The Qualified Individual

PODCAST · education

The Qualified Individual

The Qualified Individual is a micro-podcast for managing partners at small and mid-sized CPA firms navigating data security compliance. Hosted by Daniel Chang, author of The Governance Gap, each 8-12 minute episode tackles multiple real issues: cyber insurance gaps, FTC Safeguards requirements, MSP oversight, access controls, and AI governance. Delivering practical, jargon-free guidance on what to do about it. Visit TheQualifiedIndividual.com

  1. 11

    The Microsoft 365 Coverage Gap Nobody Talks About

    Most CPA firms use Microsoft 365 for email and collaboration, and most firms assume they understand their data security there. But Microsoft's default settings leave significant gaps—particularly around shared mailboxes, file sharing, and recovery. We're breaking down what M365 does and doesn't do, and what controls your firm needs to add.

  2. 10

    Tax Season Is Hacker Season

    Tax season brings volume, pressure, and fatigue—exactly when hackers strike. From phishing attacks targeting busy staff to stolen credentials accessing dormant systems, tax time is peak season for breaches. Here's how to prepare your firm's security culture and controls to survive the busiest time of year.

  3. 9

    Why Your Biggest Clients Are About to Start Asking Questions

    Your largest clients are increasingly asking about your security practices—how you protect their data, what controls you have, whether you meet compliance standards. We're talking about what these client security questionnaires are really asking, why they're becoming standard, and what it means for your firm's compliance.

  4. 8

    The Intern Who Still Has Access to Everything

    Offboarding is how most breaches actually start—not with external hackers, but with former employees or contractors who kept their access. We're talking about why access removal is harder than it sounds, what gets missed, and the framework for making sure that when someone leaves, their doors actually close.

  5. 7

    Your MSP Isn't Your Security Program

    Many CPA firms rely on their Managed Service Provider for security. But an MSP handles servers and systems—not your security program. We're breaking down what an MSP does, what they don't do, and why your firm still needs a documented, independent security program even if your IT is completely outsourced.

  6. 6

    What Happens in the First 48 Hours After a Breach

    When a breach happens, the first two days matter more than everything that comes after. You need to know: how to detect it, who to call first, what to preserve, and how to communicate both internally and with authorities. We're walking through the incident response framework and the practical steps that keep a small situation from becoming a firm-threatening crisis.

  7. 5

    The One Person the FTC Says You Must Have

    The Safeguards Rule now requires you to designate a Qualified Individual to oversee your security program. Who should this person be? What do they actually need to do? And what happens if you don't have one? We're breaking down the role and how it works in practice at a small to mid-sized firm.

  8. 4

    You're a Financial Institution (And You Probably Didn't Know It)

    The FTC classified CPA firms as financial institutions under the Safeguards Rule. What does that mean? It means new compliance obligations, specific security requirements, and if you get it wrong, substantial penalties. Here's what you need to know about the rule, how it applies to you, and what your first steps should be.

  9. 3

    Your Cyber Insurance Might Not Pay. Here's Why.

    Most CPA firms think their cyber insurance will cover a breach. It won't—at least not the way they think it will. We're breaking down why policies deny claims, how sublimits shrink your actual coverage, and what you need to do before disaster strikes to make sure you're protected when it matters most.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

The Qualified Individual is a micro-podcast for managing partners at small and mid-sized CPA firms navigating data security compliance. Hosted by Daniel Chang, author of The Governance Gap, each 8-12 minute episode tackles multiple real issues: cyber insurance gaps, FTC Safeguards requirements, MSP oversight, access controls, and AI governance. Delivering practical, jargon-free guidance on what to do about it. Visit TheQualifiedIndividual.com

HOSTED BY

The Qualified Individual

CATEGORIES

URL copied to clipboard!