
Why Tax Professionals Are Prime Targets for Cybercriminals
Tax professionals handle a concentration of sensitive financial data that few other businesses match. A single tax preparer's client files contain Social Security numbers, employer identification numbers, bank account details, investment records, and prior-year tax returns for hundreds of individuals and businesses simultaneously. That combination makes tax practices among the most attractive targets in the financial services sector.
The IRS reports thousands of data theft incidents targeting tax professionals each year, with attackers stealing an average of 400 taxpayer records per incident. These breaches carry consequences that extend far beyond immediate disruption: EFIN suspension, state penalties reaching $250,000, mandatory client notification for every affected taxpayer, and lasting reputational harm that can destroy practices built over decades.
The ten threat categories below represent the active attack patterns most frequently targeting tax practices right now, ranked by impact and frequency. Each section covers how the attack works, why tax practices are specifically targeted, and the specific technical and procedural controls that stop it. Understanding these tax preparer security threats is the foundation of any defense aligned with IRS Publication 4557.
Tax Preparer Cybersecurity By The Numbers
IRS annual data theft report averages
Penalties vary by state; some exceed this threshold
Verizon 2025 Data Breach Investigations Report
1. Ransomware Attacks Timed to Tax Season Deadlines
Ransomware encrypts every file it can reach and demands payment for the decryption key. For a tax practice, that means losing access to every client record, tax return, and business document simultaneously, typically during the most pressured weeks before filing deadlines, when the disruption cost is highest and the pressure to pay quickly is strongest.
Attackers time their campaigns deliberately. The average ransom demand against a small tax practice runs into the tens of thousands of dollars, and paying is no guarantee of recovery. The FBI reports that only 65% of victims who pay a ransom successfully recover their files, and 37% of those who do recover still find data corruption requiring additional remediation.
The most common delivery mechanisms are phishing emails with malicious attachments disguised as client documents or IRS notices, compromised Remote Desktop Protocol (RDP) connections, malicious macros embedded in Excel or Word files, and software vulnerabilities in unpatched tax software or operating systems.
Prevention requires a layered approach. The 3-2-1 backup rule remains the baseline: maintain three copies of data on two different media types, with one copy stored offline and air-gapped from any network. For tax practices, daily backups during filing season with weekly offline rotation is the minimum. Pair tested offline backups with an Endpoint Detection and Response (EDR) solution that detects ransomware behavior before encryption begins, and patch all software within 72 hours of each security release. Our ransomware protection guide for tax practices covers layered defense implementation in detail.
Tax Season Ransomware Warning
Ransomware operators actively time campaigns to hit tax practices in February through April, when deadline pressure is highest. Double-extortion groups now steal your client data before encrypting it, then threaten to publish Social Security numbers and financial records publicly if the ransom goes unpaid. Tested offline backups address encryption, but not the public exposure threat. Your incident response plan must address both scenarios.
2. Phishing and Spear Phishing: The Primary Attack Vector
Phishing is the most common initial attack vector across all industries, responsible for 94% of successful breaches according to the Verizon 2025 Data Breach Investigations Report (DBIR). Generic phishing campaigns send mass emails hoping for any response; spear phishing targets specific individuals with personalized messages built from reconnaissance on your firm, your staff, and your clients.
Tax professionals receive phishing emails impersonating the IRS, fake CP2000 notices, PTIN suspension warnings, e-Services login alerts, as well as tax software vendors such as Intuit, Drake, and Thomson Reuters, clients requesting document status updates, and financial institutions. During peak filing season, some tax offices report 50 to 100 phishing attempts per day in March and April.
The IRS Security Summit has identified several phishing tactics gaining momentum in 2026. AI-generated voice phishing (vishing) uses deepfake audio of partners or clients requesting urgent file access. QR code phishing arrives in physical mail claiming to be IRS security updates requiring mobile scanning. Multi-channel attacks combine email, text, and phone calls to establish false legitimacy before the actual fraud request. Tax software update scams deliver credential-stealing malware disguised as mandatory security patches. Client portal spoofing replicates your secure portal login page to harvest credentials at scale.
