DOUBLE RULEA Black Lantern Labs practice
Services

A complete security program, built around how your firm actually works.

Double Rule gives accounting firms a practical way to establish, operate, and improve their security program without hiring an internal security department or replacing the technology providers they already trust.

Every relationship begins with the Accounting Security Foundation. Once the program exists, Managed Accounting Security keeps it current and moves the work forward.

Accounting Security Foundation

Know what you have, where the risks are, and what must happen next.

Most firms have accumulated years of software, devices, vendors, user accounts, remote access, shared workflows, and informal exceptions.

The Accounting Security Foundation turns that environment into a program the partners can understand and support.

1. Map the environment

We document the systems and relationships that affect client information, including:

  • Employees, contractors, and seasonal personnel
  • Laptops, desktops, mobile devices, and servers
  • Microsoft 365 or Google Workspace
  • Tax, accounting, payroll, document, and portal applications
  • Service providers and technology vendors
  • Administrative and privileged accounts
  • Client-data storage and transfer workflows
  • Remote access and office connectivity
  • Backup systems and recovery dependencies

This creates a reliable baseline for every security and compliance decision that follows.

2. Verify the safeguards

We review whether the firm's most important protections are present, appropriately configured, and consistently applied.

That includes:

  • Multi-factor authentication coverage
  • Administrative-access controls
  • Email-security configuration
  • Whether endpoint protection and device management are in place
  • Encryption at rest and in transit
  • Backup architecture and recoverability
  • Microsoft 365 or Google Workspace controls
  • External exposure
  • Client portals and file-sharing workflows
  • Onboarding and offboarding procedures

The goal is not to produce a theoretical score. It is to identify where client information can realistically be exposed and what will reduce that exposure.

3. Build the required program

We create or rebuild the core documentation around the firm's real environment:

  • Written Information Security Plan
  • Written risk assessment
  • Incident response plan
  • Core information-security policies
  • Vendor and service-provider register
  • Initial risk register
  • Roles and security responsibilities
  • Evidence inventory
  • Executive reporting structure

The documents reflect the controls and workflows that actually exist. Where reality does not yet match the required state, the gap is documented and assigned.

4. Prioritize remediation

Not every weakness deserves the same urgency.

We convert the findings into a staged roadmap that shows:

  • What should be fixed immediately
  • What can wait
  • What creates the greatest reduction in risk
  • Who should perform the work
  • Whether the change requires new technology
  • What can be handled by the existing IT provider
  • What evidence will show that the item is complete

Double Rule coordinates with your existing providers so the roadmap becomes completed work, not another abandoned spreadsheet.

5. Brief the partners

The engagement concludes with a plain-language executive review.

Leadership receives a clear view of:

  • The firm's largest exposures
  • The safeguards already in place
  • Material gaps and business consequences
  • The remediation sequence
  • Responsibilities and ownership
  • Decisions requiring partner approval
  • The ongoing operating plan

Typical duration: 2–6 weeks

Structure: one-time fixed-fee engagement

Managed Accounting Security

Keep the program current and the work moving.

A security program starts becoming outdated as soon as employees, vendors, systems, regulations, and threats change.

Managed Accounting Security gives the firm ongoing program ownership without requiring a full-time internal security leader.

Program maintenance

We maintain the documents and records that support the program:

  • Written Information Security Plan
  • Security policies
  • Risk register
  • Vendor register
  • Incident response procedures
  • Evidence and decision records
  • Remediation roadmap

Risk and remediation oversight

We track open risks, verify progress, coordinate with responsible providers, and escalate decisions that require leadership attention.

The partners do not have to chase several vendors to determine whether an important security item was completed.

Identity and access oversight

We periodically review administrative access, multi-factor authentication, onboarding, offboarding, and other identity controls with the firm and its IT provider.

