Accounting and tax firms

Cybersecurity for accounting firms and tax practices

CPA and tax firms hold exactly the data attackers want: returns, bank details and Social Security numbers. We help you meet the FTC Safeguards Rule, build a WISP that reflects how you really work and reach SOC 2 when clients ask for it.

  • WISP and FTC Safeguards Rule programs
  • SOC 2 for a 200+ person SoCal accounting firm
  • vCISO guidance on policy, risk and tools
Two colleagues reviewing financial reports
Professional working at a computer from home

The challenge

Why accounting firms are targeted, especially in tax season

Accounting firms handle tax returns, financial statements and personal data for every client, and much of it moves through email, portals and remote access. Attackers time phishing and account takeover attempts for tax season, when staff are busiest and least likely to stop and check.

The rules are specific. Tax and accounting professionals are treated as financial institutions under the FTC Safeguards Rule, which requires a written information security program, a qualified individual to run it, risk assessments, MFA, encryption, testing and vendor oversight. Since May 2024, a breach involving unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery. Growing firms also field more requests from business clients for SOC 2 reports.

  • Client tax and financial data across email, portals and cloud apps
  • Remote and seasonal staff
  • Phishing and account takeover timed for tax season
  • Acquired firms with different systems and controls
  • Client security questionnaires and SOC 2 requests

Guide

What CPA firm cybersecurity requires

Most accounting and tax firms answer to three overlapping sets of expectations. Here’s how they fit together.

The FTC Safeguards Rule

The Safeguards Rule (16 CFR Part 314) is the binding federal requirement for many tax preparers and CPA firms. It requires a written information security program with a designated qualified individual, a written risk assessment, access controls, encryption of customer information, multi-factor authentication, regular testing or monitoring, staff training, oversight of service providers, an incident response plan and periodic reporting to firm leadership.

IRS Publication 4557 and your WISP

IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS guide for tax professionals on meeting those obligations. It explains the core safeguards and how to create a written information security plan, often called a WISP. A WISP should describe your firm as it really operates: who has access to what, how data is stored and sent, which vendors you use and what happens when something goes wrong.

SOC 2 for accounting firms

SOC 2 is voluntary, but business clients increasingly ask for it, especially for firms that host client data or provide outsourced accounting. A SOC 2 report shows an independent auditor has tested your controls. The work you do for the Safeguards Rule gives you much of the foundation.

First steps for a small or mid-sized firm

  1. Name a qualified individual and write down who is responsible for security
  2. Complete a written risk assessment of your systems, data and vendors
  3. Require MFA for email, remote access, tax software and portals
  4. Encrypt client data and keep immutable, tested backups
  5. Train staff before every tax season and test with phishing simulations
  6. Write or update your WISP and incident response plan

Regulations and frameworks

Requirements we help accounting firms meet

  • FTC Safeguards Rule written information security program
  • IRS Publication 4557 safeguards
  • WISP creation and annual updates
  • FTC breach notification readiness
  • SOC 2 readiness and ongoing compliance
  • State privacy laws such as the CCPA
  • Vendor and service provider oversight
  • Incident response planning and tabletop exercises

Case study

SOC 2 compliance for a Southern California accounting firm

An established accounting firm with more than 200 professionals in Los Angeles and Orange County, handles sensitive client financial data and PII for businesses, nonprofits and high-net-worth individuals. As it grew, it needed SOC 2 compliance and continuous security guidance.

We designed a cybersecurity program mapped to SOC 2, with discovery and assessment, multi-factor authentication, PII segmentation and 24/7 SOC services. We later added immutable backups and now serve as the firm’s vCISO.

  • A SOC 2 compliant environment that protects client data
  • Immutable backups that keep ransomware from disrupting the business
  • Ongoing vCISO guidance on policy, risk and security tools

FAQ

Accounting firm cybersecurity questions

In most cases, yes. The FTC treats tax preparers and many accounting firms as financial institutions under GLBA, so the Safeguards Rule applies. It requires a written information security program, a qualified individual, risk assessments, MFA, encryption, testing, training and vendor oversight.

A written information security plan documents how your firm protects taxpayer data: who is responsible, what risks you’ve identified, the safeguards you use, how you oversee vendors and how you respond to incidents. IRS Publication 4557 explains what it should cover.

It isn’t legally required, but business clients often ask for it before sharing data or outsourcing work. We help firms decide when SOC 2 makes sense and build toward it from the Safeguards Rule program they already need.

Follow your incident response plan, contain the issue and preserve evidence. If unencrypted information of 500 or more consumers was acquired, the Safeguards Rule requires notice to the FTC within 30 days of discovery, and state notification laws and IRS reporting may also apply. An incident response retainer set up in advance puts responders under agreement before you need them.

The number of staff, offices and systems, whether you need SOC 2 or Safeguards Rule compliance, and how much you want managed, such as 24/7 SOC or vCISO. We scope the work after a short call and quote a fixed price.

Our vCISO service can fill that role or support someone at your firm who holds it. Either way, the firm stays responsible for the program, and we make sure it’s documented and working.

Talk to an advisor

Protect client data and meet the Safeguards Rule

Tell us about your firm, your offices and what clients are asking for, and an advisor will reply by email to set up a conversation.

  • A starting point for your WISP and Safeguards Rule program
  • A path to SOC 2 if your clients need it

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message