Cybersecurity for Reno Accounting and CPA Firms
Accounting and tax firms hold Social Security numbers, bank details and financial statements for every client, and tax preparation firms are covered by the FTC Safeguards Rule. We help Reno, Sparks and Carson City CPA firms with MFA and zero trust access, email security, 24/7/365 monitoring by our SOC and incident response, supporting the safeguards your written information security plan describes.
FTC Safeguards Rule and your WISP.
The FTC lists tax preparation firms among the financial institutions covered by the FTC Safeguards Rule. It requires a written information security program with a Qualified Individual, a written risk assessment, MFA, encryption, monitoring or testing, staff training and an incident response plan.1
The IRS reinforces the requirement through Publication 5708, which helps tax and accounting practices create a written information security plan (WISP).2 If unencrypted information on 500 or more consumers is taken, the firm must notify the FTC within 30 days. Firms with customer information on fewer than 5,000 consumers are exempt from a few provisions, including the written risk assessment, the written incident response plan, the annual board report and the testing requirement.
Tax season brings more attacks.
Criminals time their campaigns to tax season, when staff are busiest and least likely to slow down. Common attacks include:
- Phishing posing as clients sending tax documents
- Fake IRS or software vendor login pages that steal credentials
- Stolen e-file credentials used to file fraudulent returns
- Business email compromise targeting client refunds and payments
- Ransomware that locks the firm out of client files at deadline time
Safeguards your WISP can point to.
Your firm owns its WISP and its risk assessment. Our services put many of the technical safeguards in place and keep them running.
MFA and access control
MFA on email, tax software, portals and remote access, with access limited to the staff who need it.
Email security
Impersonation protection and encrypted email for sending client documents.
24/7/365 MDR
EDR on every workstation, watched by our SOC, including evenings and weekends in April.
Logging and monitoring
Activity logging and detection of unauthorized access, which the Safeguards Rule requires.
Staff training
Phishing simulations modeled on tax-season lures.
Vulnerability management
Regular scanning for firms that choose SecurityPlus, supporting the rule's testing requirement.
Where most firms start.
- Turn on MFA everywhere client data lives.
- Confirm your WISP exists, names a Qualified Individual and matches how the firm works. Our vCISO guidance can advise on security priorities.
- Get someone watching for attacks around the clock, especially during tax season.
- Ask your cloud vendors for their SOC 2 reports.
Firms that also offer financial planning or advisory services should see cybersecurity for financial services. This page is general information, not legal advice.
Accounting firm cybersecurity FAQ
Find out where your business is exposed.
Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.