Call Today

+1 440-322-ILER(4537)

}
Hours

Mon – Fri, 9am to 5pm

Tech Blog

your go-to resource for all things tech! Stay updated on the latest trends, industry insights, and expert tips to navigate the ever-evolving world of technology.

CPA Data Security: How CPA Firms Can Better Protect Client Tax and Financial Data

by | Sep 9, 2026

CPA data securityCPA data security is not something an accounting firm can afford to treat like another item on the someday list.

Your clients trust you with information they would not hand to almost anybody else.

Tax returns.

Social Security numbers.

Bank account information.

Payroll records.

Business financial statements.

Employee information.

Investment details.

Maybe even copies of driver’s licenses and other identity documents.

That makes your firm valuable to your clients.

Unfortunately, it can also make your firm valuable to criminals.

The IRS warns that tax professionals remain attractive targets for sophisticated cybercriminals looking for client information that can be used to commit identity theft and tax fraud.

The answer is not to panic.

The answer is to make CPA data security intentional.

Start by Knowing Where Client Data Actually Lives

Ask a managing partner where the firm’s client data is stored and you may hear:

“Our server.”

That answer used to be easier.

Today, client information may be spread across:

  • Tax preparation software

  • QuickBooks

  • Microsoft 365

  • Email

  • OneDrive or SharePoint

  • Client portals

  • Document-management systems

  • Employee laptops

  • Remote-access platforms

  • Cloud applications

  • Backup systems

And occasionally — bless its little insecure heart — somebody’s desktop folder.

Before you can protect sensitive data, you need to know where it lives, who has access to it and how it moves between people and systems.

That is one reason a cybersecurity risk assessment can be so valuable.

You cannot properly secure what you do not know exists.

CPA Data Security Begins With Access Control

Not everybody in your firm needs access to everything.

A new employee probably does not need unrestricted access to every client file your firm has accumulated over the past 15 years.

Employees should receive the access required to perform their responsibilities — and no more.

That means firms should regularly review user accounts and permissions.

Ask:

Who can access sensitive client information?

Do former employees still have active accounts?

Are administrative permissions limited?

Does your firm remove access promptly when someone leaves?

Are employees sharing credentials?

Are outside vendors using accounts that nobody reviews?

Access tends to accumulate over time.

Someone receives permission for a project. The project ends. Nobody takes the permission away.

Repeat that for five or ten years and you can wind up with an IT environment that has more open doors than a church potluck.

Multi-Factor Authentication Should Be Normal

Passwords are important.

But passwords alone are not enough.

Employees reuse passwords. Passwords can be stolen in phishing attacks. Credentials may also be exposed through breaches involving unrelated services.

Multi-factor authentication adds another layer between a stolen password and your firm’s sensitive information.

For accounting firms, MFA should be strongly considered for critical systems, including email, remote access and cloud applications that contain confidential information.

The IRS Security Summit’s cybersecurity recommendations include two-factor authentication among its fundamental safeguards for tax professionals.

If an application containing confidential client information offers MFA and your firm is not using it, that is a conversation worth having.

Email Is Still One of the Biggest Doors Into Your Firm

Cybersecurity criminals do not always break through the technological equivalent of a concrete wall.

Sometimes they send an email.

An employee receives what looks like a Microsoft password expiration message.

Or a fake DocuSign request.

Or a message that appears to come from a partner asking for a document.

One click can turn into a very expensive afternoon.

Strong CPA data security therefore needs both technology and people.

Email filtering helps.

Endpoint protection helps.

Multi-factor authentication helps.

But employees also need to recognize the warning signs.

Security-awareness training should not be a 90-minute video employees watch once a year while answering email in another window.

Keep it practical.

Use short training.

Run phishing simulations.

Explain why the threats matter to the firm and its clients.

Then help employees improve without making cybersecurity feel like a game of “Gotcha.”

Keep Systems Patched and Supported

There is a phrase nobody wants to hear after a breach:

“We knew that system was old.”

Unsupported operating systems and outdated applications create unnecessary risk.

Software vendors regularly release security patches because vulnerabilities are discovered.

If those patches are not being applied consistently, a known vulnerability may remain open long after a fix exists.

During tax season, firms understandably hesitate to change anything.

When everything is moving a hundred miles an hour, nobody wants an update breaking tax software on March 28.

That is exactly why patching needs structure.

Updates should be tested, scheduled, monitored and documented instead of being left to chance.

Your Written Information Security Plan Cannot Just Collect Dust

This one deserves special attention.

