We're here to help you protect client data with an October action plan covering passwords, phishing, backups, security plans, and incident response for accounting firms. Don't miss the October Action Checklist at the end of this article.
October is Cybersecurity Awareness Month, an opportunity to examine how your practice protects the information clients entrust to you. Depending on your services, that information may include Social Security numbers, bank details, payroll records, tax returns, and identification documents. Protecting it involves the same attention to detail you bring to your accounting work.
This Insightful Accountant guide connects cybersecurity for accounting firms to everyday workflows: receiving documents, granting access, changing payment instructions, and recovering records. The October checklist assigns responsibility and identifies evidence of completion, so your team can turn a discussion into documented improvements.
Start with your highest-risk gaps. Work with your IT provider and qualified legal counsel where technical configuration or regulatory obligations require their expertise.
Cybersecurity Awareness Month gives your firm a useful annual checkpoint for reviewing safeguards and assigning improvements. CISA coordinates the federal campaign each October, while the IRS provides guidance tailored to protecting taxpayer information. Your firm's response should reflect the data you handle and the services you provide.
Translate broad intentions into observable changes. Instead of recording “improve account security,” assign someone to review MFA enrollment for every staff account. Instead of recording “review backups,” schedule a restoration exercise with a defined data set and an expected recovery outcome.
Keep a short register of gaps, owners, target dates, and completion evidence. If a task cannot be completed in October, document the reason, any interim safeguard, and the next review date. That makes unfinished work visible rather than allowing it to disappear after the awareness campaign.
A client-data inventory identifies the information your firm handles, where it resides, and who can reach it. Start with your accounting and tax applications, then follow the documents through email, client portals, local downloads, mobile devices, backups, and paper storage.
Include QuickBooks Online (QBO), QuickBooks Desktop, payroll systems, banking portals, and connected applications where relevant. Keep product versions and environments distinct: a cloud service, a hosted desktop application, and a local workstation can have different access and recovery arrangements.
For each location, document the categories of information, the person responsible, authorized users, sharing methods, and retention policy. Include contractors and service providers. A vendor connection can continue to access information after an employee stops using the application that created it.
Check actual user lists against current responsibilities. Remove departed employees and unnecessary access through an approved process, while preserving records required for business or legal purposes. For active staff, narrow permissions to the client work and functions they need.
Downloaded spreadsheets, scanned identification documents, printed returns, and removable drives deserve the same attention as primary systems. Ask staff to identify temporary copies used in their normal work, then establish approved storage and disposal procedures consistent with your retention obligations.
Document your findings without creating a new exposure. Store the inventory securely, and avoid placing passwords, recovery codes, or unnecessary client identifiers in it. A list of systems and access arrangements is itself sensitive operational information.
Unique passwords and multifactor authentication reduce the risk that stolen credentials will provide access to your firm. Prioritize email, remote access, accounting software, tax applications, and banking accounts because those services support sensitive work and account recovery.
Use an approved password manager to generate and store long, unique passwords. Protect the manager itself with MFA and documented recovery arrangements. Give staff individual accounts wherever supported; shared logins make it harder to attribute activity or remove one person's access.
Review MFA status account by account. Confirm that administrators, temporary staff, and service accounts are included in your assessment. If a system cannot support your required controls, record that limitation and work with your IT provider on appropriate alternatives or replacement plans.
Insightful Accountant's historical authentication coverage illustrates how account protection has evolved. Consult current provider documentation for today's settings and supported methods rather than treating older product coverage as configuration instructions.
CISA's MFA guidance distinguishes phishing-resistant authentication from methods that rely on codes or approval prompts. FIDO/WebAuthn-based security keys and passkeys, where supported and appropriately configured, bind authentication to the legitimate service rather than a look-alike login page.
Authenticator-app and SMS codes still add protection beyond passwords, but can be phished. Discuss stronger methods with your IT provider, starting with high-value accounts. Keep recovery methods secure, and teach staff never to approve an unexpected authentication request or disclose a verification code.
Phishing attempts to persuade someone to disclose information, sign in to a fake service, or open harmful content. Accounting workflows offer plausible pretexts: a prospective client's tax documents, an apparent payroll correction, a supplier invoice, or a message claiming to concern an IRS notice.
Teach staff to evaluate the requested action as well as the sender. An email from a familiar address can come from a compromised account. Professional wording and recognizable branding do not establish that a request is legitimate.
Use a defined intake process for unfamiliar contacts. Before opening unexpected attachments or following document links, establish the prospective client's identity through an independently verified channel. Direct documents into your approved intake system rather than improvising a new sharing method for each inquiry.