Defense requires both technical controls and human awareness. Deploy email filtering that blocks known malicious domains and analyzes message headers for spoofing indicators. Use DNS filtering to block access to malicious sites even when someone clicks a link. Implement DMARC (Domain-based Message Authentication, Reporting, and Conformance) in enforcement mode, not monitoring mode, to prevent domain spoofing. Pair these technical controls with monthly phishing simulation exercises for all staff with access to client data. Our phishing attack detection guide covers each of these tactics with specific identification and response guidance for tax practices.
Phishing Defense Checklist for Tax Practices
- Configure DMARC, DKIM, and SPF records on your email domain in enforcement mode (p=reject)
- Enable email filtering that scans attachments and blocks known malicious domains
- Implement DNS filtering to block malicious site access even after a link is clicked
- Conduct monthly phishing simulation exercises for all staff with access to client data
- Train staff to verify unexpected requests from partners or clients by phone, not by reply email
- Never install tax software updates delivered by email without verifying through the vendor's official website
- Report all suspected phishing attempts to the IRS at phishing@irs.gov
- Establish a written procedure for flagging and escalating suspicious emails before any action is taken
3. Business Email Compromise (BEC) and Refund Fraud
Business Email Compromise (BEC) involves compromising or spoofing a trusted email account to manipulate the recipient into transferring money or sensitive data. The FBI's Internet Crime Complaint Center (IC3) reported $2.9 billion in BEC losses in 2025, with tax professionals representing a disproportionately targeted sector because of their direct connection to client financial accounts and refund processing.
In a tax context, a common BEC attack works like this: an attacker compromises a client's email account and sends a request to change refund direct deposit routing to an attacker-controlled account. By the time the legitimate client realizes their refund never arrived, the funds have moved through a network of money mules and are unrecoverable. A second common pattern involves attackers impersonating firm partners or senior preparers to instruct junior staff to send client data to an external address for an "urgent prospective client meeting", a request that appears legitimate to an untrained employee.
Prevention starts with email authentication. DMARC, DKIM, and SPF records verify that emails claiming to come from your domain are actually sent from your authorized mail servers. Equally important: establish verbal verification procedures for any change to financial information, including refund routing, payment instructions, or wire transfer details. A 30-second call to a known, pre-established phone number, not a number provided in the suspicious email, prevents losses that cannot be reversed after the fact.
For a deeper look at the security program requirements that address BEC at the organizational level, see our FTC Safeguards Rule guide for tax preparers, which covers the access controls and authentication requirements that reduce BEC exposure.
4. Credential Theft and Account Takeover
Attackers steal login credentials through phishing, keylogger malware, credential stuffing (automated testing of passwords exposed in prior data breaches), or by purchasing credentials from dark web marketplaces. The 2025 Verizon DBIR found stolen credentials involved in 49% of breaches, the second most prevalent attack pattern after phishing, which is itself frequently used to steal credentials in the first place.
Once an attacker has your tax software credentials, they can access your entire client database. If they obtain your IRS e-Services credentials, they can compromise your EFIN and file fraudulent returns under your professional identity. Credential stuffing is particularly effective against tax professionals who reuse passwords across multiple services, automated tools can test billions of username/password combinations obtained from unrelated breaches in hours.
IRS Publication 4557 Section 2.3 specifically requires strong authentication controls: unique passwords for every account with no reuse across services, complex passwords following NIST SP 800-63B guidelines (minimum 12 characters, recommended 16+), and multi-factor authentication (MFA) on all systems containing taxpayer data. For tax software, the IRS requires MFA for all professionals accessing EFIN-linked systems.
A practical starting point: use an enterprise password manager to generate and store unique credentials for every account. Our password manager comparison for tax practices covers the options best suited to small and mid-sized firms. Enable MFA with a preference for authenticator apps or hardware security keys over SMS codes. Add dark web monitoring to receive alerts when your credentials appear in breach datasets, often before the attacker has used them.
