DOUBLE RULEA Black Lantern Labs practice
Security programs for accounting firms

Your clients trust you with everything. Attackers are counting on it.

Double Rule builds and runs security programs for accounting firms.

We identify where sensitive client information is exposed, put the required safeguards and documentation in place, coordinate remediation with your existing IT provider, and keep the program current as your firm changes.

No generic assessment. No binder that becomes outdated six months later. One accountable security partner your firm can call when something changes, something breaks, or something does not look right.

30 minutes. No obligation. A direct conversation about your firm, your current exposure, and what needs to happen next.

The gap

Security should not be another responsibility sitting between the partners and the IT provider.

Most accounting firms have technology support.

Far fewer have someone responsible for the security program itself.

That leaves critical work scattered across vendors, internal staff, insurance questionnaires, policy templates, and decisions nobody is fully qualified or authorized to own.

Double Rule closes that gap.

We build the program, coordinate the technical work, maintain the evidence, and report directly to firm leadership.

The path in

First, we establish the program. Then, we keep it working.

Accounting Security Foundation

A structured engagement that turns an incomplete or informal security posture into a documented, actionable program.

We map the firm's systems, users, vendors, sensitive-data workflows, access controls, and external exposure. We identify the largest risks, establish the required policies and plans, and give your firm a prioritized remediation roadmap.

At the end of the engagement, your partners know:

  • What sensitive information the firm holds
  • Where that information is stored and transmitted
  • Which risks require immediate attention
  • Which safeguards are already working
  • What the firm must change next
  • Who is responsible for each action
  • What evidence exists to support the program
One-time onboarding · typically 2–6 weeks

Managed Accounting Security

Security does not stay finished.

Employees join and leave. Vendors change. New software gets introduced. Access accumulates. Threats evolve. Policies become outdated.

We keep the program current and the work moving.

That includes maintaining the risk register and security documentation, tracking remediation, reviewing important environmental changes, coordinating with your technology providers, overseeing training, and putting clear security reporting in front of the partners.

Ongoing monthly program · one accountable relationship
With your IT

Your IT provider manages technology. We make sure the security program works.

Double Rule is not designed to replace a capable IT provider.

We work alongside them.

Your IT provider may manage devices, accounts, software, support requests, backups, and infrastructure. Double Rule determines whether the firm's safeguards are appropriate, whether important risks are being addressed, whether the required program is documented, and whether leadership has reliable evidence that the work is happening.

When something needs to change, we help define the requirement and coordinate the work through completion.

No turf war. No duplicated helpdesk. No assumption that someone else is handling it.

Why a specialist

Built for accounting firms, not adapted to them.

Accounting firms operate differently from ordinary small businesses.

Client information moves through portals, email, tax platforms, document-management systems, remote staff, seasonal employees, and outside service providers. The busiest part of the year is also the worst time to discover that a security control was poorly designed.

Our operating model accounts for that.

Major changes are planned around the firm's calendar. Filing season shifts into a protect-and-monitor posture. Recommendations account for real workflows, real deadlines, and the systems your staff already depend on.

Your firm does not pay us to learn why March is different from June.

Also offered

Additional capabilities, without another vendor search

Once the core program is established, Double Rule can support the specialized work the firm needs next.

Technology

Security technology

We help select, purchase, configure, and manage security tools that fit the firm's actual risks and budget.

Testing

Security testing

We test external exposure, internal systems, cloud configurations, and critical workflows to determine whether safeguards work outside the policy document.

Seasonal

Tax-season protection

We review high-risk access, seasonal accounts, email exposure, vendor dependencies, and likely attack paths before filing activity peaks.

Automation

Secure automation

We design controlled workflows for repetitive operational tasks such as evidence collection, onboarding, access reviews, document intake, and seasonal rollover.

You only add capabilities that solve a defined problem. Every item is scoped and priced clearly.

The requirement

The requirement already exists. The program should too.

The FTC Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program with appropriate administrative, technical, and physical safeguards. The IRS also states that tax professionals are required to maintain a Written Information Security Plan.

Double Rule helps turn those requirements into an operating program that reflects what your firm actually does.

Book an introductory call

Tell us how your firm operates today. We will identify the likely gaps, explain how the engagement works, and tell you plainly whether Double Rule is the right fit.