Compliance for Accountants: Why Cybersecurity Is Really a Client Trust Issue
Key Takeaways
- Compliance for accountants is less about satisfying a regulator and more about proving your firm protects the client data it holds.
- The FTC Safeguards Rule, IRS guidance, and state breach-notification laws all point in the same direction: protect data, document your controls, and be ready to respond.
- Recent breaches at accounting and tax firms show the real cost of an incident is reputational and legal, not just regulatory.
- A written information security plan (WISP), risk assessments, training records, and vendor reviews are the proof points regulators, insurers, and clients now expect.
- Cybersecurity compliance works best as a firm-wide responsibility, not a task handed entirely to IT.
When you hear the words compliance for accountants, you may think about regulations, audits, checklists, and paperwork.
Most clients do not. What clients care about is trust.
They trust their accountant with some of the most sensitive information they own. Tax returns. Payroll data. Bank account details. Social Security numbers. Financial statements. Information they may not even share with close friends or family.
That is why cybersecurity has become such an important topic for your firm. Not because regulators say so, but because protecting client data has become part of protecting client relationships.
The compliance requirements that continue to emerge across the industry are not creating a new responsibility. They are formalizing one you have always had.
When you recognize that shift, you start approaching cybersecurity differently. You are no longer asking, “What do we need to do to be compliant?”
The better question: Can you demonstrate that you are protecting the trust your clients place in you every day?
Why Firms Must Prove Compliance, Not Just Claim It
You have always worked in a world built around proof. Documentation matters. Controls matter. Review matters. Evidence matters.
Cybersecurity is now entering that same world.
It is no longer enough to say, “We take security seriously.” That may be true, but it is not especially useful after a client asks what happened, an insurer reviews a claim, a regulator asks for evidence, or a plaintiff’s attorney looks for your written policies and controls.
The practical question has changed. It is not just whether you have security tools in place. It is whether you can show a reasonable, documented pattern of care around client data.
That is where compliance becomes valuable. Not as paperwork for the sake of paperwork, but as evidence that you have treated client information with the care it deserves.
What Compliance for Accountants Actually Requires
Compliance for accountants covers a mix of federal rules, IRS guidance, state privacy and breach-notification laws, professional standards, cyber insurance expectations, and client due diligence requirements.
The details matter, but the direction is consistent: protect client data, document what you are doing, train your people, manage vendors, and be ready to respond if something goes wrong.
A few of the most important layers include:
FTC Safeguards Rule
Tax preparation firms are specifically called out as examples of financial institutions covered by the rule. The FTC Safeguards Rule focuses on protecting customer information, and the breach-notification requirement that took effect in 2024 requires covered firms to report certain security events involving at least 500 consumers no later than 30 days after discovery. The rule includes exemptions for certain requirements.
IRS Publication 4557 and WISP expectations
The IRS makes clear that tax professionals are targets because they hold valuable taxpayer data. The GLBA and FTC Safeguards Rule require covered firms to maintain written information security plans. IRS Publication 4557 and related IRS guidance points tax professionals toward security planning, basic safeguards, phishing awareness, data-loss response, and Written Information Security Plans.
State privacy and breach-notification laws
A firm’s obligations may be shaped by where its clients live, not only where the firm is located. State laws have differing jurisdictional requirements, thresholds, and exemptions.
Professional responsibility
For accountants, confidentiality is not just a technology issue. It connects directly to the trust clients place in the profession.
Insurance and client expectations
Cyber-insurance applications and client questionnaires increasingly ask about practical controls such as MFA, backups, encryption, training, incident response, and vendor oversight.
Plain-English takeaway: You do not have to turn this into a legal exercise. The stronger message is that the rules are evidence of a bigger market shift: you now need to prove you are protecting client data.
The Real Cost of Data Breach at an Accounting Firm
Many cybersecurity vendors lead with regulatory penalties.
The problem is that you are likely skeptical of fear-based marketing, and with good reason. You work with details for a living. You know when a number is being used to create urgency more than clarity.
