• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

security

Article 04.4.2018 Dean Dorton

“No one would be interested in my data.” Nothing could be further from the truth! Announced in late March, the Department of Justice filed criminal charges and sanctions against nine Iranian hackers accused of compromising hundreds of universities, private companies, and government agencies.

It is estimated that some 320 universities, in the U.S. and abroad, have been compromised. Government agencies are also believed to have been breached. Also targeted were private sector law firms and consulting companies. The accused were focused on acquiring and selling science and engineering research information.

This incident brings further focus and attention on the growing threats and required attention for cybersecurity at all organizations. We find that there is no private, public, or nonprofit entity immune to the ever-growing and more sophisticated threats posed by cybercriminals. The amount of electronic information and communications used today only continues to grow. Our business and organizations rely on data and systems to function in nearly all aspects.

If your organization is not yet taking cybersecurity seriously, now is the time. More areas of compliance require organizations to formalize their attention on cyber risk. Financial institutions and higher education organizations have Gramm Leach Bliley Act (GLBA), healthcare has HIPAA, and companies with clients or constituents in the European Union will soon have GDPR, just to name a few.

Here are a few key areas that you should focus on:

  • Annual cyber risk assessment
  • User awareness training
  • Processes for monitoring and detecting incidents
  • Formal incident response plan
  • Adequate cyber insurance

If your organization needs help with any of these areas, Dean Dorton has a team of qualified consultants ready to help. Contact Jason Miller, Director of Business & Technology Consulting, at 859.425.7626 or jmiller@ddaftech.com. Don’t wait until it is too late.

Filed Under: Cybersecurity, Services, Technology Tagged With: Cyber, Cybersecurity, Data, Insurance, jason, miller, security

Article 03.29.2018 Dean Dorton

For years now, one of the reasons that organizations have not moved toward cloud computing systems has been due to concerns about security. However, as more and more organizations are adopting cloud-based or cloud-hybrid systems, cloud providers have progressively hardened and formalized security measures.

Today, the cloud is proving itself to be a safer environment for your critical data than on-premise, legacy systems. Here are 5 reasons why:

1) Physical security:

In many organizations, a locked door is all that separates your network from intrusion. Cloud security providers, on the other hand, typically use guards, security cameras, physical barriers, and other real-world measures to protect your data. This level of physical protection keeps unauthorized employees, vendors, and guests from accessing unauthorized systems, at least in the real world.

2) Disaster recovery:

Organizations need a concrete plan for disaster recovery that can be implemented at a moment’s notice. An organization also needs to account for the security of backups in the form of protection from fire, earthquakes, or other natural hazards. Knowing that even if there were a fire in your offices, your data would remain safe and accessible provides extra security and peace of mind. Cloud storage providers use redundant systems so you always have a backup and have access to active disaster recovery plans in place and ready to go if you need them.

3) Security expertise:

For most businesses, the IT department has many areas of expertise and a broad array of responsibilities. This means that emerging security threats, new tools, and changing practices may not always be top-of-mind. Hiring an on-staff cybersecurity expert devoted to the task can be difficult and expensive.  However, a cloud provider responsible for your data security has cybersecurity experts, who are tasked with nothing but protecting your data and staying on top of the latest threats. In addition, cloud-based cybersecurity providers are increasingly leveraging artificial intelligence and machine learning for constant vigilance and immediate response to threats and intrusions.

4) Always current and compliant:

Updating your local hardware and software to always be compliant with the latest security measures can be difficult, time-consuming, and expensive. Additionally, it isn’t always easy to encourage staff to comply with the latest standards and adopt best security practices. Cloud storage providers regularly update all their systems to protect against the latest threats and conform to the highest security standards, reducing the burden on your own IT department. It’s easier to deploy updates or improve standards across your entire data system, providing greater protection and improving compliance.

5) Security auditing:

Cloud storage providers conduct thorough yearly security audits to ensure their systems are safe and current. Many organizations don’t have the resources to devote to these kinds of systematic audits, so they don’t get comprehensive reports of the state of their security and therefore struggle to identify and correct vulnerabilities.

Ultimately, data security is a shared responsibility, between an organization and their cloud solution provider, and between leadership and employees within an organization. Adopting a comprehensive, collaborative approach allows a business to leverage the security expertise and specialization of a cloud provider, and use a portion of the cost and time savings to apply stronger internal procedural security measures.

It’s possible to get the reliability and accessibility of cloud storage, along with the security and control you need for your critical information.

