Skip to content
Bellator Cyber Guard
Tax13 min readStandard

Cybersecurity Training for Seasonal Tax Preparers in 2026

Cybersecurity training for seasonal tax preparers should cover phishing, data handling, and your WISP. See what to include and how to roll it out.

By Bellator Cyber Guard Security Team

What Seasonal Tax Preparer Training Should Cover

Cybersecurity training for seasonal tax preparers means teaching short-tenure staff, often hired for just 10 to 16 weeks during filing season, how to spot phishing, protect client Social Security numbers and financial data, and follow your firm's written information security plan (WISP) before they touch a single return. A written information security plan (WISP) is a documented set of policies a firm uses to protect client data, and it's the framework most tax season training should tie back to. Seasonal hires are attractive targets for attackers because they're new to your systems, working under deadline pressure, and less likely to recognize a spoofed request from a "partner" or "client." A short, focused training session before the first W-2 arrives closes most of that gap.

Quick Answer

Cybersecurity training for seasonal tax preparers should cover phishing recognition, secure handling of client data, password and multi-factor authentication (MFA) basics, and your firm's WISP requirements, delivered before returns start flowing and refreshed once mid-season. IRS Publication 4557 and the IRS Security Six recommendations both expect staff-level security awareness regardless of how long an employee has been with the firm. Because seasonal preparers have limited tenure and less exposure to your normal systems, keep training focused on the handful of actions that stop most incidents: recognizing phishing, verifying unusual requests, and reporting anything suspicious immediately.

Why Seasonal Preparers Are a Bigger Target Than You'd Think

Tax season concentrates high-value client data, Social Security numbers, bank routing numbers, prior-year returns, into a few frantic months, and attackers know it. According to Verizon's 2025 Data Breach Investigations Report, phishing and stolen or misused credentials remain among the leading paths into confirmed data breaches across industries. Tax and accounting firms are a recurring target during filing season specifically because of the volume of taxpayer data flowing through their systems. Seasonal preparers add risk on top of that baseline: they're often working remotely, they haven't seen a full year of your firm's normal email patterns, and they may not know who to call the moment something looks off. For a closer look at how these attacks target the profession, see our guide to phishing attacks on tax professionals.

What to Include in Seasonal Preparer Training

  • Recognize phishing emails impersonating the IRS, clients, or partners
  • Verify unusual requests for W-2s, wire transfers, or client data by phone before acting
  • Use a unique password and multi-factor authentication on every tax software and email login
  • Handle and store client Social Security numbers and financial data per the firm's WISP
  • Avoid working on client files over public or unsecured Wi-Fi
  • Report anything suspicious immediately, before trying to fix it alone
  • Know how to identify fake or spoofed tax software login pages

What the IRS and FTC Expect From Your Training Program

The IRS's Security Six recommendations and Publication 4557, Safeguarding Taxpayer Data, direct tax professionals to train staff, including seasonal and part-time preparers, on recognizing phishing, protecting taxpayer data, and reporting suspicious activity. We break down the full set of expectations in our IRS Publication 4557 requirements 2026 guide and our IRS Security Six checklist.

If your firm is subject to the Federal Trade Commission's Safeguards Rule, which applies to most paid tax preparation businesses as "financial institutions" under the Gramm-Leach-Bliley Act, employee training is one of the documented safeguards a WISP is expected to include. A WISP without evidence that seasonal staff actually completed training can create a documentation gap if your firm is ever asked to show its safeguards are in place. Legal questions about whether your specific firm meets these requirements should go to your attorney or compliance advisor; this is general guidance, not legal advice.

Time Training Before System Access, Not After

If seasonal preparers start handling returns before completing security training, they're working with live client data without having seen your phishing-reporting process or WISP requirements. Build training into onboarding, before credentials are issued, not after the first busy week.

Rolling Out Training in a Short Season

1

Before day one

Require a recorded or live session on phishing and data handling as part of onboarding, before granting access to tax software or client files.

2

First week

Run a simulated phishing test to confirm the training stuck, and pair new preparers with an experienced staff member for their first client interactions.

3

Mid-season

Send a short reminder as phishing volume typically rises closer to the filing deadline, and confirm staff know exactly how to report a suspicious email.

Training Reduces Risk, It Doesn't Eliminate It

Well-trained seasonal preparers will still click the occasional convincing phishing link during a stressful week in March. Training lowers how often that happens and how quickly it gets reported; it doesn't replace technical safeguards that catch what training misses. Pairing staff training with managed endpoint detection and response and MFA on every tax software login, email account, and file-sharing tool gives your firm a second layer of protection if someone clicks before they think. Compare Bellator's options on the protection plans page if you're deciding how much technical coverage to pair with training.

If you don't yet have a documented WISP that spells out training requirements, timing, and recordkeepingBellator's custom WISP starts at $749 for firms with up to 5 users, with larger practices quoted separately; most firms recover that cost through the 20 to 40 billable hours it typically saves compared with building one from scratch. See our IRS WISP template guide for what a compliant plan needs to include.

Key Takeaway

Train seasonal preparers before they get system access, not during their first busy week. A focused phishing and data-handling session, reinforced with MFA and a documented WISP, addresses most of the risk tax season adds.

Get Help Building a Tax Season Training and WISP Plan

Talk through what your seasonal staff actually need to know, and whether your current WISP already covers it. No pressure.

Frequently Asked Questions

Yes. IRS Publication 4557 and the Security Six recommendations don't carve out an exemption based on hours worked or length of employment, any preparer handling taxpayer data is expected to understand how to protect it and recognize phishing attempts.

Once before a preparer starts working with client data, with a short refresher mid-season when phishing volume tends to increase as the filing deadline approaches.

No. The IRS doesn't mandate a specific course or vendor. Publication 4557 and the Security Six describe the topics staff should understand, recognizing phishing, safeguarding taxpayer data, and reporting incidents, and leave the delivery method to the firm.

A 30- to 60-minute recorded or live session covering phishing recognition, data handling, and your WISP, followed by a simulated phishing test in the first week, covers the topics regulators expect without pulling staff away from returns for long.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.