Pumpkin
    Cybersecurity Essentials for Accounting Firms
    Security

    Cybersecurity Essentials for Accounting Firms

    By Aaron WatersJuly 28, 2026Updated August 15, 20266 min read

    Cybersecurity for accounting firms starts with an uncomfortable fact. Your firm is a better target than a bank. A bank keeps money behind layered defenses and a full-time security team. You keep Social Security numbers, prior-year returns, bank details, and e-file credentials behind whatever the IT budget allowed, and attackers have done that math. The essentials aren't exotic: strong logins, filtered email, tested backups, patched machines, controlled access, and a written plan for the bad day. Six things. Most firms have two and assume they have five.

    Let's walk the list in the order it pays off, with a detour through what happens when it doesn't get done.

    Why accountants are worth robbing

    The data on your server is only half the attraction. The other half is what that data reaches. A stolen return sells once. A stolen e-file credential lets someone file fraudulent returns that look legitimate all season. And one compromised firm login can touch client bank feeds, payroll platforms, and tax software in a single afternoon. Break into a firm of eight people and you've potentially exposed four hundred households. That ratio is the whole business model.

    It's also why the attacks cluster in the spring. Phishing aimed at preparers spikes during filing season because that's when your inbox is loudest, your staff is most tired, and a fake "client document" blends into fifty real ones. The attackers read your calendar. They plan around it more carefully than most firms do.

    The breach that arrived right on schedule

    The Lynx ransomware gang claimed a breach of CSA Tax & Advisory, a Massachusetts accounting firm, and posted samples on its dark-web leak site as proof. Social Security numbers, tax returns, client records. The exact inventory you'd expect a tax practice to hold, offered up to anyone browsing. And the timing was the tell: weeks before filing season, when the firm would be most desperate to get its systems back and least able to stop and rebuild. That wasn't luck. Ransomware crews schedule around their victims' calendars the way you schedule around April 15th.

    Here's the part worth sitting with. An incident like that doesn't require some sophisticated, unstoppable technique. It requires one working way in, and a network where one way in was enough. The firms that ride these things out tend to be the ones that went looking for their own weak points first, often during an unglamorous technology audit in the off season, when there was still time to fix what turned up. The firms that end up in the news found out what was broken from a leak site.

    Start with the logins

    Multi-factor authentication on everything that touches client data. Email, tax software, the client portal, remote desktop, cloud storage. If a system supports it, turn it on, and don't grant exceptions for partners who find it annoying. It's the cheapest large reduction in risk available to a small firm, and insurers now treat it as table stakes.

    It's also a floor, not a finish line. Attackers have learned to tire people into approving prompts and to build convincing proxy login pages, which is why MFA alone won't save you from someone targeting your firm specifically. Turn it on anyway. Then keep going.

    Email is the front door

    Most small-firm breaches start in the inbox. Basic spam filtering catches the junk, and it does nothing about the carefully written message from "a client" with an attachment named after this year's forms. You want filtering that analyzes links, opens attachments in a sandbox before your people can, and flags senders pretending to be someone your team knows.

    You also want your staff rehearsed on what February phishing actually looks like, because some percentage will always get through the filter. We wrote up the whole two-headed problem in our piece on phishing and ransomware protection.

    Backups you've actually restored

    Ransomware turns your file server into a brick and offers to sell it back to you. The only answer that doesn't involve negotiating with criminals is a clean backup, stored separately from your network with separate credentials, and tested by restoring real files on a schedule. A backup you've never restored is a theory. Test it in the off season, time how long a full restore takes, and ask whether that number would survive March.

    The unglamorous pair

    Patching and endpoint protection. Nobody brings either up at a partner meeting, and together they stop an enormous share of what actually hits small firms. Turn on automatic updates wherever the software allows it, and get critical patches applied within days, not quarters. Then replace bare antivirus with endpoint detection and response, the category of tool that watches how a machine behaves and isolates it the moment it starts acting like it belongs to someone else.

    Who can open what

    Your seasonal preparer doesn't need the full client archive. Your receptionist doesn't need the document management system. Give each person the access their job requires and nothing extra, review the list quarterly, and shut off accounts the day someone leaves. The day. Old accounts with live credentials are how quiet breaches happen months after the goodbye cake.

    People, in February

    Quarterly training beats the annual seminar everyone sleeps through. Keep it short, keep it specific to your world (fake IRS notices, spoofed client emails, wire change requests), and run simulated phishing so reflexes get tested when nothing is at stake. One rule matters more than the rest: make it safe to report a suspected click. A person who hides a mistake hands the attacker a head start measured in weeks.

    The plan you write in July

    When something gets through anyway, the difference between a bad week and a firm-ending event is whether anyone knows what to do in the first hour. Who unplugs what and who calls the insurer. Who talks to clients, and who absolutely doesn't. That's a breach response plan, it fits on a few pages, and July is the right time to write it, because February is the likely time to need it.

    The IRS already assigned this homework

    None of the above is optional for a tax practice, and it hasn't been for years. IRS Publication 4557 lays out data security expectations for preparers, including a written information security plan, and the PTIN renewal now asks you to affirm you have one. Plenty of firms discover the requirement the first time an insurer or a large client asks to see the document. If that's where you are, our IRS Publication 4557 compliance service exists for exactly that conversation.

    Where to start if you're behind

    Don't form a committee. Turn on MFA everywhere this week. Confirm your backup actually restores. Book the first training. Write the one-page plan. Then work through the rest at a pace that survives busy season.

    The broader picture, including the law-firm angle, insurance requirements, and the compliance side, lives in our cybersecurity guide for firms. Start anywhere on the list. Just start before the spring does.