CPA Firms Should Verify 10 Core Cybersecurity Controls Before Tax Season
Before tax season begins, a CPA firm should verify 10 essential cybersecurity controls: multi-factor authentication, endpoint detection and response, email security, secure backups, patch management, vulnerability scanning, encryption, access control, employee security training, and an incident-response plan.
For a firm with 25–50 employees, these controls should protect every employee account, workstation, laptop, server, cloud application, remote-access method, and location used to handle taxpayer information. Critical safeguards should be monitored continuously, backups should be checked daily and recovery-tested regularly, access rights should be reviewed at least quarterly, and the overall security program should be formally reviewed at least once a year.
The goal is not to eliminate every possible risk. It is to reduce the likelihood that a stolen password, phishing email, unpatched computer, lost laptop, or failed backup will become a firm-wide emergency during the busiest time of the year.
Why CPA Firms Face Greater Cybersecurity Risk During Tax Season
CPA firms hold information that criminals can use for identity theft, tax fraud, account takeover, extortion, and financial theft. This may include:
- Social Security numbers
- Tax returns and supporting documents
- Bank and routing information
- Payroll records
- Employee information
- Business financial statements
- Copies of identification documents
- Electronic signatures
- Client portal credentials
- Email conversations involving payments and financial decisions
Tax season also creates urgency. Employees process more email, exchange more documents, work longer hours, use remote access more frequently, and may feel pressure to complete requests quickly. Attackers can exploit that pressure with fake client messages, fraudulent document-sharing notifications, false MFA prompts, impersonated executive requests, and malicious attachments.
A strong security program accounts for both technology and human behavior. Buying a collection of security products is not enough. The firm needs clear procedures, assigned responsibilities, ongoing monitoring, employee training, and tested recovery plans.
The 911 IT 10-Point CPA Tax Season Security Framework
Use the following framework to evaluate whether the firm's safeguards are ready before employees begin processing peak-season workloads.
1. Require Multi-Factor Authentication Everywhere It Is Available
Multi-factor authentication, commonly called MFA, requires users to provide an additional form of verification beyond a password. It should be required for:
- Microsoft 365 and business email
- Tax preparation software
- Cloud accounting applications
- Client portals
- Remote desktop and VPN access
- Password managers
- Backup administration
- Firewall and network administration
- Domain and website management
- Any system containing taxpayer or financial information
MFA should be enforced through centralized policies rather than relying on employees to activate it voluntarily. Administrative accounts require particular attention because a compromised administrator may be able to access multiple users, systems, or security settings.
The firm should also train employees to reject unexpected MFA prompts. Repeated prompts can indicate that someone already has the employee's password and is attempting to persuade the user to approve access.
2. Protect Every Workstation and Server With Managed EDR
Traditional antivirus software looks primarily for known malicious files. Endpoint detection and response, or EDR, monitors computer behavior and can help identify suspicious activity such as ransomware execution, unauthorized software, credential theft, unusual command-line activity, or attempts to disable security tools.
Before tax season, confirm that EDR is:
- Installed on every supported desktop, laptop, and server
- Actively communicating with the management platform
- Receiving current policies and updates
- Monitored by qualified personnel
- Configured to isolate a device when serious activity is detected
- Protected from removal by ordinary users
- Included in employee onboarding and device-replacement procedures
A security product that is installed but not monitored may generate warnings without ensuring that anyone investigates them. Learn how 911 IT's cybersecurity services combine endpoint protection with broader security monitoring and management.
3. Secure Email and Microsoft 365
Email is central to client communication, document exchange, billing, payroll, and financial approvals. It is also one of the most common entry points for phishing, credential theft, malware, and business email compromise.
A pre-tax-season Microsoft 365 and email review should include:
- MFA enforcement
- Administrator-role review
- Removal of inactive accounts
- Disabling unsupported or unnecessary authentication methods
- Reviewing mailbox-forwarding rules
- Monitoring suspicious sign-ins
- Restricting high-risk external sharing
- Configuring anti-phishing and impersonation protection
- Scanning links and attachments
- Protecting the firm's email domain against spoofing
- Reviewing third-party applications connected to employee accounts
The firm should also establish a separate verification procedure for requests involving payments, bank-account changes, payroll updates, tax documents, or sensitive client information. Employees should never rely on email alone when a request is unusual or financially significant.
4. Maintain Protected Backups and Test Recovery
Backups are the firm's last line of defense against ransomware, hardware failure, accidental deletion, application corruption, and other forms of data loss. However, a successful backup notification does not prove that systems can be restored within the required timeframe.
