Your Tax Season Cybersecurity Checklist
Complete these security tasks before filing season starts. Protect your practice during the highest-risk period of the year.
By the Numbers
What Tax Season Cybersecurity Checklist Covers
Software Updates
Update all tax software, operating systems, antivirus, and firmware before filing begins.
Password Reset
Change all passwords, verify MFA is active, and review user access lists.
Backup Verification
Test your backup systems, verify recovery procedures, and ensure off-site copies.
Staff Training Refresher
Conduct a pre-season security awareness session focused on current phishing threats.
Network Security Audit
Review firewall rules, wireless settings, and ensure all devices are accounted for.
WISP Review & Update
Review and update your WISP for the new tax year, documenting any changes.
How to Get Started
Update Everything
Patch all software, update antivirus definitions, and check firmware on routers and printers.
Reset Credentials
Change passwords, verify MFA, remove departed employee access, and review admin accounts.
Test Backups
Perform a test restore from backups to verify data recovery works before you need it.
Train & Document
Brief staff on current threats, update your WISP, and document all pre-season security actions.
Frequently Asked Questions
Ideally complete all security tasks in December before filing season begins in January. Some tasks like software updates should be repeated monthly throughout the season.
Phishing emails are the biggest risk. Criminals know tax pros are busy and stressed, making them more likely to click malicious links. Phishing volume increases 300%+ during January through April.
Yes. The IRS requires annual review of your WISP. Update it to reflect any changes in technology, personnel, or threats. Document the review date even if no changes are needed.
Address critical issues immediately — don't start filing until they are resolved. Document the finding, your remediation steps, and any timeline for full resolution in your WISP.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
Learn first. Decide when you are ready.
Use what you learned—or follow the next question
Continue with a related explanation, compare the options, or ask a specialist to help apply the guidance to your situation. You do not need to jump straight to a sales call.
Answer the question in front of you
Use the guide to understand the risk, decision, or safeguard without unnecessary jargon.
Follow the useful branch
Move to a checklist, comparison, deeper guide, or adjacent question that matches your situation.
Ask for context if needed
Bring the remaining question to a person when general guidance is no longer enough.
