
Tax Data Backup Plan: IRS Compliance Guide for Tax Professionals
A compliant tax data backup plan is a mandatory requirement for every tax professional handling sensitive client data. The IRS mandates thorough backup strategies through IRS Publication 4557, making data backups the fourth essential component of the Security Six framework. If you prepare tax returns professionally and hold a PTIN, you must implement and document a compliant plan. There are no exemptions for solo practitioners or small firms.
Non-compliance carries real consequences: IRS investigations, regulatory penalties under the FTC Safeguards Rule, PTIN suspension, and lasting damage to professional credentials. For a practice managing hundreds or thousands of client returns containing Social Security numbers, bank account details, and financial records, your backup strategy determines whether you recover from a ransomware attack in hours or lose your entire practice.
This guide covers the specific IRS backup requirements, how to apply the 3-2-1-1-0 strategy to a tax practice, software-specific backup paths most practitioners miss, and what to do when backups fail during filing season.
Tax Data Security: By the Numbers
Sophos research: attackers attempt to compromise backups in 94% of ransomware incidents
IRS Security Summit: nearly 300 breaches exposed data on up to 250,000 clients in the first half of 2025
Sophos 2024: average ransomware recovery cost, up $1M from the prior year
2026 Filing Season Compliance Requirement
The IRS requires all credentialed tax preparers to maintain a documented backup plan as part of a compliant Written Information Security Plan (WISP). Firms without written backup procedures cannot demonstrate compliance during Security Summit inspections, FTC audits, or data breach investigations. Review your plan before the 2026 filing season opens.
Why Tax Professionals Are Prime Ransomware Targets
The threat environment facing tax professionals has shifted significantly. According to the IRS Security Summit, nearly 300 data breaches affecting tax professionals in the first half of 2025 alone exposed data on up to 250,000 clients. Sophos research found that 94% of ransomware victims experienced attackers attempting to compromise their backup systems, with 57% of those attempts succeeding.
Ransomware operators specifically target backup systems because businesses with intact, isolated backups can recover without paying ransom. When backups are compromised alongside production systems, victims face a stark choice: pay the ransom or lose years of client data permanently.
Tax preparers manage an extraordinarily valuable dataset. A single completed tax return contains full names, Social Security numbers, dates of birth, addresses, employment information, and bank account details. That combination is worth significantly more on criminal markets than individual stolen credentials, and attackers know it.
Several factors make tax practices especially attractive targets:
- Seasonal pressure windows: January through April operations run under extreme time pressure with temporary staff, creating security gaps attackers actively exploit.
- Small firm security posture: Most tax preparers operate as solo practitioners or firms with fewer than 10 employees, often without dedicated IT security resources.
- Regulatory pressure to pay: The threat of IRS penalties, PTIN suspension, and malpractice liability creates pressure to pay ransoms quickly to resume operations.
- High data density: A single tax software database may contain complete identity packages for hundreds or thousands of clients in one file.
The financial stakes extend beyond ransom payments. The IBM Cost of Data Breach Report found that breaches in the financial services sector, which includes tax preparation under the Gramm-Leach-Bliley Act (GLBA), average $6.08 million per incident. Downtime alone can cost mid-sized organizations more than $300,000 per hour according to industry estimates. For a small tax practice, even a fraction of those costs can be existential.
To understand the full scope of threats targeting your practice, see our overview of how ransomware attacks work and our assessment of tax client portal security risks.
IRS Security Six Backup Requirements
The IRS Security Six framework defines the minimum baseline of cybersecurity controls required for tax professionals with a PTIN. Data backups are the fourth pillar of this framework, alongside two-factor authentication, antivirus protection, firewalls, drive encryption, and virtual private networks. The mandate applies universally. There are no size-based exemptions.
IRS Publication 4557, "Safeguarding Taxpayer Data," establishes specific requirements for tax preparer backup systems. These requirements align with CISA's Cyber Essentials guidance and the NIST Cybersecurity Framework 2.0, specifically the Protect (PR.IP-4) and Recover (RC.RP-1) functions:
- Complete coverage: Back up all systems, applications, and data repositories that store, process, or transmit taxpayer information, including tax software, document management systems, email servers, and client portals.
- Consistent scheduling: Implement automated backup procedures on a defined schedule without requiring manual intervention. Daily backups for active client data, weekly for archived records.
