Mark Su

  • About
  • Writing
  • Contact

Home  /  Writing

When Cybersecurity Is Really a Management Problem

by Mark Su | Sep 4, 2026

Originally published on IT Assure.

Professional firms often approach cybersecurity by asking a technology question: What tools should we use to keep our data safe?

Endpoint protection. Multi-factor authentication. Email security. Backups. Monitoring. Perhaps a cybersecurity provider to manage them.

All of these matter. But consider a hypothetical 40-person accounting firm. The firm has MFA, endpoint protection, backups, a secure client portal, and someone responsible for IT. On paper, it may look reasonably protected.

Now suppose 15 people in the tax department can access essentially every tax client’s folder—not because they need all of that information, but because the permissions were designed years ago around convenience. A staff accountant working on five clients may technically be able to open hundreds of other clients’ tax returns, financial statements, Social Security numbers, and supporting documents.

Nothing has necessarily gone wrong. No security product has necessarily failed. But if that employee’s account is compromised, the amount of client information potentially exposed is determined partly by a management decision that was made long before the attacker arrived.

How much information should that employee have been able to access in the first place?

How does sensitive information actually move through the firm, and who really needs access to it?

These are questions that deserve more management attention.

Cybersecurity is not simply a collection of technical protections surrounding an otherwise fixed business. It is also a management discipline. The firm’s operating model—what information it collects, where that information is stored, who can access it, how it moves through a workflow, and how long it is retained—helps determine how much exposure the technology ultimately has to protect against.

The implication is straightforward: before trying to secure every piece of information everywhere, reduce unnecessary exposure in the first place.

Cybersecurity Is an Enterprise-Management Issue

This isn’t merely a philosophical distinction.

NIST’s Cybersecurity Framework 2.0 added Govern as one of its six core cybersecurity functions, alongside Identify, Protect, Detect, Respond, and Recover. Governance includes establishing responsibility, policy, and cybersecurity risk-management expectations and connecting those decisions to broader enterprise risk management.

NIST specifically explains that the Govern function was added to emphasize roles, responsibilities, risk tolerances, policies, and alignment between cybersecurity and enterprise risk management.

That matters because technology cannot—and should not—decide fundamental business questions for management.

A security product cannot decide which employees actually need access to a client’s tax records. It cannot decide whether the firm still needs to retain a client’s bank information. It cannot decide whether one employee should be able to initiate and approve the same sensitive transaction. And it cannot determine how much business disruption management is willing to accept in exchange for tighter access restrictions.

Technology can help enforce these decisions.

Management has to make them.

Start With the Information, Not the Attacker

Many cybersecurity conversations begin with the threat: ransomware, phishing, wire fraud, stolen credentials, or some new method attackers are using.

Those threats matter. But an equally useful management exercise is to work backward from the information being protected.

Suppose an attacker compromises one employee’s credentials.

The eventual damage can depend substantially on what that employee can reach.

  • Can the employee see only the clients necessary for the employee’s current work—or every client in the firm?
  • Does the account provide access to one application—or several interconnected systems?
  • Can the employee only read a record, or also download, change, and transmit it?
  • Does the system contain information the firm no longer needs?

The attack may begin outside the organization, but the amount of exposure it encounters is partly created inside the organization.

That is why access design matters.

NIST’s principle of least privilege calls for restricting users to the resources and authorizations necessary to perform assigned tasks. NIST security guidance also recognizes separation of duties where combining functions creates inappropriate authority or risk.

These are not merely technical configurations. They are operating-design decisions.

Six Questions Management Should Ask About Sensitive Information

A practical way to begin is with six familiar questions: What, Why, Who, Where, When, and How.

1. What Information Are We Collecting?

Inventory the sensitive information the firm receives or creates.

For a professional firm, that might include tax IDs, financial statements, payroll records, banking information, employee data, legal documents, or confidential business information.

Then ask a harder question:

Do we actually need all of it?

Information that no longer serves a legitimate business, legal, or regulatory purpose may represent exposure without corresponding value.

Data minimization is an established privacy and security principle. NIST describes minimization as limiting the creation, collection, use, storage, and disclosure of personally identifiable information to what is relevant and necessary, and retaining it only as long as necessary for the purpose.

2. Why Do We Need It—and for How Long?

Information should have a business purpose.

If the firm cannot explain why a sensitive data element is being collected, that should prompt review.

The same applies to retention. A firm may legitimately need information today that it no longer needs five years later.

The objective isn’t indiscriminate deletion. Legal, regulatory, contractual, and professional obligations may require retention. The objective is to make retention intentional rather than accidental.

For firms subject to the FTC Safeguards Rule, the FTC expressly addresses secure disposal of customer information, while allowing longer retention when there is a legitimate business need, legal requirement, or targeted disposal isn’t feasible.

3. Who Really Needs Access?

This is where least privilege becomes operational.

Instead of asking whether an employee is “authorized,” ask what the employee actually needs to accomplish the job.

  • Does everyone working in tax need access to every tax client?
  • Does every administrator need the same privileges?
  • Does someone who reviews work need the same ability to modify source information as the person preparing it?

Sometimes the answer will be yes. Frequently it will be no.

Access should follow the work.

This is also where the hypothetical 40-person firm becomes useful. The problem isn’t necessarily that its file system or security software is defective. The problem may simply be that permissions reflect an old organizational assumption: everyone in this department needs access to everything in this department.

Cybersecurity becomes a management question when leadership asks whether that assumption is still justified.

4. Where Does the Information Live and Move?

Map the information’s journey.

A client may upload a document through a portal. The information may move into a document-management system, tax application, spreadsheet, email exchange, local download, and archive.

