A CPA Firm Should Take Seven Immediate Actions After a Cybersecurity Incident
After discovering a suspected cybersecurity incident, a CPA firm should take seven immediate actions: report the incident, contain affected systems, preserve evidence, protect employee and client accounts, activate the response team, assess the scope, and begin controlled recovery.
The first 15–60 minutes can significantly affect the outcome. Employees should contact the firm’s designated IT or security provider immediately, stop interacting with suspicious messages or devices, and avoid deleting files, restarting systems, or conducting their own investigation unless instructed to do so.
A firm with 25–50 employees should already have a written incident-response plan that identifies decision-makers, technical contacts, legal counsel, cyber insurance contacts, communication responsibilities, and backup-recovery procedures. The goal is to contain the threat without destroying evidence or making rushed changes that increase downtime.
What Is Considered a Cybersecurity Incident?
A cybersecurity incident is any event that may compromise the confidentiality, integrity, or availability of the firm’s systems or information.
Examples include:
- An employee enters a password into a phishing website.
- An unexpected multi-factor authentication request is approved.
- A Microsoft 365 account begins sending suspicious messages.
- Taxpayer information is sent to the wrong recipient.
- A laptop containing client information is lost or stolen.
- Files are encrypted by ransomware.
- An employee discovers unauthorized mailbox-forwarding rules.
- A server or cloud application shows unusual administrator activity.
- A fraudulent payment or bank-account change is requested.
- A vendor reports that its systems were compromised.
- Backup data is deleted or altered unexpectedly.
- A former employee continues accessing firm systems.
Employees should report suspicious events even when they are uncertain that an incident occurred. Early investigation is less costly than waiting for visible damage.
The 911 IT Seven-Step CPA Incident Response Framework
Use the following framework to guide the firm’s initial response, investigation, recovery, and improvement process.
1. Report the Incident Immediately
The employee who discovers the problem should contact the designated IT or security team using the firm’s established emergency channel.
The report should include:
- The employee’s name and contact information
- The affected device or account
- What the employee observed
- When the activity occurred
- Whether a link or attachment was opened
- Whether credentials or MFA approval were provided
- Whether money or information was transferred
- Whether the device is still connected to the network
The employee should not feel pressured to determine whether the event is serious. The response team should make that assessment.
911 IT provides 24/7 access to technical support so suspicious activity can be reported outside normal business hours, including evenings and weekends during tax season.
2. Contain the Affected Device, Account, or System
Containment limits the attacker’s ability to access additional information, spread malware, or disrupt more systems.
Depending on the incident, the response team may:
- Isolate a workstation or server from the network.
- Disable a Microsoft 365 or application account.
- Revoke active login sessions.
- Reset passwords and authentication tokens.
- Block malicious email senders, links, domains, or internet addresses.
- Disable compromised remote-access methods.
- Restrict affected file shares.
- Temporarily suspend a vendor integration.
- Separate infected systems from backup infrastructure.
Employees should not disconnect, power off, or restart a suspected device unless instructed. In some situations, isolating the device while leaving it powered on may preserve information needed for the investigation.
3. Preserve Evidence and Document Every Action
Incident evidence may be needed to determine what happened, identify affected information, support insurance requirements, or assist legal and regulatory analysis.
The response team should preserve relevant information such as:
- Email messages and headers
- Login and audit logs
- Endpoint-security alerts
- Firewall and network logs
- Cloud application activity
- Mailbox rules and delegated access
- Files created, modified, encrypted, or deleted
- Employee notes and screenshots
- Vendor notifications
- A timeline of containment and recovery actions
Every significant action should be recorded with the date, time, responsible person, and reason. This creates a defensible timeline and reduces confusion when several technical, legal, insurance, and leadership teams are involved.
4. Protect Identities, Email, and Financial Workflows
Account compromise can extend beyond one password. An attacker may create forwarding rules, register new authentication methods, access connected applications, impersonate employees, or target clients and vendors.
