Cybersecurity Is Becoming A Central Compliance Issue For CPA Firms

For accounting and tax firms, cybersecurity is no longer simply an IT concern. It is becoming an essential part of regulatory compliance, professional responsibility, and client service.

On July 7, 2026, the IRS and its Security Summit partners launched a five-week “Protect Your Clients; Protect Yourself” campaign. The campaign focuses on practical steps that tax professionals can take to defend their firms and clients against evolving tax-related identity theft and data security threats.

The message from the IRS is clear: Tax professionals remain attractive targets for cybercriminals because they handle large volumes of valuable taxpayer and financial information.

A successful attack on one accounting firm could expose:

  • Social Security numbers

  • Tax returns and supporting documents

  • Bank account and routing information

  • Payroll and employee records

  • Business financial statements

  • Login credentials

  • Electronic filing information

  • Confidential client correspondence

Cybercriminals can use this information to file fraudulent tax returns, redirect refunds, impersonate taxpayers, steal funds, or launch additional attacks against the firm’s clients.

A Written Information Security Plan Is Required

One of the most important compliance responsibilities highlighted by the IRS is that tax professionals must maintain a Written Information Security Plan (WISP).

In guidance issued June 16, 2026, the IRS reiterated that tax professionals are required by law to have a WISP to protect client information.

The requirement comes from the Federal Trade Commission’s Safeguards Rule. The rule requires covered financial institutions, including professional tax return preparers, to develop, implement and maintain an information-security program containing administrative, technical and physical safeguards.

A WISP should not be a generic document downloaded from the internet and stored away. It should reflect the actual size, complexity, technology, employees, vendors and risks of the accounting firm.

A practical WISP should explain:

  • What sensitive client information the firm collects

  • Where that information is stored

  • Who is permitted to access it

  • How employee accounts and devices are protected

  • How vendors and service providers are evaluated

  • How security risks are identified and addressed

  • How employees are trained

  • How backups are protected and tested

  • What happens when suspicious activity is detected

  • How the firm will respond to a data breach

  • Who is responsible for managing the security program

The IRS recommends reviewing and updating the plan regularly, especially when the firm changes software, adds employees, begins using new cloud services, or experiences other operational changes.

A WISP Must Be Supported by Real Security Controls

Writing a security plan is only the beginning. The firm must also implement the protections described in the plan.

For example, stating that the firm protects employee accounts is not meaningful unless safeguards such as multifactor authentication, strong access controls and account monitoring are actually in place.

Depending on the firm’s risks and operations, important protections may include:

  • Multifactor authentication for email, tax software and cloud applications

  • Advanced email filtering and phishing protection

  • Endpoint detection and response on computers and servers

  • Encryption for sensitive data

  • Secure client portals for exchanging documents

  • Restricted administrative privileges

  • Regular software and security updates

  • Tested, isolated backups

  • Employee cybersecurity training

  • Vulnerability assessments

  • Continuous security monitoring

  • A documented incident-response procedure

The IRS also encourages tax professionals to consult qualified technical experts because security threats and technologies continue to evolve.

Smaller Firms Are Not Exempt From Cyber Risk

Some small accounting firms may assume that cybercriminals primarily target national or regional firms. In reality, smaller practices can be appealing targets because attackers may expect them to have fewer security resources and less monitoring.

A criminal need not compromise the firm’s entire network to cause serious damage. Access to one employee’s email account may be enough to:

  • Send fraudulent payment instructions

  • Reset passwords for other services

  • Impersonate a partner

  • Access client documents

  • Redirect tax-related communications

  • Send phishing messages to the firm’s clients

This is why cybersecurity protections must apply throughout the organization—not only to partners, servers or tax-preparation systems.

Cybersecurity Is Also a Professional Responsibility

CPA firms are trusted with information that can significantly affect a client’s financial life or business operations. Clients reasonably expect that this information will be handled carefully.

A cybersecurity incident may therefore create consequences that go far beyond the immediate technical damage. A firm may also face:

  • Regulatory investigations

  • Client notification requirements

  • Legal expenses

  • Business interruption

  • Cyber-insurance claims

  • Fraudulent transactions

  • Reputational damage

  • Lost clients and referrals

For practitioners subject to professional standards, protecting taxpayer information may also be connected to their professional obligations. IRS professional-responsibility guidance has specifically addressed the importance of written security plans for CPAs, attorneys, enrolled agents and other tax practitioners.

Firms Must Be Prepared to Respond

Even firms with strong security controls cannot eliminate every risk. That is why an effective cybersecurity program must include an incident-response plan.

Firm leaders should know in advance:

  • Who employees should contact when they notice suspicious activity

  • Who has authority to disconnect a device or disable an account

  • Which cybersecurity, insurance and legal professionals should be contacted

  • How the firm will determine what information was affected

  • How critical systems will continue operating

  • How backups will be restored

  • When clients or government agencies must be notified

The FTC’s Safeguards Rule also includes a notification requirement for certain security events affecting covered customer information.

Trying to make these decisions for the first time during a ransomware attack or data breach can increase downtime, confusion, and financial loss.

What CPA Firm Leaders Should Do Now

Accounting firm leaders should review cybersecurity with the same seriousness they give tax procedures, quality control and professional ethics.

Begin by asking:

  1. Does our firm have a current Written Information Security Plan?

  2. Does the plan accurately describe our actual technology and procedures?

  3. Is multifactor authentication required for all critical systems?

  4. Are employees trained to recognize phishing and payment fraud?

  5. Are security alerts actively monitored and investigated?

  6. Are backups protected from ransomware and tested regularly?

  7. Do we know what to do if client information is compromised?

  8. Are our technology providers following appropriate security practices?

  9. When was our last formal cybersecurity risk assessment?

  10. Who is responsible for maintaining and updating our security program?

If the answers are unclear, incomplete, or based entirely on assumptions, the firm may have compliance and operational gaps that need attention.

Why This Matters

Cybersecurity is no longer an optional technology upgrade for CPA firms. It is becoming a documented business requirement tied to protecting taxpayer information, meeting regulatory expectations and preserving client trust.

A WISP provides the framework, but the firm’s technology, employees and everyday procedures must support what the document promises.

ADS Consulting Group helps CPA and accounting firms evaluate cybersecurity risks, strengthen safeguards and align their technology practices with today’s data-protection expectations. A cybersecurity and WISP readiness review can help identify gaps before they lead to a data breach, business interruption, or compliance problem.

Accounting firm

Get updated on the latest Information Technology news, Cybersecurity, Information Technology Trends, and recent real-world troubleshooting experiences.

SUBSCRIBE NOW!