Skip to main content

#security

Security

Protect your financial data with security best practices and tools

47 postsView all tags
AI Deepfake CEO Fraud: Wire-Transfer Controls That Actually Work
·mike

AI Deepfake CEO Fraud: Wire-Transfer Controls That Actually Work

The FBI logged over 22,000 reports of AI voice or video fraud with nearly $893 million in losses in a single recent year; callback verification on a separate channel, a rotating code word, and a dollar-threshold second approver are the three no-cost controls that stop deepfake wire-transfer fraud.

ai
fraud-prevention
fraud-detection
State Data Breach Notification Laws: A Small Business Compliance Guide
·mike

State Data Breach Notification Laws: A Small Business Compliance Guide

Every US state has its own data breach notification law, with individual-notice deadlines ranging from 30 days (California, Colorado, Florida, New York, Washington) to 60 days (Connecticut, Texas), and small businesses must comply with the law of every state where an affected person lives, not just their home state.

security
compliance
small-business
Business Email Compromise: The Accounts Payable Controls That Stop Wire Fraud
·mike

Business Email Compromise: The Accounts Payable Controls That Stop Wire Fraud

Business email compromise cost U.S. victims over $3 billion in reported losses in 2025, and 86% of it moves by wire or ACH. Six accounts payable controls — callback verification, dual approval, vendor master file locks — stop fraudulent transfers before the money leaves.

fraud-prevention
accounts-payable
small-business
Beancount MCP: Connect Your Ledger to Claude, Cursor, and Any AI Assistant
·mike

Beancount MCP: Connect Your Ledger to Claude, Cursor, and Any AI Assistant

The Beancount MCP server connects your plain-text ledger to Claude, Cursor, Windsurf, and any MCP-compatible AI client over OAuth 2.1 — ask questions, run BQL queries, and commit ledger edits without leaving your AI tool.

ai
llm
automation
Business Identity Theft: A Practical Detection and Recovery Playbook for Small Business Owners
·mike

Business Identity Theft: A Practical Detection and Recovery Playbook for Small Business Owners

A 72-hour response playbook for small business owners facing EIN-based tax fraud, registered agent hijacking, or payroll account takeover — including how to file IRS Form 14039-B, place fraud alerts at Dun & Bradstreet, Experian Business, and Equifax Small Business, and harden IRS, Secretary of State, banking, and payroll footprints year-round.

small-business
fraud-detection
fraud-prevention
California SB 53 Compliance: A Practical Guide to the Transparency in Frontier AI Act
·mike

California SB 53 Compliance: A Practical Guide to the Transparency in Frontier AI Act

California's SB 53 (Transparency in Frontier AI Act) took operative effect on January 1, 2026, requiring foundation model developers training above 10^26 FLOPs to publish safety frameworks, report critical incidents to Cal OES within 15 days (24 hours for imminent threats), maintain anonymous whistleblower channels, and face civil penalties up to $1 million per violation enforced by the California Attorney General.

ai
llm
compliance
SEC Cybersecurity Incident Disclosure: Hitting the Four-Business-Day Clock on Item 1.05 in 2026
·mike

SEC Cybersecurity Incident Disclosure: Hitting the Four-Business-Day Clock on Item 1.05 in 2026

A 2026 operating guide to SEC Item 1.05 Form 8-K cybersecurity disclosure — when the four-business-day clock starts, how to make the materiality call without unreasonable delay, when the Attorney General can grant a delay, the Item 1.05 vs. Item 8.01 trap, and what Regulation S-K Item 106 requires in your annual 10-K.

compliance
security
incident-response
SOC 2 Type II for SaaS Startups: Scope, Survive, and Ship Your First Customer-Driven Audit
·mike

SOC 2 Type II for SaaS Startups: Scope, Survive, and Ship Your First Customer-Driven Audit

A founder's guide to SOC 2 Type II in 2026 — what it actually tests, realistic cost ($20K–$35K first year) and timeline (3–12 month observation window), which Trust Services Criteria to scope, the seven controls that trip startups up, and how to keep enterprise deals moving with Type I bridge letters while the audit runs.

saas
startup
compliance
PCI DSS 4.0.1 in 2026: The Small Merchant's Guide to SAQ A, Script Tampering, and MFA
·mike

PCI DSS 4.0.1 in 2026: The Small Merchant's Guide to SAQ A, Script Tampering, and MFA

PCI DSS v4.0.1 governs every 2026 assessment, and FAQ 1588 has narrowed who qualifies for SAQ A. This guide walks small merchants through the new script-tampering rules (6.4.3 and 11.6.1), the 12-character password and MFA requirements, what non-compliance actually costs, and a 12-step checklist for getting it right.

compliance
security
payments
The 2026 WISP Playbook for Tax Pros and Bookkeepers: Building an FTC Safeguards Rule-Compliant Data Security Program Without a CISO
·mike

The 2026 WISP Playbook for Tax Pros and Bookkeepers: Building an FTC Safeguards Rule-Compliant Data Security Program Without a CISO

A 2026 guide for solo tax preparers and small bookkeeping firms to build a Written Information Security Plan that satisfies the FTC Safeguards Rule's nine elements, the IRS PTIN attestation, and the 30-day breach notification requirement — using IRS Publication 5708 as the scaffold and a 90-day rollout.

security
compliance
tax-preparation
WISP Compliance: Why Every Tax Pro Needs a Written Information Security Plan in 2026
·mike

WISP Compliance: Why Every Tax Pro Needs a Written Information Security Plan in 2026

A practical guide to building a Written Information Security Plan that satisfies the FTC Safeguards Rule and IRS Publication 5708 — covering the nine required elements, technical controls like MFA and encryption, penalty exposure up to $46,517 per violation per day, and a six-week roadmap for tax preparers, CPAs, and bookkeepers.

security
compliance
tax-compliance
CMMC 2.0 and NIST 800-171 in 2026: A Small Defense Contractor's Certification Roadmap
·mike

CMMC 2.0 and NIST 800-171 in 2026: A Small Defense Contractor's Certification Roadmap

CMMC 2.0 took effect November 10, 2025, and Level 2 third-party assessments begin November 10, 2026. A practical guide to scope, cost ($80K–$250K over three years), the 14 control families, the POA&M rule, and a 90-day path for small DoD contractors.

compliance
security
small-business
Showing 25–36 of 47 posts