naming them is expected. What reviewers want to see is that you oversee them, which means you should be able to produce their security documentation on request. If your provider cannot supply it, that is worth knowing before a client asks.

Put one person in charge

Questionnaires that get routed to whoever is least busy produce inconsistent answers. One owner, with your IT provider supplying the technical rows, produces a document that holds together. For firms without an obvious owner, a vCISO arrangement covers the role without a full-time hire.

Frisco, Plano and Irving: Who Is Getting Asked

Irving and Las Colinas firms face this earliest and hardest. The corridor’s corporate and institutional tenant base runs mature vendor due diligence, so a Las Colinas firm often fields an enterprise-grade questionnaire while still small enough that nobody owns security. Our Managed IT Irving practice works from an office at 7301 State Hwy 161, and our Managed IT Irving team spends a disproportionate share of its time on exactly these responses.

Plano firms tend to receive them from long-standing clients whose own compliance posture has tightened, which makes the request feel like a change in a relationship rather than a new one. Our Managed IT Plano team handles these for advisory and accounting practices, and our Managed IT Plano security practice supplies the technical evidence.

Frisco firms are newer and more often growing into their first questionnaires as they move upmarket. The good news is that cloud-native firms usually have better underlying controls than they realize and simply lack the documentation. DKBinnovative is headquartered in Frisco; our Managed IT Frisco and Managed IT Frisco teams cover this work.

Frequently Asked Questions

What is a client security questionnaire?

A client security questionnaire is a structured assessment a client sends to verify that your firm protects their data adequately before or during an engagement. Professional firms receive them because regulations like SEC Regulation S-P and the GLBA Safeguards Rule require covered institutions to oversee their service providers, and your firm is a service provider.

Why are we suddenly getting so many?

Because both Reg S-P compliance dates have now passed, in December 2025 for larger entities and June 2026 for smaller ones. Covered institutions that were preparing are now executing, and service provider oversight is one of the obligations they execute by sending questionnaires downstream.

Do we have to answer them?

Not legally, in most cases. Commercially, declining to answer usually ends the engagement, because your client cannot discharge their own oversight obligation without your response.

What if we cannot answer yes to everything?

Almost nobody can. Say the control is partial, describe what exists, and give a remediation date. Reviewers routinely accept gaps with credible plans. What they do not accept is a claim that fails on a follow-up question, because that damages the whole submission.

Should our IT provider complete it for us?

They should complete the technical sections and supply their own security documentation, but the firm should own the submission. The questionnaire is a representation your firm makes to a client, and answers you have not read are answers you cannot stand behind.

How can we use Cybersecurity Awareness Month at a professional firm?

Treat a client security questionnaire as the exercise. Answer a real or blank questionnaire honestly as a firm during October, and you finish the month with a ranked gap list, a reusable evidence pack, and a named owner for security. CISA’s baseline steps for the month each map to a row on a client questionnaire.

How long does a questionnaire take to complete?

The first one commonly takes two to three weeks of intermittent work. Once the underlying evidence pack exists, subsequent questionnaires typically take a day or two, because most of the work is mapping existing answers to a new format.

Working With DKBinnovative

We have supported professional firms across Dallas-Fort Worth since 2004, which is 22 years, and we complete client security questionnaires as a standard deliverable rather than a favour. Today that spans 2,632+ end users across 55+ companies, with a 78% first-call resolution rate and 98.14% client satisfaction. Our infrastructure standardizes on Microsoft Azure and Microsoft 365, and we deploy Hatz.AI where firms need governed AI that keeps client material inside their own tenant.

If a questionnaire is sitting on your desk, send it to us. We will tell you which rows you can already answer, which need work, and how long that work takes.

Call (888) 352-4832 or send us the questionnaire.

Related reading: Investment & Professional Firms · IT Support for Law & Accounting Firms · Reg S-P Is Now in Force · IT Due Diligence · Financial Services IT

External references: 17 CFR Part 248, IRS Publication 4557, Shared Assessments SIG, CSA Cloud Controls Matrix, NIST CSF, CIS Controls, CISA Cybersecurity Awareness Month.

Multi-Office IT for Law, CPA and RIA Firms in Frisco, Plano & Irving

 

Multi-Office IT for Law, CPA and RIA Firms in Frisco, Plano & Irving

Multi-office IT for professional firms rarely fails at the moment of the merger. It fails about four months later, when nobody can say which office owns the client file.

An RIA in Frisco absorbs a two-adviser practice in Southlake and inherits a file server nobody has patched since 2022. A Plano CPA firm opens a second office and discovers its document management license does not cover a second site. A law firm with offices in Irving and Fort Worth finds that the same matter exists in two places, with two different version histories, and no way to tell which one a court would consider authoritative.

Multi-office IT for professional firms is now a standing condition across Dallas-Fort Worth, not an edge case. Firms here are consolidating. RIA roll-ups, CPA succession mergers and law firm lateral moves all produce the same technical problem: two working environments that each made sense alone and make no sense together.

This guide covers multi-office IT for professional firms from the inside: what actually breaks when a firm goes from one office to several, the order to fix it in, and how to tell whether your provider can handle the transition before you are mid-deal.

DKBinnovative vCIO discussing multi-office IT strategy with a professional services firm
Pre-close is where the useful conversations happen.

Best Managed IT Services for Multi-Location Businesses

The best managed IT services for multi-location businesses share one trait: they centralize identity, data and policy while leaving each office’s local workflow alone. That means a single sign-on directory, one document repository with per-office permissions, uniform security baselines, and a support desk that knows which office a caller is in. Firms that instead replicate one office’s setup onto the next end up with parallel systems that drift.

The word doing the work in that answer is “identity.” Most multi-office problems trace back to two directories that were never merged, because merging them felt risky and postponing it felt free.

How to Centralize IT for Growing Multi-Site Companies

Centralization follows a fixed order, and firms that take it out of order pay for it twice.

  1. Identity first. One directory, one set of credentials, conditional access applied uniformly. Until this is done, every other consolidation step has to be redone later.
  2. Data second. One repository with a defensible structure, migrated with permissions intact and with a record of what moved.
  3. Policy third. Retention, legal hold, device standards and acceptable use, written once and applied to both offices rather than negotiated per site.
  4. Applications fourth. Practice management, time and billing, portfolio accounting. These are the loudest problem and the one people want to solve first, which is why so many firms end up with a consolidated application sitting on two unconsolidated identity systems.
  5. Network last. Connectivity between offices matters, but it is the easiest piece to change and the least likely to cause a compliance problem.

The reason identity comes first is not technical elegance. It is that every obligation discussed below, from Reg S-P service provider oversight to ABA supervision duties, depends on being able to say who had access to what, and when. Two directories means two answers to that question.

DKBinnovative supporting a multi-office professional firm across DFW locations
Two offices, one obligation.

What Actually Breaks When the Second Office Opens

The same document exists twice

This is the most common and the most dangerous. Two offices, two repositories, one matter. For a law firm this collides directly with preservation duties, because a legal hold applied in one system does not reach the copy in the other. For a CPA firm it means a return exists in two states during the one month you cannot afford ambiguity.

Permissions carried over from the acquired firm

Acquired environments almost always arrive with over-broad access. The departing owner’s account still has domain admin. A former contractor still has a mailbox. A shared folder is open to everyone because that was easier in a six-person office. None of it is malicious and all of it is now yours.

Nobody owns the seam

Each office has an idea of who handles IT. Neither idea covers the space between them. Tickets about cross-office issues sit because they are nobody’s obviously.

Compliance evidence fragments

If your firm is subject to Regulation S-P, you owe an incident response program covering customer information wherever it sits, including in the office you acquired last quarter. If you are a CPA firm, your Written Information Security Plan now has to describe an environment it was not written for. A WISP that describes one office while the firm operates three is not a WISP.

Opening a second office or closing on a merger? We run a pre-integration review that maps both environments and tells you what has to be resolved before close rather than after. Call (888) 352-4832 or request a review.

Our IT Can’t Keep Up With How Fast We’re Growing. What Are Our Options?

Three, and the right one depends on where the constraint actually sits.

Option Fits when Watch out for
Keep internal IT, add a co-managed partner You have someone good who is simply outnumbered, and institutional knowledge matters Needs a clear split of duties in writing, or both sides assume the other has it
Move to a fully managed provider No internal IT, or the role has been a rotating side job Documentation ownership on exit; settle it in the contract
Hire ahead of the growth Rare. Works only if you can hire depth, not one generalist One person cannot cover after-hours, security operations and compliance evidence

For most DFW professional firms between roughly 10 and 150 people, the co-managed route is the one that survives contact with a merger. It keeps the person who knows why the Plano office does things differently, and adds the capacity that a second office demands.

