『The Accounting Technology Lab』のカバーアート

The Accounting Technology Lab

The Accounting Technology Lab

著者: Brian Tankersley & Randy Johnston
無料で聴く

In-depth, honest accounting software and technology reviews capturing the real-life experiences of using particular products and solutions - presented by CPA Practice Advisor and technology experts Randy Johnston and Brian Tankersley, CPA.(c) 2026 CPA Practice Advisor 経済学
エピソード
  • ATL272: The Gathering Storm: Open Source AI
    2026/08/31


    In ATL272, “The Gathering Storm,” Randy Johnston and Brian Tankersley argue that AI is changing cybersecurity faster than many accounting firms are changing their defenses. The issue is not simply smarter phishing or more malware. AI can automate reconnaissance, vulnerability discovery, exploit development, credential testing, and lateral movement at machine speed, while open-weight models and falling token costs may make those capabilities cheaper and more widely available. That matters especially for CPA firms because they hold an unusually valuable combination of tax data, identity information, client credentials, banking access, payment authority, and long-retained documents.
    The hosts also point to a dangerous mismatch: attackers are getting faster while many firms still rely on home-grade routers, unsupported operating systems, aging hardware, and definition-based security tools. Human error remains a major weakness, when convincing phishing messages land during stressful periods.
    Their recommendation is practical: harden systems now, eliminate unsupported technology, rehearse incident response, shorten detection-to-containment time, test backup restores, inventory every AI tool and agent in the firm, map where client data goes, inspect audit trails, and maintain control of firm data. The takeaway is caution without panic: this is not “Terminator and Skynet,” but waiting for certainty is not a cybersecurity strategy.
    Pull Quotes

    TimeSpeakerQuote
    00:01:07 | Randy Johnston | “We want you to start being proactive now on protecting your businesses.”
    00:02:32 | Brian Tankersley | “I think that security is going through a similar transition right now.”
    00:04:47 | Randy Johnston | “The time to first attack after a vulnerability is exposed is well below an hour now.”
    00:07:02 | Brian Tankersley | “We have pretty much the dream identity theft set of data.”
    00:11:58 | Randy Johnston | “We are trying to have you think about how you stand up your defenses and how the attackers are trying to defeat your defenses or guardrails.”
    00:16:59 | Brian Tankersley | “You really need to step up your cybersecurity posture now, because we’re going into a very bad neighborhood with very scary things going on.”
    00:17:35 | Randy Johnston | “The attackers’ tools are actually dropping in cost very rapidly.”
    00:18:17 | Brian Tankersley | “When these things are out, they’re out, and there’s no real coming back.”
    00:20:17 | Brian Tankersley | “We have cheaper attacks, we have more targets. We have the machine speed shrinking the response time.”
    00:21:09 | Randy Johnston | “It’s not Terminator and Skynet at this point.”
    00:22:27 | Randy Johnston | “Get the fundamentals right, including testing the backups.”
    00:23:33 | Randy Johnston | “If you’re waiting for things to be certain, that ain’t going to happen.”
    00:25:12 | Randy Johnston | “Pollyanna Randy is suggesting that you may well have some really ugly conditions in front of you, and I’m trying to keep you out of the storm.”

    続きを読む 一部表示
    26 分
  • ATL271: Why Your WISP Is Essential in 2026
    2026/08/21

    Episode Summary: ATL271 - Why Your WISP Is Essential in 2026

    Podcast Page/Subscription Links: https://podcast.cpate.ch
    Wiki Page:
    ATL271 - CPA Tech Wiki


    In ATL271, “Why Your WISP Is Essential in 2026,” Randy Johnston and Brian Tankersley explain why a written information security plan is no longer a compliance document that can sit on a shelf. Accounting firms hold concentrated stores of tax, financial, identity, and sometimes health information, making them attractive targets for phishing, credential theft, ransomware, fraudulent wire instructions, and AI-enhanced attacks. The hosts walk through the overlapping expectations of the IRS, FTC Safeguards Rule, and HIPAA, including written policies, multi-factor authentication, encryption, logging, incident response, training, governance, vendor oversight, and regular risk assessment. They emphasize that penalties can be severe, but the larger business risk may be client loss, reputational damage, litigation, and disruption during tax season. The episode also highlights practical governance: assign accountability, review the WISP regularly, connect security spending to risk, and report results to leadership. Randy and Brian close with five high-impact controls—MFA, full-disk encryption, tested backups, a written incident response plan, and vendor security questionnaires—plus a recurring calendar for log reviews, backup restores, phishing simulations, vulnerability scans, training, patching, and annual WISP updates. Their message: security is an operating discipline, not paperwork. For firms of every size, preparation now is cheaper than recovery.

