CybertronIT Blog

Cybertron Blog

Cybertron has been serving the Wichita area since 1997, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

10 Questions Every CPA Firm Should Ask Before Buying an FTC Safeguards Solution

Before you read

You run an accounting or tax firm. You hold Social Security numbers, bank details, and returns for hundreds or thousands of clients. A vendor emailed you about the FTC Safeguards Rule, or your E&O carrier asked whether you have a written plan, or the IRS PTIN renewal asked if you have a data security plan, and now your inbox is full of companies promising to make compliance painless. Every one of them sounds confident. Every proposal has a number on it. And you're nodding along to words like "WISP," "MFA," "encryption at rest," and "Qualified Individual," hoping the person across the table actually understands what they mean for a firm that has to close during busy season and keep clients' trust the rest of the year.

Here's the thing most vendors won't lead with: the FTC Safeguards Rule already applies to you. Under the Gramm-Leach-Bliley Act, the FTC treats tax preparers and accounting firms as "financial institutions," and the amended Safeguards Rule (16 CFR Part 314), with its major provisions in force since June 2023, requires you to protect your clients' nonpublic personal information with a real, written security program. There is no exemption based on how small your firm is. Firms with fewer than 5,000 clients get a lighter path on exactly one item, the annual written report, but every core control, MFA, encryption, risk assessment, incident response, still applies in full.

And the stakes are not theoretical. FTC civil penalties run into the tens of thousands of dollars per violation, adjusted for inflation each year. The IRS can revoke your PTIN if you don't have a data security plan. And since the FTC finalized its breach-notification requirement, a breach affecting 500 or more clients has to be reported to the FTC within 30 days, and that notice becomes public.

So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what the Safeguards Rule actually asks for, in plain English. Then we give you a ten-minute exercise to map where your clients' data lives. Then the ten questions we'd ask if we were sitting in your chair, each with what a strong answer sounds like, what a weak one sounds like, and a real requirement to hold the vendor to.

Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague. How a vendor handles these ten tells you more than any proposal ever will.

One note on us. We run managed IT and security for firms that handle sensitive data, and we help build and maintain the written security program the Safeguards Rule requires: the risk assessment, the technical controls, the vendor oversight, the incident response plan, and the documentation that proves it. We deliver that on one agreement, with the labor included rather than billed by the hour. We've built our own PCs and servers on our own line in Wichita since 1997.


The FTC Safeguards Rule in plain English

What it is. The FTC Safeguards Rule (16 CFR Part 314) implements the security requirements of the Gramm-Leach-Bliley Act for the "financial institutions" the FTC regulates. It was amended in 2021, with the major new provisions taking effect in June 2023. It's a federal rule with enforcement behind it.

Why it applies to you. The FTC's definition of "financial institution" includes tax preparers, accountants and CPA firms, financial advisors, and similar businesses that handle consumers' financial information. If you prepare returns or handle client financial data, you're in scope. There's no small-firm carve-out from the core requirements.

What it requires. At its heart, the Rule requires a written information security program, a WISP, with administrative, technical, and physical safeguards. Underneath that, the Rule names specific elements: designate a Qualified Individual, perform a written risk assessment, put access controls in place, encrypt customer information at rest and in transit, require multi-factor authentication for anyone accessing that information, oversee your service providers, keep an incident response plan, train your people, and periodically test and monitor your safeguards.

The one size-based break. Firms that maintain information on fewer than 5,000 consumers are exempt from a short list of items, most notably the written annual report. The core controls, MFA, encryption, the WISP itself, and incident response planning, still apply in full. Don't let a vendor tell you "you're small, so you don't have to worry about it."

Breach notification. If you experience a security event affecting 500 or more consumers, you must notify the FTC within 30 days, and that notification becomes part of the public record.

The IRS overlap. The IRS requires tax professionals to have a written data security plan and points to the FTC Safeguards Rule for the standard. IRS Publication 4557 lays out the safeguards, and PTIN renewal asks whether you have a plan. For a tax firm, the WISP is tied to your ability to keep preparing returns.

Where CybertronIT sits. We help you build and run the technical and administrative side of the program, the MFA, the encryption, the monitoring, the vendor oversight, the incident response, and we help you write and maintain the WISP. We're not a law firm and not your auditor; the Qualified Individual and the ultimate responsibility stay with your firm.


