Editor’s note: Small firms frequently turn to Stephanie Otero, CPA, the AICPA’s small firm advocate, with questions.
But there are practical steps sole practitioners and small firms can take to strengthen their defenses.
Although cybersecurity requires a layered approach, if I had to prioritize one action for sole practitioners, it would be implementing multifactor authentication (MFA) on every business-critical system.
Once cybercriminals obtain login credentials, they may be able to access email accounts, cloud applications, client portals, and firm data.
(To learn more, see, “Enhance the Client Experience with Two Simple Shifts,” AICPA & CIMA Professional Insights, June 8, 2026.)