by
Dor Israel, CPA, ProAxis Tax & Accounting Services
| August 26, 2026
Every small firm holds Social Security numbers, bank statements, payroll records and driver's license copies for every client it has ever served. Most of it arrived by email, and plenty is still sitting in somebody’s inbox. That gap, between how sensitive the data is and how casually it moves, is the real security problem at small to midsize firms.
No firm gets all of this right on day one. But after building a practice that runs entirely online, here are the 10 steps I’d suggest firms work through:
- Start with the written plan. Under the Federal Trade Commission (FTC) Safeguards Rule, professional tax preparers are treated as financial institutions, and the IRS expects every preparer to keep a written information security plan (WISP). Publication 4557 is the standard reference, and Preparer Tax Identification Number (PTIN) renewal now asks you to confirm you understand your data security responsibilities. A useful WISP names a security lead, lists where client data lives, says who can touch it and spells out what happens the day something goes wrong. Write it, date it and look at it once a year.
- Get documents out of email. An emailed W-2 sits unencrypted in two mailboxes forever, including on phones you’ll never see or control. A portal gives you encryption, an access log and some say over how long the file sticks around. Clients will keep emailing things anyway. When they do, thank them, move the file to the portal, delete the attachment and mention the portal again.
- Put multi-factor authentication on everything. This includes email, tax software, the portal, payroll and bank feeds. It’s usually free. Ten minutes of setup buys more protection than almost anything else you can do. Use an authenticator app rather than text message codes where you can. A stolen password by itself shouldn’t be enough to open a client file.
- Give each person only what the work requires and review the list quarterly. Access rights are the piece firms often forget, because nothing visibly breaks when they’re wrong. In plenty of incidents, the culprit isn’t a hacker at all. It’s the still-active login of someone who left eight months ago. When staff or contractors move on, their credentials should go the same day.
- Encrypt the hardware. Laptops get left in cars and coffee shops, and full-disk encryption plus an automatic screen lock is the difference between losing a laptop and losing client data.
- Keep client files off personal devices. It’s important to hold home setups to the office standard.
- Ask vendors harder questions than most of us ask. The cloud tax software, the bookkeeping platform and the portal all hold client data on your behalf. Ask what security certifications they carry, where the data physically sits and how fast they’ll tell you if they’re breached. Have that conversation before you sign.
- Train clients, not just staff. Phishing is still how most firms get burned, so run short sessions and test people occasionally. With clients, three rules cover most of it: no Social Security numbers by text or email, use the portal and any change to banking or wire instructions gets verified by phone at a number you already had on file. That last call stops a lot of payment fraud by itself.
- Dispose of old files. This is the unglamorous half. Old returns, retired drives and paper files stay sensitive long after the engagement closes. Keep a written retention schedule, shred the paper and wipe or destroy storage media before it leaves the building. Holding on to everything forever isn’t diligence.
- Finally, decide in advance what a bad day looks like. Figure out who gets called first, how affected clients hear about it, what you owe the IRS and states involved and know who to contact at your insurer. Rehearsing a breach is nobody’s idea of a good afternoon, which is why the firms that prepare beforehand stay calm during a real one.
None of this takes an enterprise budget. It takes consistency and a willingness to be slightly annoying about the portal. Clients hand us the most sensitive information they have, and most never ask what we do with it. That seems like a good reason to have a plan ready.