
How an agtech IoT pioneer offloaded workload overload, accelerated month-end close times, and brought multi-layered review to its financial operations.

The Challenge
"I'm managing day-to-day finance tasks, including processing orders from customers, making sure that the right devices are fulfilled... I'm also staying on top of compliance, tax issues, sales tax... and providing ad hoc analysis for different departments."
— Brian Johansing, Controller
The Partnership
After hiring Scrubbed in early 2023, Arable Labs implemented a "triage-style" team approach featuring specialists in revenue recognition and lease accounting. Within just a few months, Scrubbed became deeply familiar with Arable's business, taking over the order-to-cash process, tax compliance, financial modeling, and month-end close routines.

"When I'm busy working on new projects, my attention gets drawn away from the day-to-day accounting. I have a call with Scrubbed every week to check in on how the month-end close is going and any new issues coming up. Over the last year, I've seen the quality of our financial reporting improve, and the number of days the month-end close takes has gotten smaller and smaller."
Brian Johansing
Controller, Arable Labs Inc.
The Results

Scrubbed introduced new efficiencies to the accounting workflow, significantly cutting down the number of days required to complete the monthly financial close.

By adding multi-layered review and specialized expertise in revenue recognition and lease accounting, Scrubbed elevated the overall quality of Arable’s financial reporting.

Offloading order-to-cash management and routine tasks freed Brian Johansing from tedious manual processes, giving him peace of mind and time for strategic planning.

Scrubbed acts as a true extension of the team—taking full ownership of accounting assignments and bringing solutions to weekly check-in calls.
Why Scrubbed
For Brian Johansing and the Arable Labs team, Scrubbed stood out for its proactive ownership, deep technical knowledge, and seamless team integration:

"They are always aiming for accuracy, and they make sure that I'm giving them the information they need to do their jobs... they just take ownership of the accounting."

Scrubbed brought specific technical specialists in revenue recognition and lease accounting, giving leadership confidence that complex accounting standards were met.

"Scrubbed follows up very well with different contributors to the company, and they're very patient and kind when trying to extract the information they need to get our books done."
"I really look forward to my call with my Scrubbed accounting team every week. They come with solutions, and it feels like they are genuinely trying to help our business."
Brian Johansing
Controller, Arable Labs Inc.