Each transition creates another point where the organization needs to understand what is occurring.

This does not mean that information should automatically be spread across multiple platforms. Fragmentation itself can increase complexity. The important question is whether the firm understands where sensitive information resides, where it can move, and what controls exist at those boundaries.

5. When and Under What Circumstances Should Access Occur?

Access does not always need to be identical under every circumstance.

A firm may decide that certain activities warrant stronger authentication, additional approval, restricted devices, or other contextual controls.

But these decisions should follow actual business risk. Location or time alone should not automatically determine whether a user is trustworthy. Modern security approaches increasingly evaluate the user, device, resource, and circumstances of the request rather than assuming that being “inside the network” makes access safe.

6. How Is the Information Protected?

Only now do many of the familiar technology questions appear.

  • How is the user authenticated?
  • How is access authorized?
  • Are devices protected?
  • Is sensitive information encrypted where appropriate?
  • Are activity and exceptions monitored?
  • Are backups available?
  • Could the firm recover?

These controls are essential. But they become more effective when they are enforcing an intentional operating model rather than compensating for an uncontrolled one.

Map the Workflow, Not Just the Network

One useful exercise is to select a single high-value client workflow and follow it from beginning to end.

For an accounting firm, that could be preparing a tax return, processing payroll, or performing an audit engagement.

Identify every major information touchpoint.

Then ask:

  • Who receives the information?
  • What exactly do they receive?
  • Why do they need it?
  • Can they change it?
  • Can they export it?
  • Where does it go next?
  • Does another person need to approve a sensitive action?
  • What happens to the information after the engagement is complete?

This exercise may reveal cybersecurity improvements that have little to do with buying another product.

  • Perhaps an entire department has access when only an engagement team needs it.
  • Perhaps old exports remain stored indefinitely.
  • Perhaps employees routinely download information locally because the workflow makes the secure method inconvenient.
  • Perhaps one account has significantly more authority than its job requires.

Those are operational questions first and technology questions second.

For tax and accounting practices, this management orientation also fits current IRS guidance. The IRS states that tax professionals are required to maintain a Written Information Security Plan and identifies responsibilities that include designating someone to coordinate the information-security program, assessing risks in relevant areas of the firm’s operations, evaluating safeguards, and regularly monitoring and testing them.

Do Not Over-Engineer the Solution

There is an important counterpoint.

The theoretically most secure workflow may also be completely impractical.

Dividing every process among multiple employees, placing data in many isolated systems, or requiring additional approvals for every routine action can make the organization slower, more expensive, and harder to manage. Complexity can itself create security problems.

The objective therefore isn’t maximum restriction.

It is appropriate restriction relative to risk.

A five-person firm will make different decisions from a 500-person firm. The value of the information, consequences of misuse, workflow requirements, staffing, and available technology all matter.

Smaller firms do not need to redesign everything simultaneously.

Start with the workflows containing the most sensitive information or presenting the greatest business consequences. Understand them first. Then improve them progressively.

Technology Should Enforce a Deliberate Operating Model

Cybersecurity will always require technology.

Attackers do exploit software vulnerabilities. Credentials do get stolen. Malware does execute. Systems do fail.

The argument is not that technology is unimportant.

The argument is that technology cannot compensate indefinitely for a business that has never decided how sensitive information should be handled in the first place.

Before asking whether you have the right cybersecurity tools, ask something more fundamental:

  • What information are we trying to protect?
  • Why do we possess it?
  • Who actually needs it?
  • Where can it travel?
  • Under what circumstances should it be accessible?
  • What would happen if one person, account, or system were compromised?

Those are management questions.

The technology comes next.

A useful place to start is not another technology purchase. Pick one important client workflow and follow the information from beginning to end. Identify what information is collected, who can access it, where it moves, how long it is retained, and whether each level of access is actually necessary to perform the work.

If you discover more information, access, or movement than the work requires, you have identified a cybersecurity improvement opportunity before changing a single security product.

Cybersecurity technology still matters enormously. But technology works best when it is enforcing deliberate business decisions rather than compensating for unclear ones.

The strongest cybersecurity programs do not begin by asking, “What else should we buy?” They begin by asking, “What are we asking technology to protect—and why?”

Management defines the boundaries. Technology helps enforce them.

Review Your Firm’s Starting Point

For a broader view of how cybersecurity is managed at your firm, take the Quick Self-Check. It reflects your answers; it is not a technical validation. If you already have a specific concern, see what happens in a Cybersecurity Review, an initial business conversation about your current arrangements and whether further validation would be useful.

References

  1. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. 2024.
  2. National Institute of Standards and Technology. “Least Privilege.” NIST Computer Security Resource Center.
  3. National Institute of Standards and Technology. “Minimization.” NIST Computer Security Resource Center.
  4. Federal Trade Commission. “Safeguards Rule.” 16 CFR Part 314.
  5. Internal Revenue Service. “Written Information Security Plans Are Essential for Tax Pros.” June 16, 2026.

About the author

Mark Su

Mark Su

Mark is the owner and CEO of IT Assure. His background spans accounting, finance, business operations, and technology. He writes about the practical lessons of owning, operating, and improving a business.

More about Mark  ·  IT Assure  ·  LinkedIn

← All writing  ·  Back to Home

Recent writing

When AI Started Doing the Work: Lessons From Refreshing Our Website

Sep 28, 2026

Browse all writing →

Mark Su

Business ownership · Management · Cybersecurity

Writing
About
Contact

  • Follow

marks@itassure.com

Copyright © 2026 Mark Su. All Rights Reserved.