Provider coordination

We work with the organizations already supporting your environment, including:

  • Managed IT providers
  • Cloud and software vendors
  • Insurance brokers and carriers
  • Payroll and benefits providers
  • Tax and accounting platforms
  • Outside consultants
  • Legal counsel when appropriate

Employee readiness

We manage a practical awareness and training cadence based on the threats accounting personnel are likely to encounter.

Leadership reporting

Partners receive clear reporting on:

  • Material risks
  • Open remediation items
  • Program changes
  • Vendor concerns
  • Training completion
  • Incidents and exceptions
  • Decisions requiring approval

The objective is not to overwhelm leadership with technical activity. It is to give them enough information to exercise responsible oversight.

A named point of accountability

When a concerning email arrives, a vendor sends a security questionnaire, an employee leaves unexpectedly, an insurance renewal asks difficult questions, or a client requests evidence, the firm has someone to call.

Structure: annual engagement delivered as a monthly program

As the program matures

Capabilities available as the program matures

Technology

Security technology selection and management

Security software is only valuable when it solves the correct problem, is configured properly, and has someone responsible for operating it.

Double Rule can help the firm:

  • Define the actual requirement
  • Compare appropriate products
  • Obtain practical pricing
  • Purchase and license the technology
  • Coordinate deployment
  • Validate configuration
  • Manage the platform
  • Transition operation to the existing IT provider

Typical categories may include endpoint security, email protection, identity security, backup, employee training, vulnerability management, device management, and secure access.

Technology is itemized separately. The firm sees what it is buying, why it is needed, and who will own it.

Testing

Security testing

Policies describe what should be true. Testing helps determine what is actually true.

Testing may include:

  • External attack-surface review
  • Vulnerability assessment
  • Penetration testing
  • Internal security testing
  • Cloud-configuration assessment
  • Microsoft 365 or Google Workspace assessment
  • Web-application testing
  • Phishing simulations
  • Control validation
  • Retesting after remediation

Findings are verified, prioritized, explained in business language, and connected directly to the firm's risk register and remediation plan.

Testing is performed or scoped through Black Lantern Labs based on the environment and objective.

Seasonal

Tax-season protection

The firm's exposure changes during filing season.

Temporary personnel are added. Access expands. Client communication increases. Employees work under time pressure. Criminal campaigns become more targeted. Major technical changes also become more disruptive.

Before filing season, Double Rule can review:

  • Seasonal and temporary accounts
  • Administrative access
  • Multi-factor authentication
  • Remote access
  • Email security
  • Client portals and file sharing
  • High-risk vendors
  • Endpoint coverage
  • Backup readiness
  • Incident contacts and procedures
  • Likely phishing and impersonation scenarios

During the season, the operating posture shifts toward stability, monitoring, rapid coordination, and minimizing unnecessary change.

Automation

Secure workflow automation

Repetitive work creates both operational cost and security risk when it depends on manual handoffs, shared spreadsheets, inconsistent permissions, or undocumented processes.

Double Rule designs controlled automations for workflows such as:

  • Employee onboarding and offboarding
  • Access-review evidence collection
  • Vendor-review tracking
  • Security questionnaire intake
  • Policy acknowledgment
  • Seasonal account rollover
  • Client-document intake
  • Remediation follow-up
  • Compliance evidence organization

Automations are designed around defined permissions, logging, exception handling, and human approval where judgment is required.

The goal is not to add AI for its own sake. It is to remove avoidable administrative work without weakening control.

How the engagement begins

How the engagement begins

1

Introductory call

We learn how the firm operates, identify the primary concern, explain the engagement, and determine fit.

30 minutes · no obligation
2

Accounting Security Foundation

We establish the baseline, verify safeguards, build the program, and prioritize remediation.

2–6 weeks · fixed fee
3

Managed Accounting Security

We maintain the program, coordinate the work, track risk, and report to leadership.

Ongoing monthly program

Start with a direct conversation about your firm.

We will explain what we see, what the likely scope looks like, and whether Double Rule is the right partner.

Book an introductory call