A secure portal is not the same as a secure firm.

Where "we're secure" comes from
Here's what that promise of security actually covers: itself.
It doesn't secure the email account that receives the portal notifications — the same account that can reset its password.
It doesn't manage the laptop a preparer takes home or the public wifi used in a coffee shop.
It doesn't stop a client file from being downloaded to a desktop and forgotten there.
The firms that get hurt aren't careless. They just protected the door the brochure called secure, and left the rest on the honor system.

Client data lives behind three layers. Most firms have only secured the first.
Layer 1 — The portal and the data behind it
Layer 2 — Email
Layer 3 — Devices
All three layers have to hold. Droptine makes sure you're secured from every angle.
Six questions worth answering honestly

CPAs and Tax preparers answer to more than one rulebook
You rarely have just one security requirement to satisfy. Your cyber insurer wants MFA, managed devices, and tested backups before it renews. Larger clients send security questionnaires before they'll share another file.
Firms that prepare tax returns are expected to keep a written information security plan; firms that provide financial services fall under the FTC Safeguards Rule. And every state has a data-breach law sitting behind all of it.
Here's the part nobody spells out: these requirements are mostly asking about the same handful of fundamentals — who can get in, from what devices, with what protection, and whether you can prove it.
Droptine builds one security program that answers all of them: the actual controls, the monitoring, and documentation that matches what's really running. When the insurance renewal, the client questionnaire, or the auditor shows up, the work is already done and the proof already exists.
What working with Droptine covers
The Droptine plan, for CPA firms
Find the exposure
Lock down what matters
Maintain the program
