MYCPE ONE

CPA and accounting firms can prevent data breaches and cyberattacks by combining a Written Information Security Plan (WISP), multifactor authentication, encryption, tested backups, secure client portals, and regular staff training. Together, these practices form the foundation of cybersecurity for accounting firms. They matter now because criminals actively target tax and financial data, and an accounting firm data breach can lead to regulatory penalties, lost clients, and costly downtime.

The IBM 2025 Cost of a Data Breach Report puts the average U.S. breach at $10.22 million. Prevention costs far less than recovery.

Your firm does not need to become a security expert, but it does need practical safeguards. Working with a provider of Cybersecurity Services for CPA and Accounting Firms is one of the fastest ways to put those safeguards in place.

Key Takeaways

  • CPA firms hold Social Security numbers, bank details, and tax data, which makes them attractive targets.
  • Phishing, business email compromise, ransomware, and AI deepfakes are the leading threats.
  • The FTC Safeguards Rule and IRS guidance require a Written Information Security Plan (WISP).
  • Multifactor authentication, encryption, tested backups, and staff training prevent most attacks.
  • A written incident response plan limits damage when something goes wrong.

What Is Cybersecurity for Accounting Firms?

Cybersecurity for CPA firms is the combination of technical controls, written policies, and staff training that protects client financial data, tax records, and firm systems from theft, loss, and unauthorized access, while meeting requirements such as the FTC Safeguards Rule and IRS data security standards.

It covers three connected areas:

  • PeopleTraining staff to recognize scams and follow secure procedures.
  • ProcessWritten security plans, access rules, and vendor reviews.
  • TechnologyMultifactor authentication, encryption, backups, and monitoring.

For a broader foundation, read our Guide to Cybersecurity for Accounting Firms.

CTA

Why Are CPA Firms a Top Target for Cybercriminals?

CPA and accounting firms are top targets because they store Social Security numbers, bank details, and complete tax records for hundreds or thousands of clients in one place. Many small and midsized firms protect that data without dedicated security staff. Tax season deadlines add pressure, which makes a quick click on a fake email more likely.

What Makes Client Tax and Financial Data So Valuable to Hackers?

A single tax return contains a Social Security number, date of birth, income details, bank account and routing numbers, and information about dependents. With that data, criminals can file fraudulent returns, redirect refunds, and open new credit accounts.

Unlike a stolen credit card, a Social Security number cannot simply be cancelled and reissued.

Why Are Small and Midsized Accounting Firms More Vulnerable?

Smaller firms hold the same sensitive data as large firms, often with fewer protections. Common gaps include:

  • No dedicated IT or security staff
  • Shared passwords or accounts without multifactor authentication
  • Heavy reliance on email to exchange client documents
  • Busy season pressure that leads staff to click and approve quickly

What Are the Biggest Cyber Threats in Accounting Today?

Most cyber threats in accounting fall into four groups. For a deeper breakdown, see Cybersecurity Threats for CPA Firms.

cyber threats

Phishing and Business Email Compromise (BEC)

Phishing emails pose as clients, the IRS, or software vendors to steal passwords. Business email compromise goes further: criminals impersonate a partner or client to redirect wire payments or request W2 data. The FBI Internet Crime Complaint Center reported nearly $3.05 billion in BEC losses in 2025.

Ransomware Attacks on Accounting Firms

Ransomware locks your files and demands payment to release them. Ransomware attacks on accounting firms often land during filing season, when downtime hurts most. Many attackers now steal data before encrypting it, then threaten to publish it.

AI Powered Deepfakes and Social Engineering Scams

Criminals now use AI to write polished phishing emails, clone a partner's voice, or fake a video call approving a payment. IBM found attackers used AI in 16% of the breaches it studied. Learn how these schemes work in our article on AI powered cyberattacks.

Insider Threats and Third Party Vendor Risks

Not every risk comes from outside. A careless employee, a departing staff member, or a vendor with weak security can expose client data. Every software provider, cloud host, and outsourcing partner with system access extends your risk.

Protect your firm from cyber threats. Schedule a call with MYCPE ONE.

What Happens When an Accounting Firm Suffers a Data Breach?

Financial, Legal, and Reputational Costs

An accounting firm data breach creates costs on several fronts:

  • Forensic investigation and system recovery
  • Client notification and credit monitoring
  • Legal fees and regulatory penalties
  • Lost billable hours during downtime
  • Higher cyber insurance premiums at renewal

The IRS can also suspend a firm's EFIN for inadequate data security, which stops electronic filing in the middle of tax season.

How a Breach Affects Client Trust and Retention

Clients trust their CPA with their most private information. After a breach, some leave quietly, referrals slow, and rebuilding reputation can take years.

Which Data Security Regulations Must CPA Firms Follow?

Under the Gramm Leach Bliley Act, the FTC Safeguards Rule treats tax and accounting professionals as financial institutions, and IRS Publication 5708 confirms this applies regardless of firm size.

RegulationWho It Applies ToCore RequirementPenalty Risk

FTC Safeguards Rule (WISP)

CPAs, tax preparers, and bookkeepers

Written security program, risk assessment, MFA, encryption, vendor oversight, and FTC notice within 30 days for breaches affecting 500 or more consumers

FTC enforcement and civil penalties

IRS Publication 4557

All paid tax return preparers

Safeguard taxpayer data and maintain a WISP; confirmed during PTIN renewal

EFIN suspension and IRS action

IRC Section 7216

Tax return preparers

Written taxpayer consent before using or disclosing tax return information

Criminal fines up to $1,000 and up to one year in prison; civil penalties under Section 6713

AICPA Standards and SOC 2

Firms and vendors whose clients expect independent assurance

Confidentiality of client information; audited security controls for service providers

Lost contracts and client trust

State Breach Notification Laws

Any firm holding resident data, in all 50 states

Notify affected residents, and sometimes the state attorney general, within set deadlines

State fines and lawsuits

How Can CPA Firms Prevent Cyberattacks? 8 Security Best Practices

These CPA firm security best practices address the most common causes of breaches. If budget is tight, start with the first three.