The accounting profession is currently going through major changes. With talent shortages, shifting client expectations, and growing competition, CPA firms are pressured to rethink how they build and manage their teams.In a recent webinar hosted by Dan Hood, the Editor-in-Chief at Accounting Today, industry experts Rizza De Guzman, the Lead Director for Firm Client Services at Scrubbed, and Jack Reagan, Partner at UHY Advisors, explored the recent shift in the industry and shared their thoughts on how firms can adjust to these challenges. They offered their expertise and strategies to help firms stay competitive and move forward with confidence.Why Firms Are Struggling With the Current Staffing ModelOne of the biggest challenges accounting firms face today is the growing gap between the demand for skilled professionals and the number of people available to do the work.Rizza highlighted several factors that could be causing this shortage, such as the retirement of experienced professionals, the lack of new professionals entering the field, and other industries attracting potential talent with competitive pay and more appealing career paths. As a result, many firms are finding their teams stretched thin. They’ve done all they can with the staff they have, and it’s becoming clear that relying solely on traditional hiring methods isn’t sustainable.Another challenge that Jack mentioned is how client needs have evolved. Work that used to be predictable and ongoing is now more project-based and specialized. So, the skills that you may need now might be different from the skills you need tomorrow. This unpredictability means that firms need to be able to quickly scale their teams up or down, and that kind of agility is hard to achieve with the current staffing model. For Jack, “having that flexibility to match not only the cycle but then the skill set that the project demands is critical.”Building Flexible Teams Through Hybrid and Outsourced StaffingOnce the challenges around talent became clear, the conversation shifted to what firms can do about it. One of the key solutions Rizza discussed was to explore other models, like outsourcing, to create a more agile and scalable workforce. She defines outsourcing as a situation when a company ”fully or partially delegates work to an external partner who becomes an extension of your team.”This kind of model helps firms stay agile and allows them to tap into specialized skills when needed, manage costs more effectively, and adjust quickly as workloads shift. Instead of trying to overload internal teams with work or hire full-time staff for short-term needs, firms can bring in the right expertise at the right time.How to Make Outsourcing Work for Your FirmOne of the most effective ways for firms to stay competitive is by bringing in outside expertise. But making that work takes more than just hiring a third party and hoping for the best. Successful outsourcing starts with clearly defined roles and expectations. Open communication is key, and the relationship needs ongoing attention, not just a one-time setup. Regular check-ins and performance reviews help keep everything on track.Rizza highlights that one of the first steps for companies to start exploring outsourcing or hybrid workforces is by taking a good look at where their team stands today. What skills are missing? What kind of work is piling up? From there, firms can start small. Try a hybrid model, see what works, and adjust as you go.Jack agreed, but noted that for these partnerships to work, firms need to treat outsourced professionals like true team members. According to him, it’s important that firms “…have a say on who is gonna be part of the team,” rather than just being assigned an employee, as this helps set the culture in the workplace.And while working remotely is nothing new, as necessitated by the recent pandemic, trust is another big piece of the puzzle. Beyond scheduled meetings, informal chats and the occasional in-person visit can go a long way in strengthening the connection between the firm and its external team and making the collaboration more effective.One example of this is leveraging fractional CFO services, which allows firms to access high-level financial expertise without the commitment of a full-time hire.Remember, there’s no single formula for success here. Every firm is different. The best approach is one that reflects your client’s needs, internal strengths, and long-term goals.Take Action TodayOne thing became clear throughout the discussion: doing nothing is not an option. For Rizza and Jack, the long-term sustainability, growth, and agility offered by outsourcing talent is the way to go.Competitors are already changing how they staff their teams, and firms that don’t adapt risk falling behind, both in terms of competitiveness and their ability to attract and retain top talent. It’s time for firms to rethink their workforce strategy, focusing on flexibility, building strong partnerships, and using technology along with specialized SaaS accounting expertise to their advantage.How can firms maintain quality control when outsourcing talent?This comes down to choosing the right partner from the start. Be sure to take the time to check their credentials and look into businesses that really understand the industry. Don’t be afraid to ask for references to make sure you find the right fit. Once you’re already working together, regular check-ins and clear communication go a long way in making sure everything stays up to your expectations.Can outsourcing help with seasonal workload spikes?One of the biggest advantages of outsourcing is the flexibility to scale up or scale down depending on your business needs. In fact, a lot of firms may bring in outsourced talent during peak times to help manage the extra workload and avoid overwhelming the internal team.Are outsourcing and hybrid models the same?While outsourcing and hybrid work environments both involve remote work, they are fundamentally different work models. Outsourcing involves bringing in external talent into the team while a hybrid set up has more to do with the location of the internal team. Hybrid can also include external talent, making it a mix of both internal and external resources.How can smaller firms start integrating an outsourced team without overextending the budget?The best thing to do is to start small; you don’t have to hire several people at once. Consider outsourcing time-consuming tasks first, like bookkeeping, to determine whether this staffing model works well for your organization. Over time, you can scale based on performance and necessity.How do I choose the right outsourced accounting provider for my biotech company?Start by identifying your company's accounting needs, such as bookkeeping, financial reporting, ASC 606 compliance, or managing R&D tax credits. Then, evaluate your potential providers based on how much experience they have in the biotech industry and with the unique challenges and regulatory requirements your business faces. Review client testimonials and references from similar biotech companies to get a sense of their track record and expertise. Finally, confirm that their services are scalable to support your business as it grows, and that budgets and service levels are in line with your goals.Connect With ExpertsThe landscape for CPA firms is shifting quickly; with fewer professionals entering the field and client needs becoming more complex, the traditional staffing model is becoming harder to sustain. Firms need more flexibility and access to high-level talent without overloading their internal teams.However, finding the right fit in a sea of talent can be difficult and overwhelming. That’s where Scrubbed comes in. We partner with CPA firms and provide outsourced accounting, finance, and audit services to help clients scale their organization smarter and more efficiently. Ready to explore alternative staffing solutions? Schedule a consultation with our team today and discover how smart outsourced accounting team can benefit you.If you missed the webinar, you can watch it here.

