Cybersecurity for Reno Accounting and CPA Firms

Accounting and tax firms hold Social Security numbers, bank details and financial statements for every client, and tax preparation firms are covered by the FTC Safeguards Rule. We help Reno, Sparks and Carson City CPA firms with MFA and zero trust access, email security, 24/7/365 monitoring by our SOC and incident response, supporting the safeguards your written information security plan describes.

FTC Safeguards Rule and your WISP.

The FTC lists tax preparation firms among the financial institutions covered by the FTC Safeguards Rule. It requires a written information security program with a Qualified Individual, a written risk assessment, MFA, encryption, monitoring or testing, staff training and an incident response plan.1

The IRS reinforces the requirement through Publication 5708, which helps tax and accounting practices create a written information security plan (WISP).2 If unencrypted information on 500 or more consumers is taken, the firm must notify the FTC within 30 days. Firms with customer information on fewer than 5,000 consumers are exempt from a few provisions, including the written risk assessment, the written incident response plan, the annual board report and the testing requirement.

Tax season brings more attacks.

Criminals time their campaigns to tax season, when staff are busiest and least likely to slow down. Common attacks include:

  • Phishing posing as clients sending tax documents
  • Fake IRS or software vendor login pages that steal credentials
  • Stolen e-file credentials used to file fraudulent returns
  • Business email compromise targeting client refunds and payments
  • Ransomware that locks the firm out of client files at deadline time

Safeguards your WISP can point to.

Your firm owns its WISP and its risk assessment. Our services put many of the technical safeguards in place and keep them running.

MFA and access control

MFA on email, tax software, portals and remote access, with access limited to the staff who need it.

Email security

Impersonation protection and encrypted email for sending client documents.

24/7/365 MDR

EDR on every workstation, watched by our SOC, including evenings and weekends in April.

Logging and monitoring

Activity logging and detection of unauthorized access, which the Safeguards Rule requires.

Staff training

Phishing simulations modeled on tax-season lures.

Vulnerability management

Regular scanning for firms that choose SecurityPlus, supporting the rule's testing requirement.

Where most firms start.

  1. Turn on MFA everywhere client data lives.
  2. Confirm your WISP exists, names a Qualified Individual and matches how the firm works. Our vCISO guidance can advise on security priorities.
  3. Get someone watching for attacks around the clock, especially during tax season.
  4. Ask your cloud vendors for their SOC 2 reports.

Firms that also offer financial planning or advisory services should see cybersecurity for financial services. This page is general information, not legal advice.

Accounting firm cybersecurity FAQ

Firms that prepare tax returns generally do. The FTC Safeguards Rule requires a written information security program, and the IRS reminds tax professionals of this requirement through Publication 5708, which includes a template for creating a WISP.
Turn on multi-factor authentication for every account that touches client data, including email, tax software, portals and remote access. It is required by the FTC Safeguards Rule and blocks many attacks that rely on stolen passwords. A free security assessment is a good next step to find the other gaps.
A SOC 2 report is an independent CPA firm's report on a service provider's security controls. Asking your cloud tax, payroll and document vendors for their SOC 2 reports is a practical way to oversee service providers, which the FTC Safeguards Rule requires.
Usually not on its own. Most in-house IT staff are busy keeping systems running and cannot watch security alerts at night, on weekends or during tax season crunch. Many firms keep their IT person or provider and add a managed security provider for 24/7 monitoring and response.

Find out where your business is exposed.

Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.