Industries — Accounting & CPA
IT support and cybersecurity for CPA and accounting firms
Under the FTC Safeguards Rule, every CPA and tax firm is a financial institution — there is no size exemption. We operate the required program and build support around the filing calendar.
A financial institution, at any size
The FTC Safeguards Rule covers CPA firms and tax preparers of any size — most firms learn this from an insurance application or an IRS notice rather than from the FTC. The rule requires a working program: a designated Qualified Individual, a written risk assessment, technical safeguards including MFA and encryption, monitoring, training, vendor oversight, and an incident response plan.
The IRS reinforces it: tax professionals attest to data-security responsibilities at PTIN renewal, and the IRS publishes a WISP template it expects preparers to maintain. A binder built from a template is not a program — the controls have to actually run, and the evidence has to exist.
Then there is the calendar. From late January to April 15, your tolerance for downtime is near zero, which changes how IT should be operated: changes frozen before deadlines, maintenance scheduled around filing peaks, priorities set by your season rather than ours. See FTC Safeguards compliance, how financial services firms carry the NYDFS version of the same duty, and the other industries we serve.
The Safeguards program, in short
A designated Qualified Individual
Written risk assessment
MFA, encryption, and access controls
Continuous monitoring or annual penetration testing
Staff training and vendor oversight
Incident response plan and annual report
What we run for accounting firms
The Safeguards elements as operated controls, plus the day-to-day IT a firm actually feels.
Safeguards program operation
We implement and run the technical elements and support your Qualified Individual with the risk assessment, WISP, and annual report — see FTC Safeguards services.
Season-aware managed IT
Managed IT with change freezes before filing deadlines and escalation priorities that follow your calendar, in writing.
Email security
Email security against the attacks aimed at preparers: client-impersonation refund fraud, EFIN and CAF phishing, and malicious organizer attachments.
Managed detection and response
MDR across endpoints and identity, monitored around the clock by our tooling, with engineer escalation.
Encrypted client data handling
Encryption at rest and in transit, secure portals instead of email attachments, and Microsoft 365 tenants configured for confidentiality.
Backup and recovery
Tested, immutable backups of the tax application server and client files — restore rehearsals happen before February, not during it.
Common questions from CPA firms
Does the FTC Safeguards Rule really apply to a firm our size?
Yes. Coverage turns on activity — preparing returns or providing financial advice — not headcount. Firms holding data on fewer than 5,000 consumers are excused from a few elements, such as the written risk assessment and the annual report, but the core safeguards, MFA included, apply to everyone. We document which tier you fall in.
Is the IRS WISP different from the FTC program?
Same program, two enforcers. The written information security plan the IRS expects from tax preparers is your documentation of the FTC Safeguards program. We maintain one plan that satisfies both, mapped to the controls we actually operate — not a template with your letterhead on it.
What happens to support during filing season?
We treat late January through April 15 as production-critical: changes are frozen except for security fixes, maintenance moves to your off-hours, and season-blocking issues go to the front of the queue. That is written into the service plan, not offered as a courtesy.
Make the Safeguards Rule a solved problem.
An assessment maps your current controls to the nine required elements before your insurer or the IRS asks — you keep the findings either way.