A Boston story
The Tuesday in March a CPA firm nearly installed the caller's software
the managing partner of a 14-person CPA firm on Moody Street in Waltham
It is Tuesday, March 10, and the firm on Moody Street has 1,100 returns open. The managing partner has run it for twenty-two years. Every client's Social Security number, W-2, brokerage statement and bank account lives on the tax server, and every one of them is due somewhere by April 15.
At 9:15 a senior associate takes a call from the tax software's support line. The caller has her name, the firm's EIN and the exact error code from a rejection she filed at 8:50. He is calm and helpful. There is a fix, he says, a small support tool, and he sends the link while she is still on the phone. It downloads in four seconds.
Her finger is on Run.
The tool never starts. She presses the report button while the caller is still talking, and an engineer calls her back in four minutes with the name of the campaign that has been hitting preparers all season. The number gets blocked. The firm files 1,100 returns on time, and the written information security program Massachusetts requires gets a new paragraph about a Tuesday in March.
The application allow-list on her machine refuses to run a program it has never seen, no matter how pleasant the voice on the phone.
What changes the ending
- Application control on every workstation, so a "support tool" from a phone call cannot run, however convincing the caller (CIS 2 Inventory and Control of Software Assets).
- Client data on an encrypted server behind MFA and access by name, which is also what 201 CMR 17.00 expects a WISP to say (CIS 3 Data Protection).
- Training that covers the phone call and the text, not just the inbox, scored per person, every March (CIS 14 Security Awareness and Skills Training).