The firm should be able to answer six questions:
- Which systems and cloud services are backed up?
- How frequently do backups run?
- How long is information retained?
- Can compromised administrator credentials delete the backups?
- When was the last successful recovery test?
- How long would it take to restore each critical system?
At least one backup copy should be protected from alteration or deletion through ordinary user and network credentials. Recovery testing should include more than restoring an individual file. The firm should periodically validate that critical applications, databases, permissions, and supporting systems can be restored together.
Review business continuity services to understand how backup, disaster recovery, and operational planning work together.
5. Patch Systems and Remove Unsupported Software
Operating systems, browsers, tax applications, PDF software, firewalls, wireless equipment, and other business tools can contain vulnerabilities that attackers exploit. Patch management reduces that exposure by applying security updates on a controlled schedule.
Before tax season:
- Install outstanding critical security updates.
- Replace or isolate unsupported operating systems.
- Update browsers and commonly targeted applications.
- Confirm that servers and workstations are checking in with the patch-management platform.
- Review firewall and network-device firmware.
- Remove software employees no longer need.
- Document applications that cannot be updated because of vendor dependencies.
- Create a plan for emergency patches during tax season.
Updates should be tested when necessary, but firms should not postpone security patches indefinitely because a system is busy. The IT provider and firm leadership should agree on maintenance windows, restart procedures, and communication expectations before peak season.
6. Scan for Vulnerabilities and Correct High-Risk Findings
Vulnerability scanning helps identify exposed services, missing updates, unsupported systems, insecure configurations, weak encryption, and other technical weaknesses.
A useful vulnerability-management process should:
- Identify all relevant devices and systems.
- Scan them on a recurring schedule.
- Prioritize findings by risk and business impact.
- Assign each remediation task to an owner.
- Set a target completion date.
- Verify that the correction was successful.
- Document accepted risks and compensating safeguards.
Not every finding presents the same risk. A vulnerability on an internet-facing system containing client information typically deserves faster attention than a low-risk issue on an isolated device. The firm's risk assessment should guide priorities.
7. Encrypt Sensitive Information and Portable Devices
Encryption makes information unreadable without the appropriate key or authorized account. CPA firms should consider encryption for taxpayer information stored on devices, transmitted over networks, shared through portals, and retained in backups.
Before tax season, verify that:
- Laptops use full-disk encryption.
- Encryption recovery keys are stored securely.
- Portable storage is restricted or encrypted.
- Remote connections use secure protocols.
- Sensitive files are shared through approved systems rather than ordinary email attachments.
- Backup data is encrypted.
- Lost or stolen managed devices can be disabled or wiped when appropriate.
One 911 IT client specifically highlighted the value of device encryption, explaining that important information would be unusable to a thief if the computer were stolen. That is the practical outcome encryption is intended to provide.
8. Apply Least-Privilege Access and Review User Accounts
Employees should have access to the information and systems required for their jobs, but they should not automatically receive broad administrator rights or access to every client file.
A pre-season access review should cover:
- Active employees and seasonal staff
- Former employees and contractors
- Shared accounts
- Local administrator rights
- Microsoft 365 administrator roles
- Tax-software permissions
- File shares and document-management systems
- Client portals
- Remote-access permissions
- Vendor and third-party access
Seasonal employees should receive access based on their roles and defined employment dates. Their access should be removed promptly when the engagement ends.
The firm should maintain documented onboarding, role-change, and offboarding checklists so that access changes do not depend on memory or informal email requests.
9. Train Employees and Conduct Phishing Tests
Technical controls can block many attacks, but employees still need to recognize suspicious requests and know how to report them.
Tax-season security training should teach employees how to:
- Identify fake client and executive messages
- Inspect document-sharing and login links
- Recognize fraudulent MFA prompts
- Verify changes to payment or banking details
- Use approved systems for taxpayer information
- Protect devices while working remotely
- Report suspicious messages immediately
- Respond to a lost device or accidental disclosure
- Avoid unapproved software and browser extensions
- Handle printed taxpayer documents securely
Training should be provided during onboarding and reinforced throughout the year. Short, recurring lessons and simulated phishing exercises can help the firm identify areas where additional coaching is needed.
Employees should be encouraged to report suspicious activity without fear of embarrassment. Early reporting can prevent one mistaken click from becoming a larger incident.
10. Document and Test an Incident-Response Plan
The firm should decide how it will respond before an account compromise, ransomware infection, lost laptop, fraudulent payment request, or data exposure occurs.
