August 26, 2026

How CPA Firms, Accounting Firms, Financial Advisors, Wealth Managers & Insurance Agencies Can Protect Client Data, Prevent Downtime, and Build a Technology Strategy That Supports Growth
The Complete Guide to Microsoft 365 Security and Secure Client Communication for Financial Firms in 2026
Financial firms run on communication.
A CPA receives tax documents from a client.
A financial advisor sends investment information.
An insurance professional requests personal documentation.
An accounting firm exchanges payroll records with a business owner.
A wealth management team collaborates on confidential client files.
Increasingly, all of this happens digitally.
Email, Microsoft 365, OneDrive, SharePoint, Teams, cloud applications, mobile devices, and client portals have made financial businesses faster and more efficient than ever.
They have also created a much larger security challenge.
The question financial firms should be asking in 2026 isn't simply:
"Do we use Microsoft 365?"
It's:
"Is our Microsoft 365 environment actually configured to protect the information our clients trust us with?"
That distinction matters.
Microsoft provides powerful security capabilities, but purchasing Microsoft 365 does not automatically mean every account, device, mailbox, file, and sharing permission is configured according to your firm's risk profile.
Security depends on how technology is configured, monitored, maintained, and used.
For CPA firms, financial advisors, accounting firms, insurance agencies, and other financial organizations, that makes Microsoft 365 security and secure client communication a critical part of the broader cybersecurity strategy.
This guide explains what financial firms should evaluate, where common vulnerabilities appear, and how organizations can create a more secure environment without making technology unnecessarily difficult for employees or clients.
Why Communication Security Matters So Much in Financial Services
Think about the information that moves through a financial firm's technology environment during an ordinary week.
Depending on the business, that could include:
- Social Security numbers
- Tax returns
- Bank statements
- Investment information
- Payroll reports
- Employee records
- Insurance documentation
- Business financial statements
- Account information
- Personally identifiable information
- Estate-planning documents
- Payment instructions
- Client identification documents
Much of this information is exchanged electronically.
That means communication security isn't separate from data security.
Communication security is data security.
If an attacker compromises an employee's email account, that attacker may gain much more than the ability to send messages.
Depending on permissions and configuration, a compromised identity could potentially provide access to email history, contacts, cloud files, shared resources, or other connected services.
That is why protecting identities has become one of the most important components of modern cybersecurity.
The Financial Industry Has a Trust Problem Cybercriminals Can Exploit
Financial businesses operate differently from many other organizations.
Clients expect unusual financial requests.
They send documents.
They receive documents.
They approve transactions.
They update account information.
They communicate about money.
They may receive urgent requests from their CPA, advisor, insurance agent, or financial institution.
Cybercriminals understand these workflows.
Rather than attempting to "hack" complicated infrastructure directly, an attacker can try to impersonate someone the victim already trusts.
Imagine receiving an email that appears to come from your financial advisor:
We need to verify your account information before completing today's request.
Or an employee receives what appears to be a message from a client:
We changed banks. Please use the attached information for future payments.
Or an accounting employee receives:
Can you send me the payroll report before the meeting?
Nothing about those requests necessarily looks unusual.
That's exactly what makes social engineering so dangerous.
Business Email Compromise: A Major Risk for Financial Firms
Business Email Compromise, commonly called BEC, is particularly dangerous for organizations that regularly handle money and confidential information.
Unlike obvious spam, BEC attacks are designed to look legitimate.
Attackers may:
- Compromise an actual email account
- Impersonate an executive
- Pretend to be a client
- Mimic a vendor
- Create a similar-looking email domain
- Insert themselves into an existing conversation
- Request payment changes
- Request sensitive information
The attack doesn't necessarily require sophisticated malware.
Sometimes the attacker's greatest weapon is credibility.
If an employee believes they're communicating with someone they know, normal security instincts can disappear.
How Business Email Compromise Can Begin
Consider a hypothetical financial advisory firm.
An employee receives what appears to be a Microsoft 365 login notification.