The Pre-Close Checklist

Run this before the deal closes, not after. Every item is cheaper to resolve while there is still negotiating leverage.

  • Inventory both environments. Every system holding client data, with an owner. See our IT due diligence definition for scope.
  • Get the acquired firm’s incident history. Ask directly whether they have had a breach, and what was disclosed. Inheriting an undisclosed incident is inheriting its notification obligation.
  • Check licensing transferability. Practice management and document management licences frequently do not survive a change of control without renegotiation.
  • Identify the data owner of record. For client files, who is the custodian after close, and does the engagement letter say so.
  • Confirm the acquired firm’s vendor list. Their service providers become your service providers, and under Reg S-P you owe oversight of them.
  • Set the identity cutover date before close. If it is not scheduled, it will not happen.

We published a worked example of this in our case study on modernizing IT for a multi-office CPA firm, which covers the sequencing in practice.

Frisco, Plano and Irving: Where the Consolidation Is Happening

Frisco sees the most greenfield second offices. Firms that started here are opening additional locations rather than acquiring them, which is the easier version of this problem: one culture, one set of standards, and a chance to do identity correctly from the start. DKBinnovative is headquartered in Frisco, and our Managed IT Frisco team handles a steady flow of these expansions. For firms in the finance vertical specifically, our Managed IT Frisco practice covers the compliance overlay.

Plano is where most of the genuine mergers happen, because it holds the region’s concentration of established firms with founders approaching succession. These are the hardest integrations: two mature environments, two sets of habits, twenty years of accumulated data on each side. Our Managed IT Plano engagements with professional firms frequently start the month after a close, and our Managed IT Plano security team handles the permissions cleanup that always follows.

Irving and Las Colinas tends to produce the satellite office rather than the merger. Firms headquartered elsewhere in the metroplex open a Las Colinas presence to sit closer to corporate clients, which means a small office with full compliance obligations and no local IT. Our Managed IT Irving practice works from an office at 7301 State Hwy 161, and our Managed IT Irving team covers exactly this pattern.

Frequently Asked Questions

What are the best managed IT services for multi-location businesses?

The best managed IT services for multi-location businesses centralize identity, data and policy while leaving each office’s local workflow alone: a single sign-on directory, one document repository with per-office permissions, uniform security baselines, and a support desk that knows which office a caller is in. Replicating one office’s setup onto the next produces parallel systems that drift.

How do you centralize IT for a growing multi-site company?

In this order: identity, then data, then policy, then applications, then network. Identity comes first because every compliance obligation depends on being able to say who had access to what and when, and two directories produce two answers. Firms that start with applications usually have to redo the work.

When should we integrate IT during a merger?

Assessment before close, execution after. The inventory, incident history, licensing check and vendor review all need to happen while you still have negotiating leverage. The cutover itself should be scheduled before close even if it runs afterwards.

Does our WISP or incident response plan need updating after we acquire a firm?

Yes. A Written Information Security Plan or Reg S-P incident response program describes a specific environment. Once the firm operates an additional office, a plan that describes only the original one no longer reflects reality, which is the first thing an examiner notices.

Can we keep our existing IT person through a merger?

Usually you should. A co-managed arrangement keeps the person who understands why each office works the way it does, while adding after-hours coverage, security operations and the integration capacity that one person cannot supply alongside daily support.

How long does multi-office IT integration take?

For a professional firm, expect 45 to 90 days from engagement to a stable consolidated environment, with identity work in the first few weeks. Complex integrations involving legacy on-premises systems on both sides run longer.

Working With DKBinnovative

We have supported professional firms across Dallas-Fort Worth since 2004, which is 22 years, and today covers 2,632+ end users across 55+ companies with a 78% first-call resolution rate and 98.14% client satisfaction. Our infrastructure standardizes on Microsoft Azure and Microsoft 365, and we deploy Hatz.AI where firms need governed AI that keeps client material inside their own tenant.

If you are looking at a second office or a merger, the most useful thing we can do is look at both environments before you close and tell you plainly what has to be resolved first.

Call (888) 352-4832 or book a pre-integration review.

Related reading: Investment & Professional Firms · Managed IT for Accounting & CPA Firms · Managed IT for Law Firms · Managed IT for RIA Firms · Can Your MSP Scale With You?

External references: 17 CFR Part 248 (Regulation S-P), IRS Publication 4557, NIST Cybersecurity Framework.

IT Support for Law and Accounting Firms in Frisco, Plano & Irving

 

IT Support for Law and Accounting Firms in Frisco, Plano & Irving

IT support for law and accounting firms is a different discipline from general business IT, and firms in Frisco, Plano and Irving usually find that out the hard way.

A litigation boutique off Legacy Drive in Plano loses access to its document management system on the Thursday before a Monday filing deadline. A four-partner CPA practice in Frisco discovers in late February that a staff mailbox has been forwarding client returns to an outside address since December. A corporate firm in Las Colinas gets a client security questionnaire that asks, in writing, whether its IT vendor carries cyber liability coverage and who reviews its access logs.

None of these are hypothetical. They are the three ways professional firms in Dallas-Fort Worth discover that IT support for law and accounting firms is a different discipline from general business IT: a deadline, a breach, and a client asking a question the firm cannot answer.

This guide covers what law and accounting firms in Frisco, Plano and Irving need from an IT partner in 2026, which obligations are genuinely binding, and how to tell a specialist from a generalist with a legal page on their website.

DKBinnovative team member assisting a client at the Frisco front desk, providing IT support for law and accounting firms
Client-facing from day one. Most firms meet us across a desk like this.

Who Specializes in IT Support for Law and Accounting Firms?

Firms that specialize in IT support for law and accounting practices build their service around three things a general MSP does not handle: professional-responsibility duties like the ABA’s confidentiality and breach-notification opinions, federal safeguards rules that treat accountants as financial institutions, and evidentiary requirements such as legal hold and defensible retention. The technical stack matters less than whether the provider can produce evidence when a regulator or a client asks.

That last sentence is the whole distinction. Most MSPs can deploy endpoint protection and patch a server. Far fewer can hand a managing partner a dated access review, a retention policy mapped to a records rule, and an incident response plan that names who calls the client and within how many days.

DKBinnovative helpdesk engineer working a support queue for DFW law and accounting firms
The seven capabilities below are what this desk is actually staffed to cover.

The Three Rulebooks That Actually Bind Your Firm

Professional firms are frequently sold compliance in the abstract. It is more useful to know precisely which rules apply to you, because they differ sharply between a law practice and an accounting practice.

For law firms: ethics opinions, not statutes

Lawyers are not regulated by a federal cybersecurity agency. They are bound by professional conduct rules, and three ABA formal opinions carry most of the weight:

  • Formal Opinion 477R (2017) addresses securing communication of protected client information, and makes clear that unencrypted email is not automatically sufficient when the sensitivity of the matter is high.
  • Formal Opinion 483 (2018) sets out what a lawyer owes clients after a breach. It defines the triggering event narrowly, as an episode where material client confidential information is misappropriated, destroyed or compromised, or where the lawyer’s ability to perform the work is significantly impaired. When that threshold is met, Model Rule 1.4 requires the firm to keep current clients reasonably informed.
  • Formal Opinion 498 (2021) covers virtual practice, which for most DFW firms now describes ordinary Tuesday operations rather than an exception.

Two supporting rules do quiet work underneath these. Model Rule 1.1 and its technology comment require lawyers to keep up with the benefits and risks of relevant technology. Model Rules 5.1 and 5.3 require supervision of others, and that explicitly reaches third-party electronic information storage vendors. Your IT provider is not outside your ethical perimeter. Supervising them is part of the duty.

For accounting firms: you are a financial institution

CPA firms and tax preparers are covered by the Gramm-Leach-Bliley Safeguards Rule. That surprises a lot of partners, but it is settled: preparing returns for compensation makes a practice a financial institution for these purposes.

The practical consequence is the Written Information Security Plan. Federal law requires tax and accounting professionals to create and maintain a WISP, and the IRS has published two documents that function as the working standard: Publication 4557, Safeguarding Taxpayer Data, and Publication 5708, which walks a practice through building the plan itself. The IRS and its Security Summit partners reissued that reminder in August 2026.

A WISP is not a document you buy once. It names a responsible individual, records a risk assessment, and gets reviewed and updated. If your current provider has never asked to see yours, that is a signal.