The more practical story is what happens when clients lose confidence in the firm that was supposed to protect their information.
Recent incidents involving accounting and tax firms illustrate the point.
Recent data breach incidents involving accounting and tax firms
Each case study below includes an inline link to the primary article or public notice so readers can review the source for themselves.
1. Ciuni & Panichi
ClassAction.org reported a proposed $592,500 class action settlement connected to a November 2024 breach at the Ohio-based accounting and financial advisory firm. The report says court documents identified about 25,593 people in the settlement class, and that potentially exposed information included names, Social Security numbers, dates of birth, and other personally identifiable information collected by the firm. Read the ClassAction.org settlement article.
Why it matters: This makes the risk tangible. The issue is not just that a rule may have been violated. It is that exposed client information can lead to public litigation, client claims, reimbursement obligations, and a permanent trust problem for your firm if your reputation is built on discretion and care.
2. Dohman, Akerlund & Eddy
ClassAction.org reported that DA&E experienced a February 28, 2024 cyberattack that led to unauthorized access to files containing personal information. The report says the Maine Attorney General filing indicated 82,207 individuals may have been affected, with potentially compromised data including names, Social Security numbers, medical information, and health insurance details. The official settlement site later described a proposed settlement involving claims tied to the February 2024 incident. Read the ClassAction.org investigation article.
Why it matters: This shows how accounting firm data can go beyond “tax documents.” When you hold financial, personal, medical, benefits, or insurance-related information, a breach can create broader client harm, more complex notification issues, and more pressure to show that you had reasonable safeguards in place before the incident.
3. Legacy Professionals LLP
ClassAction.org reported that Legacy Professionals detected suspicious network activity in late April 2024. Legacy Professionals later determined in November 2024 that some files had been taken by an unauthorized party, and by early February 2025 confirmed 216,752 affected individuals and that exposed data might include names, Social Security numbers, driver’s license or state ID numbers, and information related to medical treatment or health insurance. Read the ClassAction.org investigation article.
Why it matters: The lesson is that breach response is not only technical. The timeline, investigation, notification process, and evidence of prior safeguards all matter. Clients will want to know what was exposed, when you knew, how quickly you acted, and whether you had a defensible security program before the breach.
4. Wonder CPA Firm
ClassAction.org reported that Wonder CPA Firm disclosed a breach that may have impacted names, addresses, dates of birth, and Social Security numbers. The report says the San Antonio firm discovered a possible breach on July 1, 2024, and later determined on October 16, 2024 that personal details may have been exposed. Read the ClassAction.org investigation article.
Why it matters: This is the everyday accounting-firm risk in plain view. If you provide tax, accounting, or payroll services, you can hold exactly the identity data criminals want. Even if you are not a national brand, a breach can still become visible to clients, regulators, attorneys, and the public.
5. Mercadien PC
ClassAction.org reported that Mercadien PC discovered an incident on November 7, 2025 and that a posted data breach notice said information may include names, addresses, dates of birth, government ID numbers, Social Security numbers, financial account details, and, for some individuals, usernames, passwords, IRS PINs, and payment card information.State filings report 402,741 affected individuals. Read the ClassAction.org investigation article.
Why it matters: This example underlines how concentrated your data can be. If you store tax credentials, financial account information, government identifiers, and login data, the potential client impact is not limited to inconvenience. It can create risk around identity theft, account fraud, and tax-related misuse.
6. Accounting & Tax Associates, Inc.
A Mass.gov notice letter stated that around May 14, 2025 an unauthorized party accessed Accounting & Tax Associates’ account on the third-party Intuit Lacerte Tax software platform. The notice says the firm’s review concluded on July 2, 2025 and determined that personal information may have been included in impacted data. The notice also offered 18 months of complimentary LifeLock Ultimate Plus identity theft protection. Read the Mass.gov breach notice.
Why it matters: This is an important reminder that compliance is not limited to systems you directly own. Tax platforms, cloud applications, portals, and third-party tools are all part of your client-data environment. You still need strong access controls, monitoring, vendor governance, and a response process for the platforms you rely on every day.
