• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

Cybersecurity

Article 04.2.2018 Dean Dorton

By: Jason Miller

“Cybersecurity” has become a buzzword over the last couple of years, especially with more cybersecurity attacks against large companies or corporations that are recognizable by name, but have you really taken the time to sit down and assess your organization’s IT security position?

Many organizations quickly punt the topic of cybersecurity to the IT department. While IT plays a huge role in cybersecurity, it is the responsibility of those charged with organization governance to ensure compliance. Board members and senior leadership should be asking the questions and confirming that the organization is devoting the proper resources and attention to cybersecurity.

“One and done” doesn’t work here

It is critical to understand that cybersecurity is not a one-time project. It is a continual evolution and initiative.

Leadership needs to also recognize there can be substantial costs associated with cybersecurity activities and for some organizations such as colleges and universities, they are not optional. Across the public and private sectors, it is imperative that organizations continue to enhance cybersecurity in order to meet evolving threats to controlled unclassified information and challenges to the security of such organizations.

With the ongoing focus on your organization’s bottom line, it might be tempting to defer projects related to cybersecurity to reduce budgets. However, doing so could put your organization in a position where you are not prepared, or even worse, in noncompliance with certain regulations specific to your industry. Cutting corners on cybersecurity compliance could wind up costing your business more in the end.

The “I’m covered already” approach

When evaluating your cybersecurity preparedness, there are several factors to consider. Let’s take a step back – right now, your priority is your business. You’re buying new technology, investing in new infrastructure and most likely trying to adapt to changing business models like cloud. It’s all good work but it takes time and effort.

Hackers desperately want access to your customer data, employee data, or intellectual property because it’s worth a lot. A single theft could cost your company severe financial damage. And sometimes, in the case of ransomware, all they have to do is lock it down and force you to pay to get it back as you’ve heard about in some of the latest attacks.

Why do you hear terms like “dynamic threat landscape” these days? Because you aren’t facing a group of hacktivists in a basement anymore – you are now facing professionals with a lot to gain.

Your business and the threat landscape around you are ever changing.  It is imperative that your organization conducts an annual cyber risk assessment. This allows the entire organization to consider current and future risks and put forth a plan to mitigate the identified risks.

Some businesses will run out and acquire every new solution they hear about for protecting their organization against cyber risks. While having a multi-layered approach to cybersecurity is important, it is also equally important to have an organized approach and to use tools that are designed to work together.  If your solution is designed properly, you could end up with what we call the security effectiveness gap. As you add more solutions that don’t work together, the complexity exponentially increases. So, every time you add another solution or another vendor, you add another gap – another vulnerability.

A robust cybersecurity solution will:

  1. Stop threats at the edge
  2. Protect users where they work (especially when team members are working remotely or on a personal device)
  3. Find and contain problems fast
  4. Control who gets on your network and from where
  5. Simplify network segmentation
  6. Provide compressive monitoring and detection

…But I have cyber security insurance

That insurance probably doesn’t cover anywhere near what you think it does. Should you invest in cybersecurity insurance? That’s a topic for a different day.

Your business, no matter what size or type, needs to be prepared to handle a cyberattack at a moment’s notice. It is important to work with credentialed professionals with cybersecurity expertise and experience to help you maximize your investment and make sure you have all the appropriate measures in place to keep hackers at bay.

Learn more about Dean Dorton’s cyber security services and solutions for your organization.

As originally featured in Louisville’s Business First

Filed Under: Cybersecurity, Services, Technology Tagged With: attack, Cyber, Cybersecurity, Insurance, jason, Jason Miller, miller, Technology

Article 01.16.2018 Dean Dorton

Here are the key risks and opportunities for 2018:

Cybersecurity and Big Data

Co-operatives can be proactive by implementing effective controls to prevent and detect cyber-crime. A successful cybersecurity campaign includes educating employees of potential phishing schemes. Potential effects of a co-op network infiltration can include shut down of an energy grid, re-direction of energy to a particular location, or theft of customer payment information. Management can use simple software applications to create data analytics which help in identifying trends in business and ultimately help make informed decisions.

