Skip to content
Bellator Cyber Guard
Incident Response Planning

Data Breach Response for Tax Professionals

When a breach happens, every minute counts. Know exactly what to do with a plan built for tax professionals.

By the Numbers

72h
IRS Notification Window
$150
Per-Record Breach Cost
60%
Of Small Firms Close After Breach

What Tax Professional Data Breach Response Covers

Immediate Containment

Isolate affected systems, change credentials, and preserve evidence within the first hour.

IRS Notification (Form 14039)

File Identity Theft Affidavits and notify the IRS Stakeholder Liaison within required timeframes.

Client Notification

Communicate with affected clients using compliant notification templates and provide next steps.

Law Enforcement Reporting

File reports with the FBI IC3, local police, and state attorneys general as required by law.

Forensic Investigation

Conduct or commission a forensic analysis to determine the scope and cause of the breach.

Recovery & Hardening

Restore systems from clean backups and implement additional security measures to prevent recurrence.

How to Get Started

1

Detect & Contain

Identify the breach, isolate affected systems, and stop ongoing unauthorized access immediately.

2

Assess & Document

Determine what data was compromised, how many clients are affected, and preserve all evidence.

3

Notify & Report

Contact the IRS, affected clients, law enforcement, and state regulators per legal requirements.

4

Recover & Strengthen

Restore operations, implement lessons learned, and update your security plan.

Frequently Asked Questions

Immediately isolate affected systems from your network, change all administrative passwords, and begin documenting everything. Do not turn off computers — preserve forensic evidence.

Contact your local IRS Stakeholder Liaison, report to the Treasury Inspector General (TIGTA), file Form 14039 for each affected taxpayer, and email the IRS at dataloss@irs.gov.

Yes, most states require individual notification to affected clients, typically within 30-60 days. You should provide them with credit monitoring and identity theft protection guidance.

Yes, if the IRS determines inadequate security measures led to the breach, your Electronic Filing Identification Number (EFIN) can be suspended or revoked.

If something may be happening now

Slow the damage, preserve evidence, and get a clear response owner

Do not erase logs, reinstall systems, or keep using a device you believe is compromised. Isolate what you safely can, record what happened, and contact someone who can help you triage the next step.

  • Isolate affected access
  • Preserve useful evidence
  • Assign one response owner

Calm first-response order

  1. 01

    Contain without destroying evidence

    Disconnect affected access where safe, but avoid wiping or “cleaning” systems first.

  2. 02

    Record the facts

    Capture times, messages, affected accounts, device names, and actions already taken.

  3. 03

    Triage and recover in order

    Confirm scope, secure identities, restore safely, and document what changes afterward.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.