The jargon, decoded

  • NPI (Nonpublic Personal Information). Your clients' financial information that isn't public: SSNs, account numbers, income, tax returns. This is what the Rule tells you to protect.
  • GLBA (Gramm-Leach-Bliley Act). The federal law the Safeguards Rule enforces.
  • WISP (Written Information Security Program). The written master document describing your safeguards, risk assessment, training, vendor oversight, and incident response. A generic template with your name pasted in is not a WISP.
  • Qualified Individual. The single person the Rule requires you to designate to oversee your program. You can lean on a provider for the technical work, but the accountability stays with your firm.
  • Risk assessment. A written, current evaluation of the threats to your clients' information and how you're addressing them.
  • MFA (Multi-Factor Authentication). Requiring more than a password before someone can reach NPI. Non-negotiable under the Rule.
  • Encryption at rest and in transit. Protecting client data both where it's stored and where it moves. The Rule requires both.
  • Service provider oversight. The Rule holds you responsible for the vendors who touch client data, including your IT provider.
  • Incident response plan. The written plan for what you do when something goes wrong. The 500-consumer, 30-day FTC notification makes having it ready a necessity.
  • IRS Pub 4557 / WISP. IRS guidance requiring tax professionals to have a written data security plan, pointing to the FTC standard.

The 10 questions

Here are the ten questions, with why each one matters for a real accounting firm. Ask all ten, and watch the reactions as closely as the answers.

1. Which parts of the FTC Safeguards Rule actually apply to my firm, and what do they require right now?

The Rule applies to CPA firms and tax preparers with no small-firm exemption from the core controls, and the IRS ties a written data security plan to your PTIN. A vendor who can't explain that you're a "financial institution" under GLBA is selling you a product, not compliance.

2. Who is my Qualified Individual, and exactly where does your responsibility end and mine begin?

The Rule requires you to designate one person to oversee the program, and that accountability stays with your firm. A vendor who says they'll simply "be your Qualified Individual" and take it all off your plate is glossing over where the buck stops.

3. What counts as client NPI in my firm, and where does it actually live?

Client data doesn't sit in one place: the tax software, email, the client portal, workpapers, a staffer's laptop, the backup, the printer, the paper file. A vendor who scopes only "the server" has missed the laptops, the portal, and the paper.

4. Do you provide MFA and encryption at rest and in transit across everything that touches NPI, and can you prove it?

MFA and encryption both at rest and in transit are non-negotiable, and "everything that touches NPI" includes email and file transfer, not just the file server. A weak vendor says "we use strong security" and can't point to the specific control.

5. How do you handle the written risk assessment, and how do you keep it current?

The Rule requires a written risk assessment, kept up to date, not a one-time checkbox. A vendor who treats it as a form you sign once is leaving out a named requirement an examiner asks for first.

6. Who builds and maintains my WISP, and does it actually match how my firm operates?

The WISP has to describe your real safeguards, vendors, and data flow. A template WISP describes a generic firm that doesn't exist, and anyone reading it against your office spots the difference fast.

7. How do you handle service-provider oversight, including your own access to my clients' data?

The Rule holds you responsible for the vendors who touch client data, and your IT provider is one of them. A vendor who never addresses that they themselves are in scope has created a blind spot that becomes yours.

8. What is my incident response plan, and how do we meet the FTC's 500-client, 30-day breach notification?

The Rule requires a written incident response plan, and a security event affecting 500 or more clients has to be reported to the FTC within 30 days, publicly. A vendor who treats a breach as an afterthought is the one you don't want when it happens.

9. What will compliant infrastructure and monitoring actually cost me, per seat, in writing?

Compliant email, MFA, encryption, monitoring, and testing carry real per-user cost. Guessing 6 users when the real number is 15, seasonal preparers included, isn't a rounding error. Make the vendor price your seats, your way.

10. How do you make sure I can prove compliance to the FTC, the IRS, and my clients, not just claim it?

Proof is now the standard. You need documentation that matches reality: the WISP, the risk assessment, evidence of MFA and encryption, training records, the incident response plan. A vendor who leaves the documentation to you has left you holding the part that gets examined.


Red flags to listen for

  • "You're too small to worry about it." There's no small-firm exemption from the core controls.
  • Vague on MFA and encryption. They can't tell you exactly where MFA is enforced or that data is encrypted at rest and in transit, including email.
  • No risk assessment, no WISP. They never mention the written risk assessment or the WISP, or treat them as one-time forms.
  • The template WISP. A plan that describes a generic firm instead of yours.
  • "We'll be your Qualified Individual, don't worry about it." The designation and accountability stay with your firm.
  • The vendor blind spot. They never address that they themselves touch your clients' NPI and are in scope for your oversight.
  • No incident response, no breach clock. They have no plan for the 500-client, 30-day FTC notification.
  • Hidden per-seat cost. No straight per-user number, no clarity on whether testing and monitoring are included.

Get the full checklist (free)

Everything above is the map. The full checklist is the tool you bring into the room. The free PDF is built to print and carry. It adds a ten-minute exercise to map your own exposure before you take a single sales call, plus where CybertronIT fits and how to score every vendor you talk to. Give us an email and it is yours.

  • Company Name *
  • First Name *
  • Last Name *
  • Comments:
  • Yes, I'd like to subscribe to:
      10 Questions Every Medical Practice Should Ask Bef...
      10 Questions Every Defense Contractor Should Ask B...
      Comment for this post has been locked by admin.
       

      Comments

      Already Registered? Login Here
      No comments made yet. Be the first to submit a comment