The Federal Trade Commission (FTC) Safeguards Rule, a critical component of the Gramm-Leach-Bliley Act (GLBA), has become a topic of hushed concern among tax and accounting firm owners. While many have encountered the rule indirectly, often as a vague notion of a "new data security requirement," a significant number struggle to articulate its specific demands. This lack of clarity is understandable, as the rule’s original drafting was geared towards regulators and legal professionals, not the day-to-day operational realities of a small, five-person tax practice striving for compliance before the next filing season. This article aims to demystify the FTC Safeguards Rule, translating its complex requirements into actionable steps for tax and accounting professionals.
The Imperative of Compliance: Why the Safeguards Rule Applies to Your Firm
The FTC Safeguards Rule is intrinsically linked to the Gramm-Leach-Bliley Act, a landmark piece of legislation enacted in 1999. The GLBA, in essence, sought to modernize the financial services industry by allowing for greater competition and innovation, but it also placed significant emphasis on protecting sensitive consumer financial information. Under the Act’s broad definition, any business considered a "financial institution" is subject to its provisions. Crucially, this definition explicitly includes tax preparers, extending beyond the commonly perceived entities like banks and lenders.
The Internal Revenue Service (IRS) further underscores this obligation in its Publication 4557, titled Safeguarding Taxpayer Data. This publication serves as a direct reinforcement of the FTC’s requirements, and every paid tax preparer is expected to adhere to its guidance. For any firm that prepares tax returns for compensation, compliance with these data security regulations is not merely advisory; it represents a fundamental legal obligation. The reality for many firms is that this compliance obligation has been in effect for some time, even if the necessary measures have not been formally documented or implemented. The impetus for understanding and acting on these requirements has intensified with increasing cybersecurity threats and heightened regulatory scrutiny.
The Cornerstone of Compliance: The Written Information Security Plan (WISP)
At the heart of the FTC Safeguards Rule lies the mandate for a Written Information Security Plan (WISP). This document is not a generic template to be downloaded and filed away; rather, it is a firm-specific, documented strategy outlining how client data is protected. It must clearly delineate who is responsible for data security within the firm and establish procedures for responding to security incidents. Both the FTC and the IRS expect the WISP to be a living document that accurately reflects the firm’s actual size, operational complexity, and the specific types of sensitive data it handles. A robust and defensible WISP typically encompasses several key areas:
- Risk Assessment: A thorough evaluation of potential risks to the confidentiality, integrity, and availability of client information. This involves identifying vulnerabilities in systems, processes, and physical security.
- Information Security Program: The implementation of measures to mitigate identified risks. This includes technical safeguards (e.g., firewalls, encryption), administrative safeguards (e.g., policies, training), and physical safeguards (e.g., secure storage of documents).
- Designated Security Lead: The appointment of a specific individual within the firm responsible for overseeing and implementing the information security program. This role ensures accountability and consistent management of security protocols.
- Employee Training: Regular training for all employees on data security policies and procedures, including how to identify and report potential threats and breaches.
- Incident Response Plan: A detailed plan outlining the steps to be taken in the event of a data breach or security incident, including notification procedures, containment strategies, and remediation efforts.
- Regular Review and Updates: A commitment to periodically reviewing and updating the WISP to address evolving threats, changes in technology, and shifts in the firm’s operations.
The "Security Six": Baseline Protections Mandated by the IRS
IRS Publication 4557 specifically highlights six baseline security protections that are expected of all tax preparers. These are not advanced, cutting-edge technologies but rather foundational measures designed to establish a robust security posture. The "Security Six" include:
- Anti-virus Software: Implementing and maintaining up-to-date anti-virus and anti-malware software on all firm devices to detect and remove malicious software.
- Firewalls: Utilizing firewalls to create a barrier between the firm’s internal network and external networks, controlling incoming and outgoing network traffic.
- Multi-Factor Authentication (MFA): Requiring more than one form of verification to access systems and data, significantly enhancing protection against unauthorized access.
- Backup Software or Services: Regularly backing up client data and ensuring that these backups are stored securely and can be readily restored in case of data loss or system failure.
- Drive Encryption: Encrypting the hard drives of computers and other devices that store sensitive client information. This ensures that data remains unreadable even if a device is lost or stolen.
