Cybersecurity for accountants is part of professional risk management. Tax records, banking details, payroll files and identity documents are valuable to criminals, while an attacker who controls email can redirect payments or impersonate a trusted adviser. A defensible program combines governance, prevention, detection and a rehearsed response.
Start with data and responsibility
Inventory the systems, vendors and devices that create, receive, store or transmit client information. Record the data type, owner, authorized users, retention period and backup location. Minimize collection and delete data according to legal, contractual and professional requirements. Assign a named security lead even in a small practice.
U.S. tax professionals should evaluate their duties under the FTC Safeguards Rule and IRS guidance, including the requirement for a written information security plan where applicable. Requirements depend on the organization and jurisdiction; this checklist is not legal advice.
Implement the highest-value controls
| Control | Minimum practice | Evidence |
|---|---|---|
| Identity | Phishing-resistant MFA; separate admin accounts | Access report and MFA coverage |
| Devices | Encryption, supported software, automatic patches | Device inventory and compliance report |
| Data | Least privilege, secure portal, approved retention | Permissions and deletion log |
| Recovery | Isolated backups and tested restore | Dated restore-test result |
Do not send sensitive files as ordinary email attachments when a controlled portal is available. Require an independent verification step for bank-detail changes and unusual payment requests. Our email security guide covers account takeover and payment fraud in more detail.
Control staff and vendor access
Grant access by role, review it periodically and remove it promptly at offboarding. Train staff to report suspicious messages without embarrassment. Evaluate cloud vendors for authentication, encryption, audit logs, data location, subprocessors, breach notification, deletion and export. A contract does not replace testing: verify that controls are enabled in the tenant.
Prepare for an incident
- Preserve evidence and record the time, account, device and observed behavior.
- Contain affected identities or devices without destroying logs.
- Engage the designated security, legal, insurer and service-provider contacts.
- Determine what data and clients were affected.
- Meet applicable notification and reporting duties.
- Recover from known-good systems, monitor and document lessons learned.
Keep the response plan available when normal systems are inaccessible. Run a tabletop exercise using a realistic scenario such as a compromised mailbox or stolen laptop.
Measure control effectiveness
Useful measures include MFA coverage, unsupported devices, critical patch age, overdue access reviews, simulated-phishing reporting, backup restore success and time to disable a departed user’s account. Avoid rewarding a low number of reported incidents; it can indicate underreporting.
Frequently asked questions
Is antivirus enough for an accounting firm?
No. Endpoint protection helps, but identity controls, secure configuration, staff procedures, backups, vendor oversight and response planning address different failure paths.
What is the safest way to exchange client files?
Use a vetted encrypted portal with MFA, role-based access, expiry options and audit logs. Confirm the recipient and avoid public links.
How often should access be reviewed?
Review privileged and sensitive access on a risk-based schedule and whenever roles change. Remove access immediately when it is no longer required.
Sources reviewed
- IRS: Protect Your Clients; Protect Yourself
- CISA: Require multifactor authentication
- FTC privacy and data security guidance
Last reviewed: August 15, 2026.