Ditch Microsoft & Google Today!

Your WISP Says You Oversee Your Vendors. Do You?

Accounting and tax firm IT: encrypted email, secure client document exchange and the safeguards your WISP has to describe

Accounting Firm IT: The Short Answer

If you prepare tax returns for compensation, the FTC treats your firm as a financial institution. The Safeguards Rule names tax preparation firms explicitly, and it is not advisory. It requires a written information security programme, and IRS Publication 4557 is the tax-profession version of the same expectations.

The Rule asks for specific things: multi-factor authentication on systems holding customer information, encryption of that information both on your systems and in transit, a designated Qualified Individual running the programme, a written risk assessment, an incident response plan, and documented oversight of the service providers you rely on. Your IT vendor is not outside that obligation — they are one of the things it covers. This page is not legal or compliance advice; it describes what the published rules say.

Accounting firm IT and the nine FTC Safeguards Rule elements, showing which a hosting and email vendor affects and which remain the firm’s own responsibility
Accounting firm IT: which Safeguards Rule elements a vendor affects

What The Safeguards Rule Actually Requires

Multi-factor authentication, not optional

The Rule asks for at least two of three factors: something you know, something you have, something you are. The only way out is written approval from your Qualified Individual for equivalent controls, which means someone has to sign their name to that decision.

Encryption at rest and in transit

Customer information must be encrypted on your systems and while moving between them. Liberation Email includes end-to-end encryption on every plan plus AES-256 at rest, hosted in the United States on servers we own.

Documented vendor oversight

You must select providers capable of protecting the data, contract for it, monitor them, and periodically reassess. That is a paperwork obligation as much as a technical one, and it is the element most firms have nothing written down for.

A Qualified Individual can be a service provider rather than an employee — but a senior person at your firm has to supervise them, and the responsibility stays with your firm. We will not pretend otherwise to win the work.

What A Breach Costs A Tax Practice

Client notification, credit monitoring, the IRS Stakeholder Liaison report, state attorney general notifications, and an FTC that can act on an inadequate security programme whether or not anyone was harmed. Add the clients who leave, quietly, the following January. Nearly every control on this page costs less per year than the notification letters alone.

Firm Email, Client Documents And The Office

Seats that track your headcount

Partners, staff accountants, the bookkeeper and the seasonal preparers you add in January. Liberation Email from $1.95 per user a month; Mail Pro at $7.95 for larger mailboxes. Add seasonal seats for the season and remove them in May.

Role addresses that survive turnover

returns@, payroll@ and partner-specific addresses that route to the right person rather than into one inbox nobody owns. When a preparer leaves, the address and its history stay with the firm — a permission change rather than a password someone remembers.

Retention, backups and a tested restore

Records outlive filing seasons by years. CodeGuard takes encrypted off-site backups from $2.09 a month with per-file version history, and the data center is backed up daily with seven days of retention. We will test a restore with you, which is also the kind of thing a WISP is supposed to describe.

Your Website And Client Intake

State boards and the AICPA set their own rules on how a CPA firm may advertise and on client confidentiality. We build the site; confirm the wording against your board and your professional standards.

What It Costs

Published per-seat pricing, so you can work out the monthly figure before you call. Network and endpoint support are quoted per firm, because a two-person practice and a fifteen-person firm with seasonal staff are different jobs.

What we will not sell you. We are not your Qualified Individual, we do not write your WISP, and we do not certify your compliance. What we provide is infrastructure that meets the technical safeguards the Rule describes, and documentation of what we do, so that the vendor-oversight section of your programme has something real in it. Anyone selling you “Safeguards Rule compliance” as a product is selling you a feeling.

Accounting And Tax Firm IT FAQs

If you prepare tax returns for compensation, yes. The FTC’s own guidance lists tax preparation firms as covered financial institutions under the Rule. Firms that do only audit or advisory work should check their position, but most practices that touch returns are in scope. IRS Publication 4557 is the tax-profession restatement of the same expectations, and a written information security plan is how you evidence both.

Four things that touch IT directly. Multi-factor authentication on systems holding customer information — at least two of knowledge, possession and inherence factors. Encryption of customer information both on your systems and in transit. A written risk assessment and incident response plan. And documented oversight of your service providers: selecting capable ones, contracting for security, monitoring them and reassessing periodically. There are nine elements in total; those are the ones a hosting and email provider affects.

No, and be careful of anyone who says yes too quickly. The Rule does allow a service provider to hold the role, but it also requires a senior person at your firm to supervise them, and responsibility stays with your firm either way. What we do is provide infrastructure that meets the technical safeguards and give you documentation of it, so the vendor-oversight part of your programme has something concrete to point at.

No. A written information security plan has to describe your firm — your systems, your staff, your risks, your incident response. A template bought from a vendor and never adapted is worse than useless, because it documents controls you do not actually have. We will tell you exactly what we do on our side so you can write that part accurately.

Hub for Teams at $7.49 per user a month gives clients somewhere to upload and retrieve returns, W-2s and statements instead of attaching them to email. The practical advantage for a firm under the Safeguards Rule is the access log: a portal tells you who opened what and when, and lets you revoke access when an engagement ends. An encrypted email gives you a sent item, which is much weaker evidence that access is controlled.

Yes. Add mailboxes in January for seasonal preparers and remove them in May — you are billed for what you run. The part worth doing properly is removal: seasonal accounts left active after the season are a standing risk and the kind of thing that shows up badly in a risk assessment.