For a suspected account compromise, review:
- Recent sign-ins and geographic locations
- Active sessions
- Multi-factor authentication methods
- Mailbox-forwarding and inbox rules
- Email delegation
- Administrator-role changes
- Third-party application access
- Recently sent and deleted messages
- File-sharing activity
- Password changes and recovery information
The firm should also review financial activity when the compromised account could approve or influence:
- Wire transfers
- ACH payments
- Payroll changes
- Vendor banking updates
- Client refunds
- Tax payments
- Purchasing activity
Any unusual transaction should be verified through a trusted telephone number or established secondary channel rather than replying to the original message.
Learn how managed cybersecurity services can help protect identities, email, endpoints, cloud services, and financial workflows.
5. Activate the Incident Response Team
A cybersecurity incident may require more than technical support. The firm’s response plan should identify when to involve:
- Firm leadership
- The managed IT or security provider
- Internal privacy or compliance personnel
- Legal counsel
- Cyber insurance
- Digital forensics specialists
- Public relations or communications support
- Law enforcement
- Software and cloud vendors
- Banking and payment partners
The firm should avoid making public statements or sending broad client notices before the relevant facts are known and appropriate advisors have been consulted.
Cyber insurance policies often contain specific reporting, consent, vendor, and documentation requirements. The designated policy contact should review those requirements early in the response.
6. Determine the Scope and Business Impact
The response team should determine what happened, when it began, which systems were affected, what information may have been accessed, and whether the threat remains active.
The investigation should seek answers to questions such as:
- How did the attacker gain access?
- Which users, devices, servers, or applications were involved?
- When did unauthorized activity begin?
- Which files or records were viewed, changed, downloaded, or deleted?
- Were administrative privileges obtained?
- Did the attacker access email, cloud storage, or client portals?
- Did the activity spread to other systems?
- Were backups affected?
- Was information sent outside the firm?
- Is the initial entry point still available?
The assessment should also measure operational impact:
- Number of affected employees
- Unavailable applications
- Delayed client work
- Missed or threatened filing deadlines
- Estimated recovery time
- Financial transactions requiring review
- Vendors or clients requiring coordination
A clear scope allows leadership to prioritize recovery and make informed communication decisions.
7. Recover Systems in a Controlled Order
Recovery should begin only after the response team has contained the known threat and identified the conditions required to restore systems safely.
A typical recovery sequence may include:
- Remove the attacker’s access.
- Correct the initial security weakness.
- Reset affected credentials and authentication methods.
- Rebuild or clean compromised devices.
- Verify that endpoint, email, and identity protections are active.
- Restore critical data from known-good backups.
- Test tax, accounting, document, and communication workflows.
- Return employees to service in stages.
- Monitor closely for recurring suspicious activity.
The firm should prioritize systems according to business importance rather than restoring everything simultaneously.
For many CPA firms, the recovery order may be:
- Identity and authentication services
- Email and internal communication
- Tax and accounting applications
- Document-management systems
- Client portals and secure file exchange
- Shared files and supporting applications
- Lower-priority archives and secondary systems
Review business continuity services to understand how backup protection, recovery testing, and operational planning support incident recovery.
What Should an Employee Do After Clicking a Phishing Link?
An employee who clicks a suspicious link should take the following five actions:
- Stop interacting with the website or message.
- Contact the designated IT or security team immediately.
- State whether a password, code, document, or payment information was entered.
- Leave the device powered on unless instructed otherwise.
- Remain available to answer questions about what occurred.
The employee should not attempt to conceal the mistake, delete the email, or wait to see whether anything happens. A password entered on a fraudulent website can be used within minutes.
The technical response may include:
- Resetting the password
- Revoking active sessions
- Reviewing MFA methods
- Inspecting mailbox rules
- Scanning or isolating the device
- Reviewing sign-in history
- Searching for similar messages sent to other employees
- Blocking the malicious website
What Should a CPA Firm Do After a Business Email Compromise?
Business email compromise occurs when an attacker uses or impersonates a trusted email account to steal information or influence financial activity.
The firm should immediately:
- Disable or secure the affected account.
- Revoke all active sessions.
- Reset the password and authentication methods.
- Remove unauthorized forwarding and inbox rules.
- Review administrator and delegated access.
- Examine sent, deleted, and archived messages.
- Identify clients, employees, or vendors contacted by the attacker.
- Review payment and bank-account changes.
- Notify the firm’s financial institution when fraud may have occurred.
- Preserve email and login evidence.
