Your clients trust you with their numbers. Protect them.
Tax preparers and accounting firms are 'financial institutions' under the FTC Safeguards Rule — and one of the most targeted small-business sectors every filing season. We build the written security program the Rule and the IRS require, lock down the email and portals attackers go after, and stand by with incident response when something slips through.
15-minute call · senior engineer · no obligation
The pressures specific to your sector.
Tax-season phishing and account takeover
Fake client documents, spoofed IRS notices, and 'new client' lures spike from January to April. One compromised mailbox exposes every return in it.
The FTC Safeguards Rule applies to you
Tax preparers are explicitly covered. That means a Qualified Individual, a written information security program, MFA, encryption, and an annual report to leadership.
IRS data-security plan expectations
Paid preparers attest to having a written data-security plan when renewing their PTIN, and IRS Publications 4557 and 5708 lay out what it should contain.
Wire fraud and client-impersonation
Attackers inside a client's or your own email redirect refunds and payments. The fix is process as much as technology — callback verification, MFA, and mail-flow rules.
Security built for how firms actually work.
- 01Written Information Security Program (WISP) aligned to the FTC Safeguards Rule and IRS guidance
- 02Qualified Individual support on a fractional / vCISO basis, including the annual leadership report
- 03MFA, conditional access, and hardening for Microsoft 365, tax software, and client portals
- 04Phishing simulation and security-awareness training timed ahead of tax season
- 05Endpoint detection and 24/7 monitoring for staff and seasonal workstations
- 06Encrypted file exchange to replace emailing returns and statements
- 07Incident response plan, retainer, and breach-notification guidance (FTC and Florida)
Examiner-ready before the next filing season.
Risk assessment of where client data lives — software, email, portals, paper, and people.
Author the WISP and name your Qualified Individual so the paperwork matches reality.
MFA, encryption, monitoring, and training rolled out before the January rush.
Annual reassessment, leadership report, and incident response on call.
Questions, answered.
Does the FTC Safeguards Rule really apply to a small CPA firm?+
Yes. The FTC lists tax preparers among the non-bank financial institutions the Rule covers. Firms that maintain information on fewer than 5,000 consumers are exempt from a few elements — such as the written risk assessment and annual report — but not from the core program.
What does the IRS expect from our data-security plan?+
The IRS expects paid preparers to maintain a written information security plan and asks them to affirm it at PTIN renewal. Publication 5708 provides a template; we tailor one to your firm and tie it to the controls you actually run, so it holds up if you ever need it.
What happens if we have a breach?+
Under the Safeguards Rule, a notification event involving 500 or more consumers must be reported to the FTC within 30 days of discovery. Florida law separately requires notifying affected residents, generally within 30 days. You should also contact your IRS Stakeholder Liaison. We run containment and help you meet each clock.
We already have IT support. Why do we need you?+
Keeping systems running and proving they're secure are different jobs. We can work alongside your IT provider — owning the WISP, the Qualified Individual role, training, and incident response — without replacing them.
Ready when you are.
Book a 15-minute introduction call. Walk away with a clear next step — whether you work with us or not.
15-minute call · senior engineer · no obligation
