Blog

Cybersecurity for CPA Firms: What the Law Requires

Cybersecurity for CPA firms is a legal duty, not just IT. What the FTC and IRS rules require, the controls that matter, and how to verify a provider.

Accountably Editorial Team 12 min read Updated 2026-07-11

A CPA firm is a vault. It holds Social Security numbers, bank logins, payroll files, and the full financial life of every client, which is exactly what an attacker wants and exactly what a client trusts the firm to guard. When that trust breaks, the cost is not only downtime and a ransom. It is a legal duty the firm failed to meet.

Cybersecurity for CPA firms is the set of written policies, technical controls, and vendor oversight a firm uses to protect the taxpayer data it holds. For a US tax or accounting practice it is a legal obligation that cannot wait for a quieter month. Federal law treats a firm that prepares returns as a financial institution, so a written security plan and specific safeguards are mandatory.

Most guides stop at the controls: turn on multi-factor login, encrypt the drives, back up the files. Those matter, and they are covered below. The part that gets skipped is what happens the moment that data moves to someone else, an IT vendor, a contractor, or an offshore team, because the firm's duty follows the data. There is a clean way to tell whether a firm and its providers actually meet that duty rather than just claim they do.

Key takeaways

Here is what matters before you judge your own firm or a provider:

  • Cybersecurity for CPA firms is a legal obligation, not just an IT project. Under the FTC's Safeguards Rule, a firm that prepares returns is a financial institution and must keep a written information security program.
  • The controls that carry the most weight are ordinary. The IRS packages them as the Security Six: anti-virus software, a firewall, backups, drive encryption, multi-factor authentication, and a VPN.
  • A written information security plan, a WISP, is the document that ties it together. The IRS shows how to build one in Publication 5708.
  • The duty follows the data. When client information goes to an outside or offshore team, the firm must vet the provider and put the safeguards in the contract, and if tax return information leaves the United States the client's written consent has to come first under Treasury Regulation §301.7216-2.
  • You can verify security instead of trusting it. Ask for the plan, evidence the controls were independently reviewed or assessed against a recognized framework, the contract clause, and the consent workflow. A real program can show them.

What does the law actually require of a CPA firm?

US tax and accounting firms are held to the same data-protection law as banks. Under the Gramm-Leach-Bliley Act, a firm that prepares returns counts as a financial institution, so the Federal Trade Commission's Safeguards Rule requires it to build and maintain a written information security program. That is the minimum the law sets, and it applies to solo preparers as much as to large firms.

The rule is specific about what that program has to contain. It names a designated qualified individual to run the program, a written risk assessment, access controls, encryption of client information in transit and at rest, and multi-factor authentication for anyone reaching a system that holds client data. It also calls for a written incident response plan and reasonable oversight of the service providers a firm relies on. The rule states these as mandatory.

The IRS turns those requirements into something a practice can actually write. Its Publication 5708 walks a tax or accounting firm through drafting its own written information security plan, and Publication 4557 is the broader IRS guide to safeguarding taxpayer data. Between them, a firm has a template and a checklist, so a firm that still has no plan is choosing to go without one.

What does a CPA firm's cybersecurity program include?

Cybersecurity for CPA firms is the combination of written policies, technical safeguards, and oversight of outside vendors that a firm uses to keep client financial data confidential, accurate, and available. It is not a single product you buy and switch on. It is a program, made of the plan on paper, the controls on the machines, the training in people's heads, and the contracts that hold your vendors to the same standard.

A useful way to picture that program is as four pillars. People, because phishing is a leading way attackers get in, and it targets a person rather than a machine. Process, because a written plan and a rehearsed response make a bad day repeatable instead of improvised. Technology, because a handful of basic controls stop the common attacks.

Oversight, because the moment data leaves your walls, someone else is holding it. A firm that funds three of the four pillars and ignores the last one is the firm that gets surprised.

Cybersecurity for CPA firms gets treated as urgent for a concrete reason. A tax practice is a concentrated store of exactly the data an identity thief needs, so it draws attention that a general small business does not. That is why those rules exist, and why a plan matters more than any single tool.

Which cybersecurity controls matter most?

The controls that block the most common attacks on a firm are not exotic. The IRS packages the essential set as the Security Six: anti-virus software, a firewall, backups, drive encryption, multi-factor authentication, and a virtual private network. Six controls, each doing one job, and together they cover most of the ground a small firm needs to defend.

Multi-factor authentication earns its place at the top of that list because it stops the most damage for the least effort. When a stolen password alone no longer opens the door, credential theft through a phishing email loses its payoff.

Multi-factor login backstops the password rather than replacing it, so the password still matters: use long, unique passwords held in a password manager, since one password reused across sites turns a single leak into a working key everywhere it was repeated.

Drive encryption and secure backups matter for the day something does go wrong, so a lost laptop is not a lost client list and a ransomware hit becomes a restore instead of a catastrophe.

Two habits matter as much as the tools. Patch software quickly, because attackers make their living on holes that already have a fix. And train the people, because a convincing phishing email walks straight past every control on the list if someone types their credentials into a fake login. The tools set the floor. Alert people raise it.

What changes when client data goes to an outside or offshore team?

When a CPA firm sends client data to an outside or offshore team, the firm's legal duty follows the data to whoever touches it next, an IT contractor, a bookkeeping vendor, or an offshore preparer. General security guides skip this part: the duty does not stop at the office door, and the firm stays responsible for how each of those parties protects the data.

The Safeguards Rule makes this explicit. A firm has to take reasonable steps to choose service providers capable of protecting client information, and it has to require them by contract to implement and maintain those safeguards, under the Safeguards Rule. A verbal assurance does not satisfy that duty. The contract is where the duty gets passed along, or where it quietly falls through.

Offshoring adds a second rule on top of the first. If tax return information is disclosed to a preparer located outside the United States, the taxpayer's written consent has to come first, under Treasury Regulation §301.7216-2 and the consent form specified in §301.7216-3. That consent has to be knowing, voluntary, signed, and dated before the file moves. It is not a checkbox you backfill later.

The consent is not a formality with no teeth. Unauthorized disclosure or use of tax return information is a federal crime. Under Treasury Regulation §301.7216-1, the penalty runs to a fine of not more than $1,000 or up to one year in prison, or both, together with the costs of prosecution. The point is not to scare a firm away from outsourcing. It is that the rule is real, so the provider you choose has to make compliance easy rather than awkward.

A provider that takes this seriously makes it simple to comply. It signs the data-protection contract, supports the client-consent workflow instead of ignoring it, encrypts files in transit and at rest, gives each worker only the access the job needs, and keeps no client files on local machines. A provider that cannot describe how it does these things is the provider that turns your compliance duty into your problem.

How do you verify a provider is secure instead of trusting it?

You verify security the same way you verify any control: you ask to see the artifacts a real program produces, and you check them. A firm running an actual program can hand over its written plan, evidence its controls were reviewed against a recognized framework, and the contract language that binds its vendors. A firm selling a feeling offers a trust badge and a confident tone. The difference is visible in an afternoon.

The gap between a program and a label shows up in what a provider can actually put in front of you.

A security program you can verify A security label you cannot
A written plan that names a responsible person "We take security seriously" on a web page
An independent review of the controls, or a documented framework-alignment assessment A trust badge with nothing behind it
A signed contract that requires the provider to maintain safeguards A handshake and a promise
A written client-consent step before any data leaves the country Silence about where the work is done
Encryption, access logs, and multi-factor login you can see "Bank-level security," left undefined

Two documents matter most for an outsourced or offshore arrangement. The first is the provider's own written information security plan, which tells you it treats security as a program and not a slogan. The second is evidence the controls hold up to outside scrutiny, whether an independent security report or a documented assessment of how the controls map to a recognized framework.

For offshore work specifically, add the consent step to the checklist. Ask to see the written client-consent language the provider expects you to use before any tax return information leaves the country, and confirm it lines up with the rule. A provider that has run offshore engagements for US firms will have this ready; a provider that looks puzzled by the question has told you something.

Frequently asked questions

Are CPA firms legally required to have a cybersecurity plan?

Yes. A US firm that prepares tax returns is treated as a financial institution under federal law, so the FTC's Safeguards Rule requires it to maintain a written information security program with named safeguards. The IRS also expects a written data security plan and provides a fill-in template in Publication 5708. This is mandatory, and it applies to solo preparers as well as large firms.

What is a WISP for a tax and accounting firm?

A WISP is a written information security plan: the document that records how a firm protects client data, who is responsible for it, and what happens if there is a breach. The FTC's Safeguards Rule requires this kind of written program, and the IRS gives tax and accounting firms a template in Publication 5708. A good WISP is short, specific, and actually used day to day.

Do I need a client's consent to send their tax data offshore?

Yes, when tax return information is involved. Once a client gives tax return information to your firm in the United States, disclosing it to a preparer located outside the country requires the client's written consent first, under Treasury Regulation §301.7216-2 and the consent form in §301.7216-3. The consent must be signed before the file moves, so have counsel put the right form in place for your facts.

Is it safe to send client tax data to an offshore team?

Offshore work can be safe when the arrangement is built correctly. Safety comes from the controls and the contract rather than the location: encryption in transit and at rest, least-privilege access, no local storage, a provider bound by contract to maintain safeguards under the Safeguards Rule, and the written client consent the tax rules require. An offshore team with weak controls is a risk, and so is an in-house setup with weak controls. What matters is whether the safeguards travel with the data, wherever the work sits.

How do I check whether an outsourcing provider is secure?

Ask for evidence, not adjectives. Request the provider's written information security plan, evidence its controls were independently reviewed or assessed against a recognized framework, and the contract clause that requires it to maintain safeguards. For tax work, ask to see the client-consent workflow it uses before data leaves the country. A provider running a real program produces these on request; hesitation tells you what a brochure will not.

The honest test of a firm's cybersecurity

The honest test of a firm's cybersecurity is a plain one: can it show you the program, or can it only describe it? A firm that meets its duty has a written plan, the everyday controls running, evidence those controls were reviewed against a recognized framework, and contracts that hold its vendors to the same line. A firm that treats security as a marketing word has a badge and a promise. The gap between them is visible in an afternoon, if you ask to see the artifacts.

Cybersecurity for CPA firms comes down to one idea. The data you hold carries a legal duty, that duty follows the data wherever it goes, and the only honest proof that the duty is met is the plan, the controls, and the records a real program leaves behind. The firms that get this right treat security as something they can demonstrate on request. The ones that get it wrong bought a tool and called it a plan.

See the work before your name is on it

Run a Free 40-Hour Proof Pilot on your own representative work, through full multi-layer review, before a single client file moves.