5. Insider Threats: The Risk Within Your Organization
Not every threat originates outside your organization. Current or former employees, contractors, and business partners with legitimate system access can compromise client data intentionally or by accident. The 2025 Ponemon Cost of Insider Threats Study found that insider incidents cost organizations an average of $16.2 million annually, with malicious insiders accounting for 26% of incidents and negligent employees responsible for 56%.
In a tax practice, the most common insider threat scenarios include: a departing seasonal preparer copying the client database to a personal USB drive before leaving to start a competing practice; an employee falling for a phishing email and entering credentials into a spoofed portal; a contractor misconfiguring cloud storage permissions and inadvertently exposing client files to public access; or staff sharing login credentials with colleagues, creating untracked access that bypasses your audit trail entirely.
Prevention requires least-privilege access controls, users should only access the systems and client files necessary for their specific job function. Revoke access within one hour of termination for involuntary departures and the same business day for resignations. Monitor user activity logs for unusual patterns: access at atypical hours, bulk downloads, or accessing client files with no clear business justification.
The FTC Safeguards Rule (16 CFR § 314.4) requires tax preparers to implement access controls and monitor for insider threats as part of their formal information security program. Audit logs of who accessed what data and when must be retained for at least three years. Your Written Information Security Plan (WISP) must document your access control and monitoring procedures by name, this is a required element, not optional documentation.
Bottom Line
56% of insider incidents involve negligent employees, not malicious ones. Access controls and revocation procedures protect against both. The moment an employee with client data access resigns or is terminated, their credentials must be disabled, not at the end of the week, not when IT gets around to it. Same-day revocation is a required control under the FTC Safeguards Rule and IRS Publication 4557.
6. Remote Desktop Protocol (RDP) Exploitation
Many tax practices use Remote Desktop Protocol (RDP) to allow remote access to office computers, enabling work from home or access to desktop tax software from outside the office. Exposed RDP services are among the most targeted entry points for ransomware operators. The Cybersecurity and Infrastructure Security Agency (CISA) lists RDP as one of the top three initial access vectors in ransomware attacks, with automated brute-force tools testing thousands of password combinations per minute against any RDP port exposed directly to the internet.
Once inside via RDP, attackers have the same access as if they were sitting at your workstation, tax software, client files, email, and a launchpad for attacks against other systems on your network. The problem compounds when practices use weak passwords on RDP accounts, expose RDP without a VPN gateway, or fail to monitor login attempts for brute-force patterns.
NIST SP 800-46 and IRS Publication 4557 require these controls for any practice using RDP: never expose RDP directly to the internet, require VPN authentication as a mandatory first step before any RDP connection is possible; enable Network Level Authentication (NLA) so credentials must be provided before a full session is established; implement account lockout after five failed login attempts; require 16-character minimum passwords with MFA enforced at the VPN layer; and alert on unusual geographic activity or abnormal login failure rates. Our guide to choosing a VPN for remote tax practice access covers configuration for common scenarios including desktop tax software access and multi-location firm environments.
7. Web Application Attacks and SQL Injection
Tax practices using web-based client portals, intake forms, or custom-built applications face web application attacks including SQL injection. SQL injection occurs when attackers insert malicious database commands into web form fields, exploiting inadequate input validation to access or manipulate the underlying database. A successful attack against your client portal could expose your entire client dataset, names, Social Security numbers, tax returns, and financial records, without triggering the failed-login alerts that protect against credential-based attacks.
The OWASP Top 10 consistently lists injection attacks among the most prevalent web application security risks. Prevention requires parameterized queries (prepared statements that separate database commands from user input), input validation and sanitization on all user-submitted data, and least-privilege database accounts so web applications never connect with administrative credentials.
