Dev Purkayastha (CEO, Indevia Accounting, Inc.) holds an M.B.A. from Harvard Business School and is a qualified Chartered Accountant. In addition to his accounting experience, he has over 25 years of experience in the venture capital business as well as in investing in public enterprises. For more information on outsource accounting & bookkeeping services please visit: http://www.indevia.com
When we talk about any “increase” we have to say compared to what. In this case the CPA has to assess the data security for on-shore operations before he can assess the increased risk posed by offshoring.
What is the typical level of data security in a small business or a CPA office?
- Since there are few staff members, there is little separation of duties. Such lack of separation encourages internal security problems.
- The data resides in paper files. Paper files are vulnerable to fire and water damage.
- The office is not physically secure. Staff members, leasing office personnel, and janitors have keys to the office. Any of them can copy confidential data.
- Paper records are not shredded before being discarded.
- The computers have no protection from unauthorized users or have relatively weak password control. Often the password is taped to the workstation.
- Any email communication is done in the clear.
- Workstations have recording devices which makes it easy to copy data.
- Usually all workstations have email and internet access. It makes unauthorized transmission of data easy.
Let us look at how these factors change when accounting is sent offshore.
- Internal control improves because the people who are authorizing the transactions are separated from the people doing the record-keeping.
- All files are maintained electronically. Such data is backed up to an off-premises secure server. So threats from fire, water, and copying are significantly reduced.
- Offshore contractors restrict physical access to keep unauthorized people out.
- Workstations have access to only the data that is processed on that workstation.
- Email communications are encrypted.
- All recording devices on the workstations are disabled.
- Only supervisors have access to email and internet.
We believe that best security practices can be installed when the client, the CPA, and the offshore contractor work together.
The first line of responsibility lies with the client. The Better Business Bureau has an excellent pamphlet on how to protect data theft. http://www.bbb.org/securityandprivacy/SecurityPrivacyMadeSimpler.pdf As the pamphlet points out technical solutions are not enough. They must be combined with good practices in everyday management of the company.
The CPA should advise the client to implement the common sense measures advocated in this pamphlet.
The offshore contractor must apply the same real world as well as technical solutions to security. The offshore contractor must consider the sensitivity of the data being entrusted to them and take appropriate measures to safeguard the information. A responsible contractor would only accept data than is essential to the task.
Let us now look at whether popular offshore destinations like India are more vulnerable to data theft. According to a March 2007 Symantec report entitled “Symantec Internet Security Threat Report Trends for July- December 2006”, US was the country with highest level of malicious activity. China was next and India did not make it into the top ten. http://eval.symantec.com/mktginfo/enterprise/white_papers/ent-whitepaper_internet_security_threat_report_xi_keyfindings_03_2007.en-us.pdf
Another common sense conclusion one can draw is that the thieves concentrate on high value targets. You can look at the data compiled by the Privacy Rights Clearinghouse. http://www.privacyrights.org/ar/ChronDataBreaches.htm#CP. During 2005, 2006, through June 20, 2007 they reported 155 million records having been compromised. Out of that less than 1000 records were compromised in attacks that netted 100 records or less. Thus records from an offshore contractor serving small businesses are less likely to be a target of identity thieves.
The CPA needs to assess the sensitivity of the data and put a value on it. The CPA can have the contractor include a liquidated damages clause if the said data is compromised. If the contractor is not willing to agree to a reasonable liquidated damage figure, find another contractor.
Data security is a complex issue. However, we can enunciate certain principles that can be applied by a small business:
- Collect the least amount of data needed to serve the customer.
- Since a large proportion of data theft involves the employees, screen them carefully.
- In addition, the employees need to be trained to recognize various strategies used by criminals to facilitate data theft.
- Take security measures in the office; for example use a locked mailbox, lock the office when it is empty even for a short period of time, shred any paper records before disposal, reformat hard drives before donating, selling, or returning a computer etc.
- Take common sense precautions against cyber attacks. Encrypt the sensitive data, use firewalls, and keep your internet security software updated.
- Comply with any specific security standards that are applicable to your business. For instance credit card information needs to be secured to a specific standard.