7 reasons to move to cloud financials now

Filed Under: Accounting Software, Cybersecurity, Sage Intacct, Services, Technology Tagged With: Cloud Accounting, legacy vs. cloud, Sage Intacct, security

Article 02.27.2018 Dean Dorton

For service-based companies, fast answers, reliability, and market strategy are critical to business growth and stability. Reliability offers strong service to the clients you already have, fast answers motivate today’s potential clients, and market strategy invigorates new business for a bright future.

A strong MSP business inspired to grow can find support in these key areas by working in the cloud.

The Cloud Leverages Up-to-Date Information

On-premises systems may very well offer the data your teams need, but that data is useless if your teams in the field can’t access it.

When companies work from the cloud, field teams can leverage company data to deliver service or seal a deal faster than a team that can provide the information “when they get back to the office.”  

The Cloud Maximizes Independence and Productivity

When your people have real-time data and detailed information about client projects, and company services, they are free to work more quickly.

With the cloud, accounting departments streamline month-end closings and reporting because their financial data is always being updated in their systems, which means faster, more accurate output.  

Also, field teams work more independently because company information travels right with them, wherever they go. Deals close faster. Important project information populates in the system in real time so everyone on the project has access to critical data more quickly.

Cloud technology streamlines the business from every angle, saving MSPs hours of time and effort.

The Cloud Optimizes Your Dependability

The most dependable systems are the ones that no one has to worry about.

Reliability and data security are critical- especially when it comes to your client’s information. When MSPs secure their data with the right cloud-based financial management system like Sage Intacct, security is already taken care of, and so are software and maintenance updates – all behind the scenes.

MSP companies that work in the cloud boost their service dependability and can rest knowing client data is safe and secure.

For MSPs, Sage Intacct, a best-in-class cloud-based financial management solution, offers:

  • 24/7 up-to-date dashboard reporting that your teams can access from anywhere to strengthen market strategies, and work in the field more productively.
  • An award-winning API that integrates with other best-in-class cloud solutions for flawless client data transfer, accurate operational data, and enhanced project management.
  • Real-time, automated financial management features that streamline book closings, eliminate spreadsheets, speed reporting and invoicing, and simplify time and expense entry.

Sage Intacct cloud-based financial management means faster, leaner, more accurate processes to support your service-based business as it grows.

“Sage Intacct has given us the ability to focus on our technology, making it work for us,” says Tom Major, CFO of Clearpointe and Sage Intacct customer. “The financial reporting and dashboards have been transformative for our business.

Whether your company has one location or many, because the cloud offers financial management flexibility, it’s the ideal environment for companies that anticipate growth.

Contact us. We want to help you find the right financial management solution that will empower your teams as your business grows.  

Want to Know More?

Read Clearpointe’s full case study to learn the benefits that a cloud-solution brought to their business.

Get the Case Study

Filed Under: Accounting Software, Sage Intacct, Services Tagged With: accounting solutions, Cloud Accounting, MSPs, productivity, real-time, Sage Intacct, security

Article 01.9.2018 Dean Dorton

Recent news reports have highlighted computer security vulnerabilities being referred to as Meltdown and Spectre. Computer researchers have found out that the main chip in most modern computers—the CPU—has a hardware bug. It’s really a design flaw in the hardware that has been there for years. This is a big deal because it affects almost every computer in existence including workstations, servers, and some mobile devices.

This hardware bug allows malicious programs to steal data that is being processed in your computer memory. Normally, applications are not able to do that because they are isolated from each other and the operating system. This hardware bug breaks that isolation.

So, if the bad guys are able to get malicious software running on your computer, they can get access to your passwords stored in a password manager or browser, your emails, instant messages and even business-critical documents.

As with most computer vulnerabilities, the best way to stay protected is to keep up to date on security patches for your devices and applications. Because of the pervasiveness of this hardware bug, vendors are still doing research, so some patches are not even available yet. So be extra vigilant with security top of mind and think before you click. In many cases, bad guys get access by tricking you into clicking on a bogus link or document.

Learn more: Meltdownattack.com

If you are interested in learning about user security awareness training and how Dean Dorton can help you, please contact our technology team.

Filed Under: Cybersecurity, Services, Technology Tagged With: bug, computer, cpu, hardware, malicious, meltdown, security, Software, spectre

Article 11.29.2017 Dean Dorton

Join us on December 14th from 2-2:30 pm ET for our monthly CloudBytes!

Bulletproof data security is critical to company survival, and your clients’ peace of mind. With so much information is at our fingertips, it seems everyone’s data these days runs the risk of being compromised at any time. The responsibility is in the hands of every company out there to put as much attention on tight security as they do in their products.

