The Accounting Technology Lab copertina

The Accounting Technology Lab

The Accounting Technology Lab

Di: Brian Tankersley & Randy Johnston
Ascolta gratuitamente

In-depth, honest accounting software and technology reviews capturing the real-life experiences of using particular products and solutions - presented by CPA Practice Advisor and technology experts Randy Johnston and Brian Tankersley, CPA.(c) 2026 CPA Practice Advisor Economia
  • ATL271: Why Your WISP Is Essential in 2026
    Aug 21 2026

    Episode Summary: ATL271 - Why Your WISP Is Essential in 2026

    Podcast Page/Subscription Links: https://podcast.cpate.ch
    Wiki Page:
    ATL271 - CPA Tech Wiki


    In ATL271, “Why Your WISP Is Essential in 2026,” Randy Johnston and Brian Tankersley explain why a written information security plan is no longer a compliance document that can sit on a shelf. Accounting firms hold concentrated stores of tax, financial, identity, and sometimes health information, making them attractive targets for phishing, credential theft, ransomware, fraudulent wire instructions, and AI-enhanced attacks. The hosts walk through the overlapping expectations of the IRS, FTC Safeguards Rule, and HIPAA, including written policies, multi-factor authentication, encryption, logging, incident response, training, governance, vendor oversight, and regular risk assessment. They emphasize that penalties can be severe, but the larger business risk may be client loss, reputational damage, litigation, and disruption during tax season. The episode also highlights practical governance: assign accountability, review the WISP regularly, connect security spending to risk, and report results to leadership. Randy and Brian close with five high-impact controls—MFA, full-disk encryption, tested backups, a written incident response plan, and vendor security questionnaires—plus a recurring calendar for log reviews, backup restores, phishing simulations, vulnerability scans, training, patching, and annual WISP updates. Their message: security is an operating discipline, not paperwork. For firms of every size, preparation now is cheaper than recovery.

    Key Takeaways

    • A WISP should be an operating system for security—not shelfware. It needs ownership, periodic review, documented changes, and executive oversight.
    • Accounting firms are unusually attractive targets because they aggregate tax, financial, identity, payroll, and other confidential information.
    • Credential theft and phishing remain central risks, while AI is making fraudulent messages and attacks more convincing.
    • Vendor management belongs inside the security program. Cloud applications, hosting companies, MSPs, AI services, and other third parties expand the firm's attack surface.
    • Incident response must be planned before the incident. Firms should understand regulatory notification obligations, internal responsibilities, legal resources, and PR response.
    • Security has a recurring calendar. Log reviews, backup restores, phishing tests, vulnerability scanning, access reviews, training, patching, and WISP updates need assigned frequencies and owners.

    Catchy Quotes

    Approx. TimeSpeakerQuote
    02:04 | Brian Tankersley | “The firms get hit because you and I are the Fort Knox of confidential data.”
    03:33 | Brian Tankersley | “The bad guys are getting better faster than the good guys are getting better.”
    07:40 | Brian Tankersley | “Anything that touches client data is a death sentence for a hard drive in my office.”
    12:10 | Brian Tankersley | “If you don't have an adequate WISP, you're in violation of the FTC safeguards rule.”
    18:20 | Randy Johnston | “You've got risk on any provider.”
    18:42 | Brian Tankersley | “As soon as you know something's happened, the clock is ticking.”
    23:11 | Brian Tankersley | “Multi-factor authentication, full disk encryption, tested backup strategies, written incident response plans, vendor security questionnaires.”
    24:55 | Randy Johnston | “Make sure that you've got your WISP … pulled out, dusted off, and updated for this year's regulations.”


    Note: Timestamps are approximate where the quote occurs inside a longer timestamped speaker segment in the transcript.

    Social Media Posts

    Mostra di più Mostra meno
    26 min
  • ATL270: Hardware Hullabaloo
    Aug 14 2026

    ATL270: Hardware Hullabaloo - Episode Summary

    Hardware is once again a strategic business issue—not merely an IT purchasing decision. In ATL270, Randy Johnston and Brian Tankersley examine how cybersecurity concerns, new processor families, and extraordinary component-price increases are reshaping technology plans for accounting firms and home offices. They begin with aging consumer routers, warning that an inexpensive or unsupported gateway can become the weak link for business data, remote access, and connected devices. Network segmentation, managed security hardware, and renewed use of VPNs are presented as practical safeguards. The conversation then surveys emerging hardware from Intel, AMD, Apple, Google, NVIDIA, and major PC manufacturers, with special attention to neural processing units and locally executed AI workloads. Brian shares his early experience with a TCL NXTPAPER tablet, while both hosts caution buyers against underpowered back-to-school systems. The sharpest lesson comes from current upgrade economics: Brian reports that the same 64 GB memory kit he bought for about $210 was listed near $979, while Randy describes a previously $18,000 server configuration approaching $74,000. Their advice is deliberately pragmatic: extend maintenance where sensible, scrutinize cloud operating costs, match purchases to measurable productivity, and avoid spending premium dollars merely to own the newest hardware. In a volatile market, disciplined technology governance matters more than specifications alone.