Power Supply Costs

Even though a proposal exists to repeal the EPA Clean Power Plan, continue to investigate alternative sources of energy, such as wind, solar, and biomass, to further diversify power sources as well as work with communities to deploy energy storage and efficiency technologies. Explore wholesale power markets as a way to obtain reliable electricity at an effective cost.

Safety, Including Overtime Management

Safety is a major concern for co-operatives as their employees routinely work in dangerous conditions (i.e. downed power line in a thunderstorm) that, if not taken seriously, can expose the co-operative. Monitor overtime hours to help protect the safety of employees; this important oversight role is a vital way to control costs.

Community and Environmental Responsibility

As an electric co-operative, you have to balance providing affordable electricity to your community, while protecting it from environmental degradation. You can launch conservation programs in your community by providing information and resources to members about how they can individually reduce their energy costs. This not only saves the members money but also keeps you from wasting energy resources and protects the environment. The enhanced use of social media and technology will facilitate great success in this area.

Succession Planning

As co-operative executives continue to grow older and retire in larger numbers than in the past, there must be a greater emphasis on succession planning and staff development. This risk flows all the way down to recruitment of top talent as urbanization continues to increase in the U.S. and competition from other industry sectors for talent intensifies. Whether you decide to use an internal or external hire to replace key top management, take the necessary steps to ensure a smooth transition.

Adoption of the New Revenue Standard

Co-operatives will need to adopt ASU 2014-09 (Revenue from Contracts with Customers) in 2019 or 2020, depending on fiscal year end. This standard focuses on a five-step process to assess revenue recognition for products and services. The concept of transfer of control is used to dictate when revenue is recognized. Identify your significant revenue streams and apply the new revenue criteria to each stream. In addition to potential changes in revenue recognition, expanded disclosures will be required. Management should use 2018 to assess this standard appropriately.

Adoption of the New Lease Standard

Co-operatives will need to adopt ASU 2016-02 (Leases) in 2020 or 2021, depending on fiscal year end. This standard focuses on placing almost all leases on the balance sheet through a right of use asset and liability. The concept of transfer of control is used to define a lease. The most important step for management in 2018 is to start building an inventory of leases. After the inventory is built, determine the need for investing in lease software to properly track the new accounting requirements.Sources: America’s Electric Cooperatives, Ernst & Young, Coop News, Cooperative Energy, Vanderbilt UniversityElectric Co-operative Key Performance IndicatorsNote: Group consists of various Kentucky-based electric co-operatives.

Measurement Trend 2016 2015 2014 2013
Debt to equity Positive 1.18 1.29 1.40 1.49
Equity to total assets Positive 43% 41% 38% 37%
Current ratio Stable 1.00 0.99 1.05 0.97
AP turnover Stable 15.48 17.72 16.58 15.59
AR turnover Stable 13.10 16.13 14.60 16.19
Operating margin %* Decline 4.2% 6.0% 6.2% 5.6%
Cost of purchase %* Stable 70% 70% 71% 72%
Capital expenditures %* Stable 9.7% 8.3% 7.3% 7.6%

* Percent of revenue

Overall, the results are positive and show the stability that exists in the electric co-operative industry in Kentucky. Operating margin slipped in 2016 due to a decline in revenue, attributed to weather patterns and increased energy efficiency programs.

Filed Under: Energy & Natural Resources, Industries Tagged With: asu, Bill, Co-operative, Cooperative, Cybersecurity, Electric, EPA, Kohm, revenue standard

Article 07.10.2017 Dean Dorton

There seems to never be an end to the stream of new cyber threats being thrown at us and our user base. Most people are starting to be more aware of phishing scams, but are your users up to speed on “smishing”? Smishing is a term used in reference cyber scams delivered through SMS (text) messaging to smartphones. Please share the following with your corporate users:Bad guys are increasingly targeting you through your smartphone. They send texts that trick you into doing something against your own best interests. At the moment, there is a mystery shopping scam going on, starting out with a text invitation, asking you to send an email for more info which then gets you roped into the scam.