At Scrubbed, we have extensive experience helping SaaS businesses achieve financial success. We’ve combined our knowledge and best practices into a clear and actionable 6-part series designed to maximize your profitability.This third installment focuses on financial forecasting and planning strategies tailored to SaaS businesses.Looking for Expert Accounting And Finance Support For Your SaaS Business? Click here!In the dynamic SaaS world, recurring revenue fuels growth, and accurate financial forecasting and planning are vital for steering your venture toward success. Your financial model serves as your compass, guiding you with clear insights into the financial impact of every choice but staring down a blank spreadsheet can feel daunting, so we’ve gathered some best practices to help you craft a model that will support your growth goals.1. Build Your Financial ModelFinancial models are the bedrock of informed decision-making in any business. They provide invaluable insights into the financial impact of your every move, allowing you to move strategically towards growth and profitability. Some of the areas where they provide valuable insight are:Pricing strategies: Models let you test different pricing options and pinpoint the sweet spot between maximizing revenue and attracting customers. You can consider factors like costs, volume, and customer segments to tailor pricing strategies for different user groups.Hiring decisions: By forecasting future needs and analyzing costs versus benefits, models help you build the optimal team size and skillset. This ensures you have the right workforce in place to support your growth plans without overspending.Investment opportunities: Models equip you to assess the financial viability of potential investments, allowing you to prioritize projects, manage risk, and allocate resources strategically. This ensures you invest in opportunities with the highest potential return, maximizing your impact with limited resources.In essence, your financial model is your decision-making compass. It provides direction and clarity, guiding you toward success by revealing the financial implications of your choices. It needs to include:Revenue forecast: The revenue forecast identifies and predicts various income streams, including subscription fees, initial setup charges, usage-based billing, and additional services. It allows you to consider key factors like diverse pricing tiers, anticipated customer acquisition, and potential churn rates. Analyzing historical revenue data is a fundamental approach to revenue forecasting for SaaS businesses. The analysis examines past trends, growth rates, seasonality patterns, and other historical metrics to identify patterns and extrapolate future performance. While historical data is your foundation, you should also integrate market analysis, growth plans, and competitor insights to paint a more complete picture.a. Expense projections: SaaS businesses have unique cost structures, and you need to factor in some specific operating expenses:b. Personnel costs, including development, sales and management teams, and customer support based on hiring plans and salary trends.c. Marketing expenses should be linked to your acquisition strategy and target audience, including paid advertising, content marketing, and affiliate programs.d. Research and development expenses, including salaries and benefits, development tools and software, and prototyping and user research.Technology costs include cloud hosting, data storage, and security tools that are your virtual backbone.Cash flow projections: Cash inflows and outflows should be forecast over a specific period, considering factors such as operating expenses, capital expenditures, and financing activities. Cash flow projections help assess liquidity, financing needs, and overall financial health.Financial goals and metrics: Track and monitor key metrics such as Monthly Recurring Revenue (MRR), Annual Recurring Revenue (ARR), Average Revenue Per User (ARPU), Customer Acquisition Cost (CAC) to Lifetime Value (CLTV) ratio, and Churn Rate. KPIs provide insights into business performance and inform your strategic decision-making.Don’t expect a clear, unchanging path. Regularly revisit and update your financial plan based on your actual performance and market changes. Think of it as a living document, not a rigid script.While many components of a SaaS financial model are similar to models for other types of businesses, there are some key differences. SaaS financial models typically focus on recurring revenue streams, subscription-based pricing models, customer retention, and scalability. Additionally, metrics such as MRR, ARR, CLTV, and churn rate are unique to the SaaS business model and play a significant role in financial planning and analysis.2. Stress-Test your ModelIt’s important to prepare for different scenarios to be ready to weather or take advantage of changes in the market or your customer base.Start by identifying the factors that significantly impact your financial health, such as pricing changes, churn rates, market growth, or competitor actions. Then, simulate various scenarios in your model to see how these key drivers affect your revenue and expenses. This will highlight potential risks and opportunities you might have missed.Use data visualization to clearly and concisely present your sensitivity analysis findings to stakeholders, including charts and graphs to make complex data easily digestible.3. Use Financial Planning to Inform Strategic Decision-MakingYour model should be a trusted advisor, guiding decisions on product development, pricing strategies, expansion plans, and resource allocation. Use it to test different options and find the one that maximizes your return on investment.However, don’t fall into the trap of over-reliance. Be aware of your financial plan’s limitations and biases, and regularly update it with new data and market insights.As the SaaS landscape evolves, so should your model. Regularly review and update your assumptions, projections, and drivers to ensure the model reflects your changing business environment.Tips to Improve Your Financial Planning:While it can sound daunting, strategic financial planning can increase your company’s sustainability, helping you make better decisions and improve your financial health. If you’re just starting out (or you’re looking to get more out of your financial planning), following these steps can help:Start simply and scale gradually. Don’t get bogged down in complexity.Collaborate with your team. Sales, marketing, and operations input create a comprehensive and realistic model.Embrace iteration. Your model is never truly finished. Continuously refine it based on new data and learnings.Stay ahead of the curve. Keep up-to-date with the latest trends in SaaS financial forecasting and planning.Remember, your financial model is a powerful tool, but its effectiveness depends on the data you feed it and the insights you extract from it. By customizing and applying these tips, you can improve the value of your financial planning and forecasting and ultimately create a more sustainable business.