If a message asks you to enable macros, install software, or enter credentials to view a document, stop and consult your security contact. Report the message through the firm's approved process. Staff should know where to escalate uncertainty without feeling pressured to decide alone.
Verify any banking, payroll, or payment-direction change using trusted contact details already established with the client or supplier. Do not rely on a new phone number supplied in the same message. For higher-risk changes, require a second authorized reviewer and record the approval.
For example, an email requesting a new payroll bank account should trigger your verification procedure before anyone edits the payment details. Record who verified the request, the trusted channel used, and who approved the change. Treat urgent timing as a reason to follow the procedure carefully.
Secure document exchange, protected devices, and maintained software work together to reduce exposure. Your policies should describe where staff may work, which devices may access client information, and which channels clients should use to submit sensitive records.
Exchange sensitive records through appropriately encrypted, access-controlled channels. Review recipient permissions before sharing a file, and restrict broad or public links. A portal's security depends on its configuration, authentication, and user practices; the word “portal” alone does not establish adequate protection.
Insightful Accountant's cloud security discussion highlights access, backups, and connected applications. Treat older coverage as background, and verify current service capabilities with the provider before applying product-specific guidance.
Give clients clear instructions for uploading documents and requesting help. When the approved process is difficult to understand, staff may receive sensitive attachments through ordinary email instead. Make the secure route easy to find and explain how your firm verifies unusual requests.
The publication's client portal discussion provides vendor-authored background on centralized communication. Evaluate actual permissions, encryption, logging, and recovery arrangements independently; convenience and security need separate review.
Require appropriate encryption, screen locking, security software, and access controls on devices handling client information. Define whether personal devices are permitted and what safeguards apply. Keep paper files secure during remote work and transport, and include lost-device reporting in staff training.
Review remote access with your IT provider. Maintain a documented inventory of authorized tools and users, and secure remote connections with appropriate authentication. A staff member should not install a new remote-support application simply because an unsolicited caller requests it.
Install security updates promptly under a defined process. Use automatic updates where appropriate, and assign responsibility for systems requiring managed maintenance. Consider compatibility and operational needs without allowing exceptions to remain open indefinitely; document their owners and remediation dates.
Insightful Accountant's layered security coverage offers additional practitioner context. Your IT provider should verify current technical recommendations and tailor configuration to the systems your firm uses.
A recovery plan should establish which records and systems you can restore, how quickly, and from what source. Backups support recovery from accidental deletion, system failure, and some cyber incidents, but do not reverse disclosure when information has been stolen.
Identify essential data sets and acceptable recovery times with the people who use them. Include accounting records, tax files, engagement documents, and configuration information where relevant. Ask your IT provider how backup copies are protected from unauthorized access and changes.
Do not assume a cloud provider's platform recovery arrangements meet every client-file restoration need. Confirm what can be restored, how far back recovery extends, what is excluded, and who can request it. Document the answers for each important application.
Insightful Accountant's QBO backup comparison provides background for evaluating options. Verify current product capabilities and your subscription's recovery scope directly; product features and service terms can change.
Restore a representative data set in an isolated, approved environment. Check completeness, usability, access permissions, and the time required. Have a practitioner confirm that the restored records support the intended accounting task, rather than relying solely on a successful technical message.
Consider quarterly tests as a starting firm policy, adjusted for risk, system changes, and professional advice. Record results and remediation tasks. Testing frequency is a planning recommendation here, not a universal legal minimum. Keep at least one recovery route protected from compromise of everyday accounts.
A Written Information Security Plan documents how your firm protects customer information. The FTC Safeguards Rule guidance identifies tax preparation firms among covered financial institutions and requires covered businesses to maintain an appropriate written information security program.
Coverage depends on activities and regulatory jurisdiction. Do not assume that a bookkeeping practice has identical obligations to a tax preparation firm. Ask qualified legal counsel to assess applicability across your services, contractual commitments, and state requirements.
IRS Publication 5708 provides a sample plan and supporting considerations for tax and accounting practices. Use it as a starting point, then describe the systems, responsibilities, safeguards, and workflows your firm implements. An unchanged template cannot demonstrate that those controls are operating.
Identify the qualified individual responsible for the program and the senior person accountable for oversight. Include risk assessment, access controls, staff training, service-provider oversight, monitoring, and response arrangements appropriate to your obligations. Reflect administrative, technical, and physical safeguards.
The FTC describes exceptions to certain provisions for covered financial institutions maintaining customer information concerning fewer than 5,000 consumers. That threshold is not a blanket exemption from the entire Rule, and it concerns consumers rather than simply the number of files or business clients.