The firm should use a trusted communication method to warn affected parties about fraudulent requests. Do not rely solely on the compromised email account for that notification.
What Should a CPA Firm Do After a Ransomware Attack?
A ransomware response requires rapid containment and careful recovery. The firm should not begin restoring data until the attacker’s access and malware persistence have been addressed.
Immediate actions may include:
- Isolating affected devices and network segments
- Protecting backup systems from further access
- Disabling compromised accounts
- Contacting the incident-response team and cyber insurer
- Preserving ransom notes, logs, alerts, and system evidence
- Determining which systems and data were affected
- Assessing whether information was stolen before encryption
- Identifying clean recovery points
- Rebuilding affected systems
- Testing restored applications and data
Payment decisions should be made with qualified legal, insurance, technical, and law-enforcement guidance. Paying a demand does not guarantee recovery, deletion of stolen information, or protection from another attack.
What Should a CPA Firm Do After Sending Client Information to the Wrong Person?
An accidental disclosure should be treated as a security incident even when the recipient appears trustworthy.
The firm should:
- Report the disclosure immediately.
- Identify exactly what was sent.
- Determine whether the recipient opened, downloaded, or forwarded it.
- Revoke access when the sharing platform permits it.
- Ask the recipient to delete the information without retaining copies.
- Preserve the email, sharing records, and communications.
- Consult appropriate legal or compliance advisors.
- Document corrective actions.
The firm should avoid assuming that an apology or deletion request resolves every responsibility. The content, recipient, exposure, applicable requirements, and evidence of access should be reviewed.
What Should a CPA Firm Do After a Laptop Is Lost or Stolen?
The employee should report the missing device immediately and provide the last known location, time, and circumstances.
The response team should determine whether:
- The laptop uses full-disk encryption.
- The device is protected by a strong password.
- Remote management is active.
- The device can be locked or wiped.
- Sensitive information was stored locally.
- The browser or applications contained active sessions.
- The employee’s credentials require reset.
- Law enforcement or insurance should be contacted.
Encryption can significantly reduce the risk that information on a stolen device will be readable, but the firm should still document the event and assess the circumstances.
A Four-Hour Cybersecurity Incident Response Timeline
The exact response will depend on the event, but the following timeline provides a practical model.
| Time from discovery | Priority actions |
|---|---|
| First 15 minutes | Report the incident, record initial facts, and contact the response team |
| 15–30 minutes | Isolate affected devices or accounts and preserve immediate evidence |
| 30–60 minutes | Assess early scope, protect related accounts, and notify leadership |
| 1–2 hours | Engage legal, insurance, vendors, or forensics when required |
| 2–4 hours | Confirm containment, begin detailed investigation, and plan recovery |
| After 4 hours | Continue investigation, restore prioritized systems, and issue approved communications |
The firm should not delay containment while waiting for a complete understanding of the incident. Initial actions can be adjusted as new evidence becomes available.
Who Should Be on a CPA Firm’s Incident Response Team?
A 25–50 employee CPA firm may not have a full-time internal security department, but it should still assign specific response roles.
| Role | Primary responsibility |
|---|---|
| Executive leader | Approves major business, financial, and communication decisions |
| Incident coordinator | Maintains the timeline, assigns actions, and coordinates participants |
| IT or security provider | Contains the threat, investigates systems, and manages technical recovery |
| Legal counsel | Advises on legal obligations, privilege, contracts, and communications |
| Cyber insurance contact | Coordinates policy reporting and approved response resources |
| Communications lead | Prepares approved employee, client, vendor, and public messaging |
| Business operations lead | Prioritizes applications, workflows, deadlines, and continuity needs |
Names, telephone numbers, backup contacts, and after-hours instructions should be stored somewhere accessible even when normal systems are unavailable.
What Information Should Be Included in an Incident Log?
The incident coordinator should maintain a central record containing:
- Date and time of discovery
- Person who reported the incident
- Initial symptoms
- Affected users, devices, and systems
- Containment actions
- Accounts disabled or reset
- Evidence preserved
- People and organizations contacted
- Investigation findings
- Recovery actions
- Communication decisions
- Costs and business impact
- Remaining risks
- Post-incident improvements
The log should distinguish confirmed facts from assumptions. Entries should be updated as the investigation changes the team’s understanding.
