Nobody’s thinking about data security in June. In June, you’re catching up on CPE, maybe taking a vacation, maybe cleaning out the files from the season that almost killed you.
Security becomes real on April 10th, when the server locks up and you’ve got 200 returns due in five days. Or when a preparer clicks a phishing link the week before the deadline and suddenly your email is sending fake invoices to every contact in your address book.
That’s the worst time to find out you don’t have a plan. And the FTC Safeguards Rule is basically the government saying: have a plan before April.
If you’ve heard the term “Safeguards Rule” floating around at a conference or in a peer group, here’s what it actually means for your firm.
What the Safeguards Rule Is
The FTC Safeguards Rule falls under the Gramm-Leach-Bliley Act (GLBA). It applies to “financial institutions,” which sounds like it only covers banks. It doesn’t. Under the FTC’s definition, tax preparers and accounting firms are financial institutions. If you’re handling clients’ financial information (and you are), this rule applies to you.
The rule requires covered businesses to develop, implement, and maintain a comprehensive information security program. In plain terms: you need a real plan for protecting client data, and you need to actually follow it.
What Changed in 2023
The original Safeguards Rule has been around since 2003. But the FTC made significant updates that took full effect in June 2023. Here’s what’s different:
The security program has to be written down. You need a documented information security program. Not a mental note. Not a verbal agreement with your IT person. A written plan.
Risk assessments are required. You need to identify the risks to client information across your firm and document how you’re addressing each one.
Access controls. Only people who need access to sensitive data should have it. That means role-based permissions, not everyone logging into the same admin account.
Encryption. Client data needs to be encrypted both in transit and at rest. If you’re emailing unencrypted tax returns to clients as PDF attachments, that’s a problem.
Multi-factor authentication. MFA is now a requirement, not a suggestion. Anyone accessing client data needs a second form of verification beyond just a password.
Monitoring and logging. You need to be able to detect unauthorized access or security events.
Incident response plan. You need a documented plan for what happens when something goes wrong.
Annual reporting to your partners. Someone has to report on the status of your security program at least once a year.
The Qualified Individual Requirement
The updated rule requires you to designate a “Qualified Individual” to oversee your information security program. The Qualified Individual doesn’t have to be an employee. The FTC explicitly allows you to use a third party, like a managed IT or security provider, to fill this role. But you, the firm, still carry the ultimate responsibility.
For a 5 to 20 person CPA firm, hiring a full-time CISO doesn’t make financial sense. That’s a $150K-plus salary for a role you need maybe a few hours a month. This is exactly where partnering with an IT provider who understands these regulations becomes practical.
What This Means for Your Firm, Practically
These eight steps aren’t just compliance boxes. Most of them will also make your firm run better, especially during busy season:
1. Get your security program documented. If you don’t have a Written Information Security Plan (WISP), start there. One well-built document can address both the IRS and FTC requirements.
2. Run a risk assessment. Look at your firm honestly. Where is client data stored? Who has access to what? What happens if a laptop gets lost?
3. Turn on MFA everywhere. Microsoft 365, your tax software portal, your client document portal, your remote access tools. This is non-negotiable under the updated rule.
4. Encrypt your data. Turn on BitLocker for all Windows devices. Make sure your email is encrypted. If you’re still emailing returns as unencrypted PDFs, this is the year to stop.
5. Set up access controls. Not everyone in the firm needs access to every client file.
6. Designate your Qualified Individual. Whether that’s someone internal or your IT provider, make it official.
7. Create an incident response plan. Write down what happens if you get breached.
8. Report annually. Set a date once a year to review the security program with your partners.
The Busy Season Connection
The time to think about security is not during tax season. It’s before tax season. Every year, we see the same pattern. Shortcuts start happening. Someone shares a password so a temp can start processing returns. A preparer downloads client documents to a personal laptop because the VPN is slow. Each one of those shortcuts is exactly what the Safeguards Rule is designed to prevent.
Getting Started Without Getting Overwhelmed
Asteroid IT works with CPA firms across the Phoenix metro area to build security programs that meet these requirements without disrupting your practice. We handle the technical side so you can focus on your clients.
If you’re not sure where your firm stands with the Safeguards Rule, let’s have a conversation. No jargon, no pressure. Just a clear picture of what you need and a realistic plan to get there.
Call us at 480-937-7021 or visit asteroidit.com to schedule a time.
