Home / Accounting & Tax Firms
For accounting & tax firmsYour data-security program may not be compliant — ABR makes it fully compliant.
Under the FTC Safeguards Rule, tax and accounting firms that prepare returns or give financial advice are treated as “financial institutions” — required to have a written information security plan (WISP) and specific safeguards. ABR writes the plan and runs the security that satisfies it.
Per the FTC Safeguards Rule (16 CFR Part 314) · IRS Publications 4557 & 5708
Most small firms don't realize it: the FTC Safeguards Rule (under the Gramm-Leach-Bliley Act) treats tax and accounting firms as “financial institutions” — regardless of size. If your firm prepares returns or provides financial advice, you're required to have a written information security plan (WISP) and specific safeguards in place.
This isn't coming — it's here. The core requirements have been enforceable since June 2023, and since May 2024 a separate rule requires reporting a breach affecting 500 or more people to the FTC within 30 days.
The IRS is blunt about it: failing to have a written security plan “may result in an FTC investigation.”
The Safeguards Rule names nine things your program must include. Here's the short version — count how many your firm has today:
A written security plan (WISP)
A documented program of administrative, technical, and physical safeguards — written, accessible, and kept current.
A designated Qualified Individual
One person accountable for the security program. This role can be outsourced.
A written risk assessment
Identify where client data lives and the risks to it.
Multi-factor authentication
MFA for anyone accessing systems with client data — with limited written exceptions.
Encryption
Client data encrypted at rest and in transit — with limited written exceptions.
Monitoring, testing & logging
Continuous monitoring — or annual penetration testing plus vulnerability scans every six months.
A written incident-response plan
A documented plan for when something goes wrong, plus 30-day FTC breach reporting.
Vendor oversight & staff training
Hold your service providers to the same standard, and train your team to spot threats.
Most providers sell you either the plan or the tools. We do both — the written WISP and the managed security that actually satisfies it, under one roof.
A real, firm-specific plan built to the FTC/IRS structure — and kept current as the rules change.
We own the program and the reporting, so your staff don't have to.
24/7 detection and response on every device — the safeguard, actively monitored.
Firewalls, segmentation, and a hardening review that closes the gaps an assessment would flag.
The two controls the rule names most — rolled out across your systems and email.
Continuous monitoring, audit logs, and a tested response plan — with breach reporting handled.
Service-provider review, staff security-awareness training, and recoverable backups.
Compliance isn't a document you file and forget — it's controls that have to actually run. ABR delivers the WISP and the managed security that backs it, on one bill, with one team to call.
Most firms we work with are also running aging phone systems. Our business phone service keeps your team reachable through tax season and from anywhere, with the same one-partner simplicity. Lines from $24.95/mo.
Is my firm really covered? We're small.
Yes — the FTC Safeguards Rule applies to tax and accounting firms that prepare returns or provide financial advice, regardless of size. Coverage attaches to that work, not to the “CPA” title. (A firm doing only audit/attest work with no tax or financial-advisory services may fall outside it.)
What exactly is a WISP?
A Written Information Security Plan — a documented program of administrative, technical, and physical safeguards required by the FTC Safeguards Rule (16 CFR 314.3). The IRS publishes a fill-in template (Publication 5708). It must be written, maintained, and actually implemented — not just filed away.
What's the deadline?
The core requirements have been enforceable since June 9, 2023. Since May 13, 2024, a separate rule requires reporting a breach affecting 500 or more people to the FTC within 30 days. In short: the deadlines have already passed.
What happens if we don't comply?
Non-compliance is enforceable by the FTC. The IRS states plainly that failing to have a written security plan “may result in an FTC investigation,” and the FTC has acted against firms that had no written program in place.
Do you write the plan, or just sell security tools?
Both. We write and maintain your WISP and can serve as your Qualified Individual, and we run the managed security that satisfies it — one partner for the plan and the protection.
Sources: FTC Safeguards Rule (16 CFR Part 314) · IRS Pub 4557 — Safeguarding Taxpayer Data · IRS Pub 5708 — WISP template
One Partner … Total Peace of Mind™
We'll review your current setup against the FTC Safeguards Rule and show you exactly what's in place and what's missing. No pressure, no jargon. Serving accounting firms across Chicago's northwest suburbs and nationwide.
Free Safeguards Rule analysis →