Always, when you get a text, remember to “Think Before You Tap”, because more and more, texts are being used for identity theft, bank account take-overs and to pressure you into giving out personal or company confidential information.User awareness is one of the most important parts to a company’s cybersecurity defense plan. Contact your Dean Dorton team to learn more about our tools and services to enhance your user awareness strategy and cybersecurity defense tools.

Filed Under: Cybersecurity, Services, Technology Tagged With: Cyber, Cybersecurity, phishing, phone, scam, smishing, Technology

Article 01.19.2017 Dean Dorton

The United States Department of Education (DOE) has sent friendly notices for two years in a row reminding colleges and universities of their requirement to comply with the strict guidelines for protecting student financial aid information. Cybersecurity should be near the top of every organization’s priority list, but for higher education institutions it should be elevated even further. Given that the DOE has provided two warnings to date, we should assume they plan to take a stricter stance on cybersecurity infrastructure, protection, and controls during compliance audits.

Cybersecurity: A Critical Boardroom Topic

Many organizations quickly punt the topic of cybersecurity to the IT department. While IT plays a huge role in cybersecurity, it is the responsibility of those charged with organization governance to ensure compliance is met. Board members and senior leadership should be asking the questions and confirming that the institution is devoting the proper resources and attention to cybersecurity.

  • It is also critical to understand that cybersecurity is not a one-time project. It is a continual evolution and initiative.
  • Leadership needs to also recognize there can be substantial costs associated with cybersecurity activities and they are not optional. The DOE letter makes this point very clear when they state “The Department understands the investment and effort required by institutions to meet and maintain the security standards established in NIST SP 800-171. Nonetheless, across the public and private sectors, it is imperative that organizations continue to enhance cybersecurity in order to meet evolving threats to controlled unclassified information and challenges to the security of such organizations.”

With the ongoing focus on higher education institution’s bottom lines, it might be tempting to defer projects related to cybersecurity to reduce budgets. However, doing so could put your institution in a position where the DOE finds your organization in noncompliance with your Program Participation Agreement (PPA) with Title IV student financial aid. Cutting corners on cybersecurity compliance could wind up costing your institution more in the long run.

The Time to Act is Now

At this point, most organizations have some form of information security or cybersecurity policies in place, but do yours include the very specific requirements outlined in the Gramm-Leach-Bliley Act (15 U.S. Code 6801) and NIST SP 800-171? When was the last time your institution performed and a thorough IT risk assessment (one that meets the NIST SP 800-171 standards)? Have proper remediation tasks been completed for any deficiencies that have been identified? If you cannot answer “Yes” with 100% confidence to all these questions, it is time to take action, before your institution faces substantial negative impacts.

For assistance in reviewing and determining is your institution’s cybersecurity position, specifically as it relates to compliance with DOE standards, contact Jason Miller at 859-425-7626 or jmiller@ddaftech.com.

Dean Dorton Technology provides specialized cybersecurity services, specific to the unique requirements and challenges of higher education institutions. Our team of IT auditors has an elite background of audit experience combined with practical IT administration and will evaluate information system control environments, identify the risks, provide a basis for reliance on the system, and deliver cost-effective control recommendations for your organization.

Filed Under: Cybersecurity, Higher Education, Industries, Services, Technology Tagged With: college, Cybersecurity, DOE, Education, Higher Education, security, University

Article 02.2.2016 Dean Dorton

The U.S. and international economies are becoming more competitive every day. Many of us are competing for the same workforce; for others it may be the same customer, but we have to ensure that we continue to respond to the rapidly changing environment in which we operate. Ten years ago, did you ever worry about cybersecurity?

These are a few of the reasons – it is critical to analyze your business risks at least annually. We recommend formally documenting your key risks along with how you are responding to those risks. This can be a very helpful exercise when strategizing how you should be spending your most valuable resources (your people). Below are a few of the key risks that you may want to monitor in 2016.