- Isolated storage: Maintain at least one backup copy that is air-gapped or immutable, preventing ransomware from encrypting both production systems and backups simultaneously.
- Encryption requirements: Encrypt all backup data both in transit and at rest using FIPS 140-2 validated cryptographic modules with AES-256 encryption.
- Access controls: Restrict backup system access to authorized personnel only, implementing role-based access control (RBAC) and multi-factor authentication for administrative functions.
- Regular testing: Conduct documented restore tests at least quarterly to validate backup integrity and measure recovery time objectives (RTO).
- Written documentation: Maintain current written procedures detailing backup frequency, retention periods, storage locations, encryption methods, responsible parties, and testing schedules.
Your backup requirements are part of a broader IRS cybersecurity compliance framework that includes your Written Information Security Plan. The backup plan is a required component of any compliant WISP. Review PTIN WISP requirements for the full picture of what credentialed preparers must document.
Bottom Line
A backup that has never been tested is not a backup. IRS Publication 4557 and FTC Safeguards Rule §314.4(f) both require documented restore testing, not just the existence of backup copies. Schedule quarterly restore tests and record the results in writing. Regulators will ask for this documentation during investigations.
Understanding RTO and RPO for Tax Practices
Two metrics determine how useful your backup plan actually is when disaster strikes: Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
RTO is the maximum amount of time your practice can afford to be offline before the impact becomes unacceptable. During filing season, an RTO of more than four hours can mean missing client deadlines, triggering penalty notices, and losing clients permanently. Off-season, a 24-hour RTO may be tolerable. Define your RTO before choosing backup technology, not after.
RPO is the maximum amount of data loss your practice can absorb, measured in time. If your backups run nightly and ransomware hits at 4 PM, you lose a full day of work. For a firm processing 20 returns per day in peak season, that means recreating 20 client files from source documents. If that cost is unacceptable, you need more frequent backups or real-time replication.
Most tax practices benefit from these target metrics:
- Filing season RTO: 2-4 hours maximum
- Off-season RTO: 24 hours acceptable
- Filing season RPO: 4 hours or less (requires multiple daily backups or continuous replication)
- Off-season RPO: 24 hours acceptable (nightly backups sufficient)
Your RTO and RPO targets directly determine which backup technologies you need. A 2-hour RTO during filing season requires local backup hardware with fast restore capabilities, not just cloud-only backups that take hours to download. A 4-hour RPO means running backups at least three times per day during active filing periods.
The 3-2-1-1-0 Backup Rule for Tax Practices
The 3-2-1-1-0 rule is the industry standard backup strategy, evolved from the original 3-2-1 rule to address modern ransomware threats that specifically target and destroy backup systems before deploying encryption payloads. Each number represents a requirement:
- 3, Maintain three copies of your data: production data plus two backups.
- 2, Store backups on two different media types, such as local NAS and cloud storage.
- 1, Keep one backup offsite or in a geographically separate cloud region.
- 1, Maintain one immutable or air-gapped backup that ransomware cannot modify or delete.
- 0, Verify zero errors through regular restore testing. Backups you have not tested are not reliable recovery options.
For most tax practices, this translates to: local encrypted backup on a NAS device in your office for fast recovery from common scenarios, automated replication to cloud storage in a separate geographic region for disaster recovery, and immutable object-locked cloud copies that prevent deletion or modification for the defined retention period.
How Immutable Backups Protect Against Ransomware
Object lock technology, available in enterprise backup solutions and cloud storage platforms, creates backup copies that cannot be modified, encrypted, or deleted for a specified retention period, even by administrators with full system access.
When ransomware operators compromise a tax practice's network, they typically spend days or weeks in reconnaissance, identifying backup systems and attempting to delete or encrypt them before deploying the encryption payload. Traditional backup systems that allow deletions or overwrites provide no protection in this scenario.
Immutable backups with object lock create a recovery point that attackers cannot reach. Even if they obtain administrator credentials to your backup system, they cannot delete or encrypt locked backup objects. For tax professionals, set object lock retention to match IRS recordkeeping requirements, typically seven years for individual returns per IRS Publication 583, though three years covers most audit scenarios.
Use compliance mode for the strongest protection (not even cloud provider root accounts can delete locked objects), or governance mode for operational flexibility with full audit trails. Immutable storage typically costs $20-50 per terabyte per month, a modest premium over standard cloud storage that provides essential ransomware protection. This approach also directly supports the incident response procedures described in your tax practice incident response plan.
