Industries
Under the Gramm-Leach-Bliley Act, tax and accounting practices count as financial institutions regardless of size, which puts them under the FTC Safeguards Rule. The Rule does not ask for good intentions. It asks for a written plan, a named person responsible for it, specific controls, and the ability to show all three.
The failure modes here are seasonal and they are specific. A deadline that will not move is a different kind of pressure than most businesses face.
Nine elements, set out at 16 CFR 314.4. They apply to a two-person practice and a fifty-person firm alike; the Rule scales the implementation to your size, not the obligation.
The Rule names specific controls rather than leaving it to taste: multi-factor authentication for anyone accessing customer information, encryption in transit and at rest, access controls that get reviewed rather than set once, and logging of authorised user activity so unauthorised access can be detected. It also requires secure disposal of customer information no later than two years after its last use, and notification to the FTC within thirty days where a security event affects 500 or more consumers.
The written plan is the part firms most often skip. The IRS covers it in Publication 5708 and Publication 4557, and states the position without hedging: tax and accounting professionals are financial institutions under GLBA, and a written information security plan is a requirement of the Safeguards Rule.
This is the mapping most providers will not put in writing. Everything below is part of the standard monthly rate.
System and data inventory, vulnerability management, and quarterly technology planning, so “when did you last review this” has a date as its answer.
Multi-factor authentication and identity hardening, encryption, reviewed access controls, email security and quarantine, DNS and web content filtering, application allow-listing.
Managed detection and response running 24/7, independent of our support hours, plus patch and vulnerability management and dark web credential monitoring.
Security awareness training and simulated phishing campaigns, with results you can put in front of an examiner or an insurer.
Vendor management, and a provider you can actually point at when the Rule asks who is responsible for what.
Detection, containment and recovery with backup verification and restore testing behind it, and audit evidence collection so the written report is assembled rather than reconstructed.
The same published rates apply: $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month. A fully equipped seat is $199 all in. No minimum, no setup fee, no automatic annual escalator. The pricing page has the calculator and the full list, with no form in front of it.
We support firms across Northeast Ohio and the Greater Houston area, including co-managed arrangements alongside internal IT.
Yes. The Gramm-Leach-Bliley Act defines the term by the activity, not the size of the business, and the FTC lists tax preparation firms explicitly among the entities covered. IRS Publication 5708 states it directly: tax and accounting professionals are considered financial institutions regardless of size. A sole practitioner is in scope on the same terms as a fifty-person firm.
We supply the technical substance — what is deployed, how it is configured, who has access, what gets logged and how incidents are handled — and the evidence that it is actually running. The plan itself is adopted by the firm, because the Rule places that responsibility on you and a plan you have not read is not much of a plan. In practice most of the work is the part we hand you, and the IRS templates in Publication 5708 cover the rest.
The Rule does allow that role to sit with a service provider, with a senior employee of yours supervising. It is a specific engagement with named accountability rather than something bundled into a standard agreement, so it gets discussed and written down. Be cautious of any provider who implies they are already doing it without having agreed to it.
First response is under two hours during business hours, and threat detection runs 24/7 regardless. The more useful answer is what happens before season: quarterly planning exists partly so that the work which would take your systems down gets scheduled in the quiet months rather than discovered in March. If a recovery is needed, restores are tested rather than assumed.
Where a security event involves unauthorised access to unencrypted information of at least 500 consumers, the Safeguards Rule requires notification to the FTC as soon as possible and no later than thirty days after discovery. There are separate IRS and state obligations, and your own professional and insurance obligations on top. We handle containment, recovery and the technical account of what was reachable; the notifications themselves are made by the firm, usually with counsel.
It depends on the activities, not the job title, and the line is genuinely fact-specific. Rather than guess on a web page: tell us what your practice actually does on the first call, and where it is unclear that is a question for your counsel rather than for us. What does not change is that you hold client financial data, which attracts the same criminals either way.
We can tell you precisely what is deployed and show the evidence behind each answer, which is the part firms find hardest. The answers go in over your signature, since the insurer is contracting with you. This exercise is also where gaps tend to surface, and an application is a far better place to find them than a claim.
We plan for a clean handover. We never withhold data or client intellectual property, and we work with your incoming provider to make the transition orderly. Onboarding in the other direction typically takes about a week, with terms of twelve, twenty-four or thirty-six months and no setup fee.
Call (440) 991-9980 or book a thirty minute call. We will walk the list with you and say which ones you already meet, which need work, and which are cheaper to fix than you expect.
See also: every industry we serve, our written answers, and the free cybersecurity score.