CPAs & Accounting Firms

You are holding more sensitive data than most of your clients, and you are required to have a written plan for protecting it.

Tax preparers and accounting firms count as financial institutions under the Gramm-Leach-Bliley Act, which puts your firm under the FTC Safeguards Rule. The IRS has required a written information security plan of every preparer since Publication 4557, and asks you to attest to your data security responsibilities when you renew your PTIN. Publication 5708 gives you a template.

Most firms we meet have the template. Fewer have the risk assessment behind it, the vendor review, the access controls, or the incident response plan it refers to. A plan that does not describe the firm is a finding waiting to be made, and it is no help at all on the morning something actually happens.

What that looks like in a firm your size

And your clients ask you first

You see the financials, you are in the room for the hard conversations, and you get asked questions that are not accounting questions: whether the cyber insurance renewal is worth it, whether the wire instructions that just changed are real, what to do about the client security questionnaire that arrived from their largest customer.

Refer those to us and they come back to you handled and documented. We do not do tax, accounting, audit or advisory work of any kind, so there is nothing of yours for us to take.

This is a partnership, not a pitch

Twenty minutes, no slide deck. Best had well before January.

Book a partner chat