Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

Cybersecurity for Accounting Firms in the Tri-State Area

CybersecurityManaged IT
Last updated: September 22, 2026

Accounting firms count as financial institutions under federal law, so the FTC Safeguards Rule requires multi-factor authentication, encryption, access controls, and secure disposal on every system holding client data. Firm size does not change that.

Most of the accounting firm owners I talk to in Rockland, Westchester, and Bergen believe cybersecurity rules are something that happens to banks. Their firm has nine people. Two of them are seasonal. The idea that federal regulators wrote a rule with them in mind sounds like something an IT company made up to sell a product.

I understand the reaction. I would be skeptical too. But the rule text names your line of work specifically, and it has been enforceable since June 2023.

It is not a proposal.

What follows is what the rule actually says, what a small firm is genuinely exempt from, and what it is not exempt from no matter how few people work there. If you want the broader picture of how we support this vertical, that lives on our IT services for accounting and CPA firms page. This piece is narrower. It is about the security controls themselves, and it sits under our cybersecurity services practice.

Accountant in a blazer lifting a manila folder of client records from an open filing cabinet

You Are Already a Financial Institution

Not by opinion. By definition.

The Gramm-Leach-Bliley Act tells the FTC to set data security standards for financial institutions, and the resulting Safeguards Rule at 16 CFR Part 314 defines that term far more broadly than ordinary conversation does. Section 314.2(h) lists thirteen examples of covered businesses, and tax preparation firms appear on that list alongside mortgage brokers and collection agencies.

The IRS says the same thing in plainer language. In IR-2026-92, issued August 18, 2026, the Security Summit restated that tax and accounting professionals are considered financial institutions and must implement a data security plan. That release also points firms to Publication 5708, a 28-page template built specifically for smaller practices that need a written plan and do not have a compliance department to write one.

There is no threshold to cross. A sole practitioner with a PTIN and a laptop is covered on exactly the same terms as a forty-person firm with three offices, because coverage under this rule turns on the activity you perform rather than the size of the operation you perform it in. What changes with size is a short list of paperwork obligations, and I will get to exactly which ones in a moment, because that is where nearly every firm I speak with has been given bad information.

The Nine Things the Rule Names

Section 314.4 lists nine elements your information security program has to include. Nine is not many. Reading the regulation cold is rough going, so here is the translation for a firm with a dozen people and a server in the back room.

What 314.4 requiresWhat it looks like in a small firm
(a) Designate a Qualified IndividualOne named person owns security. Can be a partner, can be your IT provider, but a partner still supervises them.
(b) Risk assessmentKnow what client data you hold and where. Under 5,000 consumers, it does not have to be written.
(c) Design and implement safeguardsThe technical core. Access controls, data inventory, encryption, app review, MFA, disposal, change management, logging.
(d) Test your safeguardsContinuous monitoring, or annual penetration testing plus vulnerability scans every six months.
(e) Train your staffSecurity awareness training with refreshers. Seasonal preparers count as staff.
(f) Oversee your service providersYour contracts have to spell out security expectations, and you have to reassess the vendor periodically.
(g) Keep the program currentRevisit it when the firm changes. New office, new software, new partner, new review.
(h) Written incident response planWho decides, who calls whom, in what order. Under 5,000 consumers, not required in writing.
(i) Annual written report to leadershipThe Qualified Individual reports to the partners at least once a year. Under 5,000 consumers, not required.

Nothing in that list is exotic. Most of it is what a competently run firm is doing anyway, just without anybody writing down that they are doing it.

The Exemption Everybody Reads Wrong

Here is the sentence that causes the most confusion in this entire area of law. Section 314.6 reads, in full: “Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.”

That is the whole exemption. Four sub-paragraphs. Read it again if you have been told your firm is too small to worry about this, because what it takes off the table is the written risk assessment, the penetration testing and scanning schedule, the written incident response plan, and the annual report to the partners.

Everything else stays.

Multi-factor authentication stays. Encryption of client data at rest and in transit stays. Access controls stay. The data inventory stays, the disposal requirement stays, the change management requirement stays, the activity logging stays, staff training stays, and vendor oversight stays. All of it. The rule does not create a small firm tier where those become optional. It creates a small firm tier where four documents become optional.

I have watched that distinction get flattened in conversation more times than I can count. Somebody hears “under 5,000 is exempt” and stops listening. The exemption is real, it is just far narrower than the shorthand suggests.

One more thing on the counting. The threshold is written in consumers rather than clients, and what it measures is the customer information you currently maintain rather than the number of returns you happened to file this past season, which are very different numbers for a firm that has been in business a while. Two decades of prior-year records add up quickly. Count what is actually on your systems before you conclude you are under the line.

Hands placing a bundle of printed client records into a locking steel document cabinet

What This Looks Like on the Software You Actually Run

Regulations are abstract. Your Tuesday is not.

The single biggest gap I find in accounting firms is email. Almost every firm in this area runs Microsoft 365, and 365 will happily let a preparer sign in with a password alone unless somebody turns that off. Client data moves through that mailbox constantly during filing season. Turning on multi-factor authentication across every account, including the ones for people who only work January through April, closes the most likely path into your client files. It also happens to be the thing 314.4(c)(5) requires by name. Turn it on.

Encryption at rest is the second gap, and it is usually a laptop problem rather than a server problem. Whole-disk encryption is built into the Windows and macOS machines your firm already owns. It is off by default on plenty of them. Check yours. A preparer’s laptop with three years of returns cached locally and no disk encryption is the scenario the rule was written about.