For firms serving investment clients: Reg S-P reaches your vendors

If your firm works with registered investment advisers, be aware that amended Regulation S-P took full effect for smaller entities on June 3, 2026, after applying to larger entities from December 3, 2025. It obliges covered institutions to oversee their service providers. Advisory clients are now passing that obligation down the chain in the form of questionnaires. We cover the detail in our companion piece on managed IT for RIA and wealth management firms.

Is a Specialized IT Partner Right for Your Firm?

Not every practice needs one. A solo practitioner running a cloud practice management suite on two laptops is usually fine with good habits and a consumer backup service.

The economics change at a predictable point. In our experience across 55+ client companies and 2,632+ supported end users, firms benefit from a specialized partner when they hit roughly these conditions:

  • Somewhere between 10 and 150 people, which is large enough that informal coordination fails and small enough that a full internal IT department is hard to justify
  • More than one office, or a genuine hybrid pattern where staff move between home and a Frisco or Las Colinas location
  • Client security questionnaires arriving at least a few times a year
  • An existing WISP or incident response plan that nobody has revisited in over a year
  • Any practice area where a deadline is court-imposed rather than self-imposed

Firms with an internal IT manager often get more value from a co-managed arrangement than from replacing that person. The internal manager keeps relationships and institutional knowledge; the partner supplies after-hours coverage, security tooling and the compliance evidence work.

Not sure which obligations apply to your practice? We run a no-cost review that maps your firm against the ABA opinions, the Safeguards Rule and your clients’ vendor requirements. Call (888) 352-4832 or request a review.

Seven Things a Legal or Accounting IT Provider Must Cover

Use this as a checklist when you evaluate anyone, including us.

1. Identity, not just antivirus

Most firm breaches now start with a credential, not malware. Phishing-resistant multifactor authentication on every account, conditional access that restricts sign-ins by location and device health, and privileged accounts held separately from daily-use accounts. On Microsoft 365, which is where the overwhelming majority of DFW professional firms live, this is configuration work rather than new spend.

2. Mailbox forwarding and delegation monitoring

The February CPA scenario at the top of this article is one of the most common incidents we see in tax season. Business email compromise usually announces itself through a quietly created forwarding rule. Alerting on rule creation, external forwarding and unusual delegate permissions catches it in hours instead of months.

3. Legal hold and defensible retention

For litigation practices this is not optional. You need the ability to preserve a custodian’s mail and files without the custodian being able to delete, and a record showing when the hold was applied. Retention settings that silently purge items after a fixed window will eventually collide with a preservation duty.

4. Encryption with a client-communication policy attached

Opinion 477R does not require encrypting everything. It requires judgment about sensitivity. That means your provider should help you build a usable rule, for example that matters involving personal financial data, health information or sealed filings go through a secure portal rather than attachments, and then make the secure path the easy one. Security controls that staff route around are not controls.

5. Backup that has actually been restored

Ask when your last restore test ran and what it produced. A backup job showing green is a claim; a completed restore is evidence. For firms with a filing calendar, we recommend documented recovery objectives per system, with the document management platform and time and billing treated as tier one.

6. Vendor and subcontractor oversight

Model Rules 5.1 and 5.3 put supervision of storage vendors on the firm. Reg S-P puts service provider oversight on your advisory clients, who then push it to you. Practically, this means keeping a current inventory of every system holding client data, with an owner and a review date against each entry.

7. Secure AI, governed before it spreads

Staff at professional firms are already using AI tools, with or without a policy. The risk for a law or accounting practice is not AI itself, it is client-confidential text leaving the firm’s control and entering a public model. We deploy Hatz.AI for this reason: it gives a firm a private, governed environment where matter content stays inside the tenant and administrators can see what was used. Getting a governed option in place early is far easier than clawing back shadow usage later.

What This Looks Like in Frisco, Plano and Irving

The three markets behave differently, and a provider who cannot describe the difference probably does not serve them.

Frisco has grown a dense population of newer, fast-scaling practices, many of them spun out of larger Dallas firms and built cloud-first from day one. The typical engagement here is less about migrating legacy servers and more about imposing governance on an environment that grew quickly without it. DKBinnovative is headquartered in Frisco, which means our Managed IT Frisco engagements get on-site response measured in minutes rather than hours. For firms wanting the broader service view, our Managed IT Frisco page covers the full scope.

Plano holds the region’s heaviest concentration of established mid-sized professional firms, including a lot of practices with 20 to 40 years of history and the accumulated systems that implies. Work here often starts with untangling an on-premises file server that three generations of IT vendors have touched. Our Managed IT Plano team handles a high share of these consolidations, and our Managed IT Plano security practice covers the financial-firm side specifically.

Irving and Las Colinas is the market most often overlooked, and in our view the most interesting for professional firms. The Las Colinas corridor carries a corporate tenant base that produces a steady stream of outside counsel and audit relationships, which means firms there face enterprise-grade vendor security reviews earlier in their growth than firms elsewhere in the metroplex. Our Managed IT Irving practice operates from an office at 7301 State Hwy 161 in Las Colinas, and our Managed IT Irving security work leans heavily toward questionnaire readiness for exactly this reason.

IT Outsourcing for Professional and Financial Services Firms

IT outsourcing for professional and financial services firms differs from general business outsourcing in one respect: the provider inherits part of your regulatory obligation. Because ABA Model Rules 5.1 and 5.3 require supervision of storage vendors, and Reg S-P requires oversight of service providers, an outsourcing arrangement in these sectors is a compliance relationship, not just a support contract.

That reframes how you scope the engagement. The contract needs to say who retains data, who notifies whom on an incident, how quickly, and what evidence the provider will produce when your client or regulator asks. Firms that outsource on price alone tend to discover these gaps during the one week they cannot afford to.

In-House IT vs. a Specialized MSP for Professional Firms

Capability One internal IT person Generalist MSP Specialized professional-services MSP
After-hours and filing-deadline coverage Limited to their availability Usually tiered or extra Included, with named escalation
ABA opinion and WISP familiarity Varies widely Rare Core competency
Client security questionnaire support Falls to a partner Ad hoc Standard deliverable
Legal hold and retention Depends on the individual Often unsupported Configured and documented
Security tooling depth Constrained by budget Good Good, plus evidence of operation
Continuity when someone leaves Single point of failure Covered Covered, with documentation held jointly

The honest caveat: a strong internal IT manager who understands your practice is genuinely valuable, and replacing them with an outside vendor is usually a downgrade. The better pattern is to keep them and add the depth around them.

How to Evaluate a Provider in One Meeting

Five questions separate specialists from generalists quickly.

  1. “Show me a client security questionnaire you completed in the last quarter.” Redacted is fine. If nothing exists, they have not been through the exercise.
  2. “What is your documented process when a client mailbox is compromised during tax season?” Listen for containment sequencing and who notifies whom, not for product names.
  3. “How would you apply a legal hold in our environment?” A specialist answers with a platform and a procedure. A generalist asks what a legal hold is.
  4. “When did you last complete a restore test for a firm like ours, and what broke?” The second half is the real question. Everyone’s restores have surprises; only honest providers describe them.
  5. “Who owns the documentation if we leave?” Firms that hold environment documentation hostage exist. Settle it before you sign.

For a fuller version of this exercise, see our criteria for choosing a secure managed IT provider.

Frequently Asked Questions

Does a small law firm really need a specialized IT provider?

Below roughly ten people, usually not. The obligations still apply, but a disciplined solo or small practice can meet them with good cloud hygiene. The case for a specialist strengthens once you add staff who are not partners, because supervision duties under Model Rules 5.1 and 5.3 become harder to discharge informally.

Are accounting firms legally required to have a written security plan?

Yes. Tax and accounting professionals are required under federal law to create and maintain a Written Information Security Plan. IRS Publications 4557 and 5708 are the practical references, and the plan should be reviewed and updated rather than written once and filed.

What happens if our firm suffers a breach?

For law firms, ABA Formal Opinion 483 governs the duty to notify current clients, triggered when material confidential information is compromised or the firm’s ability to perform the work is significantly impaired. For accounting firms, the WISP obligations include reporting an incident affecting 500 or more individuals within 30 days. State breach notification law may apply on top of both.

Can we keep our internal IT person and still use a managed provider?

Yes, and for firms with existing internal IT this is usually the better arrangement. A co-managed model keeps your internal knowledge in place while adding after-hours coverage, security operations and the compliance documentation work that a single person cannot sustain.

How long does onboarding take?

For a professional firm, expect 45 to 90 days from signature to steady state. Discovery and documentation take the first few weeks, security baseline work follows, and compliance artifacts like the WISP review and access reviews come once the environment is stable.

