Why stronger portal security, identity controls, staff habits, and AI guardrails matter for protecting financial data year-round.

Key Takeaways:
- What cybersecurity risks do accounting firms face?
- How can CPA firms protect client data?
- Are AI tools safe for accounting workflows?
If a client-data request looked normal but arrived through the wrong channel today, would everyone on your team know how to verify it?
We may be well past tax season, but adversaries haven’t gone on holiday. Cybersecurity for accounting firms remains a top priority when handling Social Security numbers, payroll records, financial statements, banking details, tax documents, and business records.
“Every tax professional in the United States (whether a member of a major accounting firm or an owner of a one-person storefront) is a potential target for highly sophisticated, well-funded and technologically adept cybercriminals around the world,” says the Internal Revenue Service (IRS), reminding tax professionals to stay vigilant against new and ongoing threats.
How can you stay ahead of adversaries?
The key is implementing the right controls along with clear rules for how people authenticate, share files, use AI, approve requests, and escalate anything unusual.
Let’s talk about it!
What Cybersecurity Risks Do Accounting Firms Face?
To determine what strong cybersecurity for accounting firms actually looks like, you need to first understand current threats.
Adversaries mainly rely on phishing to get their hands on your treasure trove of data.
They may use “email, the phone, or other means to trick you into giving up computer passwords, e-Services passwords, to steal your EFINs or CAF numbers, or even to take remote control of your entire computer system,” warns the IRS
Once they get that initial access, lateral movement across your network can be easy when there are:
- Weak or reused passwords.
- Unsecured client portals or file-sharing links.
- Over-permissioned users and former employees.
- Unmanaged laptops and remote-work devices.
However, phishing isn’t the only risk.
Sometimes, accounting firms get exposed because they didn’t thoroughly vet third-party partners or stop to ask whether they were giving them too much access.
Other times it’s something simple like an employee entering sensitive financial or taxpayer information into AI tools without approval.
Strong cybersecurity for accounting firms helps you mitigate these risks, minimize downtime, filing disruption, and fraud exposure, meet regulatory obligations, and uphold client trust.
The next section covers essential practices to tighten CPA firm cybersecurity.
What’s my action item? List the three systems where your firm stores the most sensitive client information and confirm who can access each one.
Seven Proven Ways to Ensure Robust Cybersecurity for Accounting Firms
1. Level up Your Client Portal Security
Your client portal is only as secure as the accounts, permissions, sharing practices, and support procedures around it.
Here’s what to do about it:
- Require multifactor authentication (MFA) where available.
- Use role-based access rather than broad shared access. This is also known as the least-privilege principle.
- Review external sharing and expired links.
- Remove access promptly whenever roles change.
- Avoid sending sensitive files through ordinary email when a secure portal exists.
- Define how staff verifies unusual portal or document requests.
“We share every client document through a secure client portal rather than regular email, so sensitive financial information never sits in an inbox. That single habit—keeping client data out of casual channels like unsecured email—closes off one of the most common ways it gets exposed,” says Farshid Kaba, founder of NRK Accounting.
That said, avoid introducing rigid controls that get in the way of how your team operates. Security improves when the safe workflow is also the easiest workflow.
What’s my action item? Review one active client portal today for MFA, stale users, external shares, and outdated permissions.
2. Strengthen Identity Controls Around Financial Data
Did you know that credential abuse was the hackers’ third-favorite way to get initial access, right behind exploitation of vulnerabilities and phishing, according to Verizon’s analysis of over 22,000 breaches between Nov 1, 2024, and Oct 31, 2025?
Here’s how to reduce the risk that a compromised account defeats an otherwise strong system.
- Ensure everyone uses hard-to-guess passwords, changes them regularly, and layers MFA on top for good measure.
- Keep in mind that hackers can sometimes hijack user sessions. Beyond MFA, ensure you have a system to continuously monitor and block fraudulent access attempts.
- Use least-privilege access to limit the damage hackers can inflict if they somehow manage to bypass your other controls.
- Review access regularly and promptly revoke it when no longer required, such as when an employee leaves.
What’s my action item? Confirm that every cloud system containing client financial data uses MFA and has a named owner responsible for reviewing access.
3. Put Clear Guardrails Around AI Tools
Are AI tools safe for accounting workflows?
It depends on what data employees enter, how the AI tool provider handles that data, what settings are enabled, and your overall AI governance policy.
Here’s how to boost organizational productivity with AI and NOT sacrifice cybersecurity for accountants:
- Decide which AI tools can (and can’t be used) in your organization and establish a simple review process for adopting new ones.
- Clarify acceptable use cases.
- Mandate that client tax records, financial information, credentials, and other confidential data should never go into AI tools. When it’s absolutely necessary to use AI, then the data should be anonymized. Remove names, account numbers, and other identifying details.
- Finally, AI-generated analysis, summaries, emails, or other work should pass through human review before reaching a client.
NIST’s Generative AI Profile provides a useful framework for thinking about AI-related privacy, security, data management, and governance risks. Whenever in doubt, use it as your reference point.
What’s my action item? Write one sentence employees can follow: “Client data may only enter AI tools that have been formally approved for that type of information.”
4. Train Staff for New-Client, Payment, and Impersonation Scams
Another way to strengthen cybersecurity for accountants is with advanced phishing awareness.
Today, it’s not enough to teach your team to spot obvious giveaways like a strange email address, a suspicious link, or bad spelling.
So, what are the prevailing real-world phishing tactics targeting tax professionals?