Insightful Accountant's earlier Safeguards Rule coverage provides historical context. Use current FTC guidance and qualified advice to determine present obligations rather than relying on an earlier compliance deadline or broad interpretation.
Maintain training records, access-review results, backup test logs, vendor assessments, and revision history securely. These records connect written policies with the work your team performs. Review the plan at least annually as a practical baseline, and update it when material changes affect your safeguards.
Include new applications and approved AI tools in change reviews. Before client information enters a new service, establish its business purpose, authorized users, data protections, and oversight. Avoid allowing an experimental workflow to become routine without a documented decision.
An incident response plan tells your team whom to contact, what to stop, and who makes decisions when something appears wrong. Prepare for suspected account compromise, lost devices, misdirected documents, ransomware, and disruption of essential services.
Define escalation contacts, after-hours arrangements, and an alternate communication method if email is unavailable. Store an accessible, protected copy of essential response information outside the system it may be needed to recover.
Staff should report suspicious activity promptly and follow your established containment instructions. Your IT or incident-response specialist can direct isolation of affected systems, account protection, and evidence preservation. Avoid uncoordinated deletion, reinstallation, or cleanup that could destroy information needed to investigate.
Keep contact details for your IT provider, insurer, legal counsel, and relevant reporting channels. For taxpayer-data incidents, include the IRS Stakeholder Liaison. Assign a person to document actions and a person authorized to communicate with clients and outside parties.
Under the FTC guidance, covered institutions must report a qualifying notification event as soon as possible and no later than 30 days after discovery. The requirement concerns unauthorized acquisition of at least 500 consumers' unencrypted information, with additional definitions and presumptions that counsel should assess.
State laws, contracts, and other obligations may impose separate duties, including notifying individuals. Do not wait for every forensic question to be resolved before involving counsel. Record discovery timing and decisions, and distinguish the FTC reporting duty from other notification requirements.
Run a tabletop exercise using a realistic scenario, such as a payroll account-change scam or an unavailable file server. Ask each participant to describe their first action, escalation route, and authority. Identify where a missing contact or unclear approval would delay the response.
Insightful Accountant's archived phishing primer provides accounting-specific examples. Use current threat examples alongside historical material, and record training attendance, lessons learned, and resulting plan changes.
Use four focused weeks to establish a baseline, close priority gaps, and test your response. The suggested schedule begins October 5; adjust dates to your practice. The roles below are examples, so replace each with a named person and assign achievable completion dates.
Maintain October's progress through a recurring review of access changes, updates, suspicious activity, and open remediation tasks. Set the cadence around your risks and responsibilities, and keep owners accountable for completing work or escalating obstacles.
Insightful Accountant's Accounting Insiders discussion connects MFA, phishing training, security planning, and risk management to accounting practice. Pair ongoing education with verified provider guidance and qualified professional advice.
Choose one improvement your team can demonstrate this week. Record what changed, who checked it, and when you will revisit it. Those small, documented decisions give your practice a stronger foundation for protecting clients throughout the year.
Covered tax preparation firms must maintain a written information security program. Small size does not create a blanket exemption. Some provisions have limited exceptions based on consumer-information thresholds; qualified counsel can determine how those apply to your practice.
Start with a data and access inventory, then address exposed sensitive accounts, MFA gaps, document sharing, and recovery capability. Your priorities should reflect actual risks. Assign owners so identified gaps lead to completed improvements rather than another unfinished checklist.
Standard authenticator codes can be phished. CISA distinguishes FIDO/WebAuthn-based methods from code-based authentication. Evaluate supported security keys or passkeys with your IT provider, and continue using layered safeguards because stronger authentication does not eliminate every account-compromise risk.
Consider quarterly restoration tests as a starting firm policy, with additional testing after important system changes. Adjust the schedule to your risks and obligations. Verify usable records and recovery time, and document failures so someone is responsible for correcting them.
Report it promptly through your incident process and follow containment instructions. Involve your IT provider, insurer, and counsel as appropriate. Preserve evidence and document discovery timing; specialists can assess scope, recovery actions, and notification obligations.
Sources and educational disclosure: This guide draws on CISA authentication guidance, FTC Safeguards Rule guidance, IRS Publication 5708, and Insightful Accountant's linked coverage. Historical and vendor-authored articles are identified as background rather than current configuration instructions. This article provides educational information, not legal advice or a vendor endorsement. Confirm technical controls and regulatory obligations with qualified professionals. QuickBooks, QuickBooks Online, QuickBooks Desktop, and ProAdvisor are trademarks of Intuit Inc.; trademark symbols are omitted from body copy for readability.