Security basics for a tax firm

The everyday controls that protect a tax practice: multi-factor authentication everywhere, the IRS "Security Six", device and email habits, staff training and least-privilege access.

None of this is exotic. Most of it is on IRS and FTC checklists written for tax professionals, and a small firm can put nearly all of it in place in an afternoon.

The IRS says it plainly in Publication 4557: protecting taxpayer data is the law. Under the Gramm-Leach-Bliley Act and the FTC's Safeguards Rule, tax and accounting professionals are treated as financial institutions regardless of size, and must keep a written information security plan. The FTC lists tax preparation firms among its examples of businesses the rule covers. The IRS adds