Working With DKBinnovative

We have supported professional firms across Dallas-Fort Worth since 2004, which is 22 years of watching what actually goes wrong in practices like yours. Today that includes 2,632+ end users across 55+ companies, a 78% first-call resolution rate, and 98.14% client satisfaction. Our infrastructure work standardizes on Microsoft Azure and Microsoft 365, and our secure AI deployments run on Hatz.AI so that client-confidential material stays inside your tenant.

If your firm is in Frisco, Plano or Irving and you are weighing a change, the most useful next step is usually the smallest one: let us map your current environment against the obligations that actually apply to your practice area, and tell you plainly where the gaps are.

Call (888) 352-4832 or book a review.

Related reading: Managed IT for Law Firms · Managed IT for Accounting & CPA Firms · Investment & Professional Firms · Financial Services IT

External references: IRS Publication 4557, IRS Publication 5708, 17 CFR Part 248 (Regulation S-P), NIST Cybersecurity Framework.

Reg S-P Is Now in Force: What DFW Investment Firms Must Prove in 2026

 

 

For two years, amended Regulation S-P was a deadline. Firms tracked it on a compliance calendar, assigned it to someone, and worked toward a date.

Both dates have now passed. Larger entities came into scope on December 3, 2025. Smaller entities, which includes SEC-registered investment advisers with less than $1.5 billion in assets under management, came into scope on June 3, 2026.

That changes the nature of the question. Reg S-P is no longer a project with a due date. It is a standing condition your firm is either meeting or not, and the way it now surfaces is through an examination request or a client’s vendor questionnaire. The operative word has shifted from “prepare” to “evidence.”

This piece covers what a firm in Frisco, Plano or Irving must be able to show today, and specifically which parts of it are IT problems rather than compliance-department problems.

DKBinnovative engineer reviewing SEC Reg S-P compliance documentation on a laptop
Reg S-P is now an evidence problem, not a calendar one.

How Can IT Services Help Meet SEC Cybersecurity Guidance?

IT services meet SEC cybersecurity guidance by producing evidence, not just protection. Reg S-P requires a written incident response program, the ability to detect unauthorized access to customer information, customer notification within 30 days of becoming aware of an incident, and documented oversight of service providers. Each of those obligations depends on logging, alerting, retention and access records that only the technology environment can supply.

The distinction matters because firms routinely buy security tooling and still fail an examination. A firm can run good endpoint protection and still be unable to answer the question an examiner actually asks, which is some version of: show me how you would know, show me when you knew, and show me what you did.

DKBinnovative technician reviewing monitoring dashboards used to evidence Reg S-P controls
Detection is a rule requirement. Someone has to be watching.

What the Amended Rule Actually Requires

The amendments adopted May 16, 2024 updated a rule that had been largely unchanged since 2000. Four elements carry the operational weight.

1. A written incident response program

Covered institutions must maintain written policies and procedures for an incident response program reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information. All three verbs matter. Detection is the one most firms underinvest in, because it is the least visible until it is needed.

2. The 30-day notification clock

When sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify affected individuals as soon as practicable and no later than 30 days after becoming aware that the incident occurred or is reasonably likely to have occurred.

Read that trigger carefully. The clock starts at awareness of a reasonably likely incident, not at confirmation of a confirmed breach. Firms that wait for certainty before starting the count are misreading the standard. The notice itself must describe the incident, the information involved, and what affected individuals can do to protect themselves.

3. Broader scope of covered information

The safeguarding and disposal requirements now apply to all customer information, defined as any record containing nonpublic personal information about a customer of a financial institution that is in the firm’s possession, or that is handled or maintained by the firm or on its behalf.

The phrase “or on its behalf” is the one that expands the perimeter. Data sitting with your custodian, your CRM vendor, your portfolio accounting platform or your outsourced IT provider is inside your obligation.

4. Service provider oversight

Firms must take reasonable steps to require service providers to protect customer information and to notify the firm of a breach. In practice this has produced a wave of questionnaires flowing downstream, which is why professional firms serving advisory clients are now fielding security reviews they never used to see.

One additional change is easy to miss: transfer agents registered with the Commission or another appropriate regulatory agency must now comply with both the safeguarding and the disposal requirements, where previously they faced only the disposal rules and only in some cases.

Who Counts as a “Smaller Entity”

The distinction only ever governed the compliance date, and both dates are now behind us. It remains useful for understanding where your peers are in their maturity curve.

Entity type Larger entity threshold (complied by Dec 3, 2025)
SEC-registered investment adviser $1.5 billion or more in assets under management
Investment company Net assets of $1 billion or more at the most recent fiscal year end
Broker-dealer Any that is not a small entity under the Exchange Act
Transfer agent Any that is not a small entity under the Exchange Act

Most independent RIAs across Dallas-Fort Worth fell into the smaller-entity group and reached their date in June 2026. If your firm treated that as a documentation exercise and has not revisited it since, the gap between the written plan and the operating environment is probably where your risk now sits.

Can your firm evidence all four requirements today? We run a Reg S-P readiness review that tests the written plan against what your environment can actually produce. Call (888) 352-4832 or request a review.

The Six Gaps We Find Most Often

These come from readiness work with advisory firms across the metroplex. They are ordered by how frequently they appear, not by severity.

1. The plan names a role that no longer exists

Incident response plans written in 2024 and 2025 routinely name an individual who has since left, or a vendor the firm no longer uses. An examiner reading a plan that names a departed employee learns something about the firm beyond that one error.

2. Logs that do not reach back 30 days in a usable form

If you become aware of a possible incident on day one and need to determine scope, you need history. Default retention on many platforms is shorter than firms assume, and the retention that exists is often not searchable by the people who would need to search it at 9pm on a Friday.

3. No alerting on the events that signal unauthorized access

Detection is a rule requirement, not a best practice. At minimum a firm should alert on impossible-travel sign-ins, new mailbox forwarding rules, mass file downloads from document storage, and changes to privileged group membership. Each of these is a common first observable in an actual compromise.

4. A vendor inventory that is out of date or does not exist

Service provider oversight requires knowing who your service providers are. Firms often have an inventory built during the original compliance push and never maintained. Every system that touches customer information needs an entry, an owner and a review date.

5. Notification mechanics never tested

The 30-day clock assumes you can identify affected individuals and reach them. Many firms have never tested whether they can produce an accurate affected-party list from their systems under time pressure. That is a tabletop exercise, and it takes an afternoon.

6. Secure AI with no governance

Staff at advisory firms are pasting client information into public AI tools. This is now one of the more direct routes to an unauthorized-use problem, and it is invisible without a governed alternative. We deploy Hatz.AI so advisory firms get a private environment where client data stays inside the tenant and administrators retain visibility. Our deeper treatment is in secure AI for investment firms.

What to Look for in a Managed IT Provider Experienced With SEC Reg S-P Compliance

A provider experienced with Reg S-P should be able to do four specific things, and you can test each in a first conversation.

  1. Map each rule requirement to a control and an artifact. Not “we do security,” but: detection maps to these alert rules, and the artifact is this report. If they cannot draw that line, they have not done this work.
  2. Produce a completed vendor security questionnaire on request. Advisory clients push oversight downstream. Your IT provider is one of your service providers, and should already be answering for itself.
  3. Run a notification tabletop. Ask them to walk through hour one through day thirty of a suspected incident at your firm, naming who decides what.
  4. Retain evidence on a defined schedule. Ask what they keep, for how long, and how you get it if you leave.

The FINRA cybersecurity advisory on the amendments is a useful cross-check, as is the rule text itself at 17 CFR Part 248. For control design, the NIST Cybersecurity Framework gives you a structure examiners recognize.

Frisco, Plano and Irving: Three Different Advisory Markets

Frisco has attracted a concentration of newer independent RIAs, many founded by advisers who broke away from wirehouses in the last decade. These firms are typically cloud-native and technically current, but they crossed into Reg S-P scope while still operating with startup-era informality about documentation. Our Managed IT Frisco work with these firms is usually less about new tooling and more about turning existing capability into evidence. DKBinnovative is headquartered in Frisco, and our broader Managed IT Frisco practice supports firms across the corridor.

Plano holds many of the region’s established advisory practices and multi-family offices, firms with longer histories, more legacy systems and more accumulated data. Scope questions are harder here, because customer information has had 20 years to spread into file shares and archives nobody has catalogued. Our Managed IT Plano engagements with advisory firms often begin with discovery of where customer information actually lives, and our Managed IT Plano security team handles the remediation that follows.

Irving and Las Colinas carries a different profile again. The corridor’s institutional and corporate presence means advisory firms there interact with counterparties who run serious vendor due diligence, so the questionnaire pressure arrives earlier and lands harder. Our Managed IT Irving practice works from an office at 7301 State Hwy 161 in Las Colinas, and our Managed IT Irving team spends a disproportionate share of its time on evidence packages for exactly these reviews.