Tax Software-Specific Backup Requirements
One of the most vital and commonly overlooked aspects of tax data backup is understanding where your tax preparation software actually stores client data. Many tax professionals assume that backing up their Documents folder or desktop provides adequate protection. In reality, most professional tax software stores live databases in custom program directories that standard file backups completely miss.
Where Professional Tax Software Stores Client Data
Professional tax platforms rarely store working data in user-accessible locations like Documents or Desktop folders. Instead, they maintain proprietary database files in protected system directories that require explicit backup configuration:
- Intuit ProSeries and Lacerte: Store client data in
C:\Users\Public\Documents\Intuit\ProSeries [Year]orC:\ProgramData\Intuit\Lacerte\[Year]. These locations fall outside standard user backup paths and require explicit inclusion in backup policies. - Drake Tax Software: Maintains client data in
C:\Drake[Year]\Databy default, though custom installations may vary. Drake uses indexed database files requiring consistent backup of the entire Data directory. - Thomson Reuters UltraTax CS: Stores data in SQL Server databases or local file-based storage at
C:\CSA\Practice CS\[Year]. SQL Server implementations require database-level backups, not simple file copies. - CCH Axcess Tax: As a cloud-based platform, client data resides on CCH servers. Firms should still back up locally downloaded returns and custom templates to local storage included in their backup plan.
- Intuit QuickBooks: Company files (.QBW) are typically stored in
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files, but multi-user configurations may store files on network shares requiring separate backup coverage.
Cloud-Based Tax Software Backup Obligations
Cloud-based platforms like Intuit ProConnect Tax, TaxDome, and CCH Axcess shift primary data storage responsibility to the vendor, but tax professionals retain backup obligations under IRS Publication 4557. Your responsibility does not end because data lives in the cloud:
- Schedule monthly exports of all client files from cloud platforms to local storage included in your backup routine.
- Review your software provider's SLA to understand their backup frequency, retention periods, and restore procedures. Vendor backups are not a substitute for your own.
- Download and archive PDF copies of all completed returns to local storage as an independent backup layer.
- Ensure supporting documentation, client communications, and engagement letters uploaded to cloud platforms are redundantly stored in your local backup system.
The security of client portals and cloud platforms deserves its own attention. See our detailed analysis of tax client portal security risks for a thorough assessment of vendor security controls.
Implementing Your Tax Data Backup Plan: Step by Step
Identify All Data and Critical Systems
Inventory every system, application, and storage location containing taxpayer data. Document exact file paths for each tax software platform. Classify data by criticality to determine which systems require the shortest RTO and RPO.
Define Your RTO and RPO Targets
Set maximum acceptable downtime (RTO) and data loss (RPO) targets for filing season and off-season separately. Filing season typically demands RTO under 4 hours and RPO under 4 hours. These targets determine which backup technologies you need.
Apply the 3-2-1-1-0 Strategy
Configure three copies of all taxpayer data across two media types, with one copy offsite, one immutable backup with object lock enabled, and zero errors verified through regular restore testing.
Configure Tax Software-Specific Backup Paths
Add explicit backup coverage for each tax software's non-standard storage directories. Test that your backup software captures ProSeries, Drake, UltraTax, or whichever platforms you use, not just the Documents folder.
Enable Encryption and Access Controls
Verify AES-256 encryption is active for backups at rest and TLS 1.3 for data in transit. Restrict backup system administrative access and require multi-factor authentication for all backup management functions.
Test and Document Restore Procedures
Conduct a full restore test immediately after setup. Schedule quarterly restore tests with documented results. Write restore procedures into your WISP so any authorized staff member can execute recovery without relying on one person's knowledge.
Eliminate Non-Compliant Storage
Audit all storage locations for taxpayer data. Remove client files from consumer services like Google Drive, Dropbox, or personal iCloud. These services fail FIPS 140-2 encryption, SOC 2 Type II, and audit logging requirements under FTC Safeguards Rule §314.4(f).
Cloud Backup Solutions for Tax Professionals
Cloud-based backups can satisfy IRS compliance requirements when properly configured. Not all cloud backup services meet the specific security and encryption standards required for taxpayer data protection under the FTC Safeguards Rule and IRS Publication 4557.
