top of page

Protecting Client Data Is a Legal Must for Accounting and Tax Firms

  • Writer: cAIberOps (SY-ber-ops) | MSSP
    cAIberOps (SY-ber-ops) | MSSP
  • Jun 9
  • 3 min read

Handling sensitive client data like Social Security numbers, income details, and financial records means your accounting or tax firm is now classified as a financial institution under the Gramm-Leach-Bliley Act (GLBA). This classification brings legal responsibilities to protect that data. The Federal Trade Commission (FTC) and the IRS enforce these rules. Protecting client data is not just good practice—it is the law.



What the FTC Safeguards Rule Means for Your Firm


Since June 2023, the FTC Safeguards Rule requires firms like yours to have a written information security program. This program must include several key elements:


  • Designate a qualified individual to oversee your information security program.


  • Conduct a written risk assessment to identify and address potential threats.


  • Maintain access controls and a data inventory to know who can access client information and what data you hold.


  • Encrypt customer information both at rest and in transit to prevent unauthorized access.


  • Use multi-factor authentication (MFA) to add an extra layer of security.


  • Monitor and log activity on your systems to detect suspicious behavior.


  • Provide staff security awareness training so your team knows how to protect data.


  • Oversee service providers to ensure they meet security standards.


  • Have a written incident response plan ready to act quickly if a breach occurs.



These requirements are not optional. The FTC can impose civil penalties exceeding $50,000 per violation. Beyond fines, a data breach can damage your reputation and cost your firm time and money.



Eye-level view of a CPA office desk with encrypted client files
Eye-level view of a CPA office desk with encrypted client files


IRS Written Information Security Plan (WISP) for Tax Professionals


The IRS also requires every tax professional to have a Written Information Security Plan (WISP). This plan outlines how you protect taxpayer data. The IRS provides guidance and templates in Publications 4557 and 5708 to help you create your WISP.



When renewing your Preparer Tax Identification Number (PTIN), you must certify that you are aware of and comply with these security requirements. False certification can lead to PTIN revocation, which means you cannot legally prepare tax returns.



The WISP is not a one-time document. It must be updated regularly to reflect changes in your firm’s operations and emerging threats.



Common Misconceptions That Put Firms at Risk


Many firms believe they are too small to be targeted by cybercriminals. This is false. Attackers often target small and medium-sized firms because they may have weaker security.



Some think their tax software vendor handles all security. While vendors provide some protections, your firm remains responsible for securing client data.



Others assume that because they have never had a breach, their security is sufficient. Cyber threats evolve constantly, so past safety does not guarantee future protection.



Finally, some treat the WISP as a document to write once and file away. The WISP must be a living document, regularly reviewed and updated.



Practical Steps to Meet Legal Requirements


To comply with the FTC Safeguards Rule and IRS WISP requirements, your firm should:


  • Assign a qualified security officer.


  • Perform a detailed risk assessment.


  • Keep an updated inventory of client data.


  • Implement strong access controls and encryption.


  • Use multi-factor authentication on all systems.


  • Monitor network and user activity continuously.


  • Train staff regularly on security best practices.


  • Review and manage third-party service providers.


  • Develop and test an incident response plan.



How cAIberOps Supports Your Security Needs


Meeting these requirements can be complex. That’s where a managed security service provider (MSSP) like cAIberOps can help. We provide technical controls and services tailored for accounting and tax firms, including:


  • Managed email security to block phishing and malware.


  • Endpoint detection and response (EDR) to catch threats on your devices.


  • Multi-factor authentication support to strengthen access controls.


  • Dark web monitoring to alert you if your credentials appear in data leaks.


  • 24/7 threat monitoring and incident response to detect and respond to attacks quickly.


  • Ongoing security awareness training with phishing simulations to keep your staff alert.



These services help you build a strong defense and maintain compliance with legal requirements. They also free you to focus on your core work without worrying about cybersecurity gaps.



Close-up of a computer screen showing multi-factor authentication prompt
Close-up of a computer screen showing multi-factor authentication prompt


The Cost of Non-Compliance


Ignoring these rules can lead to serious consequences. The FTC can fine firms more than $50,000 per violation. Beyond fines, a data breach can cause loss of client trust, legal action, and costly recovery efforts.



Taking cybersecurity seriously protects your clients and your firm’s future. It also shows your commitment to professionalism and trustworthiness.



Final Thoughts


Protecting client data is a legal obligation for accounting, CPA, and tax firms. The FTC Safeguards Rule and IRS WISP requirements set clear standards. Meeting these rules requires ongoing effort, not just a one-time fix.



Working with a trusted MSSP like cAIberOps helps you meet these requirements with expert support and proven technology. This partnership lets you focus on growing your firm while keeping client data safe.



Take the next step to secure your firm and comply with the law. Learn more about how cAIberOps can help you protect your clients and your business.

Comments


bottom of page