Cybersecurity for accounting and tax firms

Cybersecurity for Accounting and Tax Preparation Firms

Accounting and tax preparation firms hold some of the most sensitive personal and financial data any small business handles. Email, Microsoft 365, tax-preparation software, client portals, remote access, and backups all affect whether that data—and your firm's Written Information Security Plan—hold up to scrutiny.

Independent verificationWorks alongside your IT provider or software vendorEvidence for the firm's qualified individualNo legal opinion issued

Business IT and client-data safeguards only—not a substitute for legal or tax-practice advice.

Who this is for

Practical guidance for firms with sensitive client information.

This page is for small and midsize CPA and accounting firms, independent tax practices, enrolled agents, seasonal tax teams, and bookkeeping or payroll businesses. Their systems and legal obligations can differ, so each engagement is scoped to the firm's actual operations.

Where information can be exposed

  • A compromised mailbox reveals tax documents or enables payment fraud.
  • A client folder is shared more broadly than intended.
  • Seasonal staff retain access after their work ends.
  • Remote access or unmanaged devices expose sensitive information.
  • Backups exist, but recovery has not been demonstrated.
  • A written policy describes controls nobody has verified.

Your IT provider and an independent review

You can retain your IT provider while obtaining an independent review of relevant safeguards and evidence. We do not suggest every provider is ineffective, and we do not provide continuous managed IT; findings and responsibilities are documented for the people who operate your environment.

Within the agreed scope

What we help review

Accounting and tax firms often focus attention on the tax-preparation software itself. But many disruptive incidents begin in ordinary business systems: an email account, an exposed remote-access service, a compromised administrator account, a shared client-document folder, or a backup that cannot be restored.

Email and Microsoft 365 security, where applicable; MFA, administrator privileges, and employee access.

Client portals, document sharing, permissions, endpoint and remote-access safeguards.

Backup and recovery evidence; staff phishing readiness and reporting procedures.

Security policies, incident responsibilities, and WISP alignment.

Relevant vendors and service providers.

Choose the right starting point.

Choose the service that matches the question you need answered. The free review is public-only; the Baseline verifies internal safeguards within its published scope; WISP support focuses on tailored documentation and implementation priorities.

Start outside. Verify inside when necessary.

Free

Free Zero-Access Exposure Review™

Identify the public security signals surrounding the firm's email, domains, websites, certificates, and internet-facing services.

  • SPF, DKIM, and DMARC
  • Lookalike domains
  • Public subdomains and services
  • Observable remote-access services
  • Website and certificate posture
  • Potential vulnerability matches requiring validation
Free Zero-Access Exposure Review™

Phishing readiness

Preparers and front-office staff both handle unexpected client and vendor requests.

Tax firms often receive new-client document requests, IRS or state-agency impersonation, portal-notification lures, and payment or billing-change messages. A properly scoped phishing test can measure whether selected participants pause to verify the request, protect credentials, and report suspicious messages rather than acting on urgency alone.

An email campaign can be scoped to selected users, but that is not equivalent to training the entire firm. Use participant-based pricing and confirm the exact audience before work begins.

Practical deliverables, clear boundaries

Scoped outputs can include findings supported by reviewed evidence, prioritized recommendations, responsibilities for the firm and its IT provider, documentation updates when included, and a leadership readout. We do not promise legal certification, unlimited remediation, or guaranteed compliance.

Questions from accounting and tax firms

Do small tax preparation firms need a written security plan?

Some tax preparation firms are covered by the FTC Safeguards Rule, but obligations depend on the firm's activities and jurisdiction. The fewer-than-5,000-consumers exception applies to certain provisions and is not a blanket exemption. Confirm your situation with qualified counsel.

Can you work with our existing IT provider?

Yes. We can review agreed evidence and give your firm and IT provider clear responsibilities and prioritized next steps without replacing ongoing IT support.

Can you review our Microsoft 365 and client-sharing settings?

Yes, when included in the agreed scope. The Business Security Baseline can review relevant Microsoft 365 identity, access, sharing, and logging evidence; it does not automatically cover every system or include penetration testing.

How should we handle seasonal staff access?

Use documented provisioning, least-privilege access, MFA where applicable, and timely offboarding. We can review evidence of those practices within the agreed scope.

Do we need to send you actual client tax returns?

Initial scoping does not require taxpayer records. Evidence collection should minimize sensitive data and use read-only exports, screenshots, or documentation where practical. Some assessments may still require authorized access or carefully selected evidence to verify specific controls.

Do you draft our Written Information Security Plan (WISP)?

No. We are not a law firm and do not draft the legal WISP document itself. The IRS publishes a free sample template (Publication 5708) that firms can adapt. Our assessments provide independent technical evidence—public exposure findings and essential-safeguard verification—that supports the risk-assessment and safeguards sections a firm's designated qualified individual maintains.

Does the Business Security Baseline guarantee FTC Safeguards Rule or IRS compliance?

No. The Baseline verifies a defined set of essential business IT safeguards and provides supporting evidence. It is not a legal compliance opinion, and it does not guarantee IRS, FTC, or state-board approval. Pair the assessment evidence with your own legal and tax-practice advisors.

Can the free review examine our tax-preparation software or client portal directly?

No. The free Zero-Access Exposure Review™ looks only at public signals—email authentication, domains, and internet-facing services. Confirming access controls, MFA enforcement, and configuration inside tax-preparation software requires an authorized assessment such as the Business Security Baseline.

Can you work with our existing IT provider or software vendor?

Yes. The assessment produces technical findings and recommended verification steps that your existing IT provider or software vendor can act on. We do not replace day-to-day IT support.

What does the $1,995 price cover?

It covers the defined Business Security Baseline for businesses with up to 25 employees. Larger or materially more complex environments receive a confirmed price after scoping.

Verify the safeguards protecting your client data.

Start with what is visible from the outside, then verify the controls protecting the client tax data your firm is responsible for.