If you use a third-party secure client portal for tax professionals, verify the vendor undergoes annual penetration testing and holds a current SOC 2 Type II certification, and request their latest audit report before onboarding. Vendors who cannot provide a recent SOC 2 report represent unquantified third-party risk to your practice's client data.
8. Wi-Fi Eavesdropping and Network Attacks
Unsecured or poorly secured wireless networks allow attackers to intercept data transmitted across the network. If your office Wi-Fi uses weak encryption, WEP, or WPA with a short or long-unchanged password, an attacker in a nearby car or building can intercept client data moving across your network without triggering any alerts. This is especially acute in shared office buildings where wireless signals overlap with neighboring businesses, or in retail tax preparation locations where public foot traffic provides cover for wireless reconnaissance.
NIST SP 800-153 provides wireless security guidance for organizations handling sensitive data: use WPA3 encryption (WPA2 at minimum, WEP and WPA with TKIP are broken by tools readily available to unsophisticated attackers); implement a strong, unique Wi-Fi password of at least 20 characters changed annually and whenever staff with Wi-Fi access depart; completely isolate guest and business networks so waiting room Wi-Fi cannot reach practice systems; and disable WPS (Wi-Fi Protected Setup), which has documented vulnerabilities allowing password bypass without brute force.
For any sensitive transactions, bulk client data transfers, tax software logins while traveling, or accessing client portals from uncertain networks, use a VPN that encrypts all traffic regardless of the underlying network's security posture. This applies equally to hotel networks, client office Wi-Fi, and any shared connection outside your own controlled environment. Our remote work security guide for small teams covers network controls for mobile tax preparers working at client locations.
9. Physical Theft and Loss of Devices
Stolen laptops, lost USB drives, and office break-ins trigger data breach notification requirements under laws in all 50 states. A single stolen laptop containing unencrypted client data can affect hundreds of taxpayers, triggering state notification timelines, generally 30 to 90 days from discovery, along with potential IRS reporting obligations and PTIN consequences.
IRS Publication 4557 Section 3.2 explicitly requires encryption of all portable devices and removable media containing taxpayer data. Use BitLocker for Windows and FileVault for macOS on all laptops and desktops. Enable remote wipe capability through Microsoft Intune or a comparable Mobile Device Management (MDM) platform so a lost or stolen device can be wiped before its contents are accessed.
For mobile tax preparers who work at client locations, encrypted cloud storage reduces exposure from local device theft, though any cloud provider must be vetted for current security certifications. Where local storage is necessary, use FIPS 140-2 validated encryption solutions and maintain a current inventory of every device containing client data. Physical security failures are among the most preventable breach causes and among the most frequently overlooked in small practices.
Physical Security Checklist for Tax Offices
- Enable full-disk encryption (BitLocker for Windows, FileVault for macOS) on all laptops and desktops
- Encrypt all USB drives and external hard drives containing client data before first use
- Implement mobile device management (MDM) with remote wipe capability on all portable devices
- Install and monitor security cameras covering entry points and work areas
- Use lockable file cabinets for physical documents and removable media containing client data
- Implement badge access or keypad entry for office access outside normal business hours
- Maintain a current device inventory with serial numbers and encryption status for every device
- Enforce a clean desk policy, no client documents left visible or accessible overnight
- Use privacy screens on monitors visible to clients, visitors, or open-plan areas
- Shred all documents containing taxpayer data using a cross-cut or micro-cut shredder before disposal
10. Supply Chain Attacks and Third-Party Risk
Supply chain attacks compromise a software vendor or service provider your practice relies on, then use that trusted relationship as a pathway into your systems. The 2020 SolarWinds incident demonstrated the scale of this threat: attackers infiltrated the software development process and distributed malware through trusted updates to over 18,000 organizations worldwide. The 2023 MOVEit Transfer vulnerability showed how a single zero-day in a widely used file transfer platform could simultaneously affect thousands of organizations, with attackers systematically exploiting the flaw across the vendor's entire customer base before a patch was available.