When evaluating cloud backup providers for tax practice use, verify they meet these requirements:
- Encryption standards: AES-256 encryption at rest and TLS 1.3 in transit with FIPS 140-2 validated cryptographic modules.
- Data sovereignty: Ability to specify geographic storage location and confirm taxpayer data remains within US jurisdiction.
- Access controls: Support for multi-factor authentication, role-based access control, and IP address restrictions.
- Immutability options: Object lock or immutable backup features that prevent deletion or modification for defined retention periods.
- Audit logging: Detailed logs of all backup, restore, and administrative operations with tamper-evident storage.
- SOC 2 Type II certification: Independent audit verification of security controls and operational effectiveness.
Hybrid Backup Strategies for Tax Practices
Most tax practices benefit from combining local and cloud backups. Local network-attached storage (NAS) in your office provides rapid recovery for common scenarios like accidental file deletion, with restore times measured in minutes rather than hours. Cloud backups protect against office-wide disasters: fire, flood, theft, or ransomware that compromises all on-premises systems simultaneously.
Configure local backups to automatically replicate to cloud storage, maintaining the 3-2-1-1-0 rule without manual intervention. Store recent backups (30-90 days) in hot storage for fast access, then automatically tier older backups to cold storage for long-term retention at lower cost.
Cloud backup costs for tax practices typically range from $30-150 per month depending on data volume. A practice with 500GB of client data might pay $40-60 monthly for enterprise-grade cloud backup with immutability features. Compare that against the cost of permanent data loss. A single ransomware attack affecting 200 client files could cost $30,000-60,000 to remediate in staff time and client inconvenience alone, before accounting for regulatory penalties or malpractice exposure.
Consumer services like Google Drive, Dropbox, or personal iCloud accounts do not meet IRS compliance requirements for taxpayer data. They lack FIPS 140-2 validated encryption, immutability features, SOC 2 Type II certification, and the audit logging required by FTC Safeguards Rule §314.4(f). Using consumer storage for client tax data creates regulatory exposure independent of any security incident.
For multi-location tax offices, backup architecture requires additional planning. Our guide to remote work security for small teams addresses backup considerations for distributed staff accessing client data from home offices.
Backup Plan Documentation Requirements
The IRS and FTC require written documentation of your tax data backup plan. During Security Summit inspections or FTC investigations, regulators will request your backup policy documentation. Absent written procedures, you cannot demonstrate compliance even if you are technically running backups correctly.
Your written plan should include these components:
- Purpose and scope: Statement that the plan protects taxpayer data in compliance with IRS Publication 4557 and FTC Safeguards Rule, listing all systems and data types covered.
- Backup schedule: Specific frequency for different backup types (daily incremental, weekly full, monthly archival) with exact timing to minimize impact on business operations.
- Technology and methods: Detailed description of backup software, storage hardware, cloud services, and encryption methods used.
- Storage locations: Physical and logical locations of all backup copies including geographic regions for cloud storage.
- Retention periods: How long different backup types are retained, aligned with IRS recordkeeping requirements.
- Access controls: Who has access to backup systems, authentication requirements, and authorization procedures.
- Testing procedures: Frequency and methodology for restore testing, documentation requirements, and acceptance criteria.
- Roles and responsibilities: Named individuals responsible for backup administration, monitoring, testing, and incident response.
- Recovery procedures: Step-by-step instructions for restoring data in various scenarios with decision trees and contact information.
- Review and update schedule: Requirement to review plan annually and after any significant IT infrastructure changes.
This documentation serves multiple purposes: it demonstrates compliance to regulators, provides operational guidance to staff, and ensures business continuity when key personnel are unavailable. Your backup policy is a required component of a compliant IRS Written Information Security Plan.
For firms needing a starting point, our free WISP template includes a complete backup policy section ready for customization. The documentation requirement also intersects with your broader IRS Publication 4557 compliance obligations and the PTIN WISP requirements that apply to every credentialed tax preparer. Firms managing the full compliance picture, including backup policies, WISP, and incident response, may find our all-in-one compliance package a practical starting point.
