CPA Firms: The FTC Is Looking at More Than Your Books
CPA firms have always been trusted with some of the most sensitive information a person or business can provide: Social Security numbers, tax returns, payroll records, banking information, financial statements, and identity documents.
What many accounting professionals still may not realize is that federal law can treat their firm as a financial institution for cybersecurity purposes.
The IRS reinforced that point again in 2026. In August, the IRS and its Security Summit partners reminded tax and accounting professionals that federal law requires them to maintain a Written Information Security Plan, or WISP, to protect client data. Then in September, the IRS specifically reminded tax professionals that multifactor authentication is required under the FTC Safeguards Rule for access to customer information, unless an equivalent control is formally approved in writing.
For Florida CPA and tax firms, this is not simply an IT best practice. It can be a compliance obligation.
Why does the FTC Safeguards Rule apply to CPA and tax firms?
The Federal Trade Commission's Safeguards Rule implements part of the Gramm-Leach-Bliley Act, or GLBA.
Although most people associate GLBA with banks and lenders, the FTC's definition of a financial institution is much broader. The FTC specifically identifies tax preparation firms as an example of businesses that can fall under the Safeguards Rule.
The IRS goes further in its current guidance, stating that tax and accounting professionals are considered financial institutions under GLBA and must implement a data security plan to protect client information.
That means a CPA firm should not assume it is exempt simply because it is not a bank.
The important questions are what services the firm performs, what customer information it maintains, and whether those activities bring the firm within the Rule.
The requirement many CPA firms overlook: a Written Information Security Plan
One of the clearest requirements is also one of the easiest to overlook.
Tax professionals are required to maintain a written information security program, commonly referred to by the IRS as a Written Information Security Plan or WISP.
A WISP should not simply be a generic cybersecurity policy downloaded from the internet.
The IRS says the plan should be appropriate to the firm's size, complexity, scope of operations, and the sensitivity of the information it handles. It should address areas such as employee management and training, information systems, and detecting and responding to system failures.
For a CPA firm, that means the plan should actually reflect how the practice operates.
Where are tax returns stored? Who has access to client portals? Are employees working remotely? Are files stored in Microsoft 365, Google Workspace, a tax application, a document management platform, or a local server? What happens when an employee leaves? How are old records destroyed?
A useful WISP should answer those questions.
What cybersecurity controls does the FTC expect?
The FTC Safeguards Rule is much more specific than simply requiring businesses to use “reasonable cybersecurity.”
Covered organizations are expected to build an information security program around documented risks and appropriate safeguards.
Among the key requirements are:
A Qualified Individual responsible for overseeing the information security program.
A written risk assessment identifying reasonably foreseeable threats to customer information.
Appropriate access controls, including regular review of who actually needs access.
An inventory of systems, devices, applications, data locations, and personnel with access to customer information.
Encryption of customer information both while stored and while being transmitted, or an approved equivalent control when encryption is not feasible.
Multifactor authentication for anyone accessing customer information, subject to a narrowly defined alternative approved in writing.
Procedures for securely disposing of customer information when there is no longer a legitimate business or legal reason to retain it.
Security review of applications that store or process customer information.
Monitoring for unauthorized access.
Employee cybersecurity awareness training.
Oversight of third-party service providers.
A written incident-response plan.
Periodic review and updating of the information security program.
For many CPA firms, some of these controls may already exist.
The problem is often that they are informal, inconsistently applied, or undocumented.
Having Microsoft 365 does not automatically mean MFA is correctly enforced. Having backups does not mean recovery has been tested. Having an IT provider does not automatically satisfy the firm's responsibility to oversee vendors.
MFA is no longer optional for most covered tax practices
The IRS's September 2026 reminder specifically highlighted multifactor authentication.
Under the FTC Safeguards Rule, covered tax preparation firms must use MFA for access to customer information unless the firm's Qualified Individual approves an equivalent secure access control in writing.
For CPA firms, MFA should generally be considered for far more than email.
Think about every system containing sensitive client information:
Microsoft 365 or Google Workspace, tax preparation software, bookkeeping platforms, payroll applications, remote-access tools, VPNs, cloud storage, document-management systems, banking portals, and administrative accounts.
A firm's cybersecurity is only as strong as the least protected account capable of reaching sensitive information.
Your vendors are part of your compliance environment
CPA firms rely heavily on third parties.
Tax software. Payroll platforms. Cloud hosting. Client portals. Managed IT providers. Backup services. Document management systems. Payment processors.
The FTC requires covered firms to select service providers capable of maintaining appropriate safeguards, include security expectations in contracts, monitor those providers, and periodically reassess whether they remain appropriate.
This is an important distinction.
Outsourcing your IT does not outsource your responsibility.
An MSP can implement and manage security controls, but the accounting firm still has an obligation to understand who has access to its information and whether appropriate protections are in place.
