Your client portal is locked. Is everything else in the firm?

How firms come to believe they are covered
That promise applies only to the product.
The mailbox where portal alerts arrive, and where a portal password can be reset, sits outside it. So does the notebook computer a preparer carries home and connects to coffee-shop Wi-Fi. So does the return saved to a desktop folder and never deleted. Firms that suffer a breach are seldom reckless. They locked the one entrance a vendor told them about and trusted the others to luck.

Three places client data is at risk, and most firms protect one
1. Portal and tax software
2. Email & cloud platforms
3. Computers and phones
A weakness in one undoes the other two. Droptine secures all three together.
A six-question self-check

Several parties now set your security requirements
A firm seldom answers to a single authority. The cyber insurance carrier will not renew without MFA, managed computers, and proven backups. Bigger clients send a security form ahead of sharing files. The FTC Safeguards Rule classifies tax preparers as financial institutions and requires a written information security plan (WISP). State breach-notification statutes apply on top of those.
What rarely gets explained is how much these demands overlap. Nearly all of them come down to a short list of basics: which people have access, on what equipment, under what safeguards, and what evidence you can show.
Droptine sets up a single program that satisfies the whole list, with working safeguards, monitoring, and paperwork that reflects your real setup. By the time a renewal form, client questionnaire, or examiner arrives, the answers are on file.