At GBA LLP, we know that protecting client data is not just a good idea—it is a necessity. We recently sat down with Ross Saunders, founder of gotaminute? IT Services, to talk about privacy legislation, cybersecurity requirements, and how small and mid-sized businesses can build practical, risk-aware systems without overwhelming complexity.
Ross: You are right—IT used to focus on just keeping the lights on: fixing computers, managing emails, helping with setup. Over time however, the field has matured. Now, privacy, security, and governance are no longer optional—they are essential, and each has become its own area of expertise. For example, privacy is often seen as a legal function rather than a technical one, but the reality is, they are interconnected. A good IT partner now needs to look at both your infrastructure and your compliance posture.
Ross: As early as possible! A lot of people think this kind of work only matters once you’re scaling or handling large volumes of client data, but starting small and early makes everything easier in the long run. Think of it like building healthy habits—you don’t need enterprise-level tools on day one, but you should start laying the groundwork.
Take something as simple as passwords. You can improve your security immediately by switching from short, complex passwords to longer, memorable passphrases. Something like Phone-Chair-Coffee-Camera5 is both strong and easier to remember than a jumble of symbols. I always tell people to skip tricks like replacing “e” with “3”—hackers already account for that.
To find out what makes a good password, click here for more.
Next step? Multi-factor authentication. This adds a second layer to prove that you are the one signing in—like a code from an authenticator app or even a physical security key (called a FIDO key). Even if someone gets your password, they won’t get in without that second factor. If you’re still relying on SMS for MFA, I’d recommend switching to an authenticator app for stronger protection. To find out which MFAs to use, click here.
Starting with small, meaningful steps like these helps you gradually strengthen your security over time. For example:
It is about building good habits early so you are not scrambling later.
Ross: The risks are significant. Yes, there are the obvious ones: hacking, phishing attacks, ransomware, and data breaches. But, For B2B (business-to-business) companies, especially in regulated fields like finance, law, or healthcare, there is another level of risk.
If a potential client does a security assessment and you cannot answer, “What do you have in place for cybersecurity?”—you might lose that potential client.
In B2C (business-to-consumer) industries, it is about trust. How are you collecting data? Where is it stored? Do you have permission to hold it? No business wants to end up in the headlines for the wrong reasons.
Ross: We saw a big gap between what big corporations could afford—dedicated privacy teams, legal counsel, consultants—and what smaller businesses had access to. That is why we built gotaminute?.
We look at both your IT systems and your business processes to understand your risks, compliance needs, and where improvements can be made. Then we help you implement changes in a way that makes sense for your size and budget.
Our job is to make sure you are not only protected but also able to demonstrate that protection, especially when it comes to due diligence or compliance reviews. We back your controls with the technical documentation you need to prove how you are protecting your business and your clients’ data.
Ross: Absolutely. Regulations are increasing, but even without a legal requirement, it makes great business sense. It protects your reputation, reduces your risk, and builds trust with clients and partners.
Having a roadmap—even a basic one—shows that you are taking things seriously. Most regulators or partners do not expect perfection right away, but they do expect progress and awareness. That is where we come in: helping businesses build that roadmap and make it real.
Ross: We start with an assessment of simple, practical areas—password habits, multi-factor authentication, antivirus tools, and how you work with your cloud services. Even Microsoft 365 or Google Workspace have built-in security features that most businesses are not using to their full potential.
It does not have to be expensive or complicated. It just needs to be intentional.
Ross: One of the most exciting developments is Passkeys—a secure, modern alternative to traditional passwords. Instead of memorizing login details, Passkeys use a pair of digital keys—one stored on your trusted device (like your phone or password manager), and one stored with the service provider (like Google or Apple). Only your device can match the two halves to sign you in.
Because each Passkey is unique to the service, even if a provider is hacked, your personal key stays safe—it never leaves your device. I recommend enabling Passkeys wherever possible and using tools like 1Password to manage them. It is faster, easier, and far more secure than traditional passwords. For more on passkeys, click here.
Cybersecurity and privacy are not just for big corporations. As Ross shared, they are foundational for any business that handles sensitive data or works with clients who expect trust and professionalism. We appreciate Ross’ practical, thoughtful approach and his passion for helping businesses build smarter, safer systems from day one.
To learn more about gotaminute? IT Services, visit gotaminute.it
Schedule a call today with one of our team members to discuss your accounting or tax needs – For More Details, Click Here.
This blog is not meant to provide specific advice or opinions regarding the topic(s) discussed above. Should you have a question about your specific situation, please discuss it with your GBA advisor.
GBA LLP is a full-service accounting firm in the Greater Toronto Area, but we primarily service all of Ontario as well as the rest of Canada virtually, except Quebec. Our team of over 30 provides audits and reviews of financial statements, compilations of financial information, and corporate tax returns. We provide specialized corporate tax and succession planning for small and medium businesses, in addition to general advisory services.
If you would like to schedule a call to discuss your accounting or tax needs with one of our team members, please complete the free, no-obligation meeting request on this page.