The message looks professional.
The employee clicks the link.
A Microsoft-looking login page appears.
They enter their email address and password.
The page reports an error.
The employee assumes nothing happened and returns to work.
But something did happen.
The credentials may have been captured.
If additional security controls don't stop the login, an attacker could attempt to access the account.
From there, the attacker may study normal communication patterns.
They may learn:
- Who handles payments
- Which clients frequently communicate with the firm
- How executives write
- Which vendors the business uses
- When transactions typically occur
Instead of attacking immediately, sophisticated criminals can wait.
Then, when the opportunity appears, they impersonate a trusted participant in a transaction.
That's why email security cannot depend on employees identifying every malicious message perfectly.
Technology must provide additional layers of protection.
Microsoft 365 Is Powerful. But Is Yours Properly Secured?
Microsoft 365 has become essential infrastructure for countless businesses.
Financial firms may use:
- Outlook
- Exchange Online
- OneDrive
- SharePoint
- Teams
- Microsoft Defender
- Entra ID
- Intune
- Microsoft Authenticator
The ecosystem can provide powerful security and management capabilities.
However, there's an important distinction:
Having access to a security feature and properly implementing that security feature are not the same thing.
Configuration matters.
Licensing matters.
Monitoring matters.
Policies matter.
Employee behavior matters.
Ongoing management matters.
A financial firm should therefore evaluate Microsoft 365 as an environment—not simply as an email subscription.
1. Multi-Factor Authentication Should Be Foundational
Passwords are no longer sufficient on their own.
Passwords can be:
- Stolen
- Reused
- Phished
- Guessed
- Exposed in unrelated breaches
- Captured by malware
Multi-factor authentication adds another verification requirement before an account can be accessed.
This significantly improves account security, but firms should also recognize that not all authentication methods provide identical levels of protection.
A mature identity-security strategy may include stronger authentication methods, carefully configured policies, and controls based on user, device, location, or risk.
For financial firms, MFA should not be viewed as an optional add-on.
It should be part of the baseline.
2. Conditional Access Adds Context to Authentication
Imagine an employee normally signs into Microsoft 365 from Nevada on a company-managed laptop.
Suddenly, the same account attempts to sign in under unusual circumstances.
Should Microsoft 365 simply accept a correct password?
A stronger security model considers context.
Conditional Access policies can be used to establish requirements based on factors such as:
- User identity
- Device status
- Application
- Location
- Sign-in risk
- Authentication requirements
The exact policies should be designed carefully around the firm's environment.
Poorly designed policies can either create unnecessary friction or leave security gaps.
That's one reason Microsoft 365 security shouldn't be treated as a one-time setup.
3. Financial Firms Need Better Control Over File Sharing
Email isn't the only concern.
Financial businesses exchange enormous numbers of documents.
OneDrive and SharePoint can make collaboration significantly easier, but convenience must be balanced with access control.
Consider a folder containing confidential client information.
Questions worth asking include:
- Who currently has access?
- Who should have access?
- Can employees share it externally?
- Are external links permanent?
- Can anyone with the link access the document?
- Is access reviewed?
- What happens when an employee leaves?
- Are sensitive documents being downloaded to unmanaged devices?
Over time, permissions can accumulate.
An employee shares a folder with someone.
A project ends.
Nobody removes the access.
Months later, the permission remains.
This is sometimes called permission sprawl, and it can quietly increase risk.
Least Privilege: Give People What They Need—Not Everything
One of the most important cybersecurity concepts is also one of the simplest:
Employees should only have access to the information and systems necessary to perform their jobs.
This is known as the principle of least privilege.
A new employee shouldn't automatically receive access to every client folder.
A temporary contractor shouldn't maintain access after the project ends.
A former employee should not retain active accounts.
Administrative permissions should be tightly controlled.
Financial firms should regularly evaluate:
- User accounts
- Administrative roles
- Shared mailboxes
- External users
- SharePoint permissions
- OneDrive sharing
- Application access
- Former employee accounts
Access management is not a one-time onboarding task.