Then there is the access control question, which is really an offboarding question. Whoever left the firm in May should not still have a login in September. Same for the bookkeeper who moved to a different client set and no longer needs the whole document library. Periodic review is written into the rule, and it is the requirement that decays fastest without someone owning it, because nothing visibly breaks when you skip it and nobody sends you a reminder.

On passwords, BitWarden is our recommended system. Shared credentials taped inside a desk drawer are still out there, and I do not say that to be unkind. It is just what happens when nobody was ever given a better option.

Your tax software matters here too. Drake, Lacerte, UltraTax, ProSeries, and the document portals that hang off them all handle client data, and 314.4(c)(4) expects you to have evaluated the security of the applications you use. That does not mean auditing a vendor’s source code. It means knowing whether the portal your clients upload their W-2s into supports multi-factor authentication, whether anyone at your firm has actually switched it on, and who at the vendor you would call if a client told you their documents had shown up somewhere unexpected.

Two States, Two Different Phone Calls

Plenty of firms here have clients on both sides of the Hudson, and the two states do not handle a breach the same way. Order matters.

New York’s SHIELD Act requires any business holding private information about New York residents to maintain reasonable administrative, technical, and physical safeguards. It also expanded what counts as a breach to include unauthorized access, not only acquisition, which is a lower bar than most people assume. Notice runs through the Attorney General’s data breach reporting portal, which forwards to the Department of State and the State Police automatically.

New Jersey inverts the order. Under N.J.S.A. 56:8-163, a business has to report the breach to the Division of State Police in advance of notifying the affected customers, and the state says so directly. Get that sequence backwards and you have a compliance problem layered on top of the breach you already have. Backwards is its own violation.

Layer the federal duty on top of both. Under 314.4(j), a security event involving at least 500 consumers goes to the FTC within 30 days of discovery, and that clock started in May 2024.

Where I Would Start

If you are reading this and recognizing gaps, the order matters more than the completeness. Working through it in this sequence gets you the most protection soonest.

  1. MFA on every Microsoft 365 account. Highest impact, lowest cost, usually done in an afternoon.
  2. Turn on whole-disk encryption everywhere, and confirm it, because assuming it is on is how firms find out it was not.
  3. Pull a list of every active login and delete the ones belonging to people who no longer work there.
  4. Write the WISP. Publication 5708 is a template. You are filling in blanks, not drafting from scratch, and it does double duty for the IRS and the FTC.
  5. Read your IT contract and find the clause about security responsibilities. If there isn’t one, that is a finding.
  6. Book the assessment. Ours is free, and you keep the findings whether or not you hire us.

Number four is the one firms skip, and it is the one both regulators ask about first. Do it anyway.

Worth saying plainly: none of this requires a security budget that competes with your payroll. Our managed IT starts at $995 a month for firms in the 5 to 60 employee range, and a meaningful share of what the Safeguards Rule asks for turns out to be configuration work on software your firm is already licensed for, done once and then left alone. If you want the tax-season operational side rather than the regulatory side, we wrote that up separately in what accounting firms should sort out before January.

What Firm Owners Actually Ask Me

Is there a firm size where this stops applying?
No, only four carve-outs. Coverage under the Safeguards Rule has no size floor, and a sole practitioner with a PTIN is covered. What firms under 5,000 consumers skip is the written risk assessment, the testing schedule, the written incident response plan, and the annual report to partners. MFA and encryption are not on that list.
Who is on the hook when the data lives in someone else’s cloud?
Both of you, on different things. Section 314.4(f) makes overseeing that vendor your responsibility, which means your contract has to spell out security expectations and you have to reassess them periodically. The accounts your staff use to reach that cloud are yours to secure too, and that is where the actual exposure usually sits. That part is yours.
How is a WISP different from what the FTC wants?
Mostly it isn’t, and that’s the useful part. The IRS asks for a Written Information Security Plan, the FTC asks for a written information security program, and a WISP built to the Publication 5708 template covers the substance of both. One document. Two regulators. Firms often think they need two separate compliance projects and they don’t.
What actually happens if we do nothing?
FTC enforcement against a small firm is rare, so that is the wrong thing to be scared of. The realistic consequences are a cyber insurance claim denied because the application you signed said you had multi-factor authentication when you did not, a corporate client whose in-house counsel asks for your security documentation before renewing the engagement, and a breach where the week you spend deciding who to call is the week that does the damage. Compliance is the floor. Not the point.
What breaks when you switch MFA on?
Less than firms fear, and the 365 admin center walks you through the rollout itself. A lot of firms do this in-house and I would rather tell you that than pretend otherwise. Where it gets messy is shared mailboxes, service accounts that break the moment you enforce a policy on them, and the seasonal preparer who cannot get the authenticator app working at nine at night on April 14th with a return still open. If your firm has someone technical who owns this, do it in-house. Genuinely.
How long does this take, start to finish?
Four to six weeks for a typical firm in this area, and most of that is scheduling rather than work. The technical controls go in over a couple of weeks. Documentation and the vendor contract review take longer because they need partner attention, and partners are hard to get during any season that ends in a filing deadline. Blame the calendar.
Find out which of the nine you’re missing

A free assessment maps your firm against the Safeguards Rule element by element and tells you what is already covered. No obligation, and you keep the findings.

Get Your Free Security Assessment →

Or call (845) 440-5000