
CPA firms need a few things locked in before January 1: a current Written Information Security Plan (WISP), multi-factor authentication enforced across tax software and email, endpoint detection and response (EDR) on every device touching client data, hardened email filtering, tested encrypted backups, and documented staff training. This tax season cybersecurity preparation guide for CPA firms walks through what the IRS and FTC require, which technical controls matter most, and the order to tackle them before the 2027 filing season opens.
Filing season compresses a year's worth of risk into about fourteen weeks. Firms move Social Security numbers, bank routing details, employer identification numbers, and prior-year returns through email, client portals, and tax software at a pace they do not sustain the rest of the year, and attackers plan their campaigns around that window. The IRS Security Summit, a coordinating partnership between the IRS, state tax agencies, and tax industry representatives formed to fight identity theft and refund fraud, has reported repeated year-over-year jumps in phishing, business email compromise (BEC), and credential-stuffing attacks aimed at tax professionals during filing season. Firms that finish their preparation before January 1 consistently report fewer incidents and faster recovery when one does happen.
Quick Answer
Before filing season opens, have a current WISP in place (required by IRS Publication 4557 and the FTC Safeguards Rule), MFA enforced on tax software, email, and remote access, EDR deployed on every device that touches client data, DMARC-enforced email filtering, and tested encrypted backups. Finish your gap assessment and WISP review in October and November, enforce MFA and train staff by December 31, and assemble your incident response contacts before the first return is filed in January.
Key Takeaway
IRS Publication 4557 and the FTC Safeguards Rule both require a written security plan, strong authentication, and documented staff training, regardless of firm size. January through April is the highest-risk window for phishing, BEC, and ransomware aimed at tax preparers, so gap assessments and MFA enforcement belong on an October through December calendar, not a January scramble. According to Verizon's 2024 Data Breach Investigations Report, 68% of breaches involve a human element, which is why documented training carries as much weight as any technical control. A tested, encrypted, offline backup is what lets a firm decline a ransom demand during the filing crunch instead of paying under deadline pressure.
What a Breach Actually Costs
Several factors stack up between January and mid-April. Returns in progress hold Social Security numbers, adjusted gross income, and banking details, so one compromised workstation can expose hundreds of client records at once.
Seasonal preparers typically get minimal security orientation and sometimes work from personal devices, which widens the attack surface without adding matching controls. Staff working under deadline pressure are more likely to click a phishing link, skip a verification step, or approve a wire transfer without dual authorization.
Remote access adds another entry point. Many preparers reach tax software and client portals from home networks, and exposed Remote Desktop Protocol (RDP) ports remain a target attackers actively scan for during filing season. Spear-phishing campaigns impersonating the IRS, tax software vendors such as Drake, UltraTax, or ProSeries, or existing clients tend to arrive in January, when staff are newly back from the holidays and least on guard.
Controls to Have in Place Before January 1
- Multi-factor authentication enforced on tax software, email, cloud portals, and remote access, not just offered as an option
- Endpoint detection and response (EDR) installed on every workstation and laptop that touches client data, including seasonal staff devices
- Email filtering with DMARC in enforcement mode, DKIM, and SPF to cut down spoofed IRS and vendor emails
- A current Written Information Security Plan (WISP) that reflects this year's systems, staff, and vendors
- Offline, encrypted backups of client files with a tested restore, not just a backup job that runs unchecked
- Documented security awareness training and phishing simulations for every employee who will touch client data this season
IRS Publication 4557, Safeguarding Taxpayer Data, directs every tax preparer to maintain a written data security plan, use strong authentication on systems that hold taxpayer data, encrypt data in transit and at rest, train staff on data security, and dispose of client records properly. These are IRS requirements for anyone who prepares federal returns professionally, not optional best practices.
Publication 4557 also expects preparers to report data theft to the IRS promptly, through their local IRS Stakeholder Liaison, and to notify affected clients so they can watch for fraudulent returns filed in their names, under IRS guidance on safeguarding taxpayer data. If your written plan needs an update, see our WISP overview for the sections IRS Publication 5708 expects your plan to cover. Firm size does not create an exemption, a solo preparer is held to the same written-plan requirement as a 40-person firm.
