Prep for a Secure Firm: A Cybersecurity Awareness Month Checklist

We asked our security team what they would tell an investment or professional firm to fix first.
None of it requires new software, a budget cycle or an outside consultant. Every recommendation below is finishable in an afternoon by whoever already administers your systems, and each one comes from what we find repeatedly when we take over environments at law, CPA and investment firms across Dallas-Fort Worth.
October is Cybersecurity Awareness Month, which makes it a convenient time to work through them. The recommendations hold the rest of the year too.
What Do Security Experts Recommend for an Investment or Professional Firm?
An investment or professional firm should use Cybersecurity Awareness Month to fix the small number of things that actually cause breaches at firms like theirs: unenforced multifactor authentication, accounts belonging to people who left, mailbox forwarding rules nobody is alerted on, and backups that have never been restored. Awareness training is worth running, but it does not change the environment. These four recommendations do.
Cybersecurity Awareness Month is run each October by the Cybersecurity and Infrastructure Security Agency. Its baseline for individuals covers phishing, strong passwords, multifactor authentication, and updates. For organizations, it adds logging, backups, encryption, and incident response planning. Everything below maps to one of those.
Recommendation One: Fix Identity Before Anything Else
Identity is the layer everything else sits on. If it is wrong, nothing above it holds.
- Enforce multifactor authentication with no exceptions. The exceptions are usually partners, and partners are the accounts attackers want. “Almost everyone” is not enforced.
- Switch off legacy authentication. It is the quiet way around MFA. If it is still enabled anywhere in your tenant, your MFA is optional.
- Find the accounts belonging to people who left. Pull a report of every account with no sign-in in ninety days. In almost every environment we inherit, at least one still has elevated access.
- Separate privileged accounts from daily-use ones. Nobody should be reading email from an account that can change tenant settings.
Recommendation Two: Make Email Compromise Visible
Email is where the money actually leaves. Business email compromise remains among the costliest categories of cybercrime in the FBI IC3 annual reports, year after year.
- Turn on alerting for mailbox forwarding rules. Compromise almost always announces itself through a quietly created forward. Alert on rule creation, external forwarding and new delegate permissions. This is the single highest-value hour on the whole list: it turns a months-long compromise into a same-day one.
- Audit delegate access on partner and executive mailboxes. Delegates accumulate over years and are almost never removed.
- Check DMARC and DKIM on every domain you own, not just the primary one. Firms routinely protect the main domain and leave the old one wide open for spoofing.
- Agree one rule for sensitive material. Matters involving personal financial data, health information or sealed filings go through a portal, not an attachment. Then make the secure path the easy one, because controls people route around are not controls.
Recommendation Three: Prove You Can Recover
This is the recommendation that produces the most uncomfortable answer, which is why it is worth acting on.
- Run an actual restore. Not a backup check. A restore. Write down the date and what broke, because something always does.
- Know your recovery order. If everything went down tonight, which system comes back first? For most firms it is the document system and time and billing, not email, and most firms have never said so out loud.
- Test that you can reach people. If your email is the thing that is down, how does the firm coordinate? A phone tree written on paper is not old-fashioned, it is a control.
A backup job reporting success is a claim. A completed restore is evidence. The difference matters the week you need it, and it matters every time a client asks.
Recommendation Four: Be Able to Show Your Work
The first three change the environment. This one lets you prove it, which is increasingly what clients want.
- Write the incident response plan down. One page naming who decides, who calls the client and within how many days beats a sophisticated plan that does not exist.
- Build the evidence pack once. A current inventory of systems holding client data, your last restore date, your access review records, a subcontractor list, training completion records. Assemble it once and every future request becomes a mapping exercise.
- Ask your IT provider for their own security documentation. You are expected to oversee them. If they cannot produce it for you, they will not produce it when a client asks either.
Four Things Worth Telling Your Team
Everything above is administrator work. This part is for everyone else, and it is short enough to paste into a firm-wide email.
- Length beats complexity on passwords. A long passphrase you can remember is stronger than a short one with symbols bolted on, and far stronger than the same password reused on twelve sites. The one that matters most is the password on your email, because that is the account that resets all the others. We wrote more on this in password security for DFW investment and professional firms.
- Use a password manager, and stop trying to remember them. Reuse is the actual risk. When a breach elsewhere exposes a password you also use at work, attackers try it against your firm within hours. Credential stuffing at that scale is routine, as the 16 billion credential leak made obvious.
- Approve nothing you did not start. If a multifactor prompt appears and you were not signing in, that means someone already has your password. Deny it and report it the same hour. Attackers rely on people approving a prompt to make it stop.
- Urgency plus a change of payment details is the tell. Almost every successful attack on a professional firm involves a message that is urgent, plausible, and asks for money to move or credentials to be entered. Slow down, and confirm it on a number you already had, never the one in the message.
None of that is new advice. It is on this list because it still works, and because the firms we onboard are rarely breached by anything cleverer.
The Best Self-Test We Know
If you want a harder version of all of the above, borrow the instrument your clients already use: a client security questionnaire.
