You run an accounting or tax firm. You hold Social Security numbers, bank details, and returns for hundreds or thousands of clients. A vendor emailed you about the FTC Safeguards Rule, or your E&O carrier asked whether you have a written plan, or the IRS PTIN renewal asked if you have a data security plan, and now your inbox is full of companies promising to make compliance painless. Every one of them sounds confident. Every proposal has a number on it. And you're nodding along to words like "WISP," "MFA," "encryption at rest," and "Qualified Individual," hoping the person across the table actually understands what they mean for a firm that has to close during busy season and keep clients' trust the rest of the year.
Here's the thing most vendors won't lead with: the FTC Safeguards Rule already applies to you. Under the Gramm-Leach-Bliley Act, the FTC treats tax preparers and accounting firms as "financial institutions," and the amended Safeguards Rule (16 CFR Part 314), with its major provisions in force since June 2023, requires you to protect your clients' nonpublic personal information with a real, written security program. There is no exemption based on how small your firm is. Firms with fewer than 5,000 clients get a lighter path on exactly one item, the annual written report, but every core control, MFA, encryption, risk assessment, incident response, still applies in full.
And the stakes are not theoretical. FTC civil penalties run into the tens of thousands of dollars per violation, adjusted for inflation each year. The IRS can revoke your PTIN if you don't have a data security plan. And since the FTC finalized its breach-notification requirement, a breach affecting 500 or more clients has to be reported to the FTC within 30 days, and that notice becomes public.
So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what the Safeguards Rule actually asks for, in plain English. Then we give you a ten-minute exercise to map where your clients' data lives. Then the ten questions we'd ask if we were sitting in your chair, each with what a strong answer sounds like, what a weak one sounds like, and a real requirement to hold the vendor to.
Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague. How a vendor handles these ten tells you more than any proposal ever will.
One note on us. We run managed IT and security for firms that handle sensitive data, and we help build and maintain the written security program the Safeguards Rule requires: the risk assessment, the technical controls, the vendor oversight, the incident response plan, and the documentation that proves it. We deliver that on one agreement, with the labor included rather than billed by the hour. We've built our own PCs and servers on our own line in Wichita since 1997.
What it is. The FTC Safeguards Rule (16 CFR Part 314) implements the security requirements of the Gramm-Leach-Bliley Act for the "financial institutions" the FTC regulates. It was amended in 2021, with the major new provisions taking effect in June 2023. It's a federal rule with enforcement behind it.
Why it applies to you. The FTC's definition of "financial institution" includes tax preparers, accountants and CPA firms, financial advisors, and similar businesses that handle consumers' financial information. If you prepare returns or handle client financial data, you're in scope. There's no small-firm carve-out from the core requirements.
What it requires. At its heart, the Rule requires a written information security program, a WISP, with administrative, technical, and physical safeguards. Underneath that, the Rule names specific elements: designate a Qualified Individual, perform a written risk assessment, put access controls in place, encrypt customer information at rest and in transit, require multi-factor authentication for anyone accessing that information, oversee your service providers, keep an incident response plan, train your people, and periodically test and monitor your safeguards.
The one size-based break. Firms that maintain information on fewer than 5,000 consumers are exempt from a short list of items, most notably the written annual report. The core controls, MFA, encryption, the WISP itself, and incident response planning, still apply in full. Don't let a vendor tell you "you're small, so you don't have to worry about it."
Breach notification. If you experience a security event affecting 500 or more consumers, you must notify the FTC within 30 days, and that notification becomes part of the public record.
The IRS overlap. The IRS requires tax professionals to have a written data security plan and points to the FTC Safeguards Rule for the standard. IRS Publication 4557 lays out the safeguards, and PTIN renewal asks whether you have a plan. For a tax firm, the WISP is tied to your ability to keep preparing returns.
Where CybertronIT sits. We help you build and run the technical and administrative side of the program, the MFA, the encryption, the monitoring, the vendor oversight, the incident response, and we help you write and maintain the WISP. We're not a law firm and not your auditor; the Qualified Individual and the ultimate responsibility stay with your firm.
Here are the ten questions, with why each one matters for a real accounting firm. Ask all ten, and watch the reactions as closely as the answers.
The Rule applies to CPA firms and tax preparers with no small-firm exemption from the core controls, and the IRS ties a written data security plan to your PTIN. A vendor who can't explain that you're a "financial institution" under GLBA is selling you a product, not compliance.
The Rule requires you to designate one person to oversee the program, and that accountability stays with your firm. A vendor who says they'll simply "be your Qualified Individual" and take it all off your plate is glossing over where the buck stops.
Client data doesn't sit in one place: the tax software, email, the client portal, workpapers, a staffer's laptop, the backup, the printer, the paper file. A vendor who scopes only "the server" has missed the laptops, the portal, and the paper.
MFA and encryption both at rest and in transit are non-negotiable, and "everything that touches NPI" includes email and file transfer, not just the file server. A weak vendor says "we use strong security" and can't point to the specific control.
The Rule requires a written risk assessment, kept up to date, not a one-time checkbox. A vendor who treats it as a form you sign once is leaving out a named requirement an examiner asks for first.
The WISP has to describe your real safeguards, vendors, and data flow. A template WISP describes a generic firm that doesn't exist, and anyone reading it against your office spots the difference fast.
The Rule holds you responsible for the vendors who touch client data, and your IT provider is one of them. A vendor who never addresses that they themselves are in scope has created a blind spot that becomes yours.
The Rule requires a written incident response plan, and a security event affecting 500 or more clients has to be reported to the FTC within 30 days, publicly. A vendor who treats a breach as an afterthought is the one you don't want when it happens.
Compliant email, MFA, encryption, monitoring, and testing carry real per-user cost. Guessing 6 users when the real number is 15, seasonal preparers included, isn't a rounding error. Make the vendor price your seats, your way.
Proof is now the standard. You need documentation that matches reality: the WISP, the risk assessment, evidence of MFA and encryption, training records, the incident response plan. A vendor who leaves the documentation to you has left you holding the part that gets examined.
Everything above is the map. The full checklist is the tool you bring into the room. The free PDF is built to print and carry. It adds a ten-minute exercise to map your own exposure before you take a single sales call, plus where CybertronIT fits and how to score every vendor you talk to. Give us an email and it is yours.
Comments