5 Key Risks Companies Should Monitor in 2016
Plan now to address employment, inflation, currency, cybersecurity and vendor risks

By: Joe Brusuelas and Rob Kastenschmidt of RSM US LLP

The U.S. economy continues its slow but steady improvement. While growth slowed to 0.6 percent in the first quarter of 2015, it rebounded to 3.9 percent in the second quarter, and we expect growth for the year of about 2.2 percent. Unemployment dropped to 5.4 percent by the second quarter and was down to 5 percent by November. Consumer demand, especially for services and autos, is strong; the housing market continues to improve; and energy and commodity costs remain low.

But the international picture is less sunny. While we expect global growth of about 3 percent in 2015, with a slight uptick next year, a variety of issues are affecting international economies. Growth in China continues to slow as it seeks to rebalance its economy from an export-oriented model to a growth model driven by internal consumption. While the long-term outlook for China is positive, its current slowing growth and the related reduction in demand for resources is adversely affecting many emerging economies. The already uncertain economic picture in Europe is being further stressed by the massive influx of refugees from the Middle East. All of this means lower international demand for U.S. goods and services. It also is leading to a divergence in monetary policy between the U.S. and other economies. In the U.S., the Federal Reserve will likely increase the federal funds rate by 25 basis points in December 2015 followed by another 50 to 70 basis points by mid-2016, while central banks in Europe, Japan and possibly even China are pushing rates toward zero.

What does all this mean for U.S. companies? For 2016, this means you should monitor and be prepared to respond to three key economic risks: a tightening domestic labor market, inflation and the challenges presented by a strengthening dollar. In addition, cybersecurity risks continue to increase and diversify, requiring heightened attention, and the increasing reliance of many companies on third parties raises new risk management issues.

1. Plan for a tighter labor market

An unemployment rate of 5 percent doesn’t tell the whole story. The number of unemployed persons per job opening is down to 1.44 from a peak of almost 7 in 2010. Not only is the overall unemployment rate down, we are also finally seeing stronger growth in higher-wage jobs. Since January 2014, the U.S. has added 2.4 million high-wage jobs compared to 2.3 million lower-wage jobs. While this is helping boost consumer confidence and demand, it also means U.S. employers need to plan for a tighter labor market. The risks of a tighter labor market? Increased labor costs, higher attrition and stronger competition for top talent. To offset these risks, employers should consider the following strategies:

  • Explore automation strategies. Now may be the time to investigate whether the expense of improved automation might be offset by savings in labor costs.
  • Consider offshoring, outsourcing and contractor services. With the U.S. economy outperforming its global peers, offshoring certain functions may offer improved returns given continued low labor costs overseas. Outsourcing non-core functions or increasing reliance on contractors is another way to manage labor costs and can have the added benefit of reducing administrative demands and benefit expenses.
  • Re-evaluate compensation programs. Competition for top performers is heating up. Take a look at your compensation practices to ensure that you are effectively rewarding and motivating your best people. This will also make you more attractive to the candidates you wish to hire.
  • Improve your recruiting practices. LinkedIn and other social media platforms are far more important now than they were prior to the economic crisis, but can’t be relied upon as the sole way of identifying potential candidates. Are your talent identification and recruiting practices keeping up?

2. Manage inflation

  • Inflation is still near historic lows and deflation continues for energy and commodities. But energy and commodity costs are likely at or near their floors, and the Fed is almost certain to start raising rates soon. According to RSM’s Middle Market Leadership Council survey, 67 percent of executives expect increases in their costs over the next six months, compared to just 54 percent in the second quarter. What to do?
  • Focus on efficiency and cost-cutting programs. Decreased costs during the crisis and recession diverted attention from these efforts at many companies. Now is the time to increase discipline.
  • Explore hedging strategies.
  • Shift your purchasing patterns and explore supply chain changes. Global economic conditions are uneven. Weaker economic conditions in other markets may present purchasing opportunities.
  • Audit vendors and monitor margin compression at key customers. Now is the time to reevaluate your vendor relationships to ensure they are delivering real value. And keep an eye on how inflation is affecting margins with your key customers so you can make appropriate pricing and relationship management decisions.

