Firewall Protection for Tax Offices
Security Six requirement #2: Both hardware and software firewalls are required to protect your network and devices. Here’s how to set them up correctly.
What the IRS requires for firewall protection
IRS Publication 4557 requires two layers of firewall protection: a hardware firewall (typically built into your router or a dedicated appliance) that protects your entire office network, and software firewalls on each individual device that accesses client data.
Your firewall is the first line of defense against unauthorized access. It monitors incoming and outgoing network traffic and blocks connections that don’t meet your security rules. Without it, every device on your network is directly exposed to the internet.
Hardware vs. software firewalls
Hardware firewalls sit between your internet connection and your network. Most business routers include one, but dedicated firewall appliances (like Fortinet or SonicWall) offer deeper inspection and better logging. Software firewalls run on each device — Windows Firewall and macOS Firewall are built-in options. Both layers are required because they protect against different threat vectors.
Firewall best practices for tax offices
Separate your networks
Keep client-data systems on a separate network segment from guest Wi-Fi and personal devices. This limits exposure if one segment is compromised.
Enable logging
The FTC Safeguards Rule requires activity logging. Your firewall should log all blocked connections and suspicious traffic for review.
Update firmware regularly
Router and firewall firmware updates patch security vulnerabilities. Enable auto-updates or check monthly at minimum.
Review rules annually
Firewall rules should be reviewed at least annually as part of your WISP update. Remove outdated rules and verify nothing is left open unnecessarily.
Firewall FAQ for tax offices
For a solo practitioner, a modern business-grade router with SPI (Stateful Packet Inspection) firewall may suffice, combined with software firewalls on each device. For multi-user offices or firms handling high volumes of client data, a dedicated firewall appliance with deeper inspection capabilities is strongly recommended.
Yes. Your home network needs the same firewall protection as a traditional office. At minimum, ensure your home router’s firewall is enabled and properly configured, software firewalls are active on your work devices, and your work network is segmented from household devices.
Check your firewall logs regularly for blocked connection attempts — that’s your firewall doing its job. You can also use online port-scanning tools to verify no unnecessary ports are open. For business-grade firewalls, review the dashboard for traffic patterns and blocked threats. Document these checks as part of your WISP.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