The FTC Safeguards Rule classifies tax preparers as financial institutions under the Gramm-Leach-Bliley Act (GLBA) and requires a documented information security program with nine required elements, including a written risk assessment, access controls, encryption, multi-factor authentication, and a designated qualified individual who oversees the program. See the FTC's Safeguards Rule guidance for the full list of required elements.
A 2023 amendment added a separate requirement: covered firms must notify the FTC within 30 days of discovering a security event that exposes the unencrypted information of 500 or more consumers. The qualified individual requirement is a governance gap many small firms overlook until an audit or an incident surfaces it, our qualified individual guide covers what the role involves at a small firm's scale. Walk through the specific requirements against your own controls with our FTC Safeguards Rule checklist.
Need a WISP Before Filing Season Opens?
A custom WISP starts at $749 for up to 5 users, with larger practices quoted separately, and most firms save 20 to 40 billable hours they would otherwise spend drafting a plan from scratch.
Your Tax Season Prep Timeline
October-November: Run a Gap Assessment
Inventory every system and data store that touches client information and map current controls against IRS Publication 4557 and the FTC Safeguards Rule. Assign remediation owners and deadlines before January 1.
November: Update and Test Your WISP
Review your written plan for accuracy, update vendor contacts and incident response roles, and run a tabletop exercise simulating a phishing or ransomware incident.
November-December: Enforce MFA Everywhere
Audit authentication on tax software, email, client portals, and remote access, and shut off any path that does not require MFA.
December-January 1: Train Every Preparer
Deliver phishing simulation and security awareness training to every employee who will touch client data, including seasonal hires, and keep completion records on file.
December: Verify and Test Backups
Confirm backups are encrypted, keep at least one copy offline, and run a test restoration before filing volume picks up.
December-January: Harden Remote Access
Restrict RDP to VPN-only connections, enforce network-level authentication, and remove external-facing RDP that is not operationally necessary.
January: Assemble Your Incident Response Contacts
Compile your IRS Stakeholder Liaison contact, your state attorney general's breach notification contact, your cyber insurance claims line, and an incident response retainer before you need any of them.
Email, Endpoint, and Credential Controls
- Enforce DMARC in reject mode, DKIM, and SPF so spoofed IRS and vendor emails stop reaching staff inboxes
- Deploy EDR, not antivirus alone, on every device that touches client data, including laptops seasonal preparers bring in
- Collect W-2s, 1099s, and ID documents through an MFA-protected client portal instead of unencrypted email attachments
- Require unique, complex passwords on every system handling taxpayer data, enforced with a business-grade password manager
CISA's guidance on using a password manager and unique passwords offers a vendor-neutral framework if you are formalizing credential rules for the first time: CISA: Use Strong Passwords.
Phishing Spikes January Through April
The IRS Security Summit consistently warns that impersonation emails targeting tax professionals spike between January and April, often referencing real firm details pulled from public sources. Never click a link in an unsolicited IRS or tax-software email, navigate to the vendor's site directly instead. Verify any unexpected wire transfer or data access request by phone, using a number you already have on file, not one provided in the email. Forward suspicious IRS-themed emails to phishing@irs.gov.
Every CPA firm needs a documented incident response plan before filing season, not during it. If a breach happens in February, you have hours, not weeks, to contain it, notify affected clients, and report to the IRS and applicable state agencies. Firms without a plan make containment decisions under time pressure, which tends to mean slower notification and wider exposure.
If your firm lacks internal security staff to run this process, a managed detection and response (MDR) retainer with a 24/7 Security Operations Center (SOC) can monitor for indicators of compromise through filing season and manage the first response when an alert fires. Our incident response plan guide walks through building the plan itself.