The per-seat products are published: Liberation Email from $1.95 a user a month, Mail Pro at $7.95, Hub for Teams at $7.49, CodeGuard from $2.09. A five-person practice wanting encrypted email, a client portal and off-site backups can add that up from this page. Network, endpoint and website work are quoted per firm.

Start With The Document Channel

Accounting firm IT, in the order that matters

Most accounting firm IT pitches start with the word compliance and end with a retainer. Here is the useful version.

The Safeguards Rule has nine elements. Four of them are technical, and a hosting and email provider affects those four. The other five are yours: the risk assessment, the training, the incident response plan, the annual report to leadership, and the person accountable for all of it.

Nobody can sell you the other five. Be suspicious of anyone who implies they can.

Accounting firm IT priorities in order: multi-factor authentication, SPF DKIM DMARC, removing seasonal accounts, a client document portal, encrypted email and tested backups

Do the free things first

Multi-factor authentication on email. It is required, it is free, and it ends the majority of account compromises before they start.

SPF, DKIM and DMARC on your domain. These stop somebody sending mail that appears to come from your firm — which, during filing season, is exactly what somebody will try.

Remove seasonal accounts in May. Dormant accounts with live credentials are the cheapest risk you will ever retire.

Then move the documents

Between January and April a small practice takes in thousands of pages carrying Social Security numbers, dates of birth, bank details and complete financial pictures.

Most of it arrives as email attachments from clients using whatever device was nearest, and most of it is still sitting in those mailboxes years later.

A portal changes two things. Clients stop emailing documents, and you gain an access log — who opened what, when, and whether their access is still live. For a firm documenting controls, the log is the part that matters.

The vendor oversight nobody has written down

This is the element we see missing most often, and it is the one we are directly part of.

The Rule asks you to select service providers capable of protecting customer information, require security by contract, monitor them, and reassess periodically. If your hosting is on a card somebody expensed four years ago and nobody has looked at since, that section of your programme is fiction.

We will tell you in writing where your data sits, what encryption applies, how backups work and how long they are retained. You still have to write the oversight into your programme, but you will have accurate facts to write.

What we are not

We are not your Qualified Individual. We do not write your WISP. We do not certify compliance, because no vendor can — the FTC examines your programme, not your supplier’s marketing.

We also will not pretend that buying encrypted email makes a firm compliant. It satisfies part of one of nine elements. That is worth doing and it is not the whole job.

Questions to ask any accounting firm IT vendor

Your programme has to document vendor oversight, so these are not idle questions — the answers go in writing.

Where does our data physically sit, and under whose law? Company location and server location are often different countries. Both belong in your risk assessment.

Is encryption included or an upgrade? The Rule requires customer information encrypted at rest and in transit. A vendor charging extra for that is telling you where it sits on their roadmap.

What exactly is backed up, how often, and for how long? Vague answers here become vague answers in your programme. Ours: CodeGuard takes encrypted off-site copies daily with per-file version history, and the data center is backed up daily with seven days of retention.

Can we get an access log? For document exchange this is the difference between asserting that access is controlled and evidencing it.

What happens when we leave? Standard formats and a clean export mean your records are portable. A proprietary system with no export is a risk you are accepting on behalf of your clients.

Who do we call at 7am on April 14th? Ticket-only support is fine in September. It is not fine during the last week of filing season, and that is the week it will matter.

A note on templates

There is a healthy market in WISP templates, and a template is a reasonable starting point.

The failure mode is adopting one unchanged. A plan describing controls your firm does not have is worse than no plan, because it documents a gap between what you claimed and what you did — which is precisely what an examiner or a plaintiff’s lawyer is looking for.

Use the template, then correct every line that is not true of your firm. The infrastructure section is the one we can give you accurate facts for.

What a five-person practice actually spends

Encrypted email for five people, a client document portal and off-site backups with version history is a small monthly figure you can total from the pricing above.

Seasonal seats flex with the season. Network and endpoint support are quoted per firm, because a two-partner practice and a fifteen-person firm with a server room are not the same job and a single number would be wrong for one of them.

Tell us how client documents arrive during filing season and where they end up afterwards. We will show you what to move out of email first, what to authenticate on your domain, and what it costs. If two changes get you most of the way, we will say that rather than quoting you six.

One last thing worth saying plainly. Compliance work has a way of becoming an annual panic in the week before something is due, and then being forgotten for eleven months. The firms that find this easy are the ones that did the free controls once, wrote down honestly what their vendors do, and then only had to revise a page each year rather than rebuild the whole thing. That is a much smaller job than it looks like from the outside, and it is mostly a matter of starting.

Custom Solutions

Take your business to the next level with Liberation's full suite of services & solutions.

Custom Management

Don’t like managing? We offer managed services for hosting, ecommerce, web sites, and more.

Custom Websites

We build custom, professional websites for small to large organizations.

Custom Apps

Our team of expert developers can design custom applications for a wide variety of purposes.

Payment Processing

Cancel-Free payment processing for a variety of industries and custom solutions.

Expert Consulting

Liberation offers consulting on strategy, infrastructure, e-commerce, and more.

Custom Ecommerce

We customize your e-commerce to fit your business needs and goals for maximum profits.

Our Promise Of Digital Independence

Liberating Your Digital World Is Our Passion

LiberationTek global edge network map

Global Edge Network

Liberation’s global edge network provides enhanced performance & security.

Population Reach
90 %
Countries
90 +
Networks
2500 +

Freedom Tech News

Stay informed on the latest tech news, new products, promotions, & more!

Ready For Digital Liberation?