Tax Data Backup Plan Implementation Checklist
- Inventory all systems, applications, and storage locations containing taxpayer data
- Identify exact file storage paths for each tax software platform used in your practice
- Define RTO and RPO targets for filing season and off-season separately
- Implement automated daily backups for all active client data without manual intervention
- Configure at least one immutable or air-gapped backup copy with object lock enabled
- Enable AES-256 encryption for all backup data at rest and TLS 1.3 for data in transit
- Require multi-factor authentication for all backup system administrative access
- Verify cloud backup provider holds SOC 2 Type II certification and stores data within US jurisdiction
- Set retention periods to at least 7 years for individual returns per IRS Publication 583
- Conduct and document a full restore test immediately after setup
- Schedule quarterly restore tests with documented results and issue tracking
- Write backup procedures into your WISP with named responsible parties
- Eliminate all consumer backup services (Google Drive, Dropbox) for taxpayer data storage
- Schedule annual backup policy review and update after any significant IT infrastructure change
Cost Planning for Tax Practice Backups
Implementing a compliant tax data backup plan requires investment, but costs scale with practice size and complexity. The ranges below reflect typical costs for practices implementing a hybrid local-plus-cloud architecture meeting IRS Publication 4557 requirements.
Practice Size
Cloud Backup (Monthly)
Local Hardware (One-Time)
Estimated Year-One Total
Solo Practitioner (Under 100 Returns)
$30-50/month
$300-500
$660-1,100
Small Firm (100-500 Returns)
$75-150/month
$800-1,500
$1,900-3,700
Medium Firm (500+ Returns)
$200-400/month
$2,000-5,000
$4,400-9,800
These investments pay for themselves during the first prevented data loss incident. The Sophos 2024 State of Ransomware report put the mean recovery cost at $2.73 million across all organizations. For a small tax practice, even a fraction of that cost can be existential. A ransomware attack affecting 200 client files could cost $30,000-60,000 to remediate in staff time alone, excluding regulatory penalties and client attrition following a publicized breach.
Practices comparing managed security options against self-managed backup should also review our comparison of EDR vs. MDR vs. XDR security solutions to understand how endpoint protection and backup interact in a full security stack.
What to Do If Your Backup System Fails
Backup failures during tax season are among the most stressful IT events a practice faces. A well-structured backup plan includes not just prevention but a defined response procedure for when backups fail or data loss is discovered.
Immediate steps when you discover a backup failure or data loss:
- Stop and contain: If you suspect ransomware or active attack rather than simple backup failure, disconnect affected systems from the network immediately before attempting recovery. Preserve forensic evidence and do not restart or wipe affected systems.
- Assess scope: Determine what data is affected, what time period is uncovered, and whether production data is intact. A failed backup is different from a successful ransomware attack that destroyed both production and backup data.
- Attempt recovery from alternate sources: Check immutable cloud copies, alternate backup sets, and any offsite copies. For cloud-based tax software, contact your vendor immediately. Most platforms retain their own backup copies for 30-90 days.
- Notify as required: Under the FTC Safeguards Rule and applicable state breach notification laws, unauthorized access to taxpayer data triggers mandatory notification obligations. Consult your incident response plan for notification thresholds and procedures.
- Document everything: Record what failed, when it was discovered, what recovery actions were taken, and what data was affected or unrecoverable. This documentation is required for regulatory reporting and essential for insurance claims.
- Fix and retest: After recovery, identify the root cause of the backup failure, implement corrective action, and conduct a full test before returning systems to production.
Tax practices that experience a data breach involving taxpayer information must also report to the IRS through the Security Summit. Our guide on what to do after a data breach covers the full notification and remediation process, including IRS reporting requirements specific to tax preparers.
What This Means for Your Practice
The Vercara 2024 Consumer Trust and Risk Report found that 70% of consumers would stop using a brand after a security incident. For tax professionals, that client attrition adds to the direct costs of breach remediation, regulatory penalties, and recovery expenses. A compliant backup plan is insurance against all of these outcomes, not just data loss.
Need Help Building a Compliant Backup Plan?
Our cybersecurity specialists help tax professionals implement fully documented backup strategies that meet IRS Security Six and FTC Safeguards Rule requirements.
Secure Your Practice with Expert Backup Implementation
Our cybersecurity specialists will assess your current backup strategy and implement a fully compliant solution that meets IRS Security Six requirements. Get confidence knowing your client data is protected.
Frequently Asked Questions
IRS Publication 4557 requires tax preparers to implement automated backups of all systems storing taxpayer data, maintain at least one offsite or immutable copy, encrypt backup data using FIPS 140-2 validated encryption, restrict access to backup systems with role-based controls and multi-factor authentication, conduct documented quarterly restore tests, and maintain written backup procedures as part of a compliant WISP. These requirements apply to all credentialed tax preparers regardless of firm size.