It is an ongoing security process.
Employee Offboarding Is a Cybersecurity Process
When an employee leaves, many businesses focus on:
- Collecting keys
- Recovering laptops
- Final payroll
- HR paperwork
Technology access can become an afterthought.
That's dangerous.
A strong offboarding process should address appropriate access to:
- Microsoft 365
- Cloud applications
- VPNs
- Financial applications
- Shared files
- Password-management systems
- Company devices
- Third-party platforms
The exact process will vary by organization, but the principle is simple:
Access should follow employment status.
An MSP can help standardize onboarding and offboarding so access changes aren't dependent on someone remembering every system manually.
Email Encryption and Sensitive Information
Financial firms routinely send confidential information.
That raises an important question:
Should sensitive financial information be sent through ordinary email?
The answer depends on the information, applicable requirements, technology configuration, and organizational policy.
But firms should establish clear rules around sensitive communication rather than leaving every employee to make that decision individually.
Possible secure communication methods can include:
- Encrypted email
- Secure client portals
- Controlled SharePoint or OneDrive links
- Purpose-built secure document exchange
- Other approved encrypted platforms
Employees should know which method to use and when.
Stop Sending Sensitive Documents as Ordinary Attachments
Attachments are convenient.
They can also create problems.
Once a traditional attachment is sent, the sender may lose meaningful control over what happens to that copy.
The recipient can:
- Download it
- Forward it
- Save it elsewhere
- Upload it to another platform
Depending on the use case, secure links or portals may offer more control.
Organizations may be able to:
- Restrict access
- Require authentication
- Set expiration periods
- Remove access
- Better manage sharing
The goal isn't to make client communication difficult.
The goal is to make the secure method the easy method.
Secure Client Communication Is Also a Client Experience Issue
Security and convenience are sometimes presented as opposites.
They don't have to be.
Clients don't want to navigate five complicated systems just to send one tax document.
Employees don't want to spend ten minutes encrypting every message manually.
When secure systems are overly difficult, people create workarounds.
They may:
- Use personal email
- Text information
- Upload documents to unauthorized platforms
- Save files locally
- Share overly permissive links
That phenomenon is often called shadow IT.
The better strategy is to design approved workflows that are both secure and practical.
A good technology partner should therefore ask two questions:
- Is this secure?
- Will people actually use it?
Both matter.
Mobile Devices Create Another Security Layer
Financial professionals don't work exclusively from desktop computers.
They check email on phones.
They access documents from laptops.
They join Teams meetings remotely.
They work while traveling.
Mobility improves productivity, but it expands the number of places from which sensitive information may be accessed.
Organizations should therefore consider:
- Device-management policies
- Screen-lock requirements
- Encryption
- Approved applications
- Remote wipe capabilities
- Device compliance
- Lost-device procedures
- Separation of personal and corporate information where appropriate
A lost phone should not automatically become a lost-data incident.
Remote Work Changed the Security Perimeter
Historically, companies protected a physical office network.
Employees came to the building.
Computers connected to the corporate network.
Security controls surrounded that environment.
Cloud computing changed that model.
An employee may now work from:
- The office
- Home
- A hotel
- A client's location
- Another branch
- A mobile device
The traditional perimeter has effectively expanded.
That is one reason modern cybersecurity increasingly focuses on identity, device health, access, and data—not simply whether someone is physically inside the office.
Financial Services Compliance Raises the Stakes
Financial firms may operate under different regulatory frameworks depending on what services they provide, their registration status, jurisdiction, and other factors.
That distinction is important.
A CPA firm, registered investment adviser, mortgage company, and insurance agency may not have identical obligations.
Businesses should work with qualified legal and compliance professionals to determine exactly which rules apply.
However, the broader direction is clear:
Organizations handling sensitive financial information are expected to take data protection seriously.
Technical safeguards increasingly intersect with regulatory responsibilities.
Regulation S-P and Customer Information
The SEC amended Regulation S-P to strengthen protections surrounding customer information for covered institutions.