    Key Takeaways

    - Treat home-office routers and remote-access hardware as part of the firm’s control environment.
    - Segment business, household, and connected-device traffic so one compromise does not expose every system.
    - Specify processors, memory, and storage around actual workloads—especially local AI—rather than marketing labels.
    - Evaluate upgrades using measurable productivity and risk reduction, not hardware envy.
    - When server replacement prices and lead times are extreme, compare extended maintenance, cloud economics, and deferral.

    Wiki: https://wiki.cpate.ch/index.php/ATL270

    Creators & Guests

    • Brian F. Tankersley - Host
    • Randy Johnston - Host
    _________________________
    Mostra di più Mostra meno
    23 min
  • ATL269: Microsoft Agent 365
    Aug 7 2026
    ATL269 — Microsoft Agent 365Program: Accounting Technology Lab Hosts: Randy Johnston and Brian F. Tankersley, CPA.CITP, CGMA Approximate runtime: 31 minutesResource: 100 Free AI Prompts for Accounting - https://cpate.ch/100-prompts-atl Primary topic: Governed deployment, monitoring, security, and economics of enterprise AI agents200-Word Episode SummaryIn ATL269, Randy Johnston and Brian Tankersley examine Microsoft Agent 365 as a control plane for deploying, monitoring, governing, and securing AI agents. They frame the shift as a move from per-seat software licensing toward an AI token economy, where tokens function like staff time, prompts replace checklists, and agents perform repeatable work at speed. Practical examples include invoice extraction, email drafting, financial-statement analysis, and budgeting—tasks that may cost pennies in model usage while still requiring review and judgment. The hosts argue that Agent 365 gives accounting firms an alternative to “Wild West” experimentation by extending Microsoft 365 security, auditability, and governance over agents. They discuss Copilot, Agent Builder, Copilot Studio, Microsoft Foundry, Azure AI, Power BI, Defender, Purview, and the E7 licensing bundle. Privacy, records retention, e-discovery, intellectual property, and workflow ownership receive attention because firms may expose sensitive client data or proprietary processes when using public AI platforms. Their practical recommendation is measured experimentation: convert checklists into prompts, move tasks into agents, retain humans in the loop, establish token budgets, and evaluate results firsthand. The message is urgent but cautious: firms need not operate at the bleeding edge, but they must start learning before competitors pull ahead.Key Takeaways· The economic unit of AI is shifting from a user license toward token consumption and task-level cost.· Tokens can be managed like staff time, prompts like procedures, and agents like digital staff assignments.· Agentic workflows depend on steps, loops, exception handling, context, permissions, and human review.· Agent 365’s differentiator is governance: visibility, monitoring, security, auditability, and centralized control.· Public AI tools create material concerns involving PII, PHI, client confidentiality, retention, e-discovery, and vendor training practices.· Proprietary workflows may be valuable intellectual property and should not be surrendered casually to a model provider.· Model selection should balance quality and cost with privacy, security, regulatory fit, and data ownership.· Accounting firms should begin with controlled experiments and measurable use cases rather than enterprise-wide autonomous deployment.· Human reviewers remain accountable for conclusions, professional judgment, client context, and exceptions.· Firms need AI governance policies, token budgets, approved-tool lists, monitoring, and documented escalation procedures.Catchy Quotes and Video Locations· 01:48–01:50 — Brian Tankersley: “Yeah, so it’s an F-150 and not a G-Wagon.”· 04:22–04:30 — Brian Tankersley: “This is like sending it to staff first, and the staff costs three cents.”· 09:35–09:51 — Brian Tankersley: “I’m seeing tokens as staff time on the schedule… We used to have checklists, and now we have prompts.”· 10:09–10:22 — Brian Tankersley: “They get work done so fast that the human is now the logjam in the process.”· 15:32–15:48 — Randy Johnston: “Microsoft Agent 365 is the control plane for agents… Is it perfect yet? No. Is it pretty doggone good? Yes.”· 17:25–17:41 — Brian Tankersley: “We have the grown-ups in charge now, and we’re going to systematize this in a way that we can regulate and do the right way.”· 28:02–28:13 — Brian Tankersley: “Take your checklists and turn them into prompts, and take tasks that are on the schedule and push them into agents.”· 29:31–29:43 — Brian Tankersley: “The train is leaving the station… If you don’t get started on this stuff, you’re going to be behind, and so it’s time to go.”· 30:19–30:30 — Brian Tankersley: “It is critical that you get your hands dirty with some of these things, because it’s the only way that you will be able to evaluate whether something really works or not.”
    Mostra di più Mostra meno
    31 min
adbl_web_anon_alc_button_suppression_t1
Ancora nessuna recensione