Providing security costs time and money. In a competitive world no business can spend more on security than what the market would pay for. Ultimately security is determined by the customers’ willingness to pay.
While more money can buy more security, one must remember that no security is absolute. Just think about how many times classified information has been stolen from the US government.
Eventually there will be a security breach. How do you deal with such a breach? It seems that the best approach is to inform the individuals or businesses whose data have been compromised, notify the law enforcement authorities, and support the affected parties to monitor their credit reports.
Security is a multi-faceted problem. The key to success is co-operation between the client, the CPA, and the offshore contractor. No one party can be effective without the others.
- Related Videos
- Related Articles
- Ask / Related Q&A
- Bookkeeping Services| Online Accounting Software Services| Taxation Service
- Create More Revenue by Outsourcing Bookkeeping Services
- Outsourcing Accounting is Working Smart!
- Why Outsourcing Accounting and Bookkeeping?
- Online Bookkeeping Services - Simple Solution, Excellent Results!
- Outsourced Accounting – for the Smooth Working of an Organization
- Accounting Bookkeeping Services
- Increase your Business Success - Use Outsourced Accounting and Bookkeeping Services




PAYE Settlement Agreements
By: brookepens | 31/12/2009Whilst all benefits and expenses do, in theory, have to be reported to H M Revenue and Customs via form P11ds and form P9ds each year, there are certain items which the Revenue accepts need not be reported. This can be a benefit for payroll services departments although it is safest to get agreement in advance from the Revenue in order to avoid any potential repercussions at a later date.
What is a QuickBooks Hosting Service?
By: D. Rosen | 30/12/2009You may not be familiar with QuickBooks web hosting and the ways that it can be a great solution for your company's accounting needs. QuickBooks hosting allows you to access QuickBooks and your business's accounting information safely and securely from anywhere in the world.
Information on QuickBooks Web Hosting
By: D. Rosen | 30/12/2009With QuickBooks web hosting, you can access your company’s accounting information at any time and from anywhere in the world.
Advantages of Having Professional Tax Accountants!
By: James parker | 30/12/2009Now, conservative business owners will opt for the first choice, probably because they are low on budget. But in reality, they are low in their minds. However, making the second choice is what every sane and smart business owner would do.
Accounting Outsourcing - To Relieve Your Shoulders From Accounting Responsibilities
By: Alvis Brazma | 30/12/2009The services of accounting outsourcing have popped up as one of the practical solution for the businesses. Providers are offering their back up to various companies on the local level as well as international level.
Cash For Clunkers - Sucess or Failure
By: Chaitali Venkatesh | 30/12/2009There has been much debate about the Car Rebate Allowance system (CARS)and whether this was successdul or not. This article attempts to look at both sides of the debate.
The Unbeatable Benefits of Outsourcing Your Accounting Needs
By: Constance Tan | 23/12/2009Have you ever seen a business running without an accounting system? I bet there is none otherwise the business is doomed to fail. Every business from small home based venture to major corporations has accounting needs because it is the barometer of every business.
Are You Tired With Your Bookkeeping Services?
By: James parker | 22/12/2009In order to reduce costs, many small businesses hire part-time book keeping services instead of the full-time. But usually what happens is that these part-time bookkeepers are not professional and expert accountants and are unable to keep accurate financial records for that business. End result is: non-satisfaction of the business owner!
A Common Sense Approach to Data Security as Applied to Offshore Accounting Service
By: Dev Purkayastha | 29/07/2008 | AccountingOne of the first things you hear about offshoring is that it would increase the potential for data theft. Let us assess this perception in a common sense way.
Strategic Application of Outsourcing in a Cpa Practice
By: Dev Purkayastha | 29/07/2008 | AccountingThe most important gain from outsourcing is the time saved, which, in turn, allows the CPA to attend to strategic matters such as client development, CPE, and retirement planning. Potential cost savings are as high as 70%.
Ten Commandments Working With an Outsourced Accounting and Bookkeeping Service
By: Dev Purkayastha | 29/07/2008 | AccountingOnce you have selected an outsourced accounting and bookkeeping vendor be prepared to invest some time in defining the relationship