Why Tax Offices Are a Target

Tax offices hold exactly what identity thieves want: names, Social Security numbers, income records and bank account details for every client.

Phishing emails that pose as clients or software vendors, stolen passwords and remote-access scams are common ways in, and filing season leaves offices busy and easy to rush.

One compromised account can lead to fraudulent returns filed in your clients’ names, a loss of trust that is hard to rebuild, and reporting obligations to the IRS and the FTC.

What the Rules Expect From Tax Professionals

Tax and accounting professionals are financial institutions under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule applies to them. The IRS and its Security Summit partners also expect every tax professional to keep a written information security plan (WISP).

The rule calls for:

A written information security plan and a named person who coordinates it

A written risk assessment of how client data is stored and handled

Multi-factor authentication for anyone who accesses customer information

Encryption of client data on your systems and in transit

Security awareness training for staff

Oversight of service providers that can access client data

A written incident response plan

Notice to the FTC within 30 days when unencrypted information of 500 or more people is exposed

The IRS publishes free guidance, including Publication 4557, Safeguarding Taxpayer Data (PDF), and Publication 5708 (PDF), a WISP template.

Links to these and other official sources are in our IT Resource Center.

How Computer Ties Supports Tax Offices

Accounts & Multi-Factor Authentication

We set up and manage MFA for Microsoft 365, email, remote access and the other systems your staff use, and remove access promptly when someone leaves.

Encryption & Secure Email

We encrypt laptops and workstations, set up secure ways to send client documents, and filter phishing before it reaches inboxes.

Backups & Recovery

We back up workstations, servers and cloud data, monitor those backups, and test that files can be restored before filing season.

CTi Tech Plaza conference room with meeting table, black chairs and wood accent wall

Help With Your Written Information Security Plan

Your WISP has to describe the systems you actually run. Computer Ties can document your devices, accounts, backups and security settings so the technical sections of your plan match reality.

We can also help you review the plan each year, update it after an office move or new software, and walk your staff through the security steps it describes.

Computer Ties does not provide legal or tax advice, and the plan remains your firm’s responsibility. Our role is to make the technology side accurate and supportable.

Frequently Asked Questions

Do tax preparers need a written information security plan?

Yes. The FTC Safeguards Rule requires tax and accounting professionals to keep a written information security program, and the IRS reminds tax pros every year to maintain a WISP. IRS Publication 5708 provides a template.

Does Computer Ties write our WISP?

The plan belongs to your firm, but we can document the technical safeguards it must describe, such as devices, accounts, MFA, encryption, backups and monitoring, and help you keep those sections current.

Can you support the computers our tax software runs on?

Yes. We support the workstations, network, Microsoft 365 and backups your tax software depends on, and work with the software vendor when a problem is inside the application.

What should we do if we suspect a data breach?

Call Computer Ties right away so we can help contain the problem and preserve evidence. The IRS asks tax professionals to report data theft quickly to their local IRS Stakeholder Liaison, and the FTC requires a report when 500 or more people are affected.

Computer Ties circular red and blue emblem

Keep Client Data Protected Year-Round

Talk with Computer Ties about your office’s devices, accounts, backups and security plan. We will review what you have and recommend practical next steps.