Key Takeaways:
- The expectations on professional services firms — law, accounting, financial advisory, consulting — have shifted faster than most firm administrators in Fort Wayne and Decatur realized. Indiana Rules of Professional Conduct 1.6 and the AICPA’s Statement on Standards for Tax Services both now expect competent technology safeguards for client information, not just diligent paper handling.
- Most three-to-twelve-attorney firms and small-to-midsize CPA practices still rely on a mix of email, shared drives, and a folder structure that has grown organically since the firm started. That is not a personal failure — it is the universal condition.
- The 2025 cyber insurance application questions have caught up with the regulatory shift. Carriers are now asking specifically about MFA, encryption, document handling, and breach response. “We’re a small firm” is not the answer that gets the policy renewed at last year’s premium.
- A 30-minute audit at your desk — without changing anything — will tell you exactly where client files actually live and which of them are protected the way the rules now expect. Most administrators are surprised by what they find.
- The conversation with the partners is much easier when you bring the audit instead of the worry. Partners respond to data and risk language, not to vague concerns about “the IT being out of date.”
If you are the firm administrator at a small Fort Wayne or Decatur law firm, CPA practice, or financial advisory office, there is a folder structure on your shared drive right now that grew organically over the last several years. Some clients have one folder. Some have ten. Some are sorted by year, some by matter type, some by partner, and some by whoever happened to set up the file when the engagement started. There is at least one folder labeled “OLD — do not delete.” There are documents from clients who haven’t been active in eight years. Some files are encrypted because a partner sent them that way. Most are not.
You are not behind because you missed something. Every professional services firm in northeast Indiana of your size has a similar structure. The drive grew with the firm. Nobody redesigned it because nobody had a quiet quarter to do that work, and the moment you started talking about “IT modernization,” the partners pointed at billable hours and asked you to bring it up next quarter.
The reason this matters in 2026 is not that the work changed. The reason is that the rules and the insurance carriers have caught up to what the work has always been. Client files contain sensitive personal, financial, and legal information. The Indiana Rules of Professional Conduct have always expected reasonable safeguards. The AICPA standards have always expected the same for CPA work. What changed is that “reasonable” now means specific, documentable, technical controls — not just a locked file room and a discreet attorney.
The good news is the same as it always is for the firm administrator: the first move is small, costs nothing, and starts at your desk.
What do the Indiana Rules of Professional Conduct actually require?
For attorneys, Rule 1.6 covers confidentiality of information — including the comment language requiring that lawyers act competently to safeguard information against unauthorized access. The Indiana Supreme Court has been clear over the past several years that “competence” includes technological competence, and that “reasonable efforts” must reflect the current state of practice. Encryption that was reasonable in 2010 is not reasonable in 2026. Email-only document delivery for sensitive matters is no longer the standard.
For CPAs, the AICPA Statements on Standards for Tax Services and the AICPA Code of Professional Conduct apply parallel logic — the practitioner must safeguard client information using methods appropriate to current professional norms. Both bodies of rules push the firm toward the same operational posture: documented controls, defined policies, and technical safeguards that match the sensitivity of the information.
The Indiana 45-day breach notification rule applies on top of all of this. If client personal information is improperly accessed, the clock starts when the firm becomes aware. Whether the breach was an attorney’s fault, a vendor’s fault, or a misconfiguration is not the question — the notification obligation runs regardless.
Where do client files actually live in a typical small firm?
You will be surprised when you actually look. The pattern across small firms is consistent:
| Location | Typical contents | Common controls (current state) |
| Office shared drive | Active matter files, document libraries | Folder permissions, sometimes |
| Practice management system (Clio, PracticePanther, ProSeries, Lacerte) | Engagement records, time, billing | Vendor-managed, often MFA optional |
| Email (sent and received) | Document drafts, client correspondence | Often the largest cache, often least controlled |
| Personal devices | Partners’ phones, laptops at home | Variable; often no policy |
| Cloud sync (Dropbox, OneDrive, Google Drive) | Used by individual attorneys/CPAs | Often shadow IT, not centrally managed |
| Old workstations | Documents that “should have been moved” | Frequently still containing client data |
| External counsel / co-counsel exchanges | Sensitive matter documents | Usually just email attachments |
The shared drive is not where most of the risk lives. The risk lives in email and in cloud sync that grew up around the official systems. A firm administrator who maps where files actually are — versus where they are supposed to be — produces a document that is more useful than any vendor proposal.
What does the 2025 cyber insurance application now ask?
Three years ago, professional services firms could renew cyber insurance with a one-page application. The 2026 versions are five to ten pages, with specific technical questions:
- Is multi-factor authentication (MFA — a second login step beyond a password) enforced on email, on the practice management system, on the document management system, on remote access?
- Are client documents encrypted at rest and in transit?
- Do you have a written incident response plan? When was it last tested?
- How do you offboard departing attorneys, paralegals, or CPAs? How long does access termination take?
- Have you had any cyber incidents in the past 24 months, even those that did not result in a breach?