Does the FTC require penetration testing and vulnerability scans?
Potentially, yes.
The Safeguards Rule requires covered institutions to regularly monitor and test their safeguards. Organizations can meet this requirement through continuous monitoring.
If they do not implement continuous monitoring, the FTC says they must conduct annual penetration testing and vulnerability assessments, including system-wide scans at least every six months, along with additional testing when material changes or circumstances warrant it.
This is one area where firms should pay attention to the Rule's small-business provisions.
Financial institutions maintaining customer information concerning fewer than 5,000 consumers are exempt from certain requirements, but that is not a blanket exemption from the Safeguards Rule. Firms should determine which provisions apply to their specific situation rather than assuming their size removes the obligation altogether.
CPA firms also need an incident-response plan
A ransomware attack at 9:00 Monday morning is not the time to decide who should call the cyber insurance carrier.
The FTC requires a written incident-response plan addressing issues including internal response procedures, roles and responsibilities, communications, remediation, documentation, reporting, and lessons learned after the incident.
For a Florida CPA firm, a practical plan should answer questions such as:
Who has authority to shut down a compromised system? Who contacts the firm's IT provider? Who contacts cyber insurance? Who determines whether legal counsel or law enforcement should become involved? How will the firm communicate if email is unavailable? Where are offline or isolated backups? Who determines whether clients must be notified?
Those decisions are much easier to make before an incident.
Breach reporting can involve both federal and Florida requirements
Since May 2024, the FTC Safeguards Rule has included a federal breach-notification requirement.
A covered financial institution generally must notify the FTC as soon as possible and no later than 30 days after discovering a qualifying security event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
Florida firms may also have obligations under the Florida Information Protection Act, or FIPA.
Florida law requires covered entities to take reasonable measures to secure electronic personal information. A breach affecting 500 or more Florida residents generally must be reported to the appropriate state department within 30 days, and affected individuals may also require notification.
These requirements can overlap, but they are not identical.
That is why incident response should involve both technical and legal guidance rather than relying solely on an IT provider to determine notification obligations.
What should a Florida CPA firm do now?
For most firms, the best starting point is not buying another cybersecurity product.
It is determining whether the security program already in place can actually be demonstrated.
A CPA firm should be able to produce a current WISP, identify its Qualified Individual, show that a risk assessment has been performed, demonstrate that MFA and encryption are properly configured, document how employees are trained, identify all vendors with access to client information, show how systems are monitored and tested, and explain what happens when a security incident occurs.
The difference between having security tools and having a cybersecurity program becomes very important here.
A firewall, endpoint protection, Microsoft 365, backups, and MFA may all be pieces of the program.
The FTC Safeguards Rule is asking firms to show how those pieces work together to protect customer information.
A practical FTC Safeguards Rule checklist for CPA firms
A Florida CPA or tax practice evaluating its cybersecurity program should be able to answer yes to questions like these:
Do we have a current Written Information Security Plan?
Have we designated someone responsible for overseeing the program?
Have we completed and documented a cybersecurity risk assessment?
Do we know everywhere client information is stored?
Is MFA enforced anywhere sensitive client information can be accessed?
Is sensitive information encrypted at rest and in transit?
Do we regularly review employee and administrative access?
Do employees receive recurring security-awareness training?
Do we evaluate the cybersecurity practices of vendors that access client data?
Are vulnerabilities identified and remediated on an ongoing basis?
Do we have tested backups and a documented recovery process?
Do we have a written incident-response plan?
Do we know our FTC and Florida breach-notification responsibilities?
If several of those questions produce an “I think so” rather than a documented answer, that is probably the place to start.
The important takeaway for CPA firms
Cybersecurity requirements for accounting firms are becoming much more explicit.
The IRS's 2026 guidance is a useful reminder that protecting taxpayer information is not simply a matter of professional reputation or good IT hygiene.
For firms subject to the FTC Safeguards Rule, practices such as a written security program, MFA, risk assessment, vendor oversight, incident planning, and ongoing monitoring may be regulatory requirements.
For Florida firms, those federal obligations also sit alongside state data-security and breach-notification requirements.
That doesn't mean every CPA practice needs an enterprise-sized cybersecurity department.
It does mean the firm should be able to show that someone is responsible, the risks are understood, appropriate safeguards are in place, and there is a documented plan for keeping those protections current.
Is your CPA firm's cybersecurity program actually documented?
SNH Technologies works with professional-service firms to evaluate their technology and cybersecurity environments, document existing safeguards, identify gaps, and put practical protections in place.
If you're not sure whether your firm's current IT environment aligns with the FTC Safeguards Rule, or whether your WISP reflects what is actually happening in your network, an IT and cybersecurity assessment is a good place to start.
This article is intended for general informational purposes and is not legal or accounting advice. Firms should consult qualified legal or compliance counsel regarding their specific regulatory obligations.