Industry
Accounting and CPA firms
Two things define the IT profile of an accounting firm: a federal security rule with specific written requirements, and a season where an outage costs several times what it would at any other point in the year. Everything worth doing here addresses one or both.
The requirement most firms lack
A current WISP
written information security plan
Required regardless of firm size, alongside a named qualified individual accountable for it.
What the Safeguards Rule requires
Eight elements, all required. The first two are where small firms are most often exposed, because they are documentation rather than technology and nobody owns them by default.
| Element | Status |
|---|---|
| Written information security planA document, maintained and current, not a template downloaded once | Required |
| Qualified individualA named person accountable for the programme. Can be supported externally, not delegated away | Required |
| Risk assessmentWritten, periodic, and reflecting the current environment | Required |
| Access controlsLeast privilege over client financial data, reviewed periodically | Required |
| EncryptionData at rest and in transit, or a documented equivalent | Required |
| Multi factor authenticationOn any system holding customer information | Required |
| Vendor oversightIncluding your IT provider, with contractual security obligations | Required |
| Incident response planWritten, with defined roles and notification steps | Required |
General information about the rule, not legal advice. Confirm your obligations with counsel or a qualified compliance adviser.
Five pressures unique to the season
- Headcount rises sharply for a few months, and seasonal staff need access provisioned fast and removed faster
- Any downtime between February and April costs disproportionately more than the same outage in August
- Client document volume spikes, and clients will use whatever channel is easiest unless a better one exists
- Long hours mean staff work from home and personal devices on deadlines
- Phishing volume targeting tax professionals rises in step with the season
The practical consequence is that significant changes are made between May and December, never during the season, and that the provisioning process is designed before the seasonal intake rather than improvised during it.
The account that outlives the employee
The single most common finding in a firm that runs seasonal staffing is a set of active accounts belonging to people who left at the end of the last season.
Each one is a working credential with access to client financial data, held by someone with no current relationship to the firm, usually with a password that has not changed and frequently without multi factor authentication because it was set up quickly during a busy week.
Deprovisioning as a defined step on the last day, and a quarterly access review to catch anything missed, closes it permanently. It is also explicitly the kind of control the Safeguards Rule expects to see operating.
Common questions
Answered before you ask.
Does the FTC Safeguards Rule really apply to a small firm?
The rule covers financial institutions under a broad definition that includes tax preparers and accounting firms handling customer financial information, and it does not exempt small firms. What scales with size is the depth of the programme rather than whether one is required. The requirement for a written information security plan and a named qualified individual applies regardless of headcount, and those two are where most small firms are exposed.
Can our IT provider be the qualified individual?
The rule expects the firm to designate someone accountable, and that accountability sits with the firm. A provider can support the role substantially, supplying the technical programme, the risk assessment input and the evidence, but a firm cannot outsource the accountability itself. In practice the workable arrangement is a named partner or manager holding the role with the provider doing the underlying work and reporting into them.
How do we handle seasonal staff securely?
Provisioning and deprovisioning as a defined process rather than an ad hoc one. Accounts created from a template with the right access rather than copied from an existing employee, which is how permissions sprawl begins. Access removed on the last day rather than whenever someone remembers. The most common finding in firms after a season is a set of active accounts belonging to people who left months earlier.
What is the safest way for clients to send us documents?
A portal, and it needs to be genuinely easier than email or clients will not use it. Most tax and practice management platforms include one. Where clients insist on email, encryption and expiry controls in Microsoft 365 help and are usually already licensed. What should be avoided entirely is documents containing social security numbers arriving as unprotected attachments, which is still routine in a great many firms.
Related
What this sector usually needs first.
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Security awareness training
Phishing simulation and short, frequent training that changes behaviour.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Financial services
GLBA, member data, fraud monitoring
Find out where the Safeguards gaps are.
The assessment reviews your technical controls against the rule and produces a findings register you can hand to whoever holds the qualified individual role.