Among other provisions, the amendments require covered institutions to establish written incident-response policies and procedures designed to detect, respond to, and recover from unauthorized access to or use of customer information.
For financial organizations subject to these requirements, cybersecurity isn't simply an operational best practice.
It becomes part of a documented governance and response framework.
That makes questions such as these increasingly important:
- Who identifies security incidents?
- Who determines what information was affected?
- Who coordinates the response?
- How is the event documented?
- How quickly can the organization understand what happened?
- Are technology vendors included in the response process?
Cybersecurity planning should answer those questions before an incident occurs.
The FTC Safeguards Rule
Certain financial institutions may also fall under the FTC's Safeguards Rule.
The Rule requires covered financial institutions under FTC jurisdiction to maintain measures designed to keep customer information secure.
The implications extend beyond installing security software.
Organizations should think in terms of a broader information-security program that considers people, processes, technology, vendors, and ongoing risk.
Again, applicability depends on the organization.
Financial firms should confirm their specific requirements with appropriate compliance counsel rather than assuming that a particular rule does—or does not—apply.
Vendor Risk Is Your Risk Too
Financial firms rarely operate alone.
They rely on:
- Cloud providers
- Accounting applications
- CRM systems
- Payroll platforms
- Document-management systems
- Financial software
- IT providers
- Email vendors
- Third-party integrations
Every connection introduces another consideration.
Your own cybersecurity can be strong while a third-party relationship creates exposure.
Financial organizations should understand:
- What information vendors access
- How vendors protect it
- How access is granted
- How access is removed
- What happens if the vendor experiences an incident
- How quickly the firm would be notified
Cybersecurity increasingly extends beyond the walls of your organization.
AI Has Created a New Data-Protection Challenge
Artificial intelligence is rapidly becoming part of everyday business.
Employees may use AI to:
- Draft emails
- Summarize documents
- Analyze information
- Generate reports
- Create marketing content
- Improve productivity
The technology can provide tremendous value.
It can also create risk if employees paste sensitive client information into tools without understanding where that information goes or how it may be handled.
Financial firms should develop clear AI policies addressing questions such as:
- Which AI tools are approved?
- What information may employees enter?
- Is client information prohibited?
- Can employees upload documents?
- Who reviews new AI applications?
- How are enterprise AI platforms configured?
Simply banning AI may not solve the problem.
Employees may use it anyway.
A better approach is to create clear governance around approved tools and acceptable use.
Microsoft Copilot and Financial Services
Microsoft Copilot presents particularly interesting opportunities because it can interact with information within the Microsoft ecosystem depending on product, configuration, permissions, and licensing.
That makes existing data permissions extremely important.
AI doesn't magically fix poor access controls.
If an organization has years of messy SharePoint permissions and overly broad access, introducing AI can make those underlying governance problems more visible.
Before deploying AI broadly, financial firms should consider cleaning up:
- SharePoint permissions
- OneDrive sharing
- Teams access
- Old user accounts
- Sensitive data locations
- Administrative permissions
AI readiness starts with data readiness.
Your Cybersecurity Strategy Should Include the Human Layer
Even perfectly configured technology cannot eliminate human error.
Financial firms should regularly train employees to recognize:
- Phishing
- Fake login pages
- Payment fraud
- Executive impersonation
- Suspicious MFA prompts
- Malicious attachments
- Social engineering
- Unusual file-sharing requests
Training should not be a once-a-year presentation employees click through while answering email.
Effective security awareness should be ongoing.
Short training sessions, phishing simulations, reminders, and real-world examples can help make cybersecurity part of everyday business culture.
Create a Verification Culture
Some of the most damaging attacks can be stopped with one simple action:
Verify unusual requests through a second communication channel.
For example:
An email asks an employee to change banking details.
Instead of replying to the email, the employee calls the known phone number already on file.
An executive requests an urgent wire.
The employee follows the organization's established approval process rather than bypassing it because the request appears urgent.
A client suddenly asks for confidential records to be sent somewhere new.
