CPA Firms Need a Written, Risk-Based Information Security Program
CPA firms can strengthen compliance with the FTC Safeguards Rule and IRS Publication 4557 by building a documented information security program around seven core activities: appointing a security leader, completing a risk assessment, maintaining a Written Information Security Plan, implementing technical safeguards, training employees, monitoring service providers, and testing the program regularly.
For a CPA firm with 25–50 employees, this is not a one-time checklist. Security controls, policies, access rights, employee training, vendor relationships, and incident-response procedures should be reviewed throughout the year and formally reassessed at least annually.
The FTC Safeguards Rule establishes data-security obligations for covered financial institutions, including many professional tax preparers. IRS Publication 4557 gives tax professionals practical guidance for protecting taxpayer information. The two resources overlap substantially, but neither should be treated as a substitute for legal advice or a firm-specific risk assessment.
What Is the FTC Safeguards Rule?
The FTC Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program designed to protect customer information. Depending on the services a CPA or tax firm provides, the organization may fall within the Rule's definition of a financial institution.
A compliant security program should be appropriate to the firm's size, complexity, activities, and the sensitivity of the information it handles. A five-person bookkeeping practice and a 50-person CPA firm may use different tools, but both need a reasoned, documented approach to protecting customer information.
Common Safeguards Rule responsibilities include:
- Designating a qualified individual to oversee the information security program
- Performing a written risk assessment
- Designing safeguards that address identified risks
- Controlling access to sensitive information
- Encrypting information where appropriate
- Using multi-factor authentication for access to information systems
- Monitoring and testing the effectiveness of safeguards
- Training employees
- Evaluating service providers
- Maintaining an incident-response plan
- Updating the security program as risks and operations change
Because applicability and specific obligations can depend on the firm's activities and circumstances, firm leadership should confirm its legal responsibilities with qualified counsel or a compliance professional.
What Is IRS Publication 4557?
IRS Publication 4557, Safeguarding Taxpayer Data, provides tax professionals with practical guidance for protecting taxpayer information and reducing the risk of identity theft, fraud, and data loss.
The publication emphasizes that tax professionals should create and maintain a written security plan, protect computers and networks, control access to taxpayer information, train employees, identify phishing attempts, use secure passwords, maintain backups, and understand how to respond when a data breach occurs.
Publication 4557 is particularly useful because it translates broad security responsibilities into operational steps that a tax practice can apply to employees, devices, software, email, remote work, document storage, and incident response.
The 7-Step CPA Information Security Framework
A CPA firm can organize its compliance work into the following seven-step process. This framework connects governance, technical controls, employee behavior, and ongoing verification rather than treating compliance as a collection of unrelated products.
1. Designate a Qualified Security Leader
Assign one qualified individual to coordinate and oversee the firm's information security program. Depending on the size of the firm, this may be an owner, managing partner, internal IT leader, compliance officer, or an external service provider working under the firm's direction.
The designated leader should have clearly documented responsibilities, including:
- Coordinating the risk assessment
- Maintaining the Written Information Security Plan
- Tracking remediation projects
- Reviewing access controls
- Coordinating employee training
- Evaluating vendors
- Managing security incidents
- Reporting material risks to firm leadership
Outsourcing technical work does not eliminate the firm's responsibility to oversee the program. Leadership should understand which tasks are assigned internally, which are handled by the IT provider, and how completion is verified.
2. Complete a Written Risk Assessment
The risk assessment is the foundation of the security program. It should identify the information the firm stores, where that information is located, who can access it, which threats could affect it, and how existing safeguards reduce those risks.
At a minimum, assess:
- Tax preparation and accounting applications
- Microsoft 365 and email accounts
- Local servers and file shares
- Cloud storage and client portals
- Laptops, desktops, and mobile devices
- Remote access systems
- Paper files and physical records
- Backup systems
- Third-party vendors
- Employee access and administrative privileges
For each risk, document the likelihood of occurrence, the potential business impact, the safeguards already in place, and the work required to reduce the risk further.
| Risk | Potential impact | Existing safeguard | Recommended action |
|---|---|---|---|
| Stolen Microsoft 365 password | Email compromise and client-data exposure | Password policy | Require MFA and conditional access |
| Ransomware infection | Downtime, data loss, and missed deadlines | Antivirus and backups | Deploy EDR and test recovery |
| Former employee retains access | Unauthorized data access | Manual offboarding | Use a documented termination checklist |
| Lost laptop | Exposure of stored taxpayer information | Device password | Enable full-disk encryption and remote management |
The assessment should be updated when the firm introduces new systems, changes locations, acquires another practice, expands remote work, or experiences a significant security incident.