Introduction Broken Access Control (BAC) might sound like a minor issue, something easily spotted, but it’s actually one of the most frequently overlooked security flaws. While many focus on threats like Remote Code Execution (RCE) or Cross-site Scripting (XSS), BAC silently allows unauthorized users to perform actions they shouldn’t, often without any complex attack. A simple forgotten backend check can lead to sensitive data exposure or elevated permissions, just by slightly modifying the target web address. In this post, we’ll walk through how you can test for Broken Access Control using Open Worldwide Application Security Project (OWASP) Juice Shop—an intentionally vulnerable web application that makes it easy (and safe) to demonstrate these issues in practice. Understanding Broken Access Control Access control directs who can do what in a system. When it’s broken, users can act outside their intended permissions. Users might be able to read other users’ data, modify other roles, or access administrative functionality without authorization. OWASP defines this category broadly and it includes: Vertical privilege escalation: Accessing higher privilege functions (e.g., a user accessing admin functions). Horizontal privilege escalation: Accessing same role resources (e.g., viewing another user’s order). IDOR (Insecure Direct Object Reference): Accessing data by manipulating object references like user IDs or filenames. Forced browsing: Accessing hidden resources or unlinked pages directly. While it might be hard to understand these concepts at first, Juice Shop does a great job showcasing these problems in a safe, intentionally vulnerable playground. Testing for Broken Access Control For this simulation, you will need to install Juice Shop in your local environment and use Burp Suite to capture traffic while interacting with it.Gaining Privileged Access Juice Shop is a deliberately vulnerable web application that exhibits the classic Forced Browsing and Vertical Privilege Escalation vulnerability. Imagine if someone could access admin functions by just visiting a URL; that would be a security nightmare. Fortunately, we can demonstrate this in Juice Shop without the risk. You can test this by attempting to access hidden resources or unlinked pages directly using keywords such as “admin,” “root,” or other common path names in the URL. In our case, the Administration page can be accessed by visiting the “/#/administration” path. This page was not linked anywhere in the standard UI, yet entering the URL directly allowed full access to the user listing and the ability to remove customer feedback.Note that this vulnerability is accessible if you are already logged in or tagged as an admin role user inside OWASP Juice Shop. However, given that this is hidden in the user interface even if you log in as an admin user, we can infer that it was not meant to be exposed to users (including admin users). In some real-world scenarios, some web applications allow access to the affected endpoint to all users as long as they enter the correct address. But you’re probably curious how we can access this page using a regular, low-privileged accountFirst, inspect how the authentication works. Upon logging in, a token will be sent to your browser and subsequently attached to every HTTP request made to Juice Shop.At this point, you will have to study JWT, but let’s assume that you already know it. What do you think would happen if we change the JWT role parameter or claim to something else, like “admin”?You guessed it right. Modifying the JWT and changing it to “admin” allowed us to access the “/#/administration” page while logged in as a regular user. All you need to do is use Burp Suite’s JWT Editor extension, modify the role parameter or JWT claim to “admin,” go to your browser’s local storage, and replace the token key with the modified JWT, and Voila! You now have access to the Administration page even as a regular user.Viewing and Tampering Another User’s Basket This is an example of Insecure Direct Object Reference (IDOR) and Horizontal Privilege Escalation. Imagine if you have an e-commerce site and anyone can add or delete items in another user’s shopping cart. That would leave your customers confused. To test this vulnerability, log in as a regular user and inspect HTTP requests and responses related to user basket actions. In Burp Suite, notice that visiting