The employee verifies the request before proceeding.
Cybercriminals rely on urgency.
Strong businesses rely on process.
Don't Forget Business Continuity
Security is only half of the equation.
Financial firms must also prepare for technology failure.
Ask:
If Microsoft 365, a critical application, an employee account, or your office network became unavailable tomorrow, could your business continue operating?
Business continuity planning should address:
- Data backups
- Disaster recovery
- Communication alternatives
- Remote work
- Critical applications
- Vendor contacts
- Incident response
- Employee responsibilities
A cybersecurity incident should not become an existential business crisis simply because nobody planned for recovery.
Backups Need to Be Tested
"We have backups."
That's reassuring.
But the better question is:
When was the last time you successfully restored something from them?
Backup monitoring and recovery testing matter.
A strong strategy considers:
- What is backed up
- How frequently
- Where copies are stored
- How they're protected
- Who monitors failures
- How quickly data can be restored
- How much data the business could lose between recovery points
Backup strategy should be designed around business requirements, not assumptions.
The 25-Point Microsoft 365 & Communication Security Checklist for Financial Firms
Use this checklist as a starting point for evaluating your environment.
Identity
- Is MFA enabled for appropriate accounts?
- Are stronger authentication options evaluated?
- Are administrator accounts tightly controlled?
- Are unused accounts disabled?
- Is employee offboarding documented?
- Is advanced email protection configured?
- Are employees trained to recognize phishing?
- Are suspicious messages easy to report?
- Are anti-impersonation protections evaluated?
- Are unusual financial requests independently verified?
Files
- Are SharePoint permissions reviewed?
- Is external sharing controlled?
- Are old sharing links removed?
- Is sensitive information stored only in approved locations?
- Are employees trained on secure file sharing?
Devices
- Are company devices managed?
- Are devices encrypted where appropriate?
- Can lost devices be remotely secured?
- Are software and operating systems patched?
- Is endpoint security actively monitored?
Governance & Recovery
- Is there a documented incident-response plan?
- Are backups monitored and tested?
- Is there a business-continuity plan?
- Are third-party technology risks evaluated?
- Does the organization have an AI acceptable-use policy?
If you answered "I don't know" to several of these questions, that's useful information.
It doesn't automatically mean your organization is insecure.
It means you have areas worth evaluating.
What Should a Financial Firm Expect From Its IT Provider?
Modern financial firms need more than someone who resets passwords and fixes printers.
Technology has become too important.
A proactive IT partner should help organizations think strategically about:
- Cybersecurity
- Identity management
- Microsoft 365
- Cloud services
- Employee onboarding and offboarding
- Backup and disaster recovery
- Business continuity
- Vendor management
- Device management
- Technology budgeting
- Long-term planning
The goal shouldn't simply be:
"Keep the computers working."
The goal should be:
"Use technology to keep the business secure, productive, resilient, and ready to grow."
Why Local IT Support Matters for Las Vegas Financial Firms
Remote technology has made it possible to support businesses from almost anywhere.
But local support still provides important advantages.
When a financial firm experiences a physical network problem, office move, hardware failure, infrastructure project, or complex on-site issue, having access to a local team can simplify resolution.
FiRa IT Services has served the Las Vegas Valley since 2013 and provides proactive managed IT services designed to identify and address technology issues before they become larger problems.
For financial firms throughout Las Vegas and surrounding communities, that means having a technology partner that can combine remote monitoring and support with local expertise when on-site assistance is needed.
How FiRa IT Services Helps Financial Firms Build More Secure Technology Environments
Financial firms don't need more technology for technology's sake.
They need technology that works.
FiRa IT Services helps Las Vegas businesses proactively manage their technology through services including:
- Managed IT services
- Security services
- Cloud solutions
- Data backup and recovery
- Remote IT support
- Network monitoring
- Technology planning
A strong IT strategy should make technology easier for employees while making the organization harder for cybercriminals to compromise.
That's the balance financial firms should pursue.
