Goldman Sachs signage on the New York Stock Exchange trading floor

In brief

• Goldman says its own systems were not affected, and client assets were not impacted.

• The exposure came through EY and involved Goldman data, with the wealth management division reportedly affected.

• The useful CPA lesson is third-party risk: client data is only as protected as every vendor and service provider that touches it.

This is the part of cybersecurity that makes every client service business uncomfortable. You can have strong internal systems and still end up in the blast radius because a trusted provider had the data.

Goldman Sachs data was exposed earlier this year in a hack involving EY. The bank said its own systems were not affected. It also said client assets were not impacted and remain safe.

That is the good version of a bad situation. No bank-system breach. No client asset issue. But the story still matters because the affected business was wealth management, where trust is the whole product.

The Breach Was Not Inside Goldman

Goldman's statement draws a clean line around the incident. The bank's systems were not affected. The exposure came through EY, one of the outside professional-service firms that handles sensitive client and business data.

That distinction matters legally and technically. But clients usually hear it differently. If their information moves through a firm, vendor, payroll provider, auditor, consultant, or tax partner, they still expect the company they trust to know where the data went and what happened to it.

Vendor Risk Is Client Risk

For CPA firms, this is the useful lesson. The risk map does not stop at the firm's firewall. It includes document portals, outsourced IT, payroll systems, audit tools, tax software, offshore support, data rooms, and every other place client information gets touched.

A firm can do the right thing internally and still be forced into a client conversation because a third party failed. That is why vendor diligence cannot be a once-a-year checkbox buried in admin work.

The Communication Clock Starts Fast

Goldman said it has been in regular contact with EY and is working with the firm to support any impacted clients. That is the right shape of the response: find the affected group, coordinate with the provider, and keep clients from learning the details through rumor.

CPA firms need the same muscle. If a vendor has an incident, someone should already know who owns the client list, who calls the vendor, who reviews contract language, who drafts client updates, and who decides whether regulators or insurers need to be involved.

The Real Test Is The Data Map

Most breach plans sound fine until someone asks a simple question: which clients had data in that system? If the answer takes three days, the firm does not really have a plan. It has a document.

That is where smaller firms can learn from a large-bank story. The size of the client does not change the basic problem. Once sensitive information leaves the building, the firm needs a current list of where it went, who touched it, and what notice rights exist if something breaks.

What CPAs Should Watch

The practical move is boring, which usually means it is important. Firms should keep a current map of where client data lives, rank vendors by sensitivity, and require breach-notice language that gives the firm enough time and detail to protect clients.

The Goldman and EY situation is not a reason for firms to panic. It is a reason to assume the next security issue may arrive through a partner instead of the front door.

Keep Reading


View More >