IRS Publication 4557 and FTC Safeguards Rule §314.4(f) both require regular restore testing with documented results. The practical minimum is quarterly testing, with additional tests after any significant infrastructure change, software migration, or backup configuration update. During filing season, consider testing monthly. A backup that has never been successfully tested cannot be relied on for recovery. Document each test with date, what was restored, any issues encountered, and resolution steps.
Yes, cloud backups can meet IRS compliance requirements when the provider offers AES-256 encryption with FIPS 140-2 validated modules, TLS 1.3 in transit, US-based data storage, SOC 2 Type II certification, immutable object lock features, detailed audit logging, and role-based access controls with MFA support. Consumer services like Google Drive, Dropbox, or iCloud do not meet these standards and should not be used for taxpayer data. Enterprise-grade services from providers with explicit financial services compliance offerings are appropriate.
Most professional tax software stores client databases outside standard Windows user directories. ProSeries and Lacerte store data under C:\ProgramData\Intuit or C:\Users\Public\Documents\Intuit. Drake Tax uses C:\Drake[Year]\Data. Thomson Reuters UltraTax may use SQL Server databases. If your backup software is configured to back up only the Documents or Desktop folder, it is likely missing these locations entirely. Audit your backup coverage by checking the actual storage path in your tax software settings, then add explicit path inclusions to your backup policy for each location.
IRS Publication 583 recommends retaining records supporting individual returns for at least three years from the filing date, or seven years if you filed a claim for a loss from worthless securities or bad debt deduction. For tax preparers, best practice is retaining client data backups for seven years to cover the full range of IRS audit scenarios. Set immutable backup retention periods to match this timeline. For state returns, check the applicable state's statute of limitations, which may exceed the federal standard.
Regular backups create copies of data that can be modified, overwritten, or deleted by anyone with administrative access to the backup system. Immutable backups use object lock technology to create copies that cannot be changed or deleted for a specified retention period, even by administrators. Sophos research found that 57% of ransomware attackers who targeted backup systems successfully compromised them. Immutable backups prevent this attack vector because locked objects cannot be encrypted or deleted even if attackers obtain full administrator credentials. The IRS and FTC increasingly expect tax preparers to maintain at least one immutable copy as part of a defensible backup strategy.
Yes. IRS Publication 4557 requires written documentation of your backup plan, not just the existence of backups. Regulators cannot confirm compliance based on verbal descriptions or system logs alone. Your written procedures must specify backup frequency, storage locations and media types, encryption methods, retention periods, access controls, testing schedules, and responsible parties by name or role. This written policy must be included in or referenced by your WISP. During investigations or inspections, regulators will request this documentation.
A solo practitioner or small firm with under 100 returns typically needs $30-50 per month for cloud backup with immutability features, plus a one-time investment of $300-500 for local NAS hardware. Total year-one cost for a hybrid compliant setup runs roughly $660-1,100. Firms with 100-500 returns should budget $75-150 monthly for cloud backup and $800-1,500 for local storage, putting year-one costs at $1,900-3,700. Immutable cloud storage typically adds $20-50 per terabyte per month above standard storage pricing.
No. Consumer services like Google Drive, Dropbox, and personal iCloud accounts do not meet IRS or FTC compliance standards for taxpayer data. They lack FIPS 140-2 validated encryption, immutability features, SOC 2 Type II certification, and the audit logging required under FTC Safeguards Rule §314.4(f). Using consumer storage for client tax data creates regulatory exposure independent of any actual security incident. If a regulator or plaintiff attorney discovers client tax data stored in a personal Dropbox or Google Drive, it constitutes a documentation and control failure regardless of whether a breach occurred.
First, determine whether the failure is a technical backup issue or evidence of an active attack. If you suspect ransomware, disconnect affected systems from the network before attempting recovery. Then assess the scope: what data is affected, how far back your last good backup extends, and whether production data is intact. Attempt recovery from immutable cloud copies or alternate backup sets. If client data was accessed without authorization, review your notification obligations under the FTC Safeguards Rule and applicable state breach notification laws. Document every step taken. After recovery, identify the root cause and conduct a full restore test before returning systems to normal operation.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