Sage Intacct strives to defend your security at every level – from where your data is housed, right down to user permissions and restrictions. Sage Intacct takes security past the obvious to protect sensitive information in the software by offering options in company security, console security, module security, and data shielding.

In this month’s Cloud Bytes session, step-by-step we show you how to shield your data using permissions, approvals, and data recording and reporting options. In this session, you’ll learn:

  • How to assign user-based and admin permissions to ensure only the right people have access to sensitive data.
  • How to ensure only authorized people can make changes to their company, client and product information with best practices for regularly scheduled user permission reviews.
  • What types of data can be tracked in audit logs and trails, and how to detect high-level system modifications.
  • How to create added security at the transaction level with customized approvals and permissions, to prevent errors and unauthorized activity.
  • Techniques to build, customized and modify transaction documents to limit user actions, and boost security in all your company transactions.
  • Unique ways to protect sensitive projects, and shield critical project data by creating highly- customized reports so only authorized users can see the data they need.

During the session, we will be taking your questions, so be sure to write down your thoughts beforehand and bring them with you to the webinar. Any questions we don’t have time to address will be covered in a follow-up email for attendees.

Today, when so many threats can compromise information, there is no such thing as too careful when it comes to your company and your clients. Join us for our free Cloud Bytes session happening on December 21, at 2 PM ET to get the most protection you can from Sage Intacct’s best-in-class financial management solutions.

Keep your data safe and sound!

Register Now

Filed Under: Accounting Software, Sage Intacct, Services Tagged With: cloudbytes, Sage Intacct, security

Article 01.19.2017 Dean Dorton

The United States Department of Education (DOE) has sent friendly notices for two years in a row reminding colleges and universities of their requirement to comply with the strict guidelines for protecting student financial aid information. Cybersecurity should be near the top of every organization’s priority list, but for higher education institutions it should be elevated even further. Given that the DOE has provided two warnings to date, we should assume they plan to take a stricter stance on cybersecurity infrastructure, protection, and controls during compliance audits.

Cybersecurity: A Critical Boardroom Topic

Many organizations quickly punt the topic of cybersecurity to the IT department. While IT plays a huge role in cybersecurity, it is the responsibility of those charged with organization governance to ensure compliance is met. Board members and senior leadership should be asking the questions and confirming that the institution is devoting the proper resources and attention to cybersecurity.

  • It is also critical to understand that cybersecurity is not a one-time project. It is a continual evolution and initiative.
  • Leadership needs to also recognize there can be substantial costs associated with cybersecurity activities and they are not optional. The DOE letter makes this point very clear when they state “The Department understands the investment and effort required by institutions to meet and maintain the security standards established in NIST SP 800-171. Nonetheless, across the public and private sectors, it is imperative that organizations continue to enhance cybersecurity in order to meet evolving threats to controlled unclassified information and challenges to the security of such organizations.”

With the ongoing focus on higher education institution’s bottom lines, it might be tempting to defer projects related to cybersecurity to reduce budgets. However, doing so could put your institution in a position where the DOE finds your organization in noncompliance with your Program Participation Agreement (PPA) with Title IV student financial aid. Cutting corners on cybersecurity compliance could wind up costing your institution more in the long run.

The Time to Act is Now

At this point, most organizations have some form of information security or cybersecurity policies in place, but do yours include the very specific requirements outlined in the Gramm-Leach-Bliley Act (15 U.S. Code 6801) and NIST SP 800-171? When was the last time your institution performed and a thorough IT risk assessment (one that meets the NIST SP 800-171 standards)? Have proper remediation tasks been completed for any deficiencies that have been identified? If you cannot answer “Yes” with 100% confidence to all these questions, it is time to take action, before your institution faces substantial negative impacts.

For assistance in reviewing and determining is your institution’s cybersecurity position, specifically as it relates to compliance with DOE standards, contact Jason Miller at 859-425-7626 or jmiller@ddaftech.com.

Dean Dorton Technology provides specialized cybersecurity services, specific to the unique requirements and challenges of higher education institutions. Our team of IT auditors has an elite background of audit experience combined with practical IT administration and will evaluate information system control environments, identify the risks, provide a basis for reliance on the system, and deliver cost-effective control recommendations for your organization.

Filed Under: Cybersecurity, Higher Education, Industries, Services, Technology Tagged With: college, Cybersecurity, DOE, Education, Higher Education, security, University

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Go to Next Page »
  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved