You are holding more sensitive data than most of your clients, and you are required to have a written plan for protecting it.
Tax preparers and accounting firms count as financial institutions under the Gramm-Leach-Bliley Act, which puts your firm under the FTC Safeguards Rule. The IRS has required a written information security plan of every preparer since Publication 4557, and asks you to attest to your data security responsibilities when you renew your PTIN. Publication 5708 gives you a template.
Most firms we meet have the template. Fewer have the risk assessment behind it, the vendor review, the access controls, or the incident response plan it refers to. A plan that does not describe the firm is a finding waiting to be made, and it is no help at all on the morning something actually happens.
What that looks like in a firm your size
- A WISP that describes your actual practice. Written against how your firm really works, not a filled-in template, and short enough that your staff can follow it.
- The season's real risk. Between January and April your people move money and documents fast, under pressure, by email. That is exactly the window fraud is aimed at, and the fix is process before it is technology.
- Client portal and vendor review. Where returns, W-2s and bank details sit, who else can reach them, and what your software vendors have committed to.
- Something to show. An answer when a client, a carrier or an examiner asks what you do about security.
And your clients ask you first
You see the financials, you are in the room for the hard conversations, and you get asked questions that are not accounting questions: whether the cyber insurance renewal is worth it, whether the wire instructions that just changed are real, what to do about the client security questionnaire that arrived from their largest customer.
Refer those to us and they come back to you handled and documented. We do not do tax, accounting, audit or advisory work of any kind, so there is nothing of yours for us to take.
This is a partnership, not a pitch
- We never compete with you. We do not do your work and we do not want to.
- The Strategic Security Pulse Check is available co-branded with your firm's logo as a value-add for your clients.
- When our clients need a CPA, we send them to a firm we trust.
Twenty minutes, no slide deck. Best had well before January.