Tax software vendors face the same attack surface. Their automatic updates install on tens of thousands of tax professional systems, making them high-value targets for this attack pattern. When your software vendor pushes an update, you have implicitly trusted their entire software development and distribution chain with access to your systems and client data, a risk most small practices have not explicitly evaluated.
The FTC Safeguards Rule requires tax preparers to assess and address third-party service provider risks. In practice, this means vetting security practices before engagement, request SOC 2 Type II reports, penetration test results, and security policies; limit access granted to third-party software using least-privilege principles; review vendor contracts for security requirements and incident notification obligations; and monitor for unusual activity from vendor connections. Require vendors to notify you of security incidents within 24 to 72 hours contractually, not as a courtesy request.
Your WISP must document your third-party risk management process per IRS Publication 4557 Section 4.2, including a vendor inventory and evidence of security due diligence for each vendor with access to taxpayer data. Maintain independent offline backups not controlled by any single vendor, if your cloud storage provider is compromised, your offline backup remains intact and unaffected. For guidance on building a vendor risk process into your security program, see our WISP implementation guide.
Emerging Tax Preparer Security Threats in 2026
Several attack categories are gaining momentum specifically against tax professionals this year, and they differ meaningfully from the ten established threats covered above.
AI-Powered Social Engineering, Attackers are using generative AI to produce phishing emails that match the recipient's communication style, use flawless grammar, and reference specific details scraped from public records and social media. These campaigns are harder to detect because they lack the traditional red flags, poor grammar, generic greetings, that standard awareness training teaches staff to recognize. AI-generated voice phishing (vishing) can now convincingly impersonate partners, managers, or clients, and the FBI has reported significant growth in vishing attacks targeting financial services professionals during filing season.
Double-Extortion Ransomware, Ransomware groups have shifted to demanding payment while simultaneously threatening to publish stolen data publicly if the ransom is not paid. For tax professionals, a public dump of client Social Security numbers, financial records, and tax returns is an existential threat to client relationships and professional standing. Tested offline backups address encryption, but not public exposure. Your incident response plan must account for both containment and potential disclosure scenarios.
Identity-Based Attacks Targeting IRS Systems, Attackers who compromise a tax professional's IRS e-Services credentials can file fraudulent returns under your EFIN, request transcripts of clients' prior-year returns for use in future fraud campaigns, and access the Income Verification Express Service (IVES) to harvest wage and income data at scale. The IRS Security Summit has documented these attack patterns and requires practitioners to implement specific controls addressing e-Services credential security.
Dark Web Trading of Tax Professional Data, Stolen tax professional credentials and client databases command significant prices on dark web marketplaces because a tax preparer's data gives buyers access to complete financial profiles of hundreds or thousands of individuals simultaneously. Dark web monitoring services alert your practice when credentials or client data appear in these markets, often before the attacker has used the data, giving you time to respond and contain the damage before account takeover occurs.
For a full picture of how these emerging threats interact in real attacks, our incident response plan guide for tax practices covers containment and recovery procedures for the attack patterns described above. You should also review our coverage of browser-in-the-middle phishing attacks, which bypass MFA and are increasingly used against tax portals and financial services logins.
Building a Layered Defense: Where to Start
Assess Your Current Security Posture
Conduct a gap analysis against IRS Publication 4557 requirements. Identify which of the ten threat categories your current controls address and which remain unmitigated. Our tax security solutions include a structured assessment against each requirement.
Deploy Endpoint Protection and EDR
Install Endpoint Detection and Response (EDR) on all workstations and servers. EDR detects ransomware behavior, credential theft tools, and lateral movement before attackers reach your client data. Configure automatic updates and threat intelligence feeds.
Implement Strong Authentication Controls
Enable multi-factor authentication on all systems containing taxpayer data, starting with tax software, IRS e-Services, and email. Deploy a password manager for unique credential generation and storage across your team.