Frequently Asked Questions

Has the Reg S-P compliance deadline passed?

Yes, both of them. Larger entities had to comply from December 3, 2025, and smaller entities from June 3, 2026. There is no remaining runway. A firm that is not currently meeting the requirements is out of compliance rather than behind schedule.

What is a managed IT provider experienced with SEC Reg S-P compliance responsible for?

The provider is responsible for the technical capability behind each requirement: detection and alerting on unauthorized access, log retention sufficient to determine scope, the access and configuration records that evidence safeguarding, and its own conduct as one of your service providers. The firm retains responsibility for the written program, the notification decision and the regulatory relationship.

Does Reg S-P apply to our firm if we are a small RIA?

If you are registered with the SEC, yes. Assets under management determined only which compliance date applied to you, not whether the rule reaches you. Firms under $1.5 billion in AUM were in the smaller-entity group with a June 3, 2026 date.

When does the 30-day notification clock start?

It starts when the firm becomes aware that an incident involving unauthorized access to sensitive customer information has occurred, or is reasonably likely to have occurred. That is an awareness-of-likelihood standard, not a confirmation standard, so the clock can start before an investigation concludes.

Do we have to oversee our IT provider under Reg S-P?

Yes. Covered institutions must take reasonable steps to require service providers to protect customer information and to notify the firm of a breach. An IT provider that cannot complete your security questionnaire creates a compliance problem for you, not only an inconvenience.

How long does a Reg S-P readiness engagement take?

A readiness review takes a few weeks. If it surfaces material gaps, remediation and full onboarding typically run 45 to 90 days depending on how much discovery the environment requires.

Working With DKBinnovative

We have supported investment and professional firms across Dallas-Fort Worth since 2004. That is 22 years, currently spanning 2,632+ end users across 55+ companies, with a 78% first-call resolution rate and 98.14% client satisfaction. We standardize on Microsoft Azure and Microsoft 365 for infrastructure, and deploy Hatz.AI where firms need governed AI that keeps client information inside their own tenant.

If your firm reached its Reg S-P date and has not revisited the program since, the useful next step is a short readiness review that tests the written plan against what your systems can actually produce. We will tell you plainly which of the four requirements you can evidence today and which you cannot.

Call (888) 352-4832 or book a readiness review.

Related reading: Managed IT for RIAs & Wealth Management Firms · Investment & Professional Firms · Financial Services IT · IT Support for Law & Accounting Firms

Post-Quantum Readiness for Law, CPA and Investment Firms in DFW

 

 Post-Quantum Readiness for Law, CPA and Investment Firms in DFW

Post-quantum readiness is usually filed under problems for later. For a law firm it is not, because attorney-client privilege has no expiry date and encrypted traffic can be copied today and opened in a decade.

Most technology risks have a shape professional firms recognize. Something happens, you respond, you notify, you recover. This one is different. The damage would be done years before anyone knows, and the decision that determines whether it happens to you is being made now, quietly, by whoever controls how your firm encrypts data in transit.

This is not a prediction about when a cryptographically relevant quantum computer arrives. Nobody credible will give you that date. It is about a much narrower question: how long does your firm’s confidential material need to stay confidential, and is that longer than the time remaining before today’s encryption stops holding?

For a great many law, CPA and investment firms in Dallas-Fort Worth, the honest answer is yes.

DKBinnovative engineer reviewing server and network infrastructure during a post-quantum readiness assessment
Readiness starts with knowing what protects what.

What Is Harvest Now, Decrypt Later?

Harvest now, decrypt later is an attack in which encrypted data is captured today and stored until quantum computing makes it decryptable. The attacker gains nothing at the moment of capture, so there is no breach to detect and nothing to notify. The exposure is realized years afterwards, which makes the risk a function of how long your data must stay secret rather than of how strong your encryption is today.

That reframing is the entire point. A firm asking “is our encryption strong enough?” is asking the wrong question. The right one is “how long does this need to hold, and will it?”

DKBinnovative vCIO advising a law firm on post-quantum readiness and crypto-agility
Early, not urgent. The distinction matters for budgeting.

Why This Lands Differently on Professional Firms

General business data has a short secrecy half-life. A price list stolen today and decrypted in 2034 is worthless. Professional firms hold the opposite kind of material.

Law firms: privilege does not expire

Attorney-client privilege survives the matter, the relationship and in most circumstances the client’s death. A privileged communication intercepted in encrypted form this year and opened in 2033 is still privileged, and its disclosure is still a harm. ABA Formal Opinion 477R already requires lawyers to make judgments about securing client communications based on sensitivity, and Model Rule 1.1’s technology comment requires keeping current with the risks of relevant technology. Neither of those obligations has a carve-out for risks that mature slowly.

Investment firms: retention outlasts the encryption

SEC recordkeeping obligations keep advisory records for years, and the customer information covered by Regulation S-P does not become harmless with age. Account numbers, tax identifiers and financial histories retain their value to an attacker far longer than a normal breach window. We cover the current obligations in our piece on what Reg S-P now requires firms to evidence.

CPA firms: the data is permanent by nature

A Social Security number does not get reissued because it was disclosed late. Tax records, beneficial ownership details and multi-year financial histories are among the longest-lived sensitive data any small firm holds, and the WISP obligations under IRS Publication 4557 apply to protecting it for as long as you hold it.

When Do Firms Need to Be Post-Quantum Ready?

Firms need to be post-quantum ready before the sum of their data’s required secrecy lifetime and their migration time exceeds the time remaining until quantum decryption is feasible. NIST has published the schedule that anchors this: quantum-vulnerable algorithms are deprecated after 2030 and disallowed after 2035, and the NSA’s CNSA 2.0 requires national security systems to migrate by 2030. A firm holding data that must stay confidential for ten years is already inside the window.

That arithmetic is worth doing explicitly, because it produces a different answer for different firms.

Firm type Typical secrecy lifetime Inside the window?
Litigation or corporate law firm Indefinite; privilege does not lapse Yes, clearly
RIA or wealth manager Client lifetime plus estate administration Yes
CPA or tax practice Decades; identifiers never change Yes
General commercial business Months to a few years Usually not yet

This is why the generic advice aimed at small business, which amounts to wait and see, is wrong for professional firms specifically. The waiting is the exposure.

Want to know where your firm’s long-lived data actually sits? We run a cryptographic inventory as part of our security assessment for professional firms. Call (888) 352-4832 or request one.

What Is Crypto-Agility, and Why Is It the Actual Deliverable?

Crypto-agility is the ability to change the cryptographic algorithms a system uses without rebuilding the system. It matters more than any individual algorithm choice, because the practical failure mode is not picking the wrong cipher. It is having encryption hard-coded into applications, appliances and integrations so deeply that changing it requires a project nobody has budgeted.

NIST published the first three post-quantum standards in 2024, including ML-KEM for key establishment and ML-DSA for digital signatures. Most firms will never touch those names. What they will experience is whether their vendors can turn the new algorithms on, and whether anyone at the firm knows which systems are waiting on which vendor.

What a Firm Should Actually Do This Year

None of this requires buying quantum anything. The useful work in 2026 is inventory and leverage.

  1. Build a cryptographic inventory. Which systems hold or transmit data with a long secrecy lifetime, what protects it, and who supplies that protection. Most firms have never written this down, and it is the prerequisite for every later decision.
  2. Classify by secrecy lifetime, not by sensitivity. These are different axes. A document can be moderately sensitive and need to stay secret for thirty years. That is the one that matters here.
  3. Put the question to your vendors now. Ask your document management, practice management, portfolio accounting, email and VPN providers for their post-quantum roadmap in writing. You are not expecting a migration date. You are establishing that you asked, and finding out which vendors have no answer at all.
  4. Prioritize data in transit. Harvest now, decrypt later is primarily an interception problem. Traffic crossing untrusted networks is the first thing to care about, ahead of data sitting on an encrypted disk in your office.
  5. Fold it into what you already do. Add a post-quantum roadmap question to your vendor review cycle, and add long-lived data to your client security questionnaire evidence pack. This should cost you a meeting, not a project.
  6. Write down the decision. Whatever you conclude, record that the firm considered it and why it chose the timeline it chose. For lawyers this is the technology-competence duty discharged in the only way that is provable later.

The NIST post-quantum cryptography project is the authoritative reference if someone at your firm wants the primary source, and the NIST Cybersecurity Framework gives you a structure to hang the inventory on.

What Not to Do

Three failure modes are already visible in how this topic gets sold.