How Should Client and Employee Communications Be Managed?
Incident communications should be accurate, timely, and approved by the appropriate response leaders. Early statements based on incomplete information can create unnecessary confusion or require correction later.
Internal updates should explain:
- Which systems are unavailable
- What employees should and should not do
- How support requests should be submitted
- Whether alternative workflows are available
- When the next update will be provided
External communications may need to address:
- What occurred
- Which services or information were affected
- What containment and recovery actions were taken
- What recipients should do
- How they can obtain additional information
The firm should coordinate external notices with qualified legal and insurance advisors when appropriate.
How Can a CPA Firm Continue Working During an Incident?
Business continuity procedures should identify alternative ways to complete essential work while affected systems are investigated or restored.
Possible temporary procedures include:
- Using approved secondary communication channels
- Moving unaffected employees to a secure remote environment
- Restoring critical applications to recovery infrastructure
- Prioritizing work according to filing deadlines
- Using documented manual procedures temporarily
- Redirecting client communications to unaffected staff
- Coordinating extensions or revised timelines when necessary
Temporary processes should still protect taxpayer information. Employees should not move sensitive data to personal email accounts, unmanaged computers, consumer storage services, or unauthorized applications simply to restore convenience.
Common Incident Response Mistakes
Waiting for Proof Before Reporting
Suspicious activity should be reported immediately. The response team can determine whether the event is harmless or requires escalation.
Restarting or Reimaging Devices Too Soon
Premature changes may destroy evidence or remove information needed to understand the attack.
Using the Compromised Account to Communicate
An attacker may still be monitoring the account. Use a trusted alternative channel.
Resetting Only One Password
The response should also review sessions, authentication methods, forwarding rules, administrator changes, and connected applications.
Restoring Systems Before Closing the Entry Point
A restored system can be compromised again when the original weakness remains available.
Failing to Contact Cyber Insurance Early
Delayed reporting may complicate access to approved legal, forensic, recovery, and communication resources.
Making Broad Statements Before Facts Are Confirmed
Communications should be coordinated and based on the best available evidence.
Returning to Normal Without a Post-Incident Review
The firm should identify what failed, what worked, and which improvements will reduce the chance or impact of recurrence.
The 911 IT CPA Incident Response Checklist
Immediate Response
- Report the suspected incident immediately.
- Record the initial facts and time of discovery.
- Contact the IT or security response team.
- Isolate affected devices, accounts, or systems.
- Preserve logs, messages, alerts, and other evidence.
- Protect related employee and administrator accounts.
Escalation and Investigation
- Notify firm leadership.
- Contact cyber insurance when appropriate.
- Engage legal counsel or forensics when required.
- Determine the incident’s entry point and duration.
- Identify affected systems and information.
- Review financial transactions and communication activity.
- Maintain a detailed incident timeline.
Recovery
- Remove unauthorized access.
- Correct the exploited security weakness.
- Reset affected credentials and authentication methods.
- Rebuild compromised devices when necessary.
- Restore data from verified backups.
- Test tax, accounting, document, and communication workflows.
- Monitor for recurring suspicious activity.
After the Incident
- Complete required and approved communications.
- Document the business and financial impact.
- Conduct a post-incident review.
- Update the incident-response plan.
- Correct technology, policy, and training gaps.
- Repeat employee training when appropriate.
- Test the revised response plan.
How to Prepare Before an Incident Happens
The quality of the response depends heavily on preparation completed before the event.
Every CPA firm should have:
- A written incident-response plan
- Current emergency contact information
- Defined decision-making authority
- A cyber insurance policy review
- Qualified legal and technical contacts
- Centralized system and vendor documentation
- Managed endpoint and identity security
- Protected backups
- Documented recovery priorities
- Employee reporting procedures
- Annual tabletop exercises
The incident-response plan should align with the firm’s Written Information Security Plan and broader risk-management program.
What Is an Incident Response Tabletop Exercise?
A tabletop exercise is a guided discussion in which firm leaders and technical advisors work through a simulated incident.
A 60–90 minute exercise might present this scenario:
A partner’s Microsoft 365 account is compromised during tax season. The attacker sends fraudulent payment instructions to three clients and creates a hidden mailbox-forwarding rule.