Secure Your Network and Remote Access
Replace direct RDP exposure with a VPN-first architecture. Implement DMARC, DKIM, and SPF on your email domain. Segment your guest Wi-Fi from your practice network. Enable DNS filtering to block malicious domains.
Create or Update Your Written Information Security Plan
Document your security controls, access procedures, incident response steps, and vendor risk management process in a WISP aligned with IRS Publication 4557. Your WISP is a required document, not a one-time exercise, and must be reviewed annually and after any significant incident.
Train Your Team and Test Your Defenses
Conduct monthly phishing simulations and annual security awareness training for all staff with access to client data. Test your backup restoration procedures at least quarterly. Review access logs for anomalies at least monthly during filing season.
Need a WISP Built for Tax Professionals?
Our WISP templates are designed specifically for tax preparers and align with IRS Publication 4557, FTC Safeguards Rule, and PTIN requirements. Download a free template or get a customized plan.
IRS Compliance Requirements for Tax Preparer Security
The IRS does not treat cybersecurity as optional for tax professionals. IRS Publication 4557 requires all tax preparers, regardless of firm size, to implement and maintain a formal security program. The FTC Safeguards Rule (16 CFR Part 314), which applies to tax preparers as financial institutions, adds additional requirements including a written information security program, risk assessments, and third-party vendor oversight.
Failure to comply does not just create regulatory exposure. The IRS can suspend your EFIN, which halts your ability to e-file returns for clients, a business-ending consequence during filing season. State tax agencies maintain their own penalty structures, with several states imposing fines up to $250,000 per incident for unauthorized disclosure of taxpayer information.
The PTIN and WISP requirements for tax preparers page explains the specific documentation you need to satisfy IRS reviewers. If you are building a security program from scratch, our WISP guide for small tax firms walks through each required element with examples sized for practices with 1 to 25 employees. For firms that have an existing WISP but have not updated it since 2024, the all-in-one compliance package includes an updated template with the current IRS Security Summit requirements incorporated.
Tax professionals who handle data for clients in multiple states should also review state-level requirements. Several states, including California, New York, and Massachusetts, have enacted security requirements that go beyond the federal baseline, including mandatory encryption standards, specific breach notification timelines, and annual security training documentation requirements.
What This Means for Your Practice
A Written Information Security Plan is not optional for tax preparers. IRS Publication 4557 requires all professionals who handle taxpayer data to maintain one, including sole practitioners. The document must address each of the threat categories above, name a security coordinator, and be reviewed annually. A template you downloaded and never updated does not satisfy this requirement. Your WISP must reflect your actual current security controls.
Book a Free Tax Cybersecurity Assessment
Our security team will evaluate your current defenses against each of the ten threat categories above and provide a prioritized remediation plan aligned with IRS Publication 4557 and the FTC Safeguards Rule.
Frequently Asked Questions
The top threats targeting tax practices in 2026 are ransomware timed to filing deadlines, phishing and spear phishing (responsible for 94% of breaches per the Verizon DBIR), Business Email Compromise (BEC) targeting refund routing changes, credential theft via phishing or dark web purchases, and supply chain attacks through compromised tax software vendors. Insider threats from departing seasonal staff and RDP exploitation for remote access are also frequent attack vectors specific to tax practice environments.
Yes. IRS Publication 4557 requires all tax preparers who handle federal tax returns to maintain a Written Information Security Plan (WISP), regardless of firm size. The FTC Safeguards Rule (16 CFR Part 314) independently requires a written information security program for tax preparers as financial institutions. A sole practitioner handling one client's return has the same obligation as a large regional firm. The WISP must document your security controls, designate a security coordinator, cover incident response procedures, and be reviewed and updated at least annually.
A confirmed data breach triggers several immediate obligations. You must notify affected clients, report to the IRS (which may result in EFIN suspension pending investigation), report to your state tax agency, and comply with state breach notification laws, which typically require notification within 30 to 90 days of discovery. Depending on the breach scope, you may also face FTC Safeguards Rule enforcement, state attorney general investigation, and civil liability from affected clients. The average IRS-reportable incident involves 400+ taxpayer records, each requiring individual notification.
