A practical guide for accounting firms

The 5,000 Record Reality Check

12 questions every smaller accounting firm should be able to answer — whether the FTC requires the paperwork or not.

The exemption reduces specific documentation requirements. It does not reduce the impact of an incident.

12
readiness questions
10
minutes to score
4
pages, no jargon
Cover of The 5,000 Record Reality Check guide by ComplyWise
What's inside

Your 10-minute readiness check

Answer Yes or No. Score what is genuinely in place today — not what you intend to do. The harder a question is to answer confidently, the more useful it is to investigate.

01Risk visibility

Can you name the three cyber risks most likely to disrupt your firm — without having to think about it?

04MFA

Is MFA enforced on every system where client data is accessed — with no exceptions?

07Staff response

If ransomware hit, would every member of staff know what to do?

12Evidence

Could you hand a client or insurer documented evidence of your security measures today?

Score yourself

12 questions, Yes or No. Your score tells you where to focus first.

10–12
Strong foundations
6–9
Exposed gaps
0–5
Priority action needed
The four things we would do anyway

From compliance minimum to operational readiness

The small-firm exemption applies to specified Safeguards Rule provisions — but these four disciplines still answer the questions that matter during an incident, insurance renewal or client security review.

01

Know your risk

Lightweight risk assessment

Identify your most sensitive information, where it lives, who can access it, and the controls you rely on — short enough to use, specific enough to drive action.

02

Test what you rely on

Security testing

Scan for vulnerabilities, verify MFA is enforced everywhere it should be, run a backup recovery test, and re-check controls after any material change.

03

Decide before the crisis

Incident response plan

An incident is a terrible time to decide who is in charge. A concise plan makes containment, escalation, communications and recovery easier under pressure.

04

Make it visible to leadership

Annual security review

Leadership should periodically review whether the security program still matches the business, its technology, its suppliers and the threats it faces.

Free download

Would you want this in place if something went wrong tomorrow?

That is the real question — not "are we required to have this?". A ransomware attack, compromised mailbox or stolen client file does not behave differently because your firm sits below a regulatory threshold.

  • All 12 readiness questions with plain-English context
  • The scoring bands — and what to do with a low score
  • The four disciplines worth doing anyway, with checklists

Get your free copy

Tell us where to send it and the 4-page guide unlocks instantly.

We use your details to send the guide and occasional security guidance for accounting firms. No spam — unsubscribe any time.

Book a complimentary Cyber Readiness Review

You will receive a written report showing where your firm stands, the key gaps we identify and what to fix first — a clear, prioritised view of your next steps.

Book your review