- Sensitive client and patient information everywhere.
- Remote access multiplying.
- Cloud applications changing constantly.
- Regulators expecting documented safeguards.
- Insurance carriers asking harder questions.
- Leadership still hearing, “I think we’re covered.”
That last sentence is the problem.
For law firms, medical practices, accounting firms, financial advisors, and other professional organizations, cybersecurity cannot be based on assumptions. You need to know what systems you operate, what information they contain, who can access it, and whether your safeguards actually reduce risk.
That is the purpose of an IT assessment.
Not a sales pitch. Not a checkbox exercise. Not a report that disappears into a shared folder.
A properly conducted IT audit gives you a defensible, prioritized view of your technology environment before a regulator, client, insurer, or cybercriminal exposes the gaps for you.
Important: FTC Safeguards Rule coverage is fact-specific. Tax preparation firms, certain financial advisors, and other businesses engaged in financial activities may be covered financial institutions. Law firms and medical practices may have additional obligations depending on the services they provide and the information they handle. Consult qualified legal counsel regarding your specific obligations.
Why an IT Assessment Matters Now
Fast-moving. Distributed. Difficult to see.
Your business may use Microsoft 365, cloud document storage, practice-management software, accounting platforms, electronic health record systems, client portals, mobile devices, remote-access tools, and third-party vendors. Each one creates another place where information can be accessed, transmitted, stored, or misconfigured.
A firewall does not tell you whether a former employee still has access to client files. Antivirus does not tell you whether your backup can actually restore your case-management database. MFA does not tell you whether sensitive information is being shared through an unapproved application.
An IT assessment connects those pieces.
The FTC’s Safeguards Rule guidance states that covered financial institutions must develop, implement, and maintain a written information security program. That program must be based on a risk assessment identifying foreseeable internal and external threats to customer information.
In practical terms, regulators do not only want to know whether you purchased security tools. They want to know whether you understand your risks and made reasonable, documented decisions to address them.
An IT Assessment Is More Than a Vulnerability Scan
A vulnerability scan is useful. It can identify exposed systems, outdated software, and known technical weaknesses.
But an IT assessment asks broader business questions:
- What sensitive information does your firm possess?
- Where is that information stored?
- Who can access it?
- Which vendors can access it?
- What happens when an employee leaves?
- How are devices protected outside the office?
- Can you recover from ransomware?
- Are your security controls documented?
- Who is responsible for managing the program?
- What evidence can you produce if someone asks?
Think of it like medical care.
A blood-pressure reading is valuable, but it is not a complete physical. A real assessment considers your history, current condition, risk factors, and treatment plan. Technology requires the same discipline.
A scan may identify a symptom. An IT assessment helps determine the cause, severity, business impact, and appropriate treatment.

What a Comprehensive IT Audit Should Examine
A useful assessment should produce more than a list of technical jargon. It should translate technology risk into business decisions.
At a minimum, your assessment should examine these six areas:
1. Data and Systems Inventory
You cannot protect what you cannot identify.
Your provider should document:
- Workstations, laptops, servers, and mobile devices
- Microsoft 365 and other cloud platforms
- Practice-management, accounting, tax, and clinical applications
- Email and file-sharing systems
- Backup and disaster recovery systems
- Network equipment and remote-access tools
- Paper records and physical storage locations
- Third-party applications and service providers
For a law firm, that may include matter files, discovery data, trust-account information, and confidential communications.
For a medical practice, it may include protected health information, insurance details, patient payment data, and clinical records.
For an accounting firm or financial advisor, it may include tax returns, Social Security numbers, bank information, investment records, and other nonpublic personal information.
2. Identity and Access Controls
Who can access what?
That question should have a precise answer.
An assessment should review MFA coverage, administrator accounts, shared credentials, inactive accounts, guest access, password policies, conditional access, and permissions on shared drives and cloud applications.
MFA is essential, but implementation quality matters. Is it required for every user? Does it protect remote access? Are legacy protocols creating a bypass? Are privileged accounts separately secured?
A user should have the access necessary to perform their role, and no more.
3. Endpoint Security
Every laptop is a potential entry point.
Your assessment should review endpoint protection, patching, disk encryption, device management, local administrator rights, screen-lock policies, USB controls, and whether remote devices meet the same standards as office computers.
This is especially important for firms with hybrid employees, traveling professionals, home offices, and mobile clinicians.
Strong endpoint security is not just about blocking malware. It helps create consistent, measurable protection across the entire device estate.
4. Backup and Ransomware Protection
“ We have backups” is not the same as “we can recover.”
A meaningful review should determine:
- What systems are backed up
- How frequently backups run
- Whether backups are protected from deletion or encryption
- Whether copies are isolated from the production environment
- How long restoration takes
- Whether recovery has been tested
- Which applications and files have recovery priorities
For a law firm, losing access to active matters can affect deadlines and client obligations. For a medical practice, downtime can disrupt patient care. For an accounting firm, an incident during tax season can create severe operational and reputational consequences.
Your ransomware protection strategy should be measured by recovery confidence, not by the existence of a backup icon.