MFA significantly reduces credential theft risk but does not eliminate it entirely. Authenticator app-based MFA (TOTP codes) can be bypassed by real-time phishing attacks that relay the code to the attacker before it expires, a technique used in Browser-in-the-Middle (BitM) attacks against financial services portals. Hardware security keys using FIDO2/WebAuthn are the only MFA method that is fully phishing-resistant, because the cryptographic challenge is bound to the legitimate domain. SMS-based MFA is the weakest option, vulnerable to SIM-swap attacks. For IRS e-Services and tax software logins, use an authenticator app at minimum; hardware keys are the recommended standard.
The most effective ransomware defense combines three controls: tested offline backups (3-2-1 rule: three copies, two media types, one offline and air-gapped), Endpoint Detection and Response (EDR) software that detects ransomware behavior before encryption begins, and consistent patching within 72 hours of security releases. During filing season, increase backup frequency to daily with offline rotation. Train staff to report suspicious attachments before opening them. Maintain a tested incident response plan so you know exactly what to do if ransomware activates, including which backup to restore from and who to notify. For double-extortion ransomware, your plan must also address the data exposure scenario separately from the encryption recovery scenario.
The FTC Safeguards Rule (16 CFR Part 314) is a federal regulation that requires financial institutions to implement a written information security program. Tax preparers are classified as financial institutions under the Gramm-Leach-Bliley Act, which means the Safeguards Rule applies to all tax preparation businesses, sole practitioners included. The Rule requires a written security program, a designated security coordinator, a risk assessment, implementation of safeguards addressing identified risks, oversight of service providers, and annual program review. Violations can result in FTC enforcement actions and civil penalties.
Supply chain attacks target the software vendor rather than your practice directly. When your tax software receives an automatic update, you trust that the vendor's development and distribution process has not been compromised. The 2020 SolarWinds incident showed how attackers can insert malware into legitimate software updates distributed to tens of thousands of organizations simultaneously. Tax software vendors are high-value targets because a single compromised update reaches the entire customer base at once. Defense includes monitoring vendor security communications, limiting software permissions using least-privilege principles, maintaining independent offline backups not dependent on any single vendor, and verifying vendor SOC 2 Type II certifications before onboarding.
IRS Publication 4557 and NIST SP 800-46 require that remote access to systems containing taxpayer data be protected by a VPN with multi-factor authentication before any Remote Desktop Protocol (RDP) or similar session is permitted. RDP must never be exposed directly to the internet. Additional required controls include Network Level Authentication (NLA), account lockout after five failed login attempts, minimum 16-character passwords, and monitoring for unusual geographic access patterns or abnormal login failure rates. Any remote access solution that bypasses these controls creates an unacceptable risk of ransomware deployment via brute-forced RDP.
Dark web monitoring is not explicitly required by name in IRS Publication 4557 or the FTC Safeguards Rule, but it fulfills the risk monitoring and early detection requirements both regulations impose. IRS Publication 4557 requires tax preparers to monitor for security incidents and respond promptly, dark web monitoring satisfies this by alerting you when credentials or client data appear in breach datasets, often before an attacker has used the data. The practical value is significant: early detection gives your practice time to change compromised credentials and notify clients before account takeover occurs, rather than discovering the breach after fraudulent returns have been filed under your EFIN.
An incident response plan for a tax practice must cover: how to identify and confirm a security incident, who to notify internally and externally (IRS, state agencies, clients, law enforcement), how to contain the incident (isolating affected systems, revoking compromised credentials), evidence preservation steps, client notification procedures and timelines, business continuity procedures for continuing to serve clients during recovery, and a post-incident review process. IRS Publication 4557 requires incident response procedures as a named component of your WISP. Your plan should be tested at least annually with a tabletop exercise, a document that has never been tested will fail when you need it most.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.