The “exposure, consequence” pattern is difficult to ignore
When client information is exposed, the consequences often extend beyond the technical response. You may face notification obligations, legal costs, client concerns, reputational impact, insurance questions, and increased scrutiny around the security measures that were in place before the incident occurred.
For most firms, that is a far more tangible risk than a theoretical regulatory fine.
What Firms Need to Prove They Are Protecting Client Data
You already understand the importance of documentation.
If it is not documented, it did not happen.
The same principle increasingly applies to cybersecurity. Having MFA enabled is valuable. Having encrypted systems is important. Using secure cloud applications matters. But regulators, insurers, clients, and potentially courts are asking a different question: Can you prove it?
Can you show the policies, training records, risk assessments, vendor reviews, incident-response plans, and security controls that demonstrate the safeguards you have implemented?
| Proof point | What it shows |
|---|---|
| A current WISP | You have a written plan that reflects how you actually protect client data. |
| Periodic risk assessment | You understand where sensitive data lives and where exposure exists, and you periodically update your evaluation of internal and external risks. |
| MFA and access controls | You limit who can access client data and reduce credential-based risk. |
| Training records | You have educated staff on phishing, data handling, and reporting issues. |
| Vendor reviews | You understand which third parties touch client data and have reviewed their safeguards. |
| Incident-response plan | You know who does what when something goes wrong. If you are exempt from the written plan requirement, you remain responsible for breach assessment and notification obligations. |
| Backup and recovery testing | You can keep operating and recover client data if systems are disrupted. |
| Logs and monitoring | You have evidence that activity is being tracked and suspicious behavior can be investigated. |
Being secure matters. Being able to show how you are secure is what turns security into due diligence.
Cybersecurity Is Not (Just) an IT Project
One of the biggest mistakes you can make is treating cybersecurity compliance as something that belongs entirely to IT.
IT matters, of course. The tools need to work. Systems need to be patched. Access needs to be controlled. Backups need to be reliable.
But compliance is broader than that. It is also operational. It is how files are exchanged, staff are trained, vendors are selected. It’s how access is removed when someone leaves, how client data is stored, how incidents are escalated and how leadership knows the program is actually being followed.
That makes cybersecurity compliance a leadership issue. It affects client trust, insurance readiness, business continuity, reputation, and your ability to defend the care you took.
A practical checklist firms can act on
Know where client data lives, including tax software, email, portals, desktops, backups, archived folders, and cloud storage.
- Make sure the WISP exists, is current, and matches real firm operations.
- Base the security program on a risk assessment and reassess risk periodically, including after material threats and before major workflow or vendor changes.
- Use MFA for email, tax systems, cloud storage, remote access, admin tools, and any system touching client data.
- Restrict access by role and remove access quickly when staff leave or change roles.
- Use secure portals or controlled file-sharing workflows instead of unsecured email attachments.
- Train staff regularly and keep evidence that training happened.
- For vendors that handle client data, make sure to select vendors capable of maintaining appropriate safeguards, require safeguards by contract, including SOC reports and breach-support obligations where available, and periodically assess providers based on risk.
- Test backups and recovery before tax season, not during a crisis.
- Where required, create an incident-response plan that addresses remediation, documentation, and post-event review, with named owners, communication steps, and notification decision points.
Compliance Is How Firms Prove They Deserve Client Trust
Accounting firms do not need to become cybersecurity companies.
But you do need to act like a careful custodian of the sensitive information that powers your practice.
That means having the right controls, documenting the right evidence, training the right people, and governing the right vendors.
When you get this right, you will be better prepared for regulators, insurers, clients, and courts. More importantly, you will be better prepared to protect the trust your practice is built on.
At the end of the day, compliance is not really about satisfying a regulator.
It is about protecting the trust your business is built on.
The right cybersecurity and cloud partner can help you protect client data, simplify compliance evidence, and reduce the operational burden on your internal teams.
Book a free 20-minute consultation to how to strengthen your firm’s security and build your compliance readiness, starting today.