Resources
Start with the checklist. Print it, mark it up, and bring it to your assessment call.
Security readiness checklist for accounting firms
- Multi-factor authentication on email, remote access and admin accounts
- A written information security program (WISP) that someone owns
- A network split into zones, so one infected PC cannot reach everything
- Separate admin accounts, with no shared passwords
- Tested, offline backups of client and tax data
- A written incident response plan you have rehearsed
- Endpoint detection and response on every computer, not just antivirus
- Central logging with at least a year of history
- Annual security training for every employee
- A yearly risk assessment and review of your vendors
- A named person responsible for security, written into your program
- Encryption on laptops, phones and any removable media
Use your browser's print command to save this page as a PDF.
Guides
What the FTC Safeguards Rule requires of tax preparers
A written information security program, a designated Qualified Individual, a written risk assessment, access controls, encryption, multi-factor authentication, service-provider oversight, staff training, and a written incident response plan. Firms must also notify the FTC of certain breaches affecting 500 or more consumers.
What IRS Publication 4557 expects
Practical safeguards for taxpayer data: a security plan, strong authentication, encryption, secure backups, and a response plan if data is stolen. Treat it as the IRS's baseline for your firm.
What cyber insurers ask before they renew
Multi-factor authentication everywhere, tested offline backups, endpoint detection, a written incident response plan, and proof that employees are trained.
Find out where your firm stands.
A 30-minute call covers your current controls, the rules that apply to you, and what a first 90 days would look like. No cost, no sales deck.