The incident-response plan should identify:
- How employees report suspected incidents
- Who has authority to disable accounts or isolate devices
- How the IT provider is contacted after hours
- How logs and other evidence are preserved
- When cyber insurance, legal counsel, and other specialists are contacted
- Who evaluates notification and reporting responsibilities
- How critical systems are restored
- Who approves communications with employees, clients, regulators, or the public
- How the firm documents lessons learned after the incident
At least once a year, leadership should conduct a tabletop exercise. Present a realistic scenario and walk through the firm's decisions. The exercise often reveals missing phone numbers, unclear authority, outdated vendor contacts, and assumptions about backup recovery that should be corrected before a real emergency.
How Often Should CPA Cybersecurity Controls Be Reviewed?
Security controls do not all require the same review frequency. The following schedule provides a practical starting point, but the firm's legal, contractual, insurance, and operational requirements may call for more frequent action.
| Security activity | Suggested frequency |
|---|---|
| Security monitoring and alert review | Continuously |
| Backup-job review | Daily |
| Critical security patches | As soon as practical based on risk |
| Endpoint and security-tool health review | Weekly |
| Vulnerability scanning | Monthly or quarterly |
| Backup recovery testing | At least quarterly for critical systems |
| User and administrator access review | Quarterly |
| Security awareness training | At onboarding and throughout the year |
| Incident-response exercise | At least annually |
| Risk assessment and WISP review | At least annually and after material changes |
The Most Common Security Gaps CPA Firms Should Check
A pre-tax-season assessment frequently focuses on gaps that are easy to overlook during normal business operations.
MFA Is Enabled for Some Accounts but Not All
Email may be protected while tax software, remote-access systems, backup consoles, or administrator accounts remain exposed.
Former Employees Still Have Active Access
Inactive accounts, forwarding rules, remembered browser sessions, and shared passwords may continue working after an employee leaves.
Employees Have Unnecessary Administrator Rights
Local administrator access can allow malicious software or unauthorized applications to make significant changes to a device.
Backups Have Never Been Fully Restored
A firm may know that backups run every night without knowing whether a server, application database, or Microsoft 365 mailbox can be restored successfully.
Microsoft 365 Uses Default Security Settings
Default settings may not reflect the firm's sensitivity, employee roles, remote-work practices, or compliance responsibilities.
Unsupported Computers Remain in Service
Older systems may continue operating but no longer receive the security updates required to protect them.
Security Training Is Limited to an Annual Video
Employees benefit from short, recurring lessons tied to current threats and the firm's actual workflows.
The WISP Does Not Match the Technology Environment
A Written Information Security Plan may mention controls that were never implemented or omit systems that were added after the document was written.
CPA firms reviewing their documentation can learn more about creating a practical Written Information Security Plan.
What Should a Pre-Tax-Season Cybersecurity Assessment Cover?
A useful assessment should evaluate the complete environment rather than checking only antivirus and firewall status.
The review should include:
- Identity security: MFA, passwords, administrator roles, inactive users, and sign-in monitoring.
- Endpoint security: EDR, encryption, patching, device inventory, and unsupported systems.
- Email and cloud security: Microsoft 365 settings, phishing protection, forwarding rules, sharing, and connected applications.
- Network security: Firewalls, wireless configuration, remote access, segmentation, and exposed services.
- Data protection: File permissions, client portals, encryption, retention, and secure disposal.
- Backup and recovery: Backup scope, retention, immutability, monitoring, and restoration testing.
- Employee readiness: Training, phishing tests, reporting procedures, and remote-work practices.
- Governance: Risk assessments, WISP documentation, vendor oversight, and assigned responsibilities.
- Incident response: Contacts, authority, insurance coordination, evidence preservation, and recovery procedures.
- Business continuity: The firm's ability to work through equipment failure, application outages, internet disruption, or a cybersecurity incident.
The 911 IT CPA Tax Season Security Checklist
Use this checklist before peak filing activity begins:
- MFA is required for email, remote access, tax software, cloud applications, and administrator accounts.
- Every active workstation, laptop, and server is protected by monitored EDR.
- Microsoft 365 administrator roles and suspicious sign-ins have been reviewed.
- Email anti-phishing and impersonation safeguards are active.
- Employees know how to verify financial and taxpayer-information requests.
- Critical operating systems, applications, firewalls, and network devices are patched.
- Unsupported systems have been replaced, isolated, or covered by a documented remediation plan.
- Vulnerability scans have been completed and high-risk findings assigned for correction.
- Portable devices use full-disk encryption.
- Recovery keys are stored securely.
- Backup jobs are monitored daily.
- Critical systems have passed a documented recovery test.
