Skip to main content
Self-Study Courses

Practical Advice for Preventing Organizational Data Breaches

2 CPE Credits $41.00/credit hour
(No Ratings Yet)
In an era where generative AI and deepfake technology have revolutionized the precision of social engineering, the risk profile for professional service firms has shifted dramatically. Financial practitioners are no longer just defending against generic “spam”; they are now targets of highly coordinated attacks designed to exploit the specific trust and authority inherent in the CPA-client relationship. This course breaks down the anatomy of a modern breach—from ransomware extortion to sophisticated supply chain vulnerabilities—and provides a practical roadmap for securing a small-to-mid-sized firm without an enterprise-level IT budget.

Moving beyond simple firewall conversations, participants will explore the transition to a “Zero Trust” environment and the implementation of high-security protocols like passkeys and FIDO2 authentication. We will examine the increased regulatory scrutiny from frameworks like GLBA, GDPR, and the FTC Safeguards Rule, emphasizing how these requirements translate into daily firm operations. Attendees will walk away with a concrete incident response plan for the critical first 24 hours of a suspected breach, ensuring they have the tools to mitigate damage, protect client confidentiality, and maintain the integrity of their practice.

Publication Date: August 2026

Designed For
CPAs and firm owners managing security for small-to-mid-sized professional practices.

Topics Covered

  • AI-Powered Threats: Defending Against Deepfakes and Precision Phishing
  • Ransomware Evolution: From Data Encryption to Exfiltration Extortion
  • Zero Trust for Small Firms: Practical Access Control Strategies
  • First Responders: Managing the Critical 24 Hours Post-Breach

Learning Objectives

  • Analyze how generative AI and deepfakes are utilized in modern social engineering attacks
  • Implement “Zero Trust” security principles to protect sensitive data in small firm environments
  • Evaluate organizational vulnerabilities within the software supply chain and third-party SaaS providers
  • Design a practical incident response plan for the first 24 hours of a breach
  • Utilize advanced authentication methods and encryption to meet evolving professional regulatory requirements

Level
Basic

Instructional Method
Self-Study

NASBA Field of Study
Information Technology (2 hours)

Program Prerequisites
None

Advance Preparation
None

Instructor

Stephen M. Yoss

Stephen M. Yoss, Jr., CPA, MS, is a certified public accountant, the senior technology strategist and partner of Devmatics, a continuing education instructor for financial professionals, and a licensed pyrotechnician. While his interests and skills are varied, they all share a common thread—his love for and skill in finding technology-based solutions.

Whether it’s teaching in the classroom, consulting clients in a boardroom, or shooting a fireworks display, Steve brings passion, hard work, value—and above all else—technological expertise to each of his clients. With an open, honest approach, he creates a unique strategy for each client specifically designed to benefit their needs and streamline their operations in order to create efficiency and maximize their financial potential. For more information about Steve, please click here to visit his personal website.
$82.00 / 2 CPE
NASBA Registered Sponsor
CPAs, EAs, CTECs Approved Credentials
QAS Quality Assured
Since 1996 Trusted Provider
CCH CPELink Chat - Support
By using our chat feature, you agree that your conversation may be recorded by Wolters Kluwer and agree to our Privacy Policy.