California and Colorado SaaS Sales Tax Changes: What Software Companies Need to Know
California and Colorado will begin taxing many SaaS transactions on January 1, 2027. Software companies should start evaluating the sales tax implications now.
October marks Cybersecurity Awareness Month, a time to reflect on the safeguards that protect our organizations, communities, and critical systems. While cyber threats exist year-round, this month serves as a reminder to take concrete steps to reduce vulnerabilities and strengthen...
October marks Cybersecurity Awareness Month, a time to reflect on the safeguards that protect our organizations, communities, and critical systems. While cyber threats exist year-round, this month serves as a reminder to take concrete steps to reduce vulnerabilities and strengthen resilience. Every business, nonprofit, and mission-driven organization relies on systems and processes that must operate securely and efficiently. Even simple measures, when consistently applied, can make a meaningful difference in protecting data, maintaining compliance, and supporting reliable operations.
AAFCPAs advises that leadership teams assess their current cybersecurity posture, review internal controls, and ensure that technology, policies, and procedures are aligned with their strategic goals.
For organizations handling sensitive data or operating under regulatory obligations, integrating these safeguards into day-to-day operations supports both compliance and operational confidence. Clear responsibilities, regular training, and documented processes help organizations act quickly if a breach or vulnerability arises, reducing potential disruption and strengthening resilience. AAFCPAs also encourages organizations to establish incident response plans and perform vendor and supply chain assessments to reinforce these protections.
Evaluating the likelihood and potential consequences of different cyber threats allows organizations to prioritize efforts, allocate resources effectively, and make informed decisions. Organizations should also be mindful of emerging risks from technologies like artificial intelligence (AI), including deepfakes that could mimic executive voices, AI-generated phishing campaigns, automated attempts to exploit system vulnerabilities, and sophisticated data manipulation—all of which can amplify cyber threats if not properly governed and monitored.
Small steps can create lasting effects. Regularly updating software, using strong passwords with a password manager, turning on multifactor authentication, and recognizing phishing attempts are actions that each team member can take to contribute to overall cybersecurity. Combined with robust policies, controls, and enterprise risk management, these practices help organizations maintain trust with clients, regulators, and partners.
Organizations that embed security awareness into daily operations are better positioned to withstand threats and maintain operational continuity. Strong systems, clear procedures, and informed teams create a foundation that supports resilience and growth. Taking action now, even in small increments, can make a meaningful difference in reducing risk and ensuring that your organization operates securely, efficiently, and with confidence throughout the year.
AAFCPAs’ Risk Advisory practice guides clients on cybersecurity and enterprise risk management solutions tailored to their operations. We help leadership teams assess vulnerabilities, strengthen internal controls, and align safeguards with strategic objectives. Our approach spans IT risk, enterprise risk management, internal controls, and compliance, combining technology, processes, and policies to reduce exposure and maintain operational resilience. We work with organizations to embed risk awareness into daily decision-making, protect sensitive data, and ensure secure systems, all while supporting confidence with clients, regulators, and stakeholders. By providing practical, right-sized strategies, AAFCPAs helps organizations balance security, compliance, and efficiency as they navigate complex operational and regulatory environments.
These insights were contributed by Vassilis Kontoglis, Partner, AI Digital Transformation & Security.
Questions? Reach out to our authors directly or your AAFCPAs partner.
AAFCPAs offers a wealth of resources on cybersecurity and IT risk solutions. Subscribe to get alerts and insights in your inbox.
California and Colorado will begin taxing many SaaS transactions on January 1, 2027. Software companies should start evaluating the sales tax implications now.
The systems and processes that helped your organization reach one stage of success are not always the ones that support the next.
Beginning in 2026, eligible Massachusetts pass-through entities can elect the new Chapter 63E PTE excise. Business owners subject to the state's surtax should understand how...