Accountant reviewing tax files on a secured workstation at night
IRS Pub 4557 · FTC Safeguards · GLBA

Cybersecurity for CPAs and accounting firms.Your firm holds every client's SSN.

Cybersecurity4CPAs delivers cyber security for accountants, tax preparers and CPA practices: the IRS Pub 4557 WISP you are required to keep, FTC Safeguards compliance, and 24/7 protection your clients assume you already have. Start with our free cyber risk checklist.

Pub 4557
IRS safeguards aligned
24/7
Monitoring & response
< 15 min
Average response time
100%
WISP attestation ready

Get the free WISP & FTC Safeguards checklist

The 12-point checklist IRS Stakeholder Liaisons and cyber-insurance carriers ask about. Sent instantly, no obligation.

We never sell your data. Unsubscribe any time.

Why accounting firms are targeted

Cyber risk for accounting firms: one compromised inbox exposes a decade of client returns.

The data is uniquely valuable

Names, SSNs, EINs, bank routing details and prior-year returns sit in one place — everything needed to file fraudulent refunds at scale.

Compliance is now mandatory

A written security plan is required to renew your PTIN, and the FTC Safeguards Rule applies to tax preparers as financial institutions.

Generic IT is not enough

Most providers have never touched Lacerte, Drake, UltraTax or CCH Axcess, and cannot produce the evidence an IRS liaison or insurer asks for.

What we do

Four services that cover everything the IRS, the FTC and your insurer expect.

WISP & FTC Safeguards Compliance

We build, document and maintain your Written Information Security Plan to IRS Pub 4557, Pub 5708 and the FTC Safeguards Rule — including the annual attestation your PTIN renewal requires.

  • Firm-specific WISP
  • Qualified Individual role
  • Carrier & IRS evidence pack

24/7 Managed Detection & Response

Round-the-clock monitoring of every workstation, server and Microsoft 365 account, tuned for the way tax teams actually work through busy season.

  • Endpoint & identity monitoring
  • Ransomware containment
  • <15 min response target

Email Security & Staff Training

Client data theft almost always starts in the inbox. We lock down Microsoft 365 and Google Workspace, enforce MFA, and train your team with simulated tax-season phishing.

  • Advanced phishing filtering
  • MFA everywhere
  • Quarterly simulations

Backup & Practice Recovery

Immutable, tested backups for Lacerte, Drake, UltraTax, CCH Axcess and your document management system, so a breach never costs you a filing deadline.

  • Immutable cloud backup
  • Quarterly restore tests
  • Documented incident plan
How it works

Protected and audit-ready in three steps.

  1. 01

    Free 30-minute risk review

    We map your software, staff and data flows against IRS Pub 4557 and the FTC Safeguards Rule and show you the gaps in writing.

  2. 02

    Deploy in days, not quarters

    Monitoring, MFA, email security, backups and training roll out without disrupting an active filing season.

  3. 03

    Stay compliant year-round

    You get your WISP, annual attestation, training records and an evidence pack ready for the IRS or your carrier.

Download the free cyber risk checklist for CPA firms

Twelve controls, written in plain English, covering the WISP, the Security Six, MFA, backups, vendor oversight and incident response. Use it to self-assess before the IRS, your carrier or an attacker does it for you.

  • Know exactly which requirements apply to your firm
  • Spot the gaps that void most cyber-insurance claims
  • Get a prioritized 90-day remediation order

Get the free WISP & FTC Safeguards checklist

The 12-point checklist IRS Stakeholder Liaisons and cyber-insurance carriers ask about. Sent instantly, no obligation.

We never sell your data. Unsubscribe any time.