your own basket generates a “GET /rest/basket/6” request to Juice Shop. Immediately, you can see from that request that our basket has an ID of “6.” Out of curiosity, if we change the basket ID to another number, will we be able to access other users’ baskets? It turns out we can. There are a couple of ways to test this, but by going to the browser’s Developer Tools > Storage > Session Storage, we can see a “bid” parameter. Modifying it to another number, in our case “3,” and refreshing the page would let us access basket #3—with no ownership check, just the data. This is an example of a horizontal IDOR vulnerability, where users at the same privilege level can access each other’s data by simply modifying object references.Alternatively, the details for basket #3 can also be accessed by repeating the original HTTP request in Burp Suite and modifying the ID to “3”.We were able to see the details of the other user’s basket, but how do we tamper with it? Let’s go back to Burp Suite and study the HTTP request and response flow. Notice that, besides viewing your own basket, adding items to our basket requires a “BasketId” parameter. This is the key to the attack. What if we modify the “BasketId” before sending the request? Will we be able to modify another user’s basket successfully? The short answer is yes, but it is not as easy as it sounds. But before we do the attack, we have the following in basket #3. Remember, our basket is basket #6.Now, let’s modify the “add to basket” request and change the “BasketId” to a different number. However, you will notice that trying to change it won’t modify the basket content of our target.So, what should we do? There are many things you can try, but to cut a long story short, you might discover that adding a second “BasketId” would push the request and modify our target’s basket as well.This tells us that if the backend interprets the requests, and if it finds another “basketID,” it will apply the same action to it. Do you see where I’m going with this? Perhaps adding more “basketID” values would enable a multi-basket attack, but I will leave that for you to try. This means that ignoring access control measures can lead to numerous issues in your web application, potentially affecting multiple accounts by disclosing sensitive information or, as in our case, the contents of a user’s basket. Forged user reviews In Juice Shop, as with almost every e-commerce site, users are allowed to write and submit reviews. This generally benefits both the store owner and enhances the overall user experience. But what if someone could forge a user review? What if a customer review was written and attributed to someone else, perhaps a high-profile user of the site? That would greatly affect the product’s performance, right? This is what we wanted to achieve here: post a user review and attribute it to a different user. Now, you’ll notice that whenever you write and submit a product review, this PUT request is sent.Remember our previous attack that affected another user’s basket? How about the attack where we found the admin email address (see Gaining Privileged Access)? Let’s test that. What would happen if we modify the author before sending it to the endpoint? Would that change the author itself? Let’s see.And what do you know, we were able to post a review using a different user! And we can confirm that by browsing the exact product in the web application.So, the lesson here? Yes, broken access control also helps attackers forge account actions. Directory enumeration and restricted file download One common pitfall of improperly implemented access control is that restricted directories and their included files become accessible for download. This vulnerability is often found in applications rushed to production or those that don’t undergo regular security testing. While this may be harder to find in the real world today, this vulnerability still exists in some web applications. But fret not, Juice Shop exhibits this weakness. If you’ve explored Juice Shop before, you might have stumbled upon various directories, including the `/ftp/` directory. You’ll notice that accessing this directory reveals a number of files without requiring any additional authentication. You can even access some of the files enumerated.Clearly, some of these files are not intended to be accessed, which in itself indicates an access control violation. If