  • Buying a product to solve it. There is no post-quantum appliance that makes a firm ready. Readiness is an inventory and a vendor posture, and anyone selling otherwise is ahead of the evidence.
  • Treating it as urgent. It is not urgent. It is early, which is a different thing and calls for a different budget. A firm that panics now will overspend on the wrong layer.
  • Ignoring it because the date is uncertain. The uncertainty cuts the other way. Because nobody can tell you when, a firm holding thirty-year secrets cannot argue it had time.

Frisco, Plano and Irving

Plano firms tend to hold the deepest archives, because the region’s established practices have twenty to forty years of accumulated matter files and client records. Long-lived data is exactly the exposure this creates, and it is usually spread across systems nobody has catalogued. Our Managed IT Plano team handles these inventories, and our Managed IT Plano security practice covers the financial-firm side.

Irving and Las Colinas firms will meet this first through someone else’s questionnaire. The corridor’s corporate and institutional clients run mature vendor diligence, and post-quantum roadmap questions have started appearing in enterprise assessments. Our Managed IT Irving practice works from an office at 7301 State Hwy 161, and our Managed IT Irving team tracks what is showing up in those reviews.

Frisco firms have the easiest version of this problem and the shortest path through it. Cloud-native practices inherit their cryptography from a small number of major platforms, which means readiness is largely a matter of knowing which platforms and keeping current. DKBinnovative is headquartered in Frisco; our Managed IT Frisco and Managed IT Frisco teams cover this work.

Frequently Asked Questions

What is harvest now, decrypt later?

Harvest now, decrypt later is an attack in which encrypted data is captured today and stored until quantum computing makes it decryptable. There is no breach to detect at the time of capture, so the risk is a function of how long your data must stay secret rather than of how strong your encryption is today.

When do firms need to be post-quantum ready?

Before the sum of their data’s required secrecy lifetime and their migration time exceeds the time remaining until quantum decryption is feasible. NIST deprecates quantum-vulnerable algorithms after 2030 and disallows them after 2035, and NSA CNSA 2.0 requires national security systems to migrate by 2030. A firm holding data that must stay confidential for ten years is already inside the window.

What is crypto-agility?

Crypto-agility is the ability to change the cryptographic algorithms a system uses without rebuilding the system. It matters more than any individual algorithm choice, because the common failure is encryption hard-coded into applications and appliances so deeply that changing it becomes an unbudgeted project.

Is this urgent for a small law or accounting firm?

It is early rather than urgent, and the distinction matters for budgeting. But it applies earlier to professional firms than to general businesses, because privilege does not expire and tax identifiers are never reissued. The work due this year is inventory and vendor questions, not spending.

Do we need to buy anything to become post-quantum ready?

No. There is no product that confers readiness. What a firm needs is a cryptographic inventory, a classification of data by secrecy lifetime, and written post-quantum roadmaps from the vendors that supply its encryption.

Does this affect our compliance obligations today?

Not directly. No current rule requires post-quantum migration for private firms. Indirectly it reaches lawyers through the technology-competence duty and reaches every firm through client security questionnaires, where post-quantum roadmap questions have begun to appear in enterprise vendor assessments.

Working With DKBinnovative

We have supported professional firms across Dallas-Fort Worth since 2004, which is 22 years, currently covering 2,632+ end users across 55+ companies with a 78% first-call resolution rate and 98.14% client satisfaction. Our infrastructure standardizes on Microsoft Azure and Microsoft 365, both of which are moving on post-quantum work at platform level, which is a large part of why cloud-native firms have a shorter path here.

If you want to know where your firm’s long-lived data sits and which vendors have an answer, that is a cryptographic inventory and it takes us a few weeks. It is the only part of this that is worth doing right now.

Call (888) 352-4832 or book an assessment.

Related reading: Investment & Professional Firms · IT Support for Law & Accounting Firms · Managed IT for Law Firms · Managed IT for RIA Firms · Client Security Questionnaires

External references: NIST Post-Quantum Cryptography Project, NIST Cybersecurity Framework, 17 CFR Part 248, IRS Publication 4557.

Which Cybersecurity-Focused Managed IT Service Has Rapid Response? 6 Checks for DFW Firms

 

By the DKBinnovative Crew | Published: September 8, 2026 | Reviewed by Peter Bertran, Chief Client Officer

Which cybersecurity-focused managed IT service has rapid response?

A cybersecurity-focused managed IT service has rapid response when analysts are employed in-house, monitoring runs continuously rather than during business hours, and the same provider that detects a threat also has the access to contain it. Speed claims that rest on a subcontracted monitoring layer usually mean a handoff, and handoffs are where the hours go.

Most providers publish a response number. Very few publish what it measures. A 15-minute guarantee on acknowledging a ticket is a different promise from a 15-minute guarantee on isolating a compromised endpoint, and only one of those matters at 2am on a Saturday.

Is response speed actually your problem?

Response time is worth paying for when your exposure is time-sensitive: client funds move through your systems, an outage stops billable work, or a regulator expects documented containment within a set window. Investment advisers, CPA firms and law practices sit in that category by default.

It is worth less if your real gap is somewhere else. If nobody has reviewed who has administrator rights, if backups have not been restored from in a year, or if half the company still signs in without multifactor authentication, a faster alert only tells you sooner about a problem you were not positioned to survive. Fix the baseline first. CISA’s cyber guidance for small businesses is a reasonable checklist for what that baseline covers.

A quick way to tell which problem you have: work out how long your business can operate with its primary systems unavailable, then compare that to how long it would take anyone to notice. If the gap between those two numbers is small, response speed is your constraint. If nobody would notice for a day, detection coverage is the constraint and speed is premature.

Firms often discover the answer during a cyber insurance renewal, when the questionnaire asks about monitoring coverage, incident response procedures and containment authority in the same section. Those questions exist because insurers price the gap between detection and containment.

Six ways to verify a provider’s response speed before you sign

1. Ask what the clock measures. First response, first human response, first qualified analyst, and containment are four different events. Ask which one the published number refers to, then ask for last quarter’s actual figures rather than the SLA target.

2. Ask who answers at 2am. Find out whether after-hours coverage is staffed, on-call, or outsourced to a partner in another timezone. The answer changes what happens in the first hour of an incident, which is the hour that decides how bad it gets.

3. Ask whether they can act or only alert. A monitoring service that emails you at 3am has transferred the problem back to you. Ask whether the provider can isolate a device, disable an account, and block a sender without waiting for your approval, and what the standing authorisation looks like.

4. Ask how many hands are behind the promise. A two-person shop can respond quickly right up to the moment both people are busy. Bench depth is what makes a response time repeatable rather than occasional.

5. Ask whether security is in-house or resold. A subcontracted security layer adds a vendor boundary at exactly the point an incident makes that boundary expensive. The joint federal advisory on cyber threats to managed service providers and their customers is worth reading before you accept a nested arrangement.

6. Ask what evidence comes out the other side. If you are examined or insured, the incident matters less than the record of it. Ask what documentation the provider produces after containment and whether an examiner has ever accepted it.

Comparing providers right now? Bring these six questions to your next call, including ours. Book a conversation with DKBinnovative or call (888) 352-4832 and ask us to answer them on the spot.

Why response times slip in practice

Providers rarely miss a response target because nobody cared. They miss it because of how the work is organised, and the same three causes come up repeatedly.

The alert queue is not triaged by a human. Tooling generates far more signals than any environment produces real incidents. When nobody filters them, the genuine event arrives in the same inbox as three hundred false positives and waits its turn. Triage is the difference between monitoring and security operations.

The people who detect cannot act. If containment requires a ticket to a different team, a different company, or a client approval nobody can give at 3am, the clock keeps running while the work sits still. This is the most common reason a good detection turns into a bad outcome.

Project work and support share the same engineers. When the team answering alerts is also running a migration that week, response degrades exactly when the provider is busiest, which tends to correlate with when clients are busiest too. Separating those tracks is a structural fix, not a staffing one.

None of these show up in a sales conversation unless you ask. All three are visible in last quarter’s numbers if the provider will share them.

What an in-house Security Operations Center changes

DKBinnovative runs its Security Operations Center in-house rather than reselling a third-party layer. It is staffed 24 hours a day, and the analysts watching your environment work for the same company as the engineers who can act on what they see. That structure is the reason the numbers hold: a 3-minute average first response including after-hours, and 78% of issues resolved on the first call.

We have supported Dallas-Fort Worth firms since 2004, from our headquarters in Frisco at 1701 Legacy Dr, with offices in Plano and Irving. That proximity matters when an incident needs hands on hardware rather than a remote session. See our cybersecurity services in Frisco, or the detail on how our managed IT with SOC support is put together.