The IRS states that tax professionals are required to maintain a Written Information Security Plan, commonly called a WISP. In June 2026, the IRS again reminded tax professionals of that requirement and emphasized areas including employee management, information systems, and detecting and managing system failures.

The FTC Safeguards Rule also requires covered financial institutions to establish and maintain an information security program appropriate to their size, complexity, activities and the sensitivity of the information involved.

A WISP should not be a pretty document somebody downloads, changes the company name on and sticks in a folder.

It needs to reflect reality.

If your plan says all employees use MFA, they should actually use MFA.

If it says backups are tested, someone should actually be testing them.

If it identifies a person responsible for security, that person should know they have the job.

Paper compliance and operational security should tell the same story.

Do Not Forget Your Vendors

Your firm probably relies on several technology vendors.

Your tax software provider.

Your cloud provider.

Your IT provider.

Your copier company.

Your document-management platform.

Your payroll application.

Potentially dozens more.

Third-party access needs oversight.

The FTC’s guidance says covered organizations should take steps to ensure service providers safeguard customer information entrusted to them.

So ask questions.

How does a vendor protect your information?

Does it support MFA?

Who has administrative access?

How is data backed up?

What happens to your information when the contract ends?

How quickly will the vendor notify you of a security incident?

Those are business questions, not just IT questions.

Back Up the Data — Then Make Sure You Can Get It Back

Backups deserve a special place in any CPA data security strategy.

Your firm needs reliable copies of critical information.

But having a backup is only half the equation.

Recovery matters too.

If your main system failed today, how long would restoration take?

Which system would you restore first?

Could the firm continue serving clients while restoration was underway?

Have you tested it?

A successful backup notification is nice.

A successful recovery test is better.

Get an IT Partner Who Understands the Accounting Business

A general IT provider may understand computers perfectly well.

But accounting firms have particular pressures.

Tax deadlines do not move because the server has a problem.

Clients expect confidentiality.

Your firm has compliance responsibilities.

Staff members use specialized tax and accounting software that must integrate with Microsoft 365, printers, scanners, portals and other platforms.

Security cannot come at the expense of making everybody’s job impossible.

That is where an accounting-focused IT strategy makes a difference.

At Iler, we help firms approach cybersecurity, support and technology planning through the lens of how an accounting business actually operates.

Explore our IT and cybersecurity services to see how an outsourced IT partner can help reduce technology headaches while strengthening the systems surrounding client information.

For further guidance, the FTC Safeguards Rule resource for businesses explains information-security responsibilities for organizations covered by the Rule.

CPA Data Security Is Really About Trust

Cybersecurity can sound technical.

Firewalls.

Encryption.

EDR.

MFA.

Conditional access.

But underneath all those acronyms is something much simpler.

A client gave you confidential information because they trust your firm.

Good CPA data security helps you honor that trust.

And it gives the managing partner something equally important: confidence that reasonable safeguards are being managed consistently instead of simply being assumed.

Schedule a CPA IT Analysis

If you are wondering whether your current security measures are enough, get a clearer picture before a client, regulator or cybercriminal finds the gaps first.

Schedule a CPA IT Analysis with Iler.

We will help identify weaknesses in your firm’s technology, cybersecurity and business-continuity approach and give you a clearer understanding of where improvements may be needed.

Schedule your CPA IT Analysis at iler-cpa-it.com

Better CPA data security starts with knowing exactly where your firm stands.

CPA data security

Small Business Cybersecurity Myths: 6 Things Businesses Still Get Wrong

Small business cybersecurity myths can give business owners a false sense of security. From believing hackers only target large companies to assuming backups guarantee recovery, here are six cybersecurity myths every small business should stop believing.

CPA data security

5 Ways AI Disaster Preparedness Planning Can Strengthen Your Business

AI disaster preparedness planning can help businesses document critical processes, identify potential gaps and build stronger response plans. Here are five practical ways to use AI while keeping human oversight at the center of your disaster recovery strategy.

CPA data security

5 Time-Saving Business Habits That Keep Your Business Productive

The best time-saving business habits aren’t complicated productivity hacks. They’re simple routines that reduce interruptions, prevent problems and keep your employees focused on getting work done.

CPA data security

Q4 IT Checklist for Small Businesses: Get Ready Before the Year-End Rush

A Q4 IT checklist for small businesses can help you identify technology, cybersecurity, backup and budgeting issues before they become year-end emergencies.

CPA data security

Manufacturing IT Outage: How Long Could Your Production Floor Keep Running?

A manufacturing IT outage can quickly turn into a production outage when ERP, networks, Wi-Fi, servers, scanners, and shop-floor systems stop communicating. Here’s how manufacturers can determine how long their operation could actually keep running.