you further explore the directory, you’ll discover that attempting to access files with extensions other than “.md” or “.pdf” results in a restriction notification. As curious individuals, we’ll want to bypass this. Fortunately, Juice Shop is vulnerable to null-byte injection.Null-byte injection is essentially an implementation-related vulnerability stemming from a weakness in the framework, underlying library, logic, or a combination of all these three. To perform a null-byte injection, we need to append a null-byte (`%00`) to the filename, hoping that the application won’t sanitize our request.Initially, adding `%00` to the end of the URL might not yield results, perhaps because the server expects a valid file extension. To address this, let’s append a `.pdf` extension.Still not working, right? Perhaps something is blocking our request. Let’s see if encoding will help us get through. Let us encode % and see what happens.Well, what do you know, it works! Now we can access the restricted file and see its content. Clearly this is a violation of access controls. How to Prevent Broken Access Control? If you’re building or maintaining web applications, Broken Access Control (BAC) is one of the most important risks to address. Here’s what you can do to avoid the issues above: Enforce Access Controls on the Server Side Don’t rely on client-side code or hidden links. Every sensitive operation should include server-side checks against the user’s authenticated identity and role. Use Context-Aware Authorization and Centralize Access Control Logic Implement logic that not only checks the user’s role but also whether the user owns the resource in the specific transaction context. For example, confirm “user.id == order.ownerId” before returning order data. Centralize your authorization logic into a single reusable library or service. This ensures that robust authorization rules are applied consistently. This also simplifies maintenance.Adopt a “Deny by Default” and Least Privilege Principle Don’t assign admin rights unless explicitly needed. Make roles granular and restrictive by default. Implement Indirect and Unpredictable Resource Identifiers Use randomly generated identifiers like UUIDs/GUIDs. Implement an indirect reference map that translates a public identifier to a real database ID only after the authorization check has passed. Apply Rate Limiting and Throttling Apply rate limiting to endpoints, especially to sensitive ones such as authentication and data access, to slow down attackers trying to bruteforce identifiers Block IPs or users that exhibit anomalous behavior or exceed reasonable request thresholds Implement a Secure Development Lifecycle (SDLC) Include security unit tests and access control checks as part of your CI/CD pipeline. Use test accounts with varying roles to test for both vertical and horizontal privilege escalation. Monitor and Log Access Violations Set up alerts for unusual access patterns or repeated unauthorized attempts. Log every access control failure, including the user, IP address, and specific resource they are trying to access. Perform regular security assessments Perform regular Web Application Penetration Tests (VAPT) against your web applications. Engage qualified professionals to perform penetration testing at least annually or after any significant changes to the environment. Final Thoughts Broken Access Control topped the OWASP Top 10 list for a reason: it’s one of the most common and dangerous issues that plague web applications. While OWASP Juice Shop is intentionally vulnerable, the lessons it teaches are very real. If you are a developer, product owner, or cybersecurity professional, the insights from Juice Shop offer a humbling reminder of why access controls must be built defensively and verified thoroughly. Looking for support to assess your web applications? If your goal is to get a real-world, adversarial assessment of your security posture, including your access controls, Scrubbed can help you perform Web Application Penetration Testing. We can test Broken Access Controls and other vulnerabilities to help you secure your applications. Not your cup of tea? We also offer other information security related services such as IT audit, Security Awareness Training, and SOC assessment support. Get started in securing your organization. Contact us at https://content.scrubbed.net/contact-us/ (Risk Advisory).