    Key Takeaways

    • A WISP should be an operating system for security—not shelfware. It needs ownership, periodic review, documented changes, and executive oversight.
    • Accounting firms are unusually attractive targets because they aggregate tax, financial, identity, payroll, and other confidential information.
    • Credential theft and phishing remain central risks, while AI is making fraudulent messages and attacks more convincing.
    • Vendor management belongs inside the security program. Cloud applications, hosting companies, MSPs, AI services, and other third parties expand the firm's attack surface.
    • Incident response must be planned before the incident. Firms should understand regulatory notification obligations, internal responsibilities, legal resources, and PR response.
    • Security has a recurring calendar. Log reviews, backup restores, phishing tests, vulnerability scanning, access reviews, training, patching, and WISP updates need assigned frequencies and owners.

    Catchy Quotes

    Approx. TimeSpeakerQuote
    02:04 | Brian Tankersley | “The firms get hit because you and I are the Fort Knox of confidential data.”
    03:33 | Brian Tankersley | “The bad guys are getting better faster than the good guys are getting better.”
    07:40 | Brian Tankersley | “Anything that touches client data is a death sentence for a hard drive in my office.”
    12:10 | Brian Tankersley | “If you don't have an adequate WISP, you're in violation of the FTC safeguards rule.”
    18:20 | Randy Johnston | “You've got risk on any provider.”
    18:42 | Brian Tankersley | “As soon as you know something's happened, the clock is ticking.”
    23:11 | Brian Tankersley | “Multi-factor authentication, full disk encryption, tested backup strategies, written incident response plans, vendor security questionnaires.”
    24:55 | Randy Johnston | “Make sure that you've got your WISP … pulled out, dusted off, and updated for this year's regulations.”


    Note: Timestamps are approximate where the quote occurs inside a longer timestamped speaker segment in the transcript.

    Social Media Posts

    続きを読む 一部表示
    26 分
  • ATL270: Hardware Hullabaloo
    2026/08/14

    ATL270: Hardware Hullabaloo - Episode Summary

    Hardware is once again a strategic business issue—not merely an IT purchasing decision. In ATL270, Randy Johnston and Brian Tankersley examine how cybersecurity concerns, new processor families, and extraordinary component-price increases are reshaping technology plans for accounting firms and home offices. They begin with aging consumer routers, warning that an inexpensive or unsupported gateway can become the weak link for business data, remote access, and connected devices. Network segmentation, managed security hardware, and renewed use of VPNs are presented as practical safeguards. The conversation then surveys emerging hardware from Intel, AMD, Apple, Google, NVIDIA, and major PC manufacturers, with special attention to neural processing units and locally executed AI workloads. Brian shares his early experience with a TCL NXTPAPER tablet, while both hosts caution buyers against underpowered back-to-school systems. The sharpest lesson comes from current upgrade economics: Brian reports that the same 64 GB memory kit he bought for about $210 was listed near $979, while Randy describes a previously $18,000 server configuration approaching $74,000. Their advice is deliberately pragmatic: extend maintenance where sensible, scrutinize cloud operating costs, match purchases to measurable productivity, and avoid spending premium dollars merely to own the newest hardware. In a volatile market, disciplined technology governance matters more than specifications alone.

    Key Takeaways

    - Treat home-office routers and remote-access hardware as part of the firm’s control environment.
    - Segment business, household, and connected-device traffic so one compromise does not expose every system.
    - Specify processors, memory, and storage around actual workloads—especially local AI—rather than marketing labels.
    - Evaluate upgrades using measurable productivity and risk reduction, not hardware envy.
    - When server replacement prices and lead times are extreme, compare extended maintenance, cloud economics, and deferral.

    Wiki: https://wiki.cpate.ch/index.php/ATL270

    Creators & Guests

    • Brian F. Tankersley - Host
    • Randy Johnston - Host
    _________________________
    続きを読む 一部表示
    23 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません