IT and Cybersecurity for Accounting Firms: What CPAs Should Fix First
Accounting firms face targeted cyberattacks during tax season and beyond. Here is what CPAs need to secure client data and meet compliance requirements.

Accounting firms hold the most sensitive data a business can produce: tax returns, payroll records, bank account numbers, Social Security numbers, and detailed financial statements. That makes every CPA practice, from a five-person firm to a regional practice with 200 staff, a high-value target for attackers who know exactly what that data is worth.
The IRS names tax professionals as a priority target in its annual Dirty Dozen phishing list, warning that phishing schemes impersonating the IRS, clients, and software providers remain a persistent threat to accounting firms. And the FTC Safeguards Rule now requires non-bank financial institutions, including accounting firms handling tax preparation, to implement specific security controls. Firms that treat IT as “the thing that keeps QuickBooks running” are carrying risk they may not survive.
Why Accounting Firms Get Targeted
Attackers go after accounting firms for three reasons that make them different from the average small business.
Concentrated high-value data. A single accounting firm may hold financial records for hundreds of businesses and thousands of individuals. One breach gives an attacker a multiplied return compared to hitting each client individually.
Seasonal staffing and access patterns. Tax season brings temporary staff, extended hours, remote access from home networks, and rushed workflows. Every one of those patterns weakens security controls that work fine during the rest of the year.
Client portal and file-sharing exposure. Accounting firms exchange sensitive documents constantly, through email, client portals, cloud storage, and sometimes USB drives. Each exchange point is a potential interception or business email compromise vector. An attacker who compromises an accountant’s email can redirect wire transfers, steal client data, or impersonate the firm to clients.
The Five Controls to Fix First
If your firm has not done a formal security assessment, start with these five areas. They address the most common gaps we see in accounting practices across Texas.
1. Email Security Beyond the Basics
Standard Microsoft 365 email filtering catches commodity spam but misses targeted phishing attacks designed to look like client communications. An attacker sending a “revised W-2” or “updated bank details” from a spoofed client domain will sail through basic filters.
What to deploy:
- Microsoft Defender for Office 365 Plan 2 for firms under 100 seats, which adds impersonation protection, safe attachments, and URL rewriting on top of standard Exchange Online Protection. For larger practices (100+ seats), consider dedicated platforms like Proofpoint or Abnormal Security that offer more granular policy control at scale
- DMARC, DKIM, and SPF records on your firm’s domain to prevent spoofing
- External email banners that warn staff when a message comes from outside the organization
2. Multi-Factor Authentication on Everything
MFA is the single most effective control for accounting firms. Your practice management software, email, client portals, remote access tools, and cloud storage all need MFA enabled. No exceptions.
Start with app-based MFA using Microsoft Authenticator or Duo. These generate push notifications or one-time codes on staff phones and work across practice management software, Microsoft 365, and remote access tools without any hardware to buy or distribute. For firms that want to go further, phishing-resistant methods like FIDO2 security keys or passkeys eliminate the risk of MFA bypass attacks entirely and work well on shared workstations. Tax season creates pressure to skip MFA for temporary staff. Do not do this. If your team is bypassing MFA because it is inconvenient, the implementation needs fixing, not the policy.
3. Client Data Encryption and Access Controls
Client files at rest (on your server or in cloud storage) and in transit (email attachments, portal uploads) must be encrypted. This is both a security requirement and a compliance one under the FTC Safeguards Rule and many state privacy laws, including the Texas Data Privacy and Security Act.
Beyond encryption, implement least-privilege access. A junior staff member working on individual returns should not have access to the firm’s entire client database. Role-based access controls in your practice management and document management systems limit the blast radius if one account is compromised.
4. Endpoint Protection That Actually Responds
Traditional antivirus is not enough for a firm handling this volume of sensitive data. You need endpoint detection and response (EDR) with a managed team behind it. EDR watches for behavioral anomalies, like a process exporting large volumes of files to an external location, or a login from an unusual geographic location at 2 AM during tax season.
The “managed” part matters. An EDR tool that sends alerts to an inbox nobody checks is expensive decoration. A managed SOC investigates, contains, and responds before data leaves your network.
5. Backup and Recovery That You Have Actually Tested
Accounting firms run on deadlines. A ransomware attack during tax season or quarterly close is not just an inconvenience; it can cause missed filing deadlines, IRS penalties for clients, and malpractice exposure for the firm.
Your backup strategy needs:
- Daily backups of practice management data, client files, and email
- Offsite or cloud replication so a local disaster does not destroy both production and backup
- Tested recovery at least twice per year, including a timed drill where you actually restore from backup and verify the data is complete and usable
If you have never tested a full restore, your backup is an assumption, not a control. Review why the tool is the easy part of a real backup strategy.
Compliance Requirements Accounting Firms Cannot Ignore
Accounting firms face overlapping compliance obligations that are growing stricter.
FTC Safeguards Rule. If your firm prepares tax returns or handles financial records, you are likely a “financial institution” under the Gramm-Leach-Bliley Act. The updated Safeguards Rule requires a written information security program, a designated qualified individual, risk assessments, access controls, encryption, MFA, and ongoing monitoring. The FTC has been actively enforcing through consent orders, and penalties include injunctive relief and monetary fines.
IRS Publication 4557. The IRS requires tax preparers to implement specific data security measures. While not a regulation with direct penalties, failure to follow these guidelines can result in loss of your PTIN (Preparer Tax Identification Number) and referral to the Office of Professional Responsibility.
State privacy laws. Texas businesses must comply with the TDPSA, which took effect July 1, 2024. If you serve clients in other states, you may face additional obligations under their privacy laws.
AICPA professional standards. The AICPA’s Code of Professional Conduct requires CPAs to protect client confidentiality. A data breach is not just a security event; it is a potential ethics violation that can trigger disciplinary proceedings.
Tax Season Security Checklist
The four weeks before tax season starts should include an IT security review. Here is what to cover:
- Verify all remote access uses MFA and connects through a managed VPN or zero-trust access solution, not a personal laptop on home WiFi with no security controls
- Audit user accounts and disable any from staff who left since last season
- Review temporary staff access so seasonal employees only reach what they need
- Test your backup recovery so you know you can restore if ransomware hits during the busiest week of the year
- Run a phishing simulation focused on tax-themed lures (W-2 requests, IRS notices, client impersonation)
- Confirm your cyber insurance is current and covers data breach notification costs, where total breach costs can run $50 to $200 per affected record
What a Managed IT Provider Should Do for Your Firm
Many accounting firms in the 25 to 150 employee range cannot justify a dedicated IT team. A single IT person, often the youngest partner who “knows computers,” is carrying the entire technology function while also managing a client book.
A managed IT partner that understands accounting firm workflows should handle:
- Practice management application support (QuickBooks, Sage, CCH, ProSystem, Drake, Thomson Reuters)
- Microsoft 365 administration including SharePoint for document management and Teams for client collaboration
- Print and document workflow management, because accounting firms still handle significant paper volume during tax season
- Compliance documentation for the FTC Safeguards Rule, including the required written security plan
- Strategic IT planning through quarterly business reviews that align technology investments with the firm’s growth
The right provider will not just fix your printer. They will tell you that your five-year-old server cannot handle the load during April, that your backup has not completed successfully in three weeks, and that your cyber insurance renewal requires controls you do not have yet.
Protect Your Firm's Client Data
We help accounting firms across Texas meet compliance requirements and defend against targeted attacks.
Schedule a Security AssessmentServing Businesses Across Texas & Oklahoma