- Virtual Private Network (VPN): Employing a VPN when remote access to the firm’s network is necessary. A VPN creates a secure, encrypted connection over the internet, protecting data in transit.
The emphasis here is not on adopting the latest technological advancements but on the diligent implementation and documented evidence of these fundamental security practices. Mere assumptions about security are insufficient; tangible proof of these measures being in place and operational is paramount.
Common Pitfalls: Where Firms Often Fall Short
In practical terms, the most frequent shortcomings in data security compliance are not typically a result of firms deliberately ignoring security. Instead, the gap often arises from having informal, yet reasonable, security practices that are not formally documented. This lack of written policy means there is no clearly designated owner of the security program, and crucially, no tangible evidence that can be presented to a regulator or a cyber-insurance carrier upon request.
A WISP that exists solely as institutional knowledge held by one partner, while perhaps effective in daily operations, does not satisfy the legal requirements. Furthermore, such an arrangement creates a critical vulnerability: if that partner becomes unavailable due to illness, departure, or an incident, the firm’s ability to respond effectively and demonstrate compliance is severely compromised.
Another pervasive issue is the slow adoption of multi-factor authentication (MFA). Despite its relatively low cost, widespread availability, and significant security benefits, firms that have maintained long-standing login workflows are often hesitant to implement MFA. This inertia persists even though MFA is explicitly identified by the IRS as one of the six essential baseline protections. The resistance to updating these foundational access controls leaves firms unnecessarily exposed to common cyber threats like credential stuffing and phishing attacks.
Charting a Path Forward: Actionable Steps for Firms
For firms that have yet to formalize their Written Information Security Plan, the task of starting from scratch can seem daunting. However, resources are readily available to guide the process. The FTC provides a small-business compliance guide that offers practical advice. Additionally, the IRS’s Publication 4557 clearly outlines the "Security Six" in accessible language, providing a solid framework for understanding baseline requirements.
The most effective and realistic starting point is a comprehensive, honest audit of the firm’s current security posture. This audit should address several key questions:
- Which of the "Security Six" protections are currently in place and fully functional within the firm?
- Which of these protections are missing or inadequately implemented?
- Who within the firm will take ownership of documenting the WISP and overseeing its ongoing implementation and maintenance?
The final point—the establishment of a named owner and the creation of an actual, written document—is often the decisive factor. It transforms a firm from one that merely assumes it is compliant to one that can demonstrably prove its adherence to data security regulations. This documented commitment is not only a legal necessity but also a critical element in building client trust and ensuring the long-term resilience of the practice against the ever-evolving landscape of cyber threats.
The Broader Implications and Future Outlook
The FTC Safeguards Rule and the IRS’s emphasis on data protection for tax preparers are not isolated regulatory demands. They are part of a broader, accelerating trend toward increased accountability for data privacy and security across all industries. As the volume and sensitivity of digital information continue to grow, so too will the expectations and enforcement efforts of regulatory bodies.
For tax and accounting firms, compliance with the Safeguards Rule is more than just a legal obligation; it is a strategic imperative. Demonstrating robust data security practices can serve as a significant competitive differentiator, assuring clients that their most sensitive financial information is handled with the utmost care. Conversely, a data breach can have devastating consequences, leading to financial penalties, reputational damage, loss of client trust, and potential legal liabilities.
The implications extend beyond individual firms. As the tax and accounting profession becomes more interconnected through cloud-based software and digital data exchange, the security of individual firms contributes to the overall security of the ecosystem. A weakness in one firm’s defenses could potentially be exploited to compromise others. Therefore, a collective commitment to strong data security practices is essential for the integrity of the entire profession.
Looking ahead, it is reasonable to anticipate that regulatory expectations will continue to evolve. Firms should not view compliance as a one-time event but as an ongoing process of vigilance, adaptation, and continuous improvement. Investing in cybersecurity training, staying informed about emerging threats, and proactively updating security protocols will be crucial for maintaining compliance and safeguarding client data in an increasingly digital world. The resources provided by the FTC and IRS are not just compliance checklists; they are foundational elements for building a resilient and trustworthy tax and accounting practice for the future.
This article was written by Mark Johnson, CPA, an accounting and technology advisor at Cloud Innovics, a provider of secure cloud hosting for accounting software. Photo credit: rawpixel.com/Freepik.