3. Create and Maintain a Written Information Security Plan
A Written Information Security Plan, commonly called a WISP, explains how the firm protects sensitive information and who is responsible for each part of the program.
A useful WISP should be specific to the firm's actual environment. A generic template that mentions controls the firm does not use can create false confidence and may be difficult to defend during an audit or incident.
The plan should address:
- Purpose and scope
- Responsible personnel
- Data classification
- Risk-assessment procedures
- Access-control requirements
- Password and MFA standards
- Encryption requirements
- Device and software management
- Backup and recovery procedures
- Employee training
- Vendor oversight
- Incident response
- Physical security
- Document retention and secure disposal
- Program testing and review
Review the firm's WISP at least annually and whenever material changes affect technology, staffing, vendors, services, or risk. Learn more about developing a Written Information Security Plan.
4. Implement Layered Technical Safeguards
Policies alone do not protect taxpayer information. The firm needs technical safeguards that prevent unauthorized access, detect suspicious activity, and support rapid recovery.
A strong baseline for a 25–50 employee CPA firm generally includes the following controls.
Multi-Factor Authentication
Require MFA for Microsoft 365, remote access, tax applications, cloud systems, administrative tools, and any service containing sensitive client information. MFA should be enforced centrally rather than left to individual employees.
Endpoint Detection and Response
Use managed endpoint detection and response on every supported workstation and server. EDR provides more advanced monitoring and response capabilities than traditional signature-based antivirus alone.
Full-Disk Encryption
Encrypt laptops and other portable devices so that stored information is not easily readable if the device is lost or stolen. Recovery keys should be documented and managed securely.
Email Security
Protect email with anti-phishing controls, impersonation protection, malicious-link scanning, attachment filtering, and appropriate domain-security records. Because business email compromise often targets financial workflows, employees should also have a defined process for verifying payment or bank-account changes.
Patch and Vulnerability Management
Apply operating-system, browser, software, firewall, and firmware updates on a documented schedule. Use vulnerability scanning to identify unsupported systems, missing patches, exposed services, and insecure configurations.
Secure Backups
Maintain automated backups that are protected from alteration or deletion by ordinary user accounts. Test recovery regularly and document recovery-time and recovery-point expectations for critical systems.
Network Security
Use a business-grade firewall, secure wireless configuration, segmentation where appropriate, monitored remote access, and restricted administrative interfaces. Remove unused accounts, services, and devices.
Microsoft 365 Security
Review administrator roles, mailbox-forwarding rules, inactive accounts, external sharing, legacy authentication, device access, and alerting. Microsoft's default configuration may not reflect the firm's risk profile.
911 IT's cybersecurity services help businesses combine identity security, endpoint protection, monitoring, training, encryption, backup, and incident response into a coordinated security program.
5. Train Employees and Test Their Readiness
Employees handle taxpayer information every day, so security training should be practical, recurring, and tied to real workflows.
Training topics should include:
- Recognizing phishing and impersonation attempts
- Verifying payment and bank-account changes
- Using approved systems for sharing client documents
- Protecting passwords and MFA prompts
- Reporting suspicious email or computer behavior
- Handling taxpayer information outside the office
- Securing remote workspaces
- Following clean-desk and document-disposal procedures
- Responding to lost or stolen devices
Provide training during onboarding and reinforce it throughout the year. Quarterly micro-training and simulated phishing exercises can help the firm measure whether employees recognize common attacks.
Training records should include the date, participants, topic, and any follow-up actions. Documentation helps demonstrate that training is part of an active security program rather than an informal conversation.
6. Evaluate and Monitor Service Providers
CPA firms rely on tax software companies, cloud providers, payroll platforms, document-management systems, payment processors, outsourced bookkeepers, IT providers, and other vendors that may store or access sensitive information.
Before approving a provider, evaluate:
- What data the provider can access
- How the provider protects that data
- Whether MFA and encryption are available
- How incidents are reported
- How data is backed up and recovered
- Whether subcontractors can access information
- How data is returned or destroyed when the relationship ends
- Which security responsibilities remain with the CPA firm
Contracts should clearly define security expectations, notification responsibilities, access limitations, and data-disposal requirements. Maintain a current vendor inventory and reassess high-risk providers periodically.
7. Test, Document, and Improve the Program
A security program is only effective when the firm verifies that its safeguards work. Testing should focus on actual outcomes rather than simply confirming that a product has been purchased.
| Activity | Suggested frequency |
|---|---|
| Security-alert review | Daily or continuously |
| Critical patch deployment | As required by risk |
| Backup monitoring | Daily |
| Recovery testing | At least quarterly for critical systems |
| Vulnerability scanning | Monthly or quarterly |
| User-access review | Quarterly |
| Security awareness training | At onboarding and throughout the year |
| Incident-response exercise | At least annually |
| Risk assessment and WISP review | At least annually and after material changes |
The correct frequency depends on risk, contractual obligations, technology, and the firm's legal responsibilities. Document each review, the findings, the responsible person, and the remediation deadline.
What Should Be Included in a CPA Firm's Incident-Response Plan?
The firm should decide what it will do before ransomware, account compromise, data theft, or accidental disclosure occurs. A written incident-response plan reduces confusion and helps leadership coordinate technical, legal, insurance, regulatory, and client-communication responsibilities.
The plan should identify:
- Who employees contact when they suspect an incident
- Who has authority to isolate systems or disable accounts
- How evidence and system logs will be preserved
- How the IT provider, insurance carrier, legal counsel, and other specialists will be contacted
- Who evaluates notification and reporting obligations
- How affected systems will be restored
- How internal and external communications will be approved
- How lessons learned will be incorporated into the security program
Employees should be instructed not to investigate incidents independently, delete suspicious messages, negotiate with attackers, or communicate externally without authorization.
Common Compliance Mistakes CPA Firms Should Avoid
Using a Generic WISP Without Customizing It
A template can provide a starting point, but the final plan should reflect the firm's actual systems, vendors, roles, procedures, and controls.
Treating Compliance as an Annual Project
Security responsibilities continue throughout the year. Employee changes, software updates, vendor changes, new threats, and business growth can make last year's documentation inaccurate.
Assuming the IT Provider Handles Everything
An MSP can manage technical safeguards and assist with documentation, but firm leadership remains responsible for governance, employee conduct, legal decisions, and oversight.
Buying Security Tools Without Confirming Configuration
MFA, backups, antivirus, firewalls, and email filters provide value only when they are configured correctly, monitored, and tested.
Leaving Former Employees and Vendors Active
Delayed offboarding creates avoidable exposure. Disable accounts, revoke sessions, recover devices, change shared credentials, and review forwarding rules immediately when access is no longer required.
Failing to Test Backups
A successful backup notification does not prove that the firm can restore systems within an acceptable timeframe. Recovery testing should validate both the data and the process.
Ignoring Paper Records
Taxpayer information may exist in printed returns, handwritten notes, mail, storage rooms, and shredding bins. The security program should address physical records as well as electronic data.
The 911 IT CPA Compliance Readiness Checklist
Use this checklist to identify immediate gaps in the firm's security program.
- A qualified individual has been designated to oversee information security.
- The firm has completed a written risk assessment.
- The WISP reflects current systems, personnel, vendors, and procedures.
- MFA is required for email, remote access, cloud systems, and administrative accounts.
- Laptops and portable devices use full-disk encryption.
- Endpoints are protected by monitored EDR.
- Security updates are managed on a documented schedule.
- Microsoft 365 security settings and administrator roles are reviewed.
- Backups are automated, protected, monitored, and recovery-tested.
- Employees receive documented security training.
- Phishing simulations or other readiness tests are performed.
- User access is reviewed at least quarterly.
- Employee onboarding and offboarding procedures are documented.
- Vendors with access to sensitive information are inventoried and evaluated.
- An incident-response plan is documented and tested.
- The firm has identified legal, insurance, and technical incident contacts.
- Paper records are stored and destroyed securely.
- The security program is reviewed after material business or technology changes.
Real Accounting Client Experience: Compliance Support and Peace of Mind
One accounting-industry client described 911 IT as an invaluable partner for meeting IRS and payment-security requirements. The client emphasized the value of having a team that understood the firm's environment, implemented backend security protocols, and could respond without requiring the firm to explain its entire setup during every issue.
“If you're serious about protecting client data and want a reliable IT partner who truly understands compliance, 911 IT is the way to go.”
Another financial-industry client said 911 IT's proactive approach helped the firm plan for remote work before an unexpected shutdown occurred during tax season. Because the technology plan was already in place, the firm was better prepared to maintain operations during a high-pressure period.
These experiences illustrate an important distinction: effective compliance support is not limited to producing a policy document. It requires a provider that understands the environment, helps implement safeguards, follows through on identified issues, and prepares the firm for future disruptions.
How 911 IT Helps CPA Firms Strengthen Security and Compliance
911 IT provides IT support for CPAs and financial firms with an emphasis on cybersecurity, availability, secure remote work, backup, and regulatory readiness.
Support may include:
- Technology and cybersecurity risk assessments
- WISP development and maintenance assistance
- Multi-factor authentication deployment
- Endpoint detection and response
- Microsoft 365 security reviews
- Email and phishing protection
- Security awareness training
- Vulnerability and patch management
- Encryption and device-management controls
- Backup monitoring and recovery testing
- Vendor-security coordination
- Incident-response planning
- Ongoing technology strategy
911 IT has served businesses since 2004 and provides 24/7 access to technical support, proactive monitoring, local assistance, and a 100% money-back guarantee. Read additional feedback from 911 IT clients.
Frequently Asked Questions
Does the FTC Safeguards Rule apply to CPA firms?
It may apply to a CPA or tax firm when the firm is considered a covered financial institution under the Rule. Tax preparation is among the financial activities commonly associated with the Rule, but each firm should confirm its status and obligations with qualified legal or compliance counsel.
Is IRS Publication 4557 a law?
IRS Publication 4557 is guidance for tax professionals on safeguarding taxpayer information. It helps firms understand practical security measures, but it does not replace applicable laws, regulations, contractual obligations, or professional advice.
What is the difference between a WISP and a risk assessment?
A risk assessment identifies sensitive information, threats, vulnerabilities, existing controls, and required improvements. A WISP documents the overall security program, including policies, responsibilities, safeguards, training, vendor oversight, and incident response. The risk assessment informs the WISP.
How often should a CPA firm update its WISP?
The firm should review the WISP at least annually and after material changes such as new software, new locations, acquisitions, staffing changes, new vendors, significant incidents, or changes in legal obligations.
Does having cyber insurance mean the firm is compliant?
No. Cyber insurance transfers a portion of financial risk, but it does not replace security controls, policies, training, oversight, or legal compliance. The insurer may also require the firm to maintain specific safeguards as a condition of coverage.
Is MFA enough to protect taxpayer data?
MFA is an essential safeguard, but it is only one layer. CPA firms also need endpoint protection, email security, encryption, patching, backups, access management, employee training, monitoring, vendor oversight, and incident-response procedures.
Can an MSP write our WISP for us?
An MSP can help document technical controls, identify risks, and organize the plan. Firm leadership and qualified legal or compliance advisors should review the final document to confirm that it accurately reflects the business and its obligations.
What should a CPA firm do first?
Begin by appointing a responsible security leader and completing a written risk assessment. Those steps establish ownership and identify which policies, safeguards, and remediation projects should be addressed first.
Build a Practical Compliance Roadmap for Your CPA Firm
FTC Safeguards Rule and IRS Publication 4557 readiness should produce more than a binder of policies. The goal is a working security program that protects taxpayer data, supports employees, withstands disruption, and improves as the firm's risks change.
Schedule a discovery call with 911 IT to discuss your current security controls, Written Information Security Plan, backup strategy, Microsoft 365 environment, employee training, and compliance priorities.