Participants should discuss:
- How the incident is reported
- Who disables the account
- How clients are contacted
- When cyber insurance is notified
- Which logs are preserved
- Who approves external communications
- How the partner continues working
- What corrective actions are required
The exercise should produce an improvement list with assigned owners and completion dates.
Real Client Scenario: Rapid Support Reduces Business Disruption
911 IT clients frequently emphasize the value of receiving immediate assistance when technical problems affect business operations. One client described the difference between waiting hours or days for support and reaching a team that responds promptly and takes ownership of the issue.
“Their responses are prompt, their support is collaborative, and they actually solve the problem the first time.”
That responsiveness is especially important during a security incident. Fast containment can limit unauthorized access, reduce the number of affected systems, preserve evidence, and allow recovery to begin sooner.
The most valuable response partner is not only available during an emergency. It also helps the firm prepare through monitoring, backup testing, employee training, documentation, and incident-response exercises.
How 911 IT Helps CPA Firms Prepare for and Respond to Cybersecurity Incidents
911 IT provides managed IT services and cybersecurity support for CPA and financial firms that need rapid technical response, stronger safeguards, and tested recovery procedures.
Incident-readiness services may include:
- 24/7 access to live technical support
- Managed endpoint detection and response
- Microsoft 365 security monitoring
- Email and anti-phishing protection
- Multi-factor authentication
- Vulnerability and patch management
- Device encryption
- Security awareness training
- Incident-response planning
- Tabletop exercises
- Backup monitoring and recovery testing
- Cyber insurance support documentation
- Business continuity planning
- Post-incident remediation
911 IT has supported businesses since 2004 and combines CPA-industry familiarity with 24/7 support, local Salt Lake City-area service, proactive cybersecurity, strategic technology planning, and a 100% satisfaction guarantee.
Explore IT support for CPA and financial firms or read experiences from 911 IT clients.
Frequently Asked Questions
Who should an employee contact after a suspected cyber incident?
The employee should contact the firm’s designated IT or security provider immediately through the established emergency channel. The reporting procedure should be available even when normal email or systems are unavailable.
Should an employee turn off a computer after a suspected attack?
Not unless instructed. Disconnecting or isolating the device may be appropriate, but powering it off can remove evidence from memory or interrupt the investigation.
What should happen after an employee enters a password on a phishing site?
Report the incident immediately, reset the password, revoke active sessions, review MFA methods, inspect mailbox rules, examine sign-in activity, and scan or isolate the device.
How quickly should a CPA firm report an incident?
Internal reporting should happen immediately. External reporting and notification decisions depend on the circumstances and should be coordinated with appropriate legal, insurance, technical, and compliance advisors.
Should the firm notify every client after an incident?
Not automatically. The response team should determine which information and people were affected, evaluate applicable responsibilities, and coordinate accurate communications with qualified advisors.
Can backups stop a ransomware attack?
Backups do not prevent ransomware, but protected and tested backups can reduce operational damage and support recovery. The firm must still remove the attacker’s access and correct the original security weakness.
How often should the incident-response plan be tested?
Conduct a tabletop exercise at least annually and after significant changes to systems, vendors, leadership, insurance, office locations, or business operations.
What is the difference between incident response and disaster recovery?
Incident response focuses on containing, investigating, and managing a security event. Disaster recovery focuses on restoring systems and data. A serious incident may require both processes.
Does cyber insurance manage the entire response?
Cyber insurance may provide access to approved legal, forensic, recovery, and communication resources, but the firm still needs internal contacts, documentation, technical controls, and decision-making procedures.
What should happen after the firm returns to normal operations?
Complete a post-incident review, document lessons learned, update the response plan, correct security gaps, train employees, and test the improvements.
Prepare the Response Before an Emergency Occurs
A cybersecurity incident creates technical, operational, financial, legal, and communication challenges at the same time. A written plan helps the firm contain the threat, protect evidence, coordinate qualified advisors, restore critical systems, and communicate responsibly.
The best time to assign roles, test backups, verify emergency contacts, and practice decisions is before an employee reports a compromised account or unavailable tax system.
Schedule a discovery call with 911 IT to discuss cybersecurity incident-response planning, backup recovery, employee readiness, and 24/7 support for your CPA firm.
