Industries

Your firm is a financial institution. The FTC says so.

Under the Gramm-Leach-Bliley Act, tax and accounting practices count as financial institutions regardless of size, which puts them under the FTC Safeguards Rule. The Rule does not ask for good intentions. It asks for a written plan, a named person responsible for it, specific controls, and the ability to show all three.

9
Elements the Rule requires
30 days
To notify the FTC of a breach
24/7
Threat monitoring
$0
Trip charges

What actually goes wrong in an accounting firm

The failure modes here are seasonal and they are specific. A deadline that will not move is a different kind of pressure than most businesses face.

During filing season

  • Tax software unreachable in the last week before a deadline, when there is no slack left in the calendar
  • A server holding seven years of returns encrypted by ransomware
  • Staff working long hours, tired, clicking the thing they would not click in July

All year round

  • Business email compromise during a client funds transfer, with altered instructions
  • A phishing click exposing client Social Security numbers, W-2s and bank details in one move
  • Portal credentials for sale on a criminal marketplace months before anyone notices

What the Safeguards Rule actually requires

Nine elements, set out at 16 CFR 314.4. They apply to a two-person practice and a fifty-person firm alike; the Rule scales the implementation to your size, not the obligation.

The programme

  • Designate a Qualified Individual to run the security programme
  • Carry out a written risk assessment
  • Keep the programme current as things change
  • Report to your board or senior leadership annually, in writing

The controls

  • Design and implement safeguards for the risks you identified
  • Monitor and test their effectiveness
  • Train your staff
  • Oversee your service providers, in the contract and afterwards
  • Maintain a written incident response plan

The Rule names specific controls rather than leaving it to taste: multi-factor authentication for anyone accessing customer information, encryption in transit and at rest, access controls that get reviewed rather than set once, and logging of authorised user activity so unauthorised access can be detected. It also requires secure disposal of customer information no later than two years after its last use, and notification to the FTC within thirty days where a security event affects 500 or more consumers.

The written plan is the part firms most often skip. The IRS covers it in Publication 5708 and Publication 4557, and states the position without hedging: tax and accounting professionals are financial institutions under GLBA, and a written information security plan is a requirement of the Safeguards Rule.

The nine elements, and what we operate against each

This is the mapping most providers will not put in writing. Everything below is part of the standard monthly rate.

Risk assessment & keeping current

System and data inventory, vulnerability management, and quarterly technology planning, so “when did you last review this” has a date as its answer.

Safeguards

Multi-factor authentication and identity hardening, encryption, reviewed access controls, email security and quarantine, DNS and web content filtering, application allow-listing.

Monitoring & testing

Managed detection and response running 24/7, independent of our support hours, plus patch and vulnerability management and dark web credential monitoring.

Staff training

Security awareness training and simulated phishing campaigns, with results you can put in front of an examiner or an insurer.

Service provider oversight

Vendor management, and a provider you can actually point at when the Rule asks who is responsible for what.

Incident response & reporting

Detection, containment and recovery with backup verification and restore testing behind it, and audit evidence collection so the written report is assembled rather than reconstructed.

Where our responsibility stops

  • We supply the technical substance of your written plan and the evidence that the controls are running. Adopting the plan, and standing behind it, is the firm’s act.
  • The Qualified Individual is a role the Rule lets you assign to a service provider, but it is a specific engagement with named accountability, not something that comes bundled. If you want us in that seat, it gets agreed and written down.
  • We do not sell attestations, certifications or seals. There is no FTC certificate to buy, and a provider offering one is telling you something.
  • Your tax software vendor keeps its own support obligations. We manage the environment it runs in and coordinate with them.

What it costs

The same published rates apply: $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month. A fully equipped seat is $199 all in. No minimum, no setup fee, no automatic annual escalator. The pricing page has the calculator and the full list, with no form in front of it.

We support firms across Northeast Ohio and the Greater Houston area, including co-managed arrangements alongside internal IT.

Questions accounting firms ask us

Yes. The Gramm-Leach-Bliley Act defines the term by the activity, not the size of the business, and the FTC lists tax preparation firms explicitly among the entities covered. IRS Publication 5708 states it directly: tax and accounting professionals are considered financial institutions regardless of size. A sole practitioner is in scope on the same terms as a fifty-person firm.

We supply the technical substance — what is deployed, how it is configured, who has access, what gets logged and how incidents are handled — and the evidence that it is actually running. The plan itself is adopted by the firm, because the Rule places that responsibility on you and a plan you have not read is not much of a plan. In practice most of the work is the part we hand you, and the IRS templates in Publication 5708 cover the rest.

The Rule does allow that role to sit with a service provider, with a senior employee of yours supervising. It is a specific engagement with named accountability rather than something bundled into a standard agreement, so it gets discussed and written down. Be cautious of any provider who implies they are already doing it without having agreed to it.

First response is under two hours during business hours, and threat detection runs 24/7 regardless. The more useful answer is what happens before season: quarterly planning exists partly so that the work which would take your systems down gets scheduled in the quiet months rather than discovered in March. If a recovery is needed, restores are tested rather than assumed.

Where a security event involves unauthorised access to unencrypted information of at least 500 consumers, the Safeguards Rule requires notification to the FTC as soon as possible and no later than thirty days after discovery. There are separate IRS and state obligations, and your own professional and insurance obligations on top. We handle containment, recovery and the technical account of what was reachable; the notifications themselves are made by the firm, usually with counsel.

It depends on the activities, not the job title, and the line is genuinely fact-specific. Rather than guess on a web page: tell us what your practice actually does on the first call, and where it is unclear that is a question for your counsel rather than for us. What does not change is that you hold client financial data, which attracts the same criminals either way.

We can tell you precisely what is deployed and show the evidence behind each answer, which is the part firms find hardest. The answers go in over your signature, since the insurer is contracting with you. This exercise is also where gaps tend to surface, and an application is a far better place to find them than a claim.

We plan for a clean handover. We never withhold data or client intellectual property, and we work with your incoming provider to make the transition orderly. Onboarding in the other direction typically takes about a week, with terms of twelve, twenty-four or thirty-six months and no setup fee.

Not sure where your firm stands against the nine elements?

Call (440) 991-9980 or book a thirty minute call. We will walk the list with you and say which ones you already meet, which need work, and which are cheaper to fix than you expect.

See also: every industry we serve, our written answers, and the free cybersecurity score.