- “New client” Schemes: A hacker sends an email asking your accounting firm to review a tax return, with an attached document that delivers malware or steals credentials when opened.
- Tax Software Provider Impersonation Scams: This is where a hacker posing as a tax software company representative requests your EFIN or CAF number, then uses it to access client data.
- Unexpected Password-Reset Messages: If someone receives an email or text reading, “Reset Password” when they didn’t request one, it’s likely a hacker on the other end.
- Urgent Money Transfers: Here, a hacker may pose as you or the company’s CFO and ask for a “confidential or secret transaction.” This attack can be particularly damaging, as demonstrated by the 2024 incident where fraudsters used deep-fake technology to trick a finance employee into transferring $25 million during a live video call.
“The most critical threat is the payment-change request. Our standing control is that no bank-detail change is ever actioned based on the channel through which the request arrived,” says Jamie Corby, CXO at Corby & Associates LLC.
Teach your team to stop, verify requests through trusted channels, and escalate anything unusual before acting. Also ensure you have a multi-person sign-off for any large financial transactions.
What’s my action item? Choose one realistic scam scenario and walk the team through exactly how it should be verified and escalated.
5. Manage Endpoints and Remote Work Consistently
Cybersecurity for accountants should also include robust endpoint management because client-data policies can break down when employees work from unmanaged or inconsistently configured devices.
- Does your team work from managed laptops and workstations?
- Is the hardware encrypted as a safety measure against theft?
- Do you have the right endpoint protection software installed?
- Are you delivering regular security updates and patches to the devices?
- Have you blocked all unapproved software?
- Is a tested backup, recovery, and incident response strategy in place?
- Do employees working from outside the office have secure remote access?
- Is there a centralized device inventory?
If you answered NO to any of the above, it’s a gap in your endpoint management strategy. Close it.
Remember, while security is everyone’s responsibility, employees should not have to invent their own security workarounds to get work done.
What’s my action item? Identify any device used for client work that is not centrally managed, patched, encrypted, and inventoried.
6. Review Vendors and Third-Party Access
Verizon’s analysis also reveals there’s third-party involvement in 48% of breaches, reinforcing the need to tighten the supply chain.
Right now, you likely rely on tax software, payroll platforms, cloud storage, portals, bookkeeping systems, and outside I.T. providers. Each one can affect how client information is protected.
Per the FTC Safeguard’s rule, cybersecurity for accountants must include regular vendor risk assessment of when their systems are linked to client data.
When’s the last time you checked whether everyone in your technology ecosystem had the right controls? Now might be the time to do it.
What’s my action item? Create a short list of vendors that can access client data and assign one person to own the security review for each.
7. Build a Written Security Plan and Incident Routine
The FTC, IRS, and some state regulators now require a Written Information Security Plan (WISP) describing your real environment as part of cybersecurity for accounting firms.
A WISP is essentially a formal document that outlines the administrative, technical, and physical safeguards the firm uses to protect sensitive client financial and personal data.
The IRS, for instance, recommends that your WISP addresses employee management, information systems, risk assessment, safeguards, monitoring, testing, and service providers.
It should explain:
- Who coordinates the security program.
- What data and systems are most sensitive.
- How risks are assessed.
- How controls are monitored and tested.
- Who is contacted after suspected data theft.
- How client and regulatory response responsibilities are escalated.
Are you covered?
Here’s the IRS’s WISP guidance if you want to dig in.
What’s my action item? Locate the firm’s current written security plan and confirm whether it reflects the tools, vendors, and AI use actually in place today.
How Managed I.T. Creates a Repeatable Security Rhythm
A secure accounting firm is not one where employees are constantly afraid of making a mistake. It is one where the expected workflow is clear, supported, and easy to follow.
Managed I.T. services can make that a reality by helping you standardize identity management, endpoint security, patching, monitoring, backups, onboarding and offboarding, vendor coordination, and evidence that reviews actually occurred. Learn more.
What’s my action item? Identify one security responsibility that currently depends on someone remembering to do it manually and turn it into a scheduled, owned process.
Frequently Asked Questions About Cybersecurity for Accounting Firms
1. What cybersecurity risks do accounting firms face?
The most common cybersecurity risks accounting firms face are phishing, credential theft, client-data exposure, insecure sharing, endpoint gaps, vendor risk, and ungoverned AI use.
2. How can CPA firms protect client data?
CPA firms can protect client data by using layered controls across identities, portals, devices, employee training, secure sharing, backups, vendor oversight, and incident response.
3. Are AI tools safe for accounting workflows?
AI tools can be appropriate for approved use cases when an accounting firm understands the provider, controls the data entered, and applies human oversight.
4. Do accounting firms need a written information security plan?
Yes. The FTC, IRS, and some state regulators require professional tax preparers to have a written information security plan or WISP.
5. Why is a client portal safer than email?
A client portal is safer than email as it provides stronger authentication, access control, logging, and controlled sharing when properly configured and consistently managed.
Security Is a Management System, Not a Tax-Season Project
Cybersecurity for accounting firms is a year-round concern, not just something to plan for during tax season.
Right now, is your security an annual checkbox or an everyday operating habit?
To protect taxpayer data, you must implement a written security plan that combines client portal security, identity and access management, AI governance, endpoint management, and vendor oversight.
What’s my action item? Schedule a 30-minute leadership review of client-data workflows and choose the single highest-risk gap to address first.
Review Your Accounting Firm’s Security Controls With Attentus
Are you fully covered?
Contact Attentus to review your client portal, identity and access controls, endpoint management, employee workflows, AI use, vendor access, and incident readiness.