Take a blank one and answer it honestly as a firm. Better still, hand it to someone who did not build the environment and ask them to answer from evidence alone. Whatever they cannot find is what a client will not be able to verify either.
We covered how these work, what reviewers are really testing, and the answers that quietly lose engagements in our guide to client security questionnaires.
What We Actually Find
None of this is theoretical. Across onboarding engagements with investment and professional firms, the same findings come up:
Multifactor authentication not enforced, legacy authentication still enabled, and stale directory accounts still live. A three-office CPA firm whose server backup jobs had been failing repeatedly across multiple years, with client financial data exposed the entire time, because the jobs reported and nobody read the reports. A wealth management firm where a business email compromise redirected a client payment to a fraudulent account.
Not one of those is exotic. No zero-day, no sophisticated adversary. Every item is a known problem with a known fix, sitting unaddressed because nobody owned it. That is what a month of focused attention is actually for.
Who Owns This After October?
The honest limitation of any checklist is that it is a moment in time. Working through these four fixes what is broken today and does nothing about what changes in March, when someone joins, a vendor is swapped, or a client sends a questionnaire with a question nobody has considered.
Security at a professional firm is a standing function, not a project. Most firms between ten and a hundred and fifty people cannot justify a full-time chief information security officer, and hiring one is rarely the right answer anyway. What they need is the function: someone accountable for the risk register, the policies, the evidence pack, the vendor reviews and the board-level reporting, on a schedule rather than in a panic.
That is what a vCISO is. Senior security direction without the hire, sized to a firm rather than an enterprise. For firms in the Legacy and Preston corridors, our vCISO practice in Plano covers exactly this, and for family offices and investment firms, we run a dedicated version with the regulatory overlay built in.
If October leaves you with a list of things nobody owns, that is the gap a vCISO closes.
Want these run for you? We do this as a security assessment for investment and professional firms, and you get the findings whether or not you engage us. Call (888) 352-4832 or book one.
Frisco, Plano and Irving
Frisco firms are typically newer and cloud-native, so the identity work is usually quick and the evidence work is the hard one: good controls, thin documentation. DKBinnovative is headquartered in Frisco, and our Managed IT Frisco team runs this work locally, while our Managed IT Frisco practice for financial and professional firms handles the compliance layer on top.
Plano holds the region’s most established practices, which means the identity work takes longer: legacy authentication, file servers and permission structures that predate anyone currently working there. Our Managed IT Plano team does most of these untanglings, and our Managed IT Plano security practice handles what the audit turns up.
Irving and Las Colinas firms are usually already being asked. The corridor’s corporate tenant base runs real vendor due diligence, so the evidence work tends to arrive uninvited. Our Managed IT Irving practice works from 7301 State Hwy 161, and our Managed IT Irving team handles the evidence side.
Frequently Asked Questions
What should an investment or professional firm do for Cybersecurity Awareness Month?
Fix the small number of things that actually cause breaches at firms like yours: unenforced multifactor authentication, accounts belonging to people who left, mailbox forwarding rules nobody is alerted on, and backups that have never been restored. Awareness training is worth running, but it does not change the environment.
When is Cybersecurity Awareness Month?
Every October, run by the Cybersecurity and Infrastructure Security Agency. Its baseline covers phishing, strong passwords, multifactor authentication and updates, with logging, backups, encryption and incident response added for organizations.
What is the single highest-value security fix for a small firm?
Alerting on mailbox forwarding rules. Business email compromise almost always announces itself through a quietly created forward, and alerting on rule creation turns a months-long compromise into a same-day one. It takes about an hour to configure.
How do we know whether our backups actually work?
Run a restore. A backup job reporting success is a claim; a completed restore is evidence. Note the date and what broke during it, because clients increasingly ask for exactly that.
Do we need a CISO, or is a vCISO enough?
For most investment and professional firms between ten and a hundred and fifty people, a vCISO is the right size. You get the function that matters, meaning the risk register, policies, evidence pack, vendor reviews and board reporting on a schedule, without carrying a full-time executive salary. A full-time CISO starts making sense at a scale most DFW investment and professional firms have not reached.
What if we already have an IT provider?
Then most of this is their job, and the useful move is to ask. Send them the four recommendations and ask which are already in place, which are not, and why. A good provider answers with specifics and dates. A provider who treats the questions as an inconvenience has told you something worth knowing.
Working With DKBinnovative
We have supported investment and professional firms across Dallas-Fort Worth since 2004, which is 22 years, currently spanning 2,632+ end users across 55+ companies with a 78% first-call resolution rate and 98.14% client satisfaction. We standardize on Microsoft Azure and Microsoft 365, and deploy Hatz.AI where firms need governed AI that keeps client material inside their own tenant.
If October is the month you finally get security attention at your firm, spend it on the four recommendations above. If you would rather we ran them for you, that is a security assessment.
Call (888) 352-4832 or book an assessment.
Related reading: The Professional Firm Tech Stack · IT Support for Law & Accounting Firms · Reg S-P Is Now in Force · Investment & Professional Firms
External references: CISA Cybersecurity Awareness Month, FBI IC3 annual reports, NIST Cybersecurity Framework.