In-house SOC, resold monitoring and break-fix compared

In-house SOC Resold monitoring Break-fix
Who watches Provider’s own analysts Third party under contract Nobody between calls
Hours 24/7/365 Varies by the vendor behind it When you call
Can contain Yes, same team Usually escalates back No
Vendor boundary in an incident None One or more Not applicable
Evidence for examiners Collected continuously Depends on the subcontract Repair invoices

What investment and professional firms should ask for

Registered investment advisers, CPA practices and law firms carry an obligation that most businesses do not: proving the control operated, not just that the incident was handled. For those firms, response speed and evidence collection are the same conversation.

Ask a prospective provider to walk you through a real containment from the past year, without naming the client: what was detected, who acted, how long each step took, and what the firm was able to hand its examiner afterwards. A provider who can narrate that from documentation is running a program. One who describes it from memory is running a habit. Our work with investment and professional firms is built around that distinction, and the NIST Cybersecurity Framework is a useful reference for what the documentation should cover.

Talk to a team that answers its own phone

If you are comparing providers on response time, ask us the six questions above and see how the answers differ. DKBinnovative supports 55 companies and more than 2,632 end users across Frisco, Plano and Irving, with 46 engineers, an in-house 24/7 Security Operations Center, and 98.14% client satisfaction scored on every ticket.

Talk to our team or call (888) 352-4832.

Frequently Asked Questions

Which cybersecurity-focused managed IT service has rapid response?

One where analysts are employed in-house, monitoring runs 24/7 rather than during business hours, and the provider that detects a threat can also contain it without a handoff. Ask what the published response number measures, because acknowledging a ticket and isolating a compromised endpoint are different events.

What is a good response time for a managed IT provider?

Judge the definition before the number. A useful benchmark is a first human response inside a few minutes at any hour, with containment actions starting without waiting on client approval. DKBinnovative averages a 3-minute first response including after-hours and resolves 78% of issues on the first call.

Does an in-house SOC really respond faster than outsourced monitoring?

Usually, because the delay in a nested arrangement is the handoff rather than the detection. When the analyst and the engineer work for the same company, containment starts in the same conversation instead of a ticket passed between vendors.

What should a provider give us after a security incident?

A written record of what was detected, what actions were taken and when, which systems and data were involved, and what changed afterwards. Regulated firms should confirm the format is one an examiner or insurer has accepted before, not a summary written for the occasion.

Do you support firms in Plano and Irving as well as Frisco?

Yes. DKBinnovative is headquartered in Frisco with offices in Plano at 1400 Preston Rd and Irving at 7301 State Hwy 161, and the same SOC and help desk cover all three.


IT Budget Planning for 2027: What Growing Firms Should Fund First

IT budget planning for 2027 for growing firms

What is IT budget planning?

IT budget planning is the process of deciding what your organization will spend on technology over the coming year and, more importantly, what that spending is meant to accomplish. A useful IT budget is not a list of renewals. It separates the cost of keeping current systems running from the cost of protecting them and the cost of supporting where the business is going — and it is built from a technology roadmap rather than from last year’s invoices.

Most firms start this work in September and October, which is the right instinct. Budget season is the one point in the year when technology decisions get made deliberately instead of under pressure.

Why Most IT Budgets Are Really Just Last Year Plus Inflation

The common approach is to pull last year’s spend, add a percentage, and submit it. It passes review, and it quietly guarantees three outcomes.

Nothing gets retired. Every tool renews because nobody had a reason to question it. Firms routinely discover they are paying for overlapping products nobody chose deliberately.

Growth is unfunded. Last year’s budget was built for last year’s headcount and last year’s footprint. If you are hiring, opening a location, or acquiring, none of that work has money attached to it — so it gets deferred until it becomes urgent, which is the most expensive moment to fund anything.

Security stays flat while exposure grows. More people, more devices, and more data mean more to protect. A security line that does not move while the business does is a real reduction.

A Three-Bucket Framework: Run, Protect, Grow

Separating spend into three categories makes the trade-offs visible, which is the entire point of budgeting.

Run is what keeps the business operating today: licensing, connectivity, support, hardware refresh, backup. This is your floor. It should be predictable, and if it is not, that is the first problem to solve.

Protect is what keeps the business defensible: security tooling, monitoring, identity management, awareness training, incident response readiness, and the evidence work that regulated firms need. It should scale with headcount and data, not stay fixed. The NIST Cybersecurity Framework is a practical reference for what belongs in this bucket.

Grow is what supports where the business is going: new locations, migrations, acquisitions, automation, and AI adoption. This is the bucket most firms never fund explicitly — and the reason growth work keeps getting done in emergency mode.

If you cannot say roughly how your spend splits across those three, the budget is a renewal list rather than a plan.

Why We Do Not Publish Budget Benchmarks

You will find articles offering a percentage of revenue you should spend on IT. We do not publish those numbers, because they mislead more often than they help.

A thirty-person RIA with examination obligations, a thirty-person construction firm with field connectivity needs, and a thirty-person software company have almost nothing in common in what their technology has to do. A benchmark built by averaging them describes none of them. What actually determines your number is regulatory exposure, how distributed your workforce is, the age of your infrastructure, and how fast you are growing. Those are questions to answer, not a percentage to copy.

Planning your 2027 technology budget? Talk to our team or call (888) 352-4832.

What Investment and Professional Firms Have to Budget That Generic Guides Miss

General IT budgeting advice assumes an unregulated business. For firms handling client money, client data, or privileged information, several line items are not optional and are routinely forgotten until an examiner or insurer asks.

  • Evidence collection, not just controls. Having multifactor authentication is one thing; being able to demonstrate it operated continuously across the period under review is another. That reporting work is a budget line.
  • Examination and audit support. For RIAs and wealth management firms, SEC Division of Examinations cycles consume real time. Budget for the support, not just the controls.
  • Written program maintenance. A written information security program is not a one-time document. Reg S-P, the FTC Safeguards Rule, and IRS Publication 4557 all expect review and update cycles.
  • Seasonal capacity. Accounting and CPA firms add seasonal staff who each need devices, accounts, and security configuration — then offboarding. That is a predictable annual cost most budgets treat as a surprise.
  • Confidentiality architecture. For law firms, each new practice area can require ethical walls and document access design. It is project work, and it belongs in Grow.
  • Cyber insurance requirements. Renewal questionnaires increasingly require specific controls, most of them mapping to baseline practices CISA recommends. Discovering a gap at renewal is worse and more expensive than budgeting for it now.

Build the Roadmap First, Then the Budget

A technology roadmap is a sequenced plan of what changes over the next one to three years and why. The budget is what that plan costs. Doing it in the other order produces a number without a rationale, which is the version that gets cut first when finance looks for savings.

A workable roadmap answers four things:

  1. What is reaching end of life? Hardware, operating systems, and applications with known end-of-support dates. These are the least negotiable items and the easiest to forecast.
  2. What does the business plan require? Headcount targets, new locations, acquisitions, new service lines. Each one has a technology cost, and it is cheaper when it is anticipated.
  3. Where is risk concentrated? Single points of failure, unsupported systems, gaps a cyber insurer or examiner would flag.
  4. What is not earning its keep? Overlapping tools, unused licenses, and services nobody has evaluated in three years.

This is the work a vCIO does. If nobody is producing a document like this for your firm, the budget is being assembled without one.

Questions to Answer Before You Finalize

  • What are we retiring this year, and what does that free up?
  • Which line items scale with headcount, and does our forecast reflect our hiring plan?
  • What in this budget is growth work, and what happens to the plan if it gets cut?
  • Which controls will our cyber insurer or regulator ask about at renewal or examination?
  • What have we deferred two years running, and what is the cost of deferring it again?
  • If we opened a second location in Q2, what in this budget would have to change?

Planning With a Partner Instead of Alone

DKBinnovative has supported businesses across Frisco, Plano, and Irving since 2004. We are a growth-minded IT partner for small and mid-sized firms, which means we plan technology around where the business is heading — new people, new offices, acquisitions — with security and compliance built into that plan rather than bolted on after something breaks.

In practice, budget season is when a dedicated vCIO earns their place: mapping end-of-life exposure, sequencing projects against your business plan, and producing a roadmap finance can actually evaluate. Behind that sit 46 engineers, a 24/7 in-house Security Operations Center, a 3-minute average first response, and 98.14% client satisfaction scored on every ticket.

If your current provider has not sat down with you to plan next year, that is worth noticing during budget season. Our guide on whether your MSP can scale with your business covers what to ask.

Frequently Asked Questions

What is IT budget planning?

