Tax and Accounting Firms
Cybersecurity Requirements for Tax Preparers & Accounting Firms
Tax and accounting firms hold information criminals value, and regulators, clients, insurers, and business partners expect organizations to protect it. The challenge is not simply installing security products. Leadership needs to understand what requirements apply, assign responsibility, maintain appropriate safeguards, and preserve evidence showing that those safeguards actually exist and operate.
Infosec Check helps organizations examine the space between written requirements, implemented technology, management representations, insurance expectations, and the evidence available to support them. Infosec Check is a Virginia-based advisory practice serving organizations nationally, and it does not provide legal, tax, or accounting advice.
What Is My Firm Actually Required to Do?
That question is more complicated than buying antivirus software or asking whether an IT provider handles cybersecurity.
A tax or accounting firm's responsibilities may arise from several different sources. Depending upon the organization and the information it handles, those sources can include federal requirements, state requirements, professional obligations, contractual commitments, insurance applications and policy conditions, client requirements, and security frameworks adopted by the organization, such as the NIST Cybersecurity Framework.
The first governance task is therefore not purchasing another product. It is determining:
- What applies?
- Why does it apply?
- Who is responsible?
- What safeguard addresses it?
- Is that safeguard actually operating?
- What evidence demonstrates that?
- When was it last verified?
- What remains unresolved?
A control that exists but cannot be demonstrated may create a very different governance position from a control supported by current evidence.
Does a Tax Preparer Need a Written Information Security Plan?
A Written Information Security Plan, commonly called a WISP, documents how an organization protects sensitive information and assigns responsibility for its information-security program.
Tax professionals should not treat a WISP as a downloaded template that is completed once and forgotten. A useful WISP should correspond to the actual organization.
It should address, as appropriate:
- information handled by the business
- responsible personnel
- risk assessment
- access controls
- authentication
- employee practices
- service providers
- systems and devices
- data handling
- incident response
- backup and recovery
- security awareness
- review and maintenance
- evidence supporting implementation
The document should describe the program the organization actually operates.
A sophisticated template describing controls that do not exist can create a different problem rather than solving the first one. Aligning documentation with operating reality is part of a GRC and regulatory program engagement.
What Does the IRS Expect From Tax Professionals?
Tax professionals handle highly sensitive taxpayer information, and the Internal Revenue Service publishes data-security guidance addressed to them.
The primary reference is IRS Publication 4557, Safeguarding Taxpayer Data. In plain English, tax professionals should understand the security practices applicable to protecting taxpayer information and should maintain a security program appropriate to their operation.
Publication 4557 is IRS guidance. It is not itself a statute. Guidance, regulatory requirements, and other legal obligations are distinct, and a firm may be subject to more than one of them at the same time. Which ones reach a specific organization is a question of that organization's activities and applicable law.
Does the FTC Safeguards Rule Apply to My Firm?
The FTC Safeguards Rule applies to financial institutions within its jurisdiction as defined under applicable law and regulation. Some businesses providing financial products or services can fall within its scope.
Whether a particular tax, accounting, bookkeeping, payroll, or related firm is covered depends upon the organization's activities and applicable law. Business name alone does not settle the question.
Two assumptions are worth avoiding. The first is "we are a small business, so it does not apply." The second is "our IT company handles this, so we are covered." Both replace a determination with a guess.
Primary sources: FTC Safeguards Rule, 16 CFR Part 314 and the FTC Safeguards Rule business guidance.
A Regulatory Applicability Assessment exists to work that determination through in an organized way. Our article on which cybersecurity regulations apply to a business covers the same reasoning in general terms.
My IT Company Handles Cybersecurity. Isn't That Enough?
An IT provider can be an essential part of a security program. It may manage firewalls, endpoints, Microsoft 365, backups, identity systems, networks, email security, monitoring, patching, or other technology, and a capable provider is a valuable partner.
Outsourcing technology does not automatically answer management questions such as:
- Which requirements apply to the business?
- Who accepted each risk?
- Are policies consistent with actual operations?
- Are vendors being governed appropriately?
- Are employees following required practices?
- Are insurance application answers supportable?
- Is evidence being retained?
- Are exceptions documented?
- Has management reviewed unresolved risks?
Technology administration and organizational governance overlap, but they are not the same function.
Where a firm wants that governance function held by an accountable advisor rather than left unassigned, a Fractional CISO engagement is one way to cover it.
If Someone Asked You to Prove It Tomorrow, Could You?
Imagine receiving tomorrow:
- a cyber insurance renewal questionnaire
- a client security questionnaire
- a regulator inquiry
- an auditor request
- an incident-response request
- a request from counsel following an event
Could management quickly produce evidence showing how important security representations were supported? Potential evidence may include:
- policies
- configuration records
- access reviews
- MFA records
- training records
- risk assessments
- incident-response exercises
- backup verification
- vendor reviews
- endpoint and security reports
- management approvals
- remediation records
- exceptions
- dated screenshots or system exports where appropriate
Infosec Check calls this Evidence Readiness: the ability to support important governance and security representations with appropriate, current evidence.
What Does This Have to Do With Cyber Insurance?
Cyber insurance applications and renewal questionnaires commonly ask organizations about security practices and controls. Questions can involve subjects such as authentication, backups, endpoint protection, employee security awareness, privileged access, incident response, email security, or other controls.
Exact questions and policy consequences vary by carrier, application, policy language, jurisdiction, and circumstances. Management should therefore understand what the organization has represented and what it could demonstrate if asked.
The goal is not to predict a claim decision. It is to reduce uncertainty between what the organization represents and what it can demonstrate.
Our cyber insurance consulting practice reviews applications, attestations, and supporting evidence, and our article on reasons cyber insurance claims are denied explains why documentation tends to matter at claim time.
Does Remote Work Change the Risk?
Remote work can expand the systems, networks, devices, authentication methods, physical environments, and workflows involved in accessing taxpayer or financial information. Seasonal preparers, contractors, and home offices tend to widen that surface further.
There is no single correct technical configuration for every firm. There is a set of questions leadership should be able to answer:
- Are devices company-managed?
- Is multi-factor authentication implemented where appropriate?
- How is remote access controlled?
- Can sensitive information be downloaded locally?
- How are terminated-user credentials removed?
- Are home or shared devices permitted?
- What happens when a device is lost?
- Are remote-work practices reflected in written policy?
- Can the organization demonstrate its controls?
The governance gap
The Governance Gap
What applies?
Identify regulatory, contractual, insurance, client, and organizational requirements.
Who owns it?
Assign responsibility rather than assuming IT owns every cybersecurity decision.
Can it be proven?
Determine whether material safeguards and representations are supported by current evidence.
What remains unresolved?
Document exceptions, gaps, accepted risks, remediation decisions, and ownership.
Cybersecurity becomes a governance issue when leadership is responsible for decisions it cannot clearly explain or demonstrate.
Questions Every Tax or Accounting Firm Should Be Able to Answer
- Do we know which cybersecurity requirements apply to our organization?
- Do we maintain a current Written Information Security Plan where appropriate?
- Does our written program reflect our actual environment?
- Who is accountable for information security?
- Have we documented our important systems and sensitive information?
- Are access rights reviewed?
- Is multi-factor authentication implemented where appropriate?
- Are employee security practices documented and reinforced?
- Do we evaluate relevant service providers?
- Do we have an incident-response process?
- Have backup and recovery processes been verified?
- Do we maintain evidence supporting important security controls?
- Can management support answers made on cyber insurance applications or renewals?
- Are unresolved risks documented and assigned?
- When was the program last reviewed?
If leadership cannot confidently answer several of these questions, the problem may not be a lack of technology. It may be a lack of governance visibility.
What Infosec Check Examines
An engagement may examine:
- regulatory applicability
- WISP and documentation alignment
- governance ownership
- risk-assessment practices
- policy-to-practice alignment
- evidence readiness
- third-party and vendor governance
- cyber insurance representations
- security-control evidence
- unresolved gaps
- executive reporting
Depending on where a firm stands, that work is delivered through a Regulatory Applicability Assessment, Evidence Readiness and Executive Readiness work, Cyber Insurance Readiness review, or an ongoing Fractional CISO relationship. Infosec Check does not issue certifications, guarantee regulatory outcomes, or replace legal counsel, your CPA, tax counsel, your IT provider, your insurer, your insurance producer, or a regulator.
Reviewed by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check.
FAQ
Tax and accounting cybersecurity questions
Do tax preparers need a WISP?
Tax professionals should evaluate applicable requirements and IRS taxpayer-data security guidance and maintain an information-security program appropriate to their circumstances. A WISP documents how that program operates, including responsibilities, safeguards, risk management, and review. Applicability and specific requirements should be evaluated based on the business and governing authorities.
What is a WISP for a tax preparer?
A Written Information Security Plan documents how a firm protects sensitive information, assigns responsibility, addresses identified risks, manages safeguards, responds to incidents, and reviews the program.
Does the FTC Safeguards Rule apply to accounting firms?
Potentially, depending upon the firm's activities and whether it falls within the definition of a financial institution subject to the Rule. Applicability should be determined from the organization's actual activities and applicable law rather than assumed from its business name alone.
Is IRS Publication 4557 mandatory?
IRS Publication 4557 is IRS guidance for safeguarding taxpayer data, and the publication itself is not a statute. Tax professionals may also be subject to separate legal, regulatory, contractual, professional, or other requirements.
Does having an IT company make my accounting firm compliant?
Not automatically. An IT provider may implement and manage important technical safeguards, but management still needs to understand applicable requirements, organizational responsibilities, policies, risks, representations, exceptions, and supporting evidence.
What cybersecurity evidence should an accounting firm keep?
Depending upon the organization's environment and requirements, useful evidence may include policies, access reviews, risk assessments, training records, security configurations, vendor reviews, backup verification, incident-response records, remediation records, and other documentation supporting material security representations.
What does cyber insurance have to do with cybersecurity documentation?
Applications and renewals can ask organizations to make representations concerning security practices. Maintaining appropriate evidence can help management understand and support those representations. Exact requirements and consequences depend upon carrier, application, policy language, law, and circumstances.
Who is responsible for cybersecurity in a tax firm?
Responsibilities may be distributed among leadership, employees, IT providers, security professionals, vendors, and other parties. Governance requires the organization to define ownership rather than assume responsibility belongs entirely to one outside provider.
How often should a WISP be reviewed?
Review should occur with sufficient frequency to keep the program aligned with the organization's risks, systems, operations, personnel, vendors, incidents, and applicable requirements. Where an applicable authority specifies a review interval, that interval governs.
Can Infosec Check determine which requirements apply to my firm?
Infosec Check can perform a Regulatory Applicability Assessment to help identify and organize potentially relevant cybersecurity and governance requirements. This is not a substitute for legal advice where a legal determination is required.
Clarify What Applies Before Assuming You're Covered
If your firm handles taxpayer or sensitive financial information and leadership is uncertain about requirements, documentation, evidence, or cyber insurance representations, Infosec Check can help clarify the position.
A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.
Call Infosec Check
(855) 624-6262