Who we help · Accounting & tax firms
Security your regulator and your insurer already expect.
Small accounting and tax firms are held to the FTC Safeguards Rule and IRS Publication 4557, and to whatever your cyber-insurer put in this year's renewal. We turn that list into work that gets done.
The pressure you’re under
What’s actually being asked of you
FTC Safeguards Rule
The amended Rule applies to tax preparers and accounting firms as "financial institutions." It requires a written information security program, a qualified individual to run it, a written risk assessment, encryption of customer data, multi-factor authentication, an incident response plan, and annual reporting to your board or owner.
IRS Publication 4557
The IRS expects every firm handling taxpayer data to have a written data security plan (a WISP). No WISP is a finding, and it is now referenced when you renew your PTIN and in the IRS "Security Six" guidance.
Cyber-insurance renewals
Carriers now require MFA everywhere, managed endpoint detection and response, tested backups, email filtering, and staff phishing training before they will renew — and they ask you to attest to it.
Client and busy-season risk
During filing season a locked-up server or a compromised email account is not an inconvenience, it is lost revenue and a breach-notification problem with client SSNs involved.
What we do about it
The work, in plain terms
- Write and maintain your WISP and the Safeguards Rule information security program, mapped to what you actually have.
- Name and support the "qualified individual" role, with a quarterly risk review and a report you can hand to ownership.
- Enforce MFA on email, remote access, and your tax software; remove shared logins.
- Encrypt laptops and desktops; confirm your tax and document systems encrypt data at rest and in transit.
- Deploy managed EDR on every machine and monitor it.
- Back up Microsoft 365 and workstations, and test a restore before busy season, not after an incident.
- Lock down email against spoofing (SPF, DKIM, DMARC at enforcement) and impersonation of partners.
- Run quarterly staff training and simulated phishing, and keep the records.
- Give you an incident response plan with names and phone numbers, and be the first call if something happens.
- Complete your cyber-insurance questionnaire with you and fix the "no" answers.
Where firms usually start with us: a fixed-scope Microsoft 365 Security Baseline plus a written WISP, delivered before busy season, then a Secure-tier monthly plan to keep it maintained and to produce the evidence at renewal time.
We provide security controls and documentation. We are not your auditor or your attorney; where you need an independent assessment or legal opinion, we will point you to people who do that.
Get started
Find out where your firm stands
Book a short consultation. We walk through the service, what we need from you, the price and the timeline — with no obligation.