Why I’d Hack Your Accountant Before I’d Hack You
- Lindsay Timcke

- Jun 24
- 2 min read
Here is something that should keep more people up at night.
CPA firms are the ones who perform SOC examinations on everyone else. They sign the attestation. They tell the market whether a service organization can be trusted with sensitive data. Private equity firms, in turn, demand SOC 2 reports from their portfolio companies and vendors as a condition of doing business. Yet as far as I can tell, neither industry holds a SOC report between them.
Sit with that for a second. The party issuing the trust attestation and the party demanding it are two of the largest unexamined repositories of sensitive financial and technical information in the economy. A CPA firm sits on tax returns, full financial statements, Social Security numbers, payroll data, and live M&A files. A PE firm holds deal data, limited partner PII, fund banking detail, and the operational crown jewels of every company in its portfolio. That is exactly the data profile that triggers a SOC 2 requirement anywhere else.
So think like the attacker for a moment, because I have spent my career doing exactly that. I would never burn a campaign on a single company when one firm holds a thousand of them. The legal exposure is identical either way. It’s a felony either way, go for the bigger pay day. Breaking into one CPA or PE firm is the same felony as breaking into any one of its clients, except one nets a single victim and the other hands me a thousand.
These firms hold the keys to the kingdom, the risk to reward is not even close, and every competent adversary runs that exact math. Now, both industries will tell you they are already overseen, and they are not wrong. CPA firms face AICPA peer review and PCAOB inspection (CPA’s overseeing CPA’s - no different than any other group monitoring itself, never works).
PE firms register as investment advisers and answer to SEC examination (SEC who is vastly overworked and understaffed). But none of that oversight is about their own information security controls.
Peer review checks audit quality. SEC exams check disclosure and conflicts. Neither asks the question a SOC 2 asks, which is whether the firm can actually protect the data it holds. That is the gap, and it is widening, because private equity is now rolling up CPA firms at speed, concentrating even more sensitive financial data under acquirers that carry no independent control attestation of their own. We are stacking unexamined data on top of unexamined data and calling it a growth strategy.
If you require a SOC 2 from your vendors, you should be able to produce one yourself (Accounting firms & PE). Attestation should run both ways, and trust without verification is just branding. So ask the uncomfortable question. Things are getting worse and we need to be demanding more.
Reach out to discuss.
