× Course by Subject Webinars Self-Study eBooks Certificates Compliance Manager Subscriptions Firm CPE Blog CCHCPELink.com

Practical Advice for Preventing Organizational Data Breaches

Date: Tuesday, August 4, 2026
Instructor: Stephen M. Yoss
Begin Time:  9:00am Pacific Time
10:00am Mountain Time
11:00am Central Time
12:00pm Eastern Time
CPE Credit:  2 hours for CPAs

In an era where generative AI and deepfake technology have revolutionized the precision of social engineering, the risk profile for professional service firms has shifted dramatically. Financial practitioners are no longer just defending against generic “spam”; they are now targets of highly coordinated attacks designed to exploit the specific trust and authority inherent in the CPA-client relationship. This course breaks down the anatomy of a modern breach—from ransomware extortion to sophisticated supply chain vulnerabilities—and provides a practical roadmap for securing a small-to-mid-sized firm without an enterprise-level IT budget.

Moving beyond simple firewall conversations, participants will explore the transition to a “Zero Trust” environment and the implementation of high-security protocols like passkeys and FIDO2 authentication. We will examine the increased regulatory scrutiny from frameworks like GLBA, GDPR, and the FTC Safeguards Rule, emphasizing how these requirements translate into daily firm operations. Attendees will walk away with a concrete incident response plan for the critical first 24 hours of a suspected breach, ensuring they have the tools to mitigate damage, protect client confidentiality, and maintain the integrity of their practice.

Who Should Attend
CPAs and firm owners managing security for small-to-mid-sized professional practices.

Topics Covered

  • AI-Powered Threats: Defending Against Deepfakes and Precision Phishing
  • Ransomware Evolution: From Data Encryption to Exfiltration Extortion
  • Zero Trust for Small Firms: Practical Access Control Strategies
  • First Responders: Managing the Critical 24 Hours Post-Breach

Learning Objectives

  • Analyze how generative AI and deepfakes are utilized in modern social engineering attacks
  • Implement “Zero Trust” security principles to protect sensitive data in small firm environments
  • Evaluate organizational vulnerabilities within the software supply chain and third-party SaaS providers
  • Design a practical incident response plan for the first 24 hours of a breach
  • Utilize advanced authentication methods and encryption to meet evolving professional regulatory requirements

Level
Basic

Instructional Method
Group: Internet-based

NASBA Field of Study
Information Technology (2 hours)

Program Prerequisites
None

Advance Preparation
None

Registration Options
Individual
*Note: 3 or more qualifies for discounted Group Participant Fee
Fees
Regular Fee $142.00
Group Participant Fee $112.00

">
 Chat — Books Support