Accounting and tax firms
Cybersecurity for accounting firms and tax practices
CPA and tax firms hold exactly the data attackers want: returns, bank details and Social Security numbers. We help you meet the FTC Safeguards Rule, build a WISP that reflects how you really work and reach SOC 2 when clients ask for it.


The challenge
Why accounting firms are targeted, especially in tax season
Accounting firms handle tax returns, financial statements and personal data for every client, and much of it moves through email, portals and remote access. Attackers time phishing and account takeover attempts for tax season, when staff are busiest and least likely to stop and check.
The rules are specific. Tax and accounting professionals are treated as financial institutions under the FTC Safeguards Rule, which requires a written information security program, a qualified individual to run it, risk assessments, MFA, encryption, testing and vendor oversight. Since May 2024, a breach involving unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery. Growing firms also field more requests from business clients for SOC 2 reports.
Guide
What CPA firm cybersecurity requires
Most accounting and tax firms answer to three overlapping sets of expectations. Here’s how they fit together.
The FTC Safeguards Rule
The Safeguards Rule (16 CFR Part 314) is the binding federal requirement for many tax preparers and CPA firms. It requires a written information security program with a designated qualified individual, a written risk assessment, access controls, encryption of customer information, multi-factor authentication, regular testing or monitoring, staff training, oversight of service providers, an incident response plan and periodic reporting to firm leadership.
IRS Publication 4557 and your WISP
IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS guide for tax professionals on meeting those obligations. It explains the core safeguards and how to create a written information security plan, often called a WISP. A WISP should describe your firm as it really operates: who has access to what, how data is stored and sent, which vendors you use and what happens when something goes wrong.
SOC 2 for accounting firms
SOC 2 is voluntary, but business clients increasingly ask for it, especially for firms that host client data or provide outsourced accounting. A SOC 2 report shows an independent auditor has tested your controls. The work you do for the Safeguards Rule gives you much of the foundation.
First steps for a small or mid-sized firm
- Name a qualified individual and write down who is responsible for security
- Complete a written risk assessment of your systems, data and vendors
- Require MFA for email, remote access, tax software and portals
- Encrypt client data and keep immutable, tested backups
- Train staff before every tax season and test with phishing simulations
- Write or update your WISP and incident response plan
How we help
Cybersecurity services for accounting firms
Regulations and frameworks
Requirements we help accounting firms meet
Case study
SOC 2 compliance for a Southern California accounting firm
An established accounting firm with more than 200 professionals in Los Angeles and Orange County, handles sensitive client financial data and PII for businesses, nonprofits and high-net-worth individuals. As it grew, it needed SOC 2 compliance and continuous security guidance.
We designed a cybersecurity program mapped to SOC 2, with discovery and assessment, multi-factor authentication, PII segmentation and 24/7 SOC services. We later added immutable backups and now serve as the firm’s vCISO.
FAQ
Accounting firm cybersecurity questions
Related services
Related services
Talk to an advisor
Protect client data and meet the Safeguards Rule
Tell us about your firm, your offices and what clients are asking for, and an advisor will reply by email to set up a conversation.
Prefer email? Write to [email protected] or call (858) 712-0040.