5. Policies, Training, and Incident Response
Technology controls cannot compensate for an organization that does not know how to respond.
Your assessment should review security awareness training, acceptable-use policies, incident reporting procedures, access approval processes, device disposal, data retention, and written incident response plans.
The FTC Safeguards Rule specifically addresses workforce training, service-provider oversight, monitoring, and incident response for covered organizations. Medical practices must also consider their HIPAA Security Rule obligations, including a documented security risk analysis.
Ask a simple question:
If someone discovers suspicious activity at 4:45 p.m. on a Friday, who do they call, and what happens next?
If the answer is “Hey Margaret usually knows what to do,” you have a process gap.
6. Evidence and Accountability
Security that cannot be demonstrated is difficult to defend.
An assessment should identify the evidence you need to maintain, such as:
- MFA and access-control reports
- Device and software inventories
- Backup test results
- Vulnerability and remediation records
- Security training records
- Incident response documentation
- Vendor agreements and security reviews
- Annual leadership or board reporting
Documentation is not bureaucracy for its own sake. It creates accountability, supports audits, strengthens client confidence, and helps your team make decisions based on facts.
The “I Got a Guy” Problem
“I got a guy.”
He is helpful. He fixes printers. He sets up laptops. He knows where the network equipment is located.
That may be valuable support. It is not necessarily a security program.
The difference is specialization and accountability. A modern managed services provider should be able to connect helpdesk support, endpoint security, identity management, compliance documentation, monitoring, backup, and strategic planning.
Consider the pros and cons of handling an assessment internally:
Potential advantages
- Your staff already understands business operations.
- Internal review may be less disruptive.
- You may avoid an immediate consulting expense.
Potential disadvantages
- Employees may lack specialized security expertise.
- Staff may overlook problems they helped create.
- Assessment work competes with daily responsibilities.
- Findings may not be prioritized objectively.
- Documentation may become outdated after the review.
An external provider can bring economies of scale, specialized tools, and experience across regulated environments. The tradeoff is that you must select a partner carefully and ensure the assessment is independent, thorough, and understandable to leadership.
The goal is not to replace your judgment. It is to give you better information.
Turning Findings Into a Business Roadmap
A report full of red, yellow, and green icons is not a strategy.
Your assessment should prioritize each finding based on:
- Business impact : What happens if this weakness is exploited?
- Likelihood : How realistic is the threat?
- Regulatory relevance : Could the gap affect FTC Safeguards compliance, HIPAA compliance, confidentiality obligations, or contractual requirements?
- Effort and cost : What resources are needed to address it?
- Dependencies : What must happen first?
- Accountability : Who owns the remediation?
- Timeline : What should be fixed immediately, within 30 days, or over the next quarter?
For example, enabling MFA for privileged users may be an immediate priority. Replacing unsupported laptops may require budgeting. Redesigning access permissions may require coordination with department leaders.
This is where a managed IT relationship becomes strategically valuable. The assessment becomes a living roadmap: not a one-time snapshot.

How Often Should You Conduct an IT Assessment?
At least annually for organizations with significant security, privacy, or compliance obligations.
You should also reassess after major changes, including:
- A merger or acquisition
- A new office or remote-work expansion
- A major cloud migration
- New practice-management or clinical software
- A significant vendor change
- A security incident
- A major change in staffing
- New regulatory or contractual requirements
The FTC’s guidance emphasizes that risks change as operations, technology, and threats change. Your assessment should change with them.
Final Word: Audit Your Technology on Your Terms
You do not need to wait for a regulator’s request, an insurance questionnaire, a client security review, or a ransomware incident to discover how your systems actually work.
For law firms, medical practices, accounting firms, and financial professionals, an IT assessment provides clarity where assumptions create risk. It shows you what is protected, what is exposed, and what should happen next.
A PC of Mind helps regulated organizations assess, secure, monitor, and improve their technology environments through managed IT services and cybersecurity services.
The path forward is straightforward:
- Inventory your data and systems.
- Identify your most important risks.
- Document your decisions.
- Prioritize remediation.
- Review the environment regularly.
Audit your technology before someone else does.
Schedule an IT and cybersecurity assessment with A PC of Mind.