Stop the unauthorized access. Isolate affected systems. Preserve evidence. Determine what happened. Restore operations.
But another clock may already be running. Depending on what information was involved and where affected individuals reside, state breach-notification laws may require the firm to notify clients, regulators or both within specific timeframes.
That creates a risk many firms overlook:
A firm can respond effectively to the technical incident and still create a separate problem by mishandling the notification process.
Peabody Properties: The Notification Delay Became Part of the Enforcement Case
In August 2025, the Massachusetts Attorney General announced a settlement with Peabody Properties following multiple phishing-related security incidents. Five separate breaches occurred between 2019 and 2021 and exposed information including Social Security numbers, driver's-license information and financial-account data belonging to nearly 14,000 Massachusetts residents. Two of those incidents were not reported to the Attorney General for almost seven months.
The notification delay was not simply a footnote to the underlying breaches. It became a specific part of the state's enforcement action.
The result was a $795,000 payment to the Commonwealth, along with required security improvements including phishing protections, multifactor authentication, vulnerability management, asset inventory, intrusion detection and prevention, and annual independent security assessments for three years.
THE BREACH CREATED THE INCIDENT.
THE DELAY CREATED AN ADDITIONAL COMPLIANCE PROBLEM.
A firm does not necessarily satisfy its obligations merely because its IT provider contained the attacker quickly.
Breach Notification Is a Separate Workstream
Technical incident response and breach notification are related, but they are not the same job. The technical team may be asking:
- How did the attacker get in?
- Which systems were accessed?
- Is the attacker still present?
- What data may have been viewed or removed?
- Can affected systems be safely restored?
At the same time, the firm and its legal advisors may need to determine:
- What information was involved?
- Which individuals were affected?
- Where do those individuals reside?
- Which state laws apply?
- When did the applicable notification clock begin?
- Must the state Attorney General or another regulator also be notified?
- What must the notice contain?
- Are law-enforcement or other permitted delays applicable?
The cyber-insurance policy may also contain its own reporting requirements.
Right Coverage, Wrong Response: How Incident-Response Mistakes Can Cost Cyber Insurance Coverage
Those questions should not be researched for the first time while the firm is already managing an active incident.
A Florida Firm May Have More Than Florida Law to Consider
A CPA firm located in Florida may naturally think first about the Florida Information Protection Act, or FIPA. But the firm's physical location is only part of the issue.
South Florida firms routinely serve clients with connections to multiple states. Individuals may have moved to Florida while retaining financial, property or business interests elsewhere. Seasonal residents may divide their time between Florida and another state. Business clients may operate offices, employ people or maintain customers in several states.
As a result, a single security incident can involve affected individuals whose state of residence—or other legally relevant connection—requires the firm and its legal counsel to evaluate breach-notification laws outside Florida.
Breach-notification requirements vary from state to state. Florida, for example, uses a 30-day notification framework and has its own threshold for notification to the Florida Attorney General. Other states may use different fixed periods or standards such as notification “without unreasonable delay.” Definitions of protected personal information and regulator-notification thresholds can also differ.
That means a single incident involving one client database may potentially require the firm to evaluate several states' laws at the same time. The wrong moment to begin building that process is after discovering that client information has already left the network.
An Accounting Firm Can Also Face Private Litigation
In Doe v. Bansley & Kierner, LLP, an Illinois accounting firm that also provided payroll and benefits-administration services became the subject of a putative class-action lawsuit following a data breach. The complaint alleged that sensitive personal information had been exposed and that affected individuals and state Attorneys General were not notified until nearly a year after the firm first became aware of the incident. The lawsuit sought damages on behalf of affected individuals.
It is important to distinguish an allegation in a civil complaint from a regulatory finding. The case does not establish that every notification delay produces liability. It demonstrates something different:
A regulator does not necessarily have to be the first party asking why notification took so long.
Small CPA Firms Show How the Gap Happens
Two documented Massachusetts breach notices involving CPA firms demonstrate how a notification gap can occur even without a published enforcement action.
Brazee & Huban, CPA
Brazee & Huban was a single-location accounting practice with roughly a dozen employees. The firm discovered unauthorized access to its systems in November 2023. Notification to affected individuals began in February 2024—approximately three months later. More than 1,000 individuals were reportedly affected, including 746 Massachusetts residents.
There is no regulatory penalty identified in the source for that delay. The significance of the case is the firm's size. This was much closer to the size of firms that often assume a formal breach-response process is unnecessary.
Fitzgerald, DePietro & Wojnas CPAs
Another accounting firm experienced unauthorized network access in June 2024. The firm acted quickly to sever the attacker's access after discovery. But its notification letter to affected individuals was dated in late September—again, roughly three months after the intrusion.
That illustrates the distinction particularly well:
Fast technical containment does not automatically produce fast notification.
The two activities require different decisions, different information and often different people.
Why Written Breach-Notification Procedures Matter
A breach-notification policy cannot determine every legal answer in advance. Each incident must still be evaluated based on its facts, and determining legal notification obligations should involve qualified legal counsel. But the firm's process can be defined ahead of time.
Before an incident, the firm should already know:
- who has authority to declare or escalate a security incident;
- who contacts legal counsel;
- who contacts the cyber-insurance carrier or broker;
- who determines what client information was affected;
- who identifies the states in which affected individuals reside;
- who tracks applicable notification deadlines;
- who approves communications;
- who is responsible for regulator notifications;
- how decisions and timelines will be documented; and
- who maintains the process as laws and business operations change.
What Does a CPA Firm's WISP Actually Need to Include?
The First Hours Should Not Be Spent Figuring Out Who Does What
During an actual breach, the firm may simultaneously be dealing with:
- inaccessible systems;
- forensic investigators;
- law enforcement;
- attorneys;
- cyber-insurance requirements;
- employees unable to work;
- concerned clients; and
- restoration of normal operations.
Adding “figure out the breach-notification laws for every state where our clients live” to that list is a recipe for delay. The better approach is to establish the framework beforehand.
The legal determination still occurs when the facts are known. But the people, responsibilities, escalation paths and information needed to make that determination should already be identified.
How GO InfoTek Can Help
GO InfoTek helps CPA and accounting firms build the operational security framework around an incident before one occurs. That can include:
- Written Information Security Plan development and maintenance;
- incident-response planning;
- breach-notification process development;
- identification of technical and organizational responsibilities;
- documentation and escalation procedures;
- cyber-insurance response coordination planning;
- security risk assessments;
- employee security-awareness programs; and
- ongoing vCISO support.
GO InfoTek does not replace the firm's legal counsel or make legal determinations about whether a particular incident requires notification. Our role is to help make sure the technical response, documentation, escalation process and security program are organized so the firm and its advisors can act quickly when an incident occurs.
The goal is simple:
Do not discover during a breach that nobody knows who is responsible for the next step.
This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.
A practical next step
Discuss Your Environment with GO InfoTek
Start with the systems, safeguards, documentation and questions your organization has today.
Schedule a Conversation