Frequently Asked Questions
Is Microsoft 365 secure enough for financial firms?
Microsoft 365 includes significant security capabilities, but security depends on licensing, configuration, identity controls, device management, monitoring, permissions, and employee practices. Simply subscribing to Microsoft 365 does not eliminate the need for an overall cybersecurity strategy.
Should financial firms use multi-factor authentication?
MFA is an important identity-security control because passwords can be stolen through phishing, malware, credential reuse, and other attacks. Financial firms should evaluate appropriate MFA and authentication policies for their environment.
Can financial firms send confidential information through email?
Organizations should establish policies governing how sensitive information is transmitted. Depending on the information and applicable requirements, encrypted email, secure portals, or controlled file-sharing platforms may be more appropriate than ordinary attachments.
What is Business Email Compromise?
Business Email Compromise is a form of fraud in which attackers impersonate or compromise trusted email accounts to convince victims to send money, disclose sensitive information, or take another action.
What's the safest way to share financial documents with clients?
The appropriate method depends on the firm's technology and requirements, but secure client portals, authenticated file-sharing platforms, access-controlled links, and encrypted communication can provide more control than ordinary attachments.
Does Microsoft 365 automatically make a company compliant?
No. Technology can support a compliance program, but compliance involves policies, procedures, governance, employee behavior, documentation, risk management, and other requirements. Organizations should work with appropriate legal or compliance professionals to determine their obligations.
What is the SEC's Regulation S-P?
Regulation S-P addresses privacy and safeguarding of customer information for covered institutions. Amendments adopted by the SEC strengthened requirements around incident response and customer information protection. Organizations should determine whether and how the regulation applies to them.
What is the FTC Safeguards Rule?
The FTC Safeguards Rule requires covered financial institutions under FTC jurisdiction to maintain safeguards designed to protect customer information. Applicability varies by organization.
How often should Microsoft 365 permissions be reviewed?
There is no universal frequency appropriate for every organization. Reviews should be performed regularly and after meaningful events such as employee departures, role changes, acquisitions, new applications, or major organizational changes.
Should financial firms allow employees to use AI?
AI can provide significant productivity benefits, but financial firms should establish policies around approved platforms and what data employees may provide to those tools. Sensitive client information should not be casually entered into unapproved AI services.
What should happen when an employee leaves?
The organization should follow a documented offboarding process that addresses accounts, devices, email, cloud applications, shared files, administrative access, and other systems the employee used.
Why should financial firms use managed IT services?
A managed IT provider can help organizations proactively manage cybersecurity, Microsoft 365, devices, networks, backups, cloud environments, employee support, and long-term technology planning without relying entirely on reactive support.
Final Thoughts: Client Trust Now Depends on Technology Trust
Financial services have always been built on trust.
Clients trust their CPA with tax records.
They trust their financial advisor with investment information.
They trust their insurance professional with personal details.
They trust their accounting firm with business finances.
Increasingly, protecting that trust requires protecting the technology through which those relationships operate.
A secure financial firm isn't one that purchases a single cybersecurity product.
It's one that builds layers.
Secure identities.
Secure devices.
Secure email.
Secure file sharing.
Secure cloud environments.
Trained employees.
Tested backups.
Documented recovery plans.
Thoughtful AI policies.
Ongoing monitoring.
And a technology strategy that evolves as threats, regulations, and the business itself change.
Cybersecurity should make your organization stronger—not make doing business impossible.
The objective is to create an environment where employees can work efficiently, clients can communicate confidently, and leadership knows the technology behind the business is being actively managed.
Is Your Financial Firm's Technology Ready for 2026?
If you're unsure whether your Microsoft 365 environment, email security, file-sharing policies, backups, or cybersecurity strategy provide the protection your organization needs, FiRa IT Services can help.
We provide proactive managed IT, cybersecurity, cloud, backup, and technology support for businesses throughout Las Vegas and the surrounding valley.
managed IT services in Las Vegas
data backup and disaster recovery
how CPA firms can protect client data