IT budget planning is the process of deciding what an organization will spend on technology over the coming year and what that spending is meant to accomplish. A useful IT budget separates the cost of running current systems from the cost of protecting them and the cost of supporting growth, and it is built from a technology roadmap rather than from last year’s invoices.

When should we start IT budget planning?

Most organizations begin in September or October for a January fiscal year, which allows time to gather end-of-life data, get quotes, and sequence projects before approval deadlines. Starting later usually means submitting last year’s numbers with an increase applied, because there is no time to build a roadmap first.

What should an IT budget include?

Group spending into three categories. Run covers licensing, connectivity, support, hardware refresh, and backup. Protect covers security tooling, monitoring, identity management, awareness training, incident response readiness, and compliance evidence work. Grow covers new locations, migrations, acquisitions, automation, and AI adoption. Most firms fund the first two and never explicitly fund the third.

How much should a company spend on IT?

Benchmarks expressed as a percentage of revenue tend to mislead, because two organizations of identical size can have completely different requirements depending on regulatory exposure, how distributed the workforce is, infrastructure age, and growth rate. The more useful approach is to build a technology roadmap covering end-of-life systems, business plans, concentrated risk, and underused tools, then cost that plan.

What is the difference between an IT budget and a technology roadmap?

A technology roadmap is a sequenced plan of what changes over the next one to three years and why. The IT budget is what that plan costs. Building the budget first produces a number without a rationale, which is the version most likely to be cut when finance looks for savings.

What do regulated firms need to budget for that other businesses do not?

Evidence collection to demonstrate controls operated continuously, examination and audit support time, maintenance cycles for written information security programs under Reg S-P, the FTC Safeguards Rule, or IRS Publication 4557, seasonal staffing capacity for firms with busy seasons, confidentiality architecture such as ethical walls, and the specific controls cyber insurers require at renewal.

How to Tell If Your MSP Can Scale With Your Business

How to tell if your MSP can scale with your business

How do I know if my MSP can scale with my business?

You find out by asking your provider to show you three things: how they onboard a new office or acquisition, what their capacity looks like beyond the people you already talk to, and whether they plan technology against your business goals or only respond to your tickets. An MSP that scales has documented answers to all three. One that does not will describe how responsive they are — which is a statement about support, not about growth.

This matters most in investment and professional services firms, where a provider who cannot produce evidence on request becomes a liability the moment an examiner or insurer asks. Most providers are perfectly capable at your current size. The question is not whether they are good today. It is whether the way they work has a mechanism for what happens next.

What Makes an IT Provider Scalable?

Five structural things separate providers that grow with clients from those that get overwhelmed by them.

Bench depth, not just responsiveness. A scalable provider has specialists across networking, cloud, security, compliance, and strategy — not two generalists who are excellent until both are busy. When you add fifty users, capacity has to already exist.

Documented, repeatable processes. Onboarding, offboarding, device builds, and site standups should follow a written standard that produces the same result every time. Providers who rely on individual knowledge hit a ceiling the moment that individual is on another project.

Project capacity separate from support. Growth work is project work. If the same engineers answer tickets and run migrations, the migration slips — every time — because tickets are louder.

Strategic planning, not just service delivery. A dedicated vCIO who plans against your business roadmap is the difference between IT that anticipates growth and IT that reacts to it after the fact.

Multi-site and multi-entity experience. Ask whether they have actually stood up a second location or integrated an acquisition — not whether they could. These are the two moments where inexperience becomes expensive.

Ten Questions to Ask Your Current Provider

  1. How many engineers would be available to us if we doubled in size next year?
  2. Walk me through how you would open a second office for us. What is the sequence?
  3. Have you integrated an acquisition before? What did the first 30 days look like?
  4. Who handles project work when the support queue is busy?
  5. What is your documented onboarding process for a new employee, and how long does it take?
  6. Show me last quarter’s resolution times by ticket priority — not first response.
  7. What percentage of our machines are patched right now?
  8. When did you last restore from one of our backups to verify it works?
  9. Who is our strategic contact, and when did we last review a technology roadmap together?
  10. If we entered a regulated space or pursued SOC 2, could you support the evidence requirements?

The answers matter less than whether they exist. A provider who can answer these from documentation is built to scale. One who has to go find out is telling you something useful.

Outgrowing your current provider? Talk to our team or call (888) 352-4832.

Which MSPs Specialize in High-Growth Businesses?

Providers built for high-growth companies look different from general small-business IT shops in ways you can check before signing anything:

  • They talk about roadmaps, not just response times. Speed matters, but a provider whose entire pitch is how fast they answer is describing a help desk.
  • They have done multi-site work. Ask for a specific example, not a capability claim.
  • Security is in-house, not resold. A subcontracted security layer adds a vendor boundary exactly when an incident makes that boundary expensive.
  • Their model flexes. Co-managed for firms with internal IT, fully managed for firms without, and the ability to move between the two as you grow rather than re-contracting.
  • They publish performance. A provider tracking first-call resolution and satisfaction on every ticket is measuring something. One who does not, is not.

DKBinnovative is an MSP for high-growth companies Plano firms work with, and we provide IT support for fast-growing companies Plano TX businesses depend on as they add people and locations. Since 2004 we have supported firms across Frisco, Plano, and Irving with 46 engineers, a 24/7 in-house Security Operations Center, a 3-minute average first response, 78% first-call resolution, and 98.14% client satisfaction scored through CrewHu on every single ticket.

Signals Your Provider Has Already Hit Its Ceiling

  • Projects keep slipping. The migration has been “next month” for two quarters.
  • You have become the documentation. They ask you how something was configured.
  • The same issues recur. Nobody is doing root-cause work because nobody has time.
  • Onboarding is a scramble. New hires wait days for access that should take hours.
  • Strategy conversations have stopped. Every interaction is a ticket. Nobody has asked where the business is going in a year.
  • You hear “we’ll need to bring in a partner for that.” Occasionally fine. Routinely, it means the capability is not theirs.

What Investment and Professional Firms Should Look For

For RIAs and wealth management firms, scaling means more advisors on custodial platforms and more client data under SEC Regulation S-P — a provider who cannot produce evidence on request is a liability at the next examination.

For accounting and CPA firms, capacity has to absorb busy season without degrading, and every seasonal hire carries IRS Publication 4557 obligations from day one.

For law firms, each new practice area adds confidentiality boundaries that have to be designed rather than improvised.

For private equity portfolio companies, the test is whether the tenth add-on acquisition onboards like the first. That only happens with a documented playbook.

We are a growth-minded IT partner for small and mid-sized businesses: we plan technology around where the firm is heading, with security and compliance built into that plan rather than bolted on afterward. See our co-managed IT services if you have an internal IT lead who needs depth behind them.

Best managed IT provider for a scaling company

The best provider for a scaling company already has the capacity you will need next year. That means bench depth across networking, cloud, security and compliance, documented onboarding that runs the same way every time, and project work on a separate track from the ticket queue. If capacity has to be hired after you sign, growth work slips.

Frequently Asked Questions

How do I know if my MSP can scale with my business?

Ask them to show you three things: their documented process for opening a new office or integrating an acquisition, what engineering capacity exists beyond the people you normally deal with, and whether they plan technology against your business goals or only respond to tickets. A provider built to scale answers all three from documentation. One that is not will talk about how responsive they are, which describes support rather than growth.

What makes an IT provider scalable?

Five structural things: bench depth across networking, cloud, security, compliance and strategy rather than a couple of generalists; documented repeatable processes for onboarding, device builds, and site standups; project capacity that is separate from the support queue; strategic planning through a dedicated vCIO; and demonstrated multi-site or multi-entity experience. Responsiveness is a support quality, not a scalability one.

Which MSPs specialize in high-growth businesses?

Providers built for high-growth companies discuss technology roadmaps rather than only response times, can cite specific multi-site or acquisition work rather than claiming the capability, run security operations in-house rather than reselling them, offer both co-managed and fully managed models so the engagement can change as you grow, and publish measured performance such as first-call resolution and satisfaction per ticket.

What are the signs we have outgrown our IT provider?

Projects that keep slipping quarter to quarter, being asked by your provider how your own systems were configured, the same issues recurring because nobody has time for root-cause work, onboarding that takes days instead of hours, strategy conversations that have stopped entirely, and routinely hearing that a third party will need to be brought in for capabilities you now require.

Should we switch providers or add capacity to the one we have?

If the gap is bandwidth, a co-managed arrangement can add depth without replacing anyone. If the gap is capability — no security operations, no project capacity, no strategic planning — adding hours does not fix it, because the missing pieces are structural rather than a matter of volume.

Sales & Support
(888) 352-4832