3. Minimize the risks and maximize the benefits of a stronger dollar

  • The U.S. economy is outperforming its global peers. Higher U.S. Treasury rates are spurring an influx of foreign capital and strengthening the dollar. For middle-market companies, this is a double-edged sword. It makes U.S. exports more expensive and diminishes the value of foreign earnings denominated in U.S. dollars. But it also drives down the cost of off-shore sourcing options and can create international acquisition opportunities.
  • Look for global supply chain opportunities. Take advantage of the strong dollar by finding offshore sourcing options.
  • Consider global hedging options to control risks and costs.
  • Consider international expansion opportunities. If expanding through acquisition in new global markets is part of your corporate strategy, the strong dollar could mean a better deal.

4. Increase attention to cybersecurity

No organization can afford lax cybersecurity controls. Many companies think they aren’t large enough to attract the attention of cyber criminals, but the NetDiligence® 2015 Cyber Claims Study shows nano organizations and small organizations actually experienced the most incidents, with 29 percent coming from each of those groups. Your best defense? Make sure you have three layers of cybersecurity controls—preventative controls that make you a hard target, detective controls to timely identify any breach and corrective controls that let you respond quickly and appropriately to intrusions.

  • Preventative controls. Your preventative controls should include a vulnerability assessment, patch management, strong access and authentication controls, a solid intrusion prevention system (IPS), configuration management, and up-to-date anti-virus protection.
  • Detective controls. Most companies choose either to outsource detection controls to a Managed Security Service Provider (MSSP) or to purchase a Security Information and Event Management (SIEM) product. Weigh that choice carefully and be sure the solution you choose is appropriate to your threat environment and internal capabilities. A strong intrusion detection system is also vital, along with compliance and operational monitoring, and anti-virus and network alerts.
  • Corrective controls. Effective corrective controls start with a robust incident response plan. You will also want strong forensic capabilities; anti-virus quarantine and isolation protocols; disaster recovery and business continuity plans; and administrative, legal and insurance protections.

5. Control your third-party risks

Corporate boundaries are getting fuzzier as businesses of all kinds explore a wide range of third-party relationships that allow them to focus on their core business while leveraging outside expertise in areas like logistics, technology and a variety of other specialized functions. That creates efficiencies that drive growth, but it also gives rise to a wide range of new risk issues. Your ability to execute your strategy now hinges partly on the performance of third parties. You could face liabilities stemming from non-performance by your vendors. Connections between your systems and those of your vendors create new security risks. And the web of social media and other connections between you and your vendors can expose your organization to reputational risk due to the failings of third parties. Here are six third-party risk questions to consider in 2016:

  • Do you know where all your contracts are located? Are they stored electronically?
  • Do you understand and are you fulfilling all of your contractual responsibilities?
  • Have your contracts been updated to reflect new regulations for privacy and data security?
  • Are you adequately monitoring the IT risks associated with your third parties?
  • Is the insurance coverage maintained by your third parties sufficient to cover losses in the event of a data breach?
  • Are your audits of the contract performance and related invoices sufficient to ensure alignment with acceptable risk levels directed by your senior management and board of directors?

If you have any questions about the key risks above or how to perform your own formal risk assessment, please contact:
Lance Mann: lmann@deandorton.com or 502.566.1005
Jim Tencza: jtencza@deandorton.com or 502.5661071

View Lance Mann’s Bio

View Jim Tencza’s Bio

Filed Under: Accounting & Tax, Construction, Energy & Natural Resources, Equine, Forensic Accounting, Healthcare, Higher Education, Industries, Manufacturing & Distribution, Nonprofit & Government, Real Estate, Risk Management, Services, Tax, Technology, Wealth & Estate Planning Tagged With: 2016, Business, Companies, Company, Currency, Cybersecurity, Employ, Inflation, Jim Tencza, Lance Mann, Risk, RSM, Vendor

Article 01.8.2016 Dean Dorton

Risk factors impacting the mining industry during 2016:

  1. Production Management
  2. Pricing
  3. Customer Concentration
  4. Declining Capital Sources
  5. Regulatory Changes and
    Political Uncertainty
  1. Global Competition
  2. Cost Management
  3. Modernization
  4. Cybersecurity
  5. Social Awareness
  1. Production Management
    Maximizing the economic efficiency of production is a competitive advantage for mining companies that do it well. Production is impacted by financial, geological, and even social factors. Mining companies that effectively manage these factors and maximize production in areas that return the most value to their company will be more successful. Additionally, companies that invest in maximizing the efficiency of their production abilities will be most prepared to take advantage of market improvements in their industry.
  2. Pricing
    Contract prices continue to be extremely volatile. Mining companies may be forced to service unfavorable contracts in order keep cash flowing and to maintain relationships with customers. Moreover, companies may want to “keep a toe” in the water to monitor contract prices as they are negotiated for short and long term orders. The best way to understand the existing market is to be in some form of sales negotiations with the customers.
  3. Customer Concentration
    Many mining companies sell most of their products to a small number of customers, which creates a significant risk to the companies’ revenue streams. The coal mining sector ships coal primarily to power plants or industrial sites. Environmental regulations have made the economics of running a coal burning power plant very difficult. Economic fluctuations, both domestic and abroad, make industrial applications unstable. Limestone producers are impacted by governmental contracts and proximity to construction projects. Companies should offset this risk by seeking to diversify their customer base through geographic expansion or alternative uses for their products.
  4. Declining Capital Sources
    Certain segments of the mining industry have lost favor with public investors and, consequentially, many financial institutions. Finance arrangements are difficult to obtain, and when obtained may come with high fees and interest. Companies should consider alternative capital sources such as international institutions, brokers, and even customers. These alternative capital sources may offer a form of strategic alliance, such as in marketing existing products, or helping to develop additional assets.
  5. Regulatory Changes and Political Uncertainty
    Regulatory and political issues can be a significant obstacle in the mining industry. Environmental agencies can block or hamper access to strategic mining areas. Certain regulations threaten the way in which extracted minerals are used, thus decreasing demand. Changing tax laws, such as Tangible Asset Regulations, can have a significant impact on companies if not properly considered.
  6. Global Competition
    Mining has grown from a local market to a national and now global market. As domestic demand declines, U.S. companies are forced to look internationally for revenue opportunities. This requires an understanding of historical relationships, trade barriers, currency values, and international regulatory requirements. Mining companies must follow and understand international markets in order to compete at the global level.
  7. Cost Management
    Failing to budget and monitor costs properly is a significant risk. Successful companies monitor their costs in great detail. It is very important for the accounting department and the production teams to be in sync in order to maximize the value of financial data given to management in a timely fashion. Companies must also manage legacy costs such as reclamation and employee benefits, which may not impact current operations, but do impact current cash flow.
  8. Modernization
    In various sectors of the mining industry, external factors impacting performance are changing very rapidly. Additionally, the average age of a mine worker across most sectors has increased for several years in a row. This indicates that the industry is not hiring and retaining young workers. Technologies used today are often similar to those used a decade ago, and often by the same people. By the nature of their operations being capital intensive, mining companies are not very nimble organizations. Companies that can modernize operations to the specifications of their market through new technologies and innovative tactics will be positioned to recognize cost savings and improve their market position.
  9. Cybersecurity
    Operators need to be proactive in cybersecurity by implementing effective controls to prevent and detect cyber-crime. Potential effects of an operator network infiltration can include theft of customer payment information, employee identify theft, and shutdown of operations.
  10. Social Awareness
    Mining companies have a unique role in the local, state, and national community. Worker safety should always be top priority, and companies must consider the impact of their actions within each unique community. Illegal or unethical practices will damage a company’s reputation and may make national headlines, and legitimate closing of a project due to financial reasons may generate significant reputational damage as well. Mining companies should consider the impact that closing a project will have on that community and the local economy.

For more information, contact Bill Kohm at bkohm@deandorton.com or (859) 425-7625, or Justin Hubbard at jhubbard@deandorton.com or (859) 425-7604.


View Bill Kohm’s Bio

Filed Under: Accounting & Tax, Energy & Natural Resources, Industries, Risk Management, Services Tagged With: Capital, Cybersecurity, Global, Mining, Political, Risk, Social, Sources

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Go to Next Page »
  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved