Who we serve

Fractional CIO for Professional Practices.

Law and accounting firms of five to thirty people hold privileged records under a professional license, so a wrong technology decision lands on the license, not on a help desk. The Business Architect seat puts one accountable seat on the practice’s side of that risk, held by a firm, starting from what the practice needs to protect and working back through the systems, the data, and the compliance obligations. Decisions, not tickets.

The situation

The risk sits on the partners’ license. Holding it is nobody’s job.

A partner-led firm runs on confidential records (client files, matter records, returns) and every one of them sits under a professional license somebody signed their name to. Not a vendor’s name. A partner’s. The IT person is capable and comes when something breaks; between the visits, nobody is watching the firm’s risk.

So it goes unwatched, quietly, for years. The first time anyone looks closely is usually a cyber-insurance questionnaire or an incident and by then the looking is being done by someone else, on their deadline, against answers the firm has already signed.

Where this actually goes wrong

The cyber-insurance questionnaire is where optimistic becomes denied.

Every practice eventually fills one out: MFA, backups, endpoint protection, incident response: a list of yes-or-no questions, answered under time pressure by whoever is nearest to the IT relationship. Those answers are tested against reality exactly once: after a loss, when it is too late to close the gap between what was written and what was true.

What gets typedWhat holds up after a loss
Is MFA enabled on all remote access?Yes, someone remembers turning it on.No screenshot. No admin log. No date.
Are backups tested and restorable?Yes, it has been running for years.No one has actually run a restore.
Is there a written incident response plan?Yes, the IT provider would handle it.Nothing written down. No one has rehearsed it.
The conflict no one names

The firm signs the questionnaire, not the IT provider being graded on it. An IT provider attesting to the strength of its own controls has an obvious incentive to answer well. The firm is the one an insurer can deny a claim against after a loss, so the firm is the one who needs an answer it can actually prove.

What we actually see

What are the technology risks a practice actually faces?

Four patterns show up in nearly every partner-led firm we assess, and none of them is a ticket. Each one lands on the license, the insurance, or the partners’ time.

Confidential records exposureA breach of client files, matter records, or returns lands on the license and the firm’s name as a bar complaint, a state board referral, or a malpractice question, before it is ever a technical event.
Compliance assumed, not trackedPrivilege and confidentiality on the legal side; on the accounting side the FTC Safeguards Rule and a written information security plan the IRS expects every paid preparer to hold. Obligations everyone believes are handled, documented nowhere.
Break-fix-only ITSomeone capable comes when things break, but nobody owns the risk between visits, or reads the invoices.
Partner time leakageTechnology decisions land on whichever partner protests least: a professional billing at partner rates, doing unpaid work outside their profession.
How the seat works here

What does the Business Architect seat do for a practice?

It takes the whole of it off the partners’ desks: one accountable seat, held by a firm, covering technology, data, growth, and risk, four questions deep in each: what should we do, what should it cost, who should do it, and is it working. The partners approve every decision. The seat answers for the result.

What the seat does for a practice

  • Verifies every questionnaire answer against evidence (screenshots, logs, dated restore tests) before the firm attests to it.
  • Keeps the risk register current and the compliance obligations tracked, not assumed: privilege, the Safeguards Rule where it applies, and client confidentiality everywhere.
  • Governs the IT provider and every vendor: reads the invoices, holds the contracts to their terms, catches the renewals.
  • Stewards the firm’s growth alongside its risk: the website, the referral pipeline, and what a new client actually experiences.
  • Translates all of it into terms the partnership can act on, and defend, if a client, an insurer, or a regulator asks.

What stays exactly the same

  • No tickets. No help desk.
  • Your existing IT provider stays exactly where it is: we oversee it, and never replace it.
  • Client files and matter records are never reviewed, only systems and controls.
  • You own everything, always, and either party can end it with 60 days’ notice.

The full model is described in the Business Architect seat. It starts with the fixed-fee Business Architecture Assessment.

The pattern we see most

A vague worry becomes a documented answer.

A cyber-insurance questionnaire arrives with questions nobody at the firm can confidently answer, and a near-miss elsewhere in the profession has the partners uneasy. IT is a capable person who comes when something breaks, but no one holds the firm’s risk. The assessment replaces the unease with a ranked, honest picture the partners can act on, and defend. Read the full account: the question the board couldn’t answer →

Fair questions

Questions partners actually ask.

Our IT provider is competent. Why add another layer?

Competent operations and accountable governance are different jobs. The question is not whether tickets get fixed. It is who holds the risk register, the vendor contracts, and the answer when a client, an insurer, or a regulator asks about security. The seat sits above your provider, not beside it, and your provider stays.

Can you complete our cyber-insurance questionnaire?

We verify each answer against evidence (screenshots, logs, dated restore tests) so the firm attests from a documented posture rather than a memory. The firm signs the questionnaire; the firm should be able to prove it.

How is client confidentiality handled during an assessment?

The assessment reviews systems and controls, never client files or matter records. Findings are reported to the partners alone, and engagement terms include confidentiality provisions sized for privileged environments.

We are a medical or dental practice. Is this page for us?

The seat is the same, but the obligations are not, so healthcare has its own page. Protected health information, business associate agreements, and the proposed HIPAA Security Rule changes are covered there rather than here. Everything on this page about privilege, insurance questionnaires and vendor oversight still applies to you.

What does the Safeguards Rule actually require of an accounting firm?

Paid tax preparers fall under the FTC Safeguards Rule through Gramm-Leach-Bliley, and the IRS expects a written information security plan: a named responsible individual, a risk assessment, safeguards, oversight of service providers, an incident response plan, and regular review. Since 2023 you confirm you hold one when you renew your PTIN. The seat keeps that plan real rather than a document written once and filed.

What does this cost a small firm?

A flat monthly fee, quoted as one number after the fixed-fee Business Architecture Assessment and sized to the practice. One prevented incident, or one denied claim avoided, typically covers years of the difference.

Is a five-person practice too small for this?

Firms of five to thirty people are exactly who this is for: large enough that a wrong decision is genuinely expensive, small enough that nobody can justify a full-time executive to prevent it. If you are smaller than that, we will say so, and point you to a fixed-scope project instead.

One prevented incident changes the math.

One prevented incident, or one denied claim avoided, typically covers years of the difference. Fifteen minutes, no prep, and an honest answer about whether the assessment is worth your money.

15 MINNO PREPHONEST ANSWER
Book the call