Security assessments for law firms and CPA firms in Texas.
If you run a law firm
The risk that matters most right now is business email compromise aimed at your trust account. The FBI's Internet Crime Complaint Center has tracked this pattern for years: an attacker gets into an email thread around a real estate closing, waits for wiring instructions to come up, and sends a replacement account number that looks like it came from you or the title company. The money doesn't come back. Under ABA Model Rule 1.6, the duty of confidentiality includes understanding the technology you use to protect client information. That's not a suggestion.
If you run a CPA or tax firm
Two rules apply whether you've read them or not. IRS Publication 4557 requires every paid tax preparer to maintain a Written Information Security Plan, a WISP, in writing. Separately, the FTC Safeguards Rule (16 CFR 314, under the Gramm-Leach-Bliley Act) applies to tax and accounting firms directly, because the FTC classifies you as a financial institution. Neither rule cares whether you meant to comply.
How this works
First
Gap Assessment
A structured review of your firm against the NIST Cybersecurity Framework, and against HIPAA or PCI DSS where either applies to what you handle. I look at email authentication, access controls, backup configuration, and how logs are, or aren't, reviewed. You get a findings report and a fix list ranked by risk, not a document nobody reads.
Then
Hardening & Setup
Fixing what the assessment found. Typically: email authentication (DMARC, SPF, DKIM), tightening access controls so the right people have the right logins and no one else does, verifying backups actually restore, and setting up monitoring so something is watching after I leave.
Ongoing
Monthly Advisory
Once things are fixed, someone still has to watch them. That's log review, a monthly report you can actually read, and a direct line to call when something looks wrong. Not a ticket queue. Me.
What a finding actually looks like
This is an anonymized excerpt from a real Gap Assessment report, edited so no firm can be identified. It's here to show the kind of work product the assessment actually produces.
Finding 4.2: Email authentication not enforced
- Domain checked
- [client-firm].com (redacted)
- Observation
- No DMARC record published. SPF present but set to ~all (soft-fail, not enforced). No DKIM selector found on the primary mail flow.
- Why it matters
- Anyone can send email that appears to come from [client-firm].com. A message that looks like it's from the managing partner, asking a client to wire funds to a new account, will pass through most spam filters unblocked.
- Fix
- Publish a DMARC record at p=quarantine, move SPF to -all once every legitimate sending source is confirmed, and enable DKIM signing on the mail provider. About two to three hours of work with access to DNS.
- Framework
- NIST CSF, Protect function (data security, identity management).
About Stephen
Stephen Matthews founded SCM Technologies, LLC in April 2024, after several years working front-line SOC and MDR operations: triaging alerts, investigating incidents, and being the person who actually reads the logs when something looks wrong. He holds the ISC2 Certified in Cybersecurity (CC), BTL1, and CompTIA A+.
SCM Technologies is Stephen. There's no tier-one help desk between you and the person who wrote your findings report, and no one else who picks up the phone when you call next month. If that's the wrong fit for a larger firm with its own IT department, it's worth knowing up front.
ISC2 CC · BTL1 · CompTIA A+
Contact
Email works: stephenmatthews@scm-technologies.com. So does the form below.