Carriers are now denying claims and refusing renewals when the application turns out to have misrepresented the controls. “We have email security” is not the same as “we have MFA enforced on email.” The honest answer matters more than the optimistic answer, because the optimistic answer voids the policy at the moment you most need it.
How do I audit our current state without making this bigger than it needs to be?
Professional Services File Audit — Working Order
Tier 1: The official systems
│ Practice management system permissions
│ Document management system permissions
│ Shared drive folder structure
▼
Tier 2: Email
│ Who has access to firm email accounts?
│ Are there email aliases for departed staff?
│ Is MFA enforced firm-wide?
▼
Tier 3: Cloud sync (often the surprise)
│ What attorneys/CPAs use Dropbox, OneDrive,
│ Google Drive for client work?
│ Are those accounts personal or firm-owned?
▼
Tier 4: Devices and dormant data
Old workstations still in the office
Partners’ personal devices with firm access
Backups that include data that should be purged
Walk through these in order. For each, capture three things: what is there, who has access, and what controls are in place. You will not change anything during the audit. You are taking inventory.
The whole exercise takes 30 to 60 minutes if you focus. The result is a one-page picture of where the firm actually stands, which is the document the partners need before they can make a decision about what to fund.
How do I bring this to the partners without sounding like I am asking for a project?
The same way you would bring any operational risk: with the data and the framing.
Partners respond to two things: risk to the firm, and risk to clients. Frame the audit findings in those terms. “Here’s where client files live. Here’s which of those locations meet the current standard for encryption and access. Here’s our exposure if something goes wrong. Here’s what I’d suggest as the next reasonable step, and roughly what it costs in time and dollars.” That is a partner briefing. Partners read partner briefings.
What loses the room is “we need to upgrade our IT” or “I’m worried about cybersecurity.” Both are true and both will be ignored. The audit makes the worry concrete, and concrete things get budget.
A useful tactical note: bring the audit during the operational portion of a partner meeting, not at the end during “any other business.” It takes 10 minutes to walk through. It deserves the time.
Want help reading what your audit found?
After the 30 minutes at your desk, you’ll have a list of locations, controls, and gaps. What you may want next is a way to look at that list and know what’s an immediate fix, what’s a quarterly project, and what is fine for now — without it turning into a vendor pitch for a document management system you may not need.
No pitch, no pressure — just a working conversation about what your audit is telling you.Call Aptica: (260) 243-5100 or schedule directly: calendly.com/jnewburg-1/15min
Frequently Asked Questions
Are we required to encrypt every email containing client information?
The standard now is encryption in transit (TLS, which most modern email systems do automatically) and encryption at rest (which Microsoft 365 and Google Workspace handle for their customers). Specific high-sensitivity communications — settlement documents, tax returns, financial account information — should additionally use a secure portal or message-level encryption rather than plain email attachments. The Indiana Rules of Professional Conduct and AICPA standards both push toward this layered approach.
What is a secure client portal for a law firm or CPA office?
A secure portal is a system where clients log in to access documents rather than receiving them as email attachments. Most practice management systems (Clio, PracticePanther, MyCase, CCH Axcess, Drake Portal) include one. For firms without practice management, standalone portals (ShareFile, Citrix, Onehub) are common. The need for one depends on the volume and sensitivity of document exchange — most modern small firms do.
How do we handle texts and chat messages with clients?
This is the underrated risk. Text messages and chat messages with clients about substantive matter content are records that should be preserved and may be subject to the same confidentiality rules as email. Firms increasingly use practice management systems with built-in client messaging to keep these records inside the controlled environment. Personal texts on personal phones are problematic for both records and confidentiality reasons.
What happens if a partner’s laptop is stolen with client files on it?
If the laptop’s drive is encrypted (BitLocker on Windows, FileVault on Mac), the loss is meaningfully smaller — the data is recoverable from backup but not accessible to the thief. If the drive is not encrypted, the firm likely has a notification obligation under Indiana law and may have professional conduct obligations as well. Full-disk encryption on every device with firm data is now table stakes.
Should we replace our current IT person with a professional-services specialist, or add one alongside?
Add one alongside, in almost every case. The firm’s existing IT person handles day-to-day operations and probably should continue to. The work above — risk assessment, written policies, professional-services-specific compliance — is increasingly a specialty. Many firms add a specialist alongside their existing IT support rather than replacing one with the other. The two-layer model preserves operational continuity while adding the depth the rules now expect.
About Aptica
Aptica is a locally owned IT provider serving manufacturers, distributors, engineers, healthcare practices, and professional services firms across Northern Indiana, Southern Michigan, and Northwest Ohio. Founded in 2003 and based in Angola and Fort Wayne. BBB Accredited, A+ rated.
Angola: 113 E Maumee St, Angola, IN 46703 · (260) 243-5100
Fort Wayne: 1690 Broadway, Bldg 19, Suite 10, Fort Wayne, IN 46802 · (260) 243-5182
Web: apticallc.com · Email: info@apticallc.com
Call us. We answer the phone.