8 Security Best Practices Cyberattacks

1. Create a Written Information Security Plan (WISP)

A WISP documents who is responsible for security, what risks exist, which controls are in place, and how you respond to incidents. The IRS offers a free sample template in Publication 5708, and Publication 4557 provides a practical checklist. Review it yearly.

2. Enforce Multifactor Authentication and Zero Trust Access

Require multifactor authentication on email, tax software, client portals, and remote access. Zero trust means no user or device is trusted by default, so staff reach only the client files they need for their role.

3. Encrypt Client Data at Rest and in Transit

Encrypt laptops, servers, and cloud storage, plus every file transfer. Encryption makes stolen data unreadable, and under the FTC rule, a breach of properly encrypted data generally does not trigger the FTC reporting duty.

4. Replace Email Attachments with Secure Client Portals

Email attachments are easy to intercept or send to the wrong person. A secure portal adds encryption, access logs, and automatic file expiry. It is one of the simplest upgrades for client data protection for CPAs.

5. Patch Systems and Deploy Endpoint Detection (EDR)

Install updates for operating systems, tax software, and browsers promptly. Endpoint detection and response tools monitor devices for unusual behavior and can isolate an infected computer before ransomware spreads.

6. Follow the 321 Backup Rule to Beat Ransomware

Keep three copies of your data, on two different storage types, with one copy offline or offsite. Test your restores every quarter. Tested backups let you recover without paying a ransom.

7. Train Staff to Spot Phishing and Deepfake Scams

Run short training sessions and phishing simulations throughout the year, with extra reminders before busy season. Teach one firm rule: verify any payment change or data request by calling a known phone number.

8. Vet Cloud Vendors and Outsourcing Partners

Before signing, ask every vendor for:

  • A current SOC 2 Type II report
  • Encryption and MFA policies
  • Breach notification terms in the contract
  • Where client data is stored and who can access it

CTA

How Is AI Changing Cybersecurity for Accounting Firms?

AI now works on both sides of security.

  • As a threat: Attackers use AI for realistic phishing, voice cloning, and deepfake video. IBM also found that heavy use of shadow AI, meaning unapproved AI tools used by staff, added about $670,000 to the average breach cost.
  • As a defense: AI tools detect unusual logins and large file downloads, filter AI written phishing, and trigger automated responses that contain threats in minutes.
  • Action step: Publish an approved AI tools policy so staff never paste client data into unvetted apps.

How Can Accounting Firms Protect Client Data When Outsourcing or Offshoring?

Outsourcing can be secure when the right controls are in place:

  • Obtain signed 7216 consent forms before sharing tax return information with offshore teams
  • Choose partners with SOC 2 or ISO 27001 certification
  • Use virtual desktops so client data never leaves your environment
  • Restrict USB drives, printing, and local downloads
  • Sign confidentiality and data protection agreements

What Should a CPA Firm's Incident Response Plan Include?

An effective incident response plan follows five steps:

  • ContainDisconnect affected devices and disable compromised accounts.
  • AssessEngage forensic experts to confirm what data was accessed.
  • ReportContact your IRS Stakeholder Liaison, your cyber insurer, and the FTC if 500 or more consumers are affected.
  • NotifyInform affected clients and state authorities as required by law.
  • Recover and Review: Restore from clean backups, fix the root cause, and update your WISP.

What Cybersecurity Mistakes Do Accounting Firms Commonly Make?

  • Treating the WISP as a one-time document instead of a living plan
  • Sending tax documents as email attachments
  • Skipping MFA on accounts that seem low risk
  • Never testing whether backups actually restore
  • Assuming cyber insurance replaces security controls
  • Giving every employee access to every client file

Conclusion

Cybersecurity for accounting firms depends on consistent, practical safeguards: a current WISP, MFA, encryption, tested backups, trained staff, and vetted vendors. Each step protects client data, keeps systems secure, supports compliance, and preserves the trust your firm depends on.

Ready to strengthen your firm's defences? Explore MYCPE ONE Cybersecurity Services for CPA and Accounting Firms

FAQs

Yes. Under the FTC Safeguards Rule and IRS guidance, tax and accounting professionals must maintain a Written Information Security Plan, regardless of firm size.

Many basics, such as MFA, device encryption, and the IRS WISP template, cost little or nothing. Managed security services typically add a monthly fee per user.

Contain the incident, preserve evidence, and contact your IRS Stakeholder Liaison and cyber insurer. Bring in forensic help before notifying clients.

It is not legally required but is strongly recommended. Policies can cover forensics, notification, legal defense, and business interruption.

At least once a year, with short refreshers and phishing simulations each quarter and before tax season.

Blaise Wabo

Blaise Wabo

Blaise Wabo is a cybersecurity and compliance expert with 12+ years of experience helping organizations meet security and regulatory requirements. As the Healthcare and Financial Services Lead at A-LIGN, he advises businesses on SOC, HIPAA, and HITRUST compliance. Since 2013, he has led more than 500 SOC reviews and 300 HITRUST/HIPAA assessments for Fortune 500 and growing companies. Blaise is recognized for simplifying complex compliance challenges into practical, scalable security solutions.

Must Read Blogs