- Backup copies are protected from unauthorized deletion or alteration.
- Former employee and vendor accounts have been disabled.
- Seasonal staff access is limited by role and employment period.
- Employees have completed current security training.
- A phishing simulation or readiness test has been performed.
- The incident-response contact list is current.
- The firm has completed an incident-response tabletop exercise.
- The risk assessment and WISP reflect the current environment.
Real Client Experience: Finding and Fixing Security Risks
One business owner described the value of completing a security audit with 911 IT. The assessment identified security issues and provided a path to correct them, giving the owner greater confidence that systems and data were protected.
“By doing a security audit, I was able to not only find the security issues, I was also able to fix the issues. I sleep better knowing my systems and data are safe.”
Another accounting client emphasized the importance of having an IT partner that understood IRS and payment-security requirements, knew the firm's environment, and could assist with both everyday issues and serious incidents. The client described that compliance expertise and familiarity as a source of meaningful peace of mind.
These experiences demonstrate why an assessment should produce more than a report. Each significant finding should result in a responsible owner, a priority, a remediation plan, and verification that the problem was corrected.
How 911 IT Helps CPA Firms Prepare for Tax Season
911 IT provides IT support for CPAs and financial firms that combines cybersecurity, responsive help desk service, business continuity, Microsoft 365 administration, and strategic technology planning.
Support may include:
- Cybersecurity and technology risk assessments
- MFA deployment and identity-security reviews
- Managed endpoint detection and response
- Email and Microsoft 365 security
- Security awareness training
- Vulnerability and patch management
- Device encryption
- Backup monitoring and recovery testing
- Written Information Security Plan support
- Incident-response planning
- Vendor coordination
- 24/7 technical support
- Ongoing technology strategy and budgeting
911 IT has supported businesses since 2004 and emphasizes instant access to technicians, proactive cybersecurity, clear technology planning, and service backed by a 100% satisfaction guarantee. :contentReference[oaicite:0]{index=0}
Read additional feedback from 911 IT clients.
Frequently Asked Questions
What is the most important cybersecurity control for a CPA firm?
No single control is sufficient, but MFA is one of the most important starting points because stolen passwords are a major risk. MFA should be combined with EDR, email security, patching, secure backups, access control, employee training, and monitoring.
When should a CPA firm complete its tax-season security review?
Begin the formal review 60–90 days before the firm's busiest period whenever possible. That provides time to replace unsupported equipment, correct high-risk findings, test backups, train employees, and resolve application dependencies without making rushed changes.
Is antivirus enough for an accounting firm?
No. Antivirus is only one layer. CPA firms should also protect identities, email, cloud systems, endpoints, networks, backups, remote access, and employees. Modern security programs often use managed EDR rather than relying solely on traditional antivirus.
How often should backups be tested?
Backup jobs should be monitored daily, and critical systems should undergo documented recovery testing regularly. Quarterly testing is a practical baseline for many firms, while particularly critical systems may require more frequent validation.
Should every employee use MFA?
Yes. MFA should be required for every employee and contractor accessing business email, remote systems, cloud applications, or taxpayer information. Administrative and privileged accounts require especially strong protection.
Do seasonal tax employees need the same security controls?
Seasonal employees should receive the same baseline protections, including MFA, managed endpoint security, training, and approved devices. Their access should be limited to what their roles require and removed promptly when employment ends.
How often should CPA firms conduct security training?
Provide training during onboarding and reinforce it throughout the year. Quarterly training or short monthly reminders can help employees retain the information and adapt to changing phishing techniques.
What should an employee do after clicking a suspicious link?
The employee should stop interacting with the message and contact the designated IT or security team immediately. Fast reporting allows the team to review the device, disable affected sessions, reset credentials, inspect mailbox activity, and contain the incident.
Does a cybersecurity assessment make a CPA firm compliant?
No. An assessment identifies risks and recommended improvements. Compliance requires the firm to implement appropriate safeguards, maintain documentation, train employees, oversee vendors, test the program, and update it as risks and operations change.
Can a CPA firm improve security during tax season?
Yes, especially when an urgent risk exists. However, major infrastructure changes should be carefully planned. During peak season, prioritize critical safeguards and stability, then schedule lower-priority projects after major filing deadlines.
Prepare Your CPA Firm Before Tax Season Begins
The best time to discover a failed backup, inactive security tool, exposed account, or unsupported system is before tax season. A structured review gives the firm time to correct problems, test recovery, prepare employees, and document how incidents will be handled.
Schedule a discovery call with 911 IT to discuss a cybersecurity and tax-season readiness assessment for your CPA firm.