What Your Incident Response Plan Must Cover
- Clear decision authority: who can initiate containment, who communicates externally, and who contacts the IRS and state agencies
- A plan to report data theft to the IRS through your Stakeholder Liaison and to clients, so they can file Form 14039 if they are affected
- A record of each client's state of residence, since most states require notifying affected residents within 30 to 60 days of a confirmed breach
- Your cyber insurance carrier's claims line, contacted before taking remediation steps, many policies require pre-authorization for covered forensic work
- A client notification letter drafted in advance, so it is not written under pressure with legally ambiguous wording
DIY Endpoint Protection vs. Managed EDR
Endpoint detection & response
- Bellator Shield ($19/computer/month)
- Antivirus or EDR that your own staff configures, watches, and triages
- Bellator Core ($33/computer/month)
- Managed EDR monitored and triaged by Bellator
Ransomware recovery
- Bellator Shield ($19/computer/month)
- Depends entirely on whether your own backups were tested
- Bellator Core ($33/computer/month)
- Standard detection and response to stop an active attack
Remote monitoring
- Bellator Shield ($19/computer/month)
- Not included, your team has to notice problems itself
- Bellator Core ($33/computer/month)
- Not included
Monthly cost
- Bellator Shield ($19/computer/month)
- Staff time plus whatever security software you already license
- Bellator Core ($33/computer/month)
- $19 per computer per month
Best fit
- Bellator Shield ($19/computer/month)
- Firms with in-house IT staff able to monitor alerts during filing season
- Bellator Core ($33/computer/month)
- Firms that want expert-managed detection without a bigger monitoring contract
| Feature | Bellator Shield ($19/computer/month) | Bellator Core ($33/computer/month) |
|---|---|---|
| Endpoint detection & response | Antivirus or EDR that your own staff configures, watches, and triages | Managed EDR monitored and triaged by Bellator |
| Ransomware recovery | Depends entirely on whether your own backups were tested | Standard detection and response to stop an active attack |
| Remote monitoring | Not included, your team has to notice problems itself | Not included |
| Monthly cost | Staff time plus whatever security software you already license | $19 per computer per month |
| Best fit | Firms with in-house IT staff able to monitor alerts during filing season | Firms that want expert-managed detection without a bigger monitoring contract |
Both plans are managed by Bellator, so no one on your staff is tasked with triaging EDR alerts during filing season. Read more about Bellator Shield and Bellator Core, or see the full breakdown on our protection plans comparison page.
Book a Free Tax Cybersecurity Assessment
Get a prioritized review of your firm's controls against IRS Publication 4557, the FTC Safeguards Rule, and NIST SP 800-171 before filing season opens.
Frequently Asked Questions
Yes. IRS Publication 4557 requires every tax preparer, including sole proprietors, to maintain a written data security plan. The FTC Safeguards Rule separately requires a documented information security program for tax preparers classified as financial institutions under the Gramm-Leach-Bliley Act. Neither requirement has a small-firm exemption.
Most of the work should be done before January 1. Gap assessments and WISP updates fit best in October and November, and MFA enforcement, staff training, and backup verification should wrap up by December 31, so your team is not making security decisions while already processing returns.
Phishing and spear-phishing emails impersonating the IRS, tax software vendors, or clients are the most common entry point. Business Email Compromise, where attackers hijack or spoof firm email to redirect payments, ransomware, credential stuffing against tax software portals, and RDP exploitation also show up repeatedly in IRS Security Summit advisories and industry breach reports.
Yes. The rule applies to any financial institution covered under GLBA, which includes tax preparers regardless of firm size. All covered firms must implement a written information security program, designate a qualified individual to oversee it, and meet the rule's nine required elements. Only the FTC notification requirement for events affecting 500 or more consumers depends on the scale of the incident, not the size of the firm.
Contact your local IRS Stakeholder Liaison as soon as you discover the theft, and notify your tax software provider. Affected clients should also be told so they can file Form 14039, the IRS Identity Theft Affidavit, to protect their accounts. If your firm meets the FTC's 500-consumer reporting threshold, you also owe the FTC a notification.
Do not click any links or open attachments. Forward the email to phishing@irs.gov and alert your IT or security contact, then go directly to IRS.gov or your tax software vendor's site rather than any link in the email. The IRS does not initiate contact with preparers or taxpayers by email about account issues, refund holds, or return problems, legitimate outreach comes by mail or through your e-Services account.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



