September 2026 · 7 min read
Cybersecurity Basics Every Small Accounting Firm Should Have
Accounting firms hold exactly the kind of data identity thieves want most: Social Security numbers, bank account details, full financial pictures, all in one place. Small firms often assume they're too small to be a target, but that assumption is backwards. Small firms are frequently targeted precisely because they tend to have weaker security than a larger firm with a dedicated IT team. Here's what actually matters, without the scare tactics.
The IRS requirement most small firms don't know exists
Any tax preparer is legally required under the FTC Safeguards Rule to have a Written Information Security Plan, usually called a WISP, on file. This isn't optional guidance, it's a requirement, and the IRS has been increasingly clear that firms without one are out of compliance. A WISP is a written document covering who's responsible for your firm's data security, what safeguards are in place, and how you'd respond to a breach. The IRS publishes a sample WISP template specifically so small firms without an IT department can build one without starting from scratch.
If your firm doesn't have one, this is worth treating as an actual to-do, not a someday item. It's one of the more commonly overlooked compliance gaps at small firms, and it's also one of the more straightforward to fix.
Multi-factor authentication, the single highest-value fix
If a firm does exactly one thing from this list, this is it. Multi-factor authentication (requiring a second verification step, like a code sent to a phone, beyond just a password) closes off the vast majority of account-takeover attempts, since a stolen password alone isn't enough to get in. Turn it on for email, your accounting software, your practice management tool, and your bank accounts, in that order of priority. Most of these platforms have had this built in for years. Turning it on takes minutes per account and meaningfully changes your actual risk.
Where client data actually leaks
The biggest real-world risk at small firms usually isn't a sophisticated hacking attempt. It's plain email. Sending a client's tax return, W-2, or bank statement as an unencrypted email attachment is common practice at a lot of small firms, and it's genuinely risky: email can be intercepted, forwarded to the wrong person, or sit in an inbox that later gets compromised. A client-facing portal with secure document upload and download closes this gap directly, since files move through an authenticated system instead of an open email thread.
Phishing: the thing that actually gets firms breached
Most real breaches at small firms start with a convincing phishing email, not a technical exploit. A message that looks like it's from a client, a bank, or even the IRS, asking someone to click a link or open an attachment. The most effective defense isn't a piece of software, it's a habit: before clicking a link or opening an attachment in an unexpected email, verify it through a separate channel, a quick call or text to the sender, especially for anything involving a wire transfer, a password reset, or a request to change payment details.
The basic checklist
- A Written Information Security Plan (WISP) on file, using the IRS sample template as a starting point if you don't have one.
- Multi-factor authentication turned on for email, accounting software, and practice management tools.
- Client documents moving through a secure portal, not unencrypted email attachments.
- A clear internal habit of verifying unexpected requests (wire changes, password resets) through a second channel before acting.
- Regular software updates, since a large share of real-world breaches exploit known vulnerabilities in software that simply hasn't been updated.
- A basic data backup routine, so a ransomware incident doesn't mean permanently losing client records.
The honest scope of this
None of this makes a firm unbreachable, and anyone promising that is overselling. What it does is close off the overwhelming majority of real-world attack methods that actually hit small firms, which tend to be opportunistic (a phishing email, a reused password, an unencrypted attachment) rather than sophisticated. Getting these basics genuinely in place is a much bigger risk reduction than most firms assume, and most of it costs nothing but time.
Documents moving through unencrypted email is one of the biggest gaps small firms have: FirmLync's client portal keeps every document request, upload, and e-signature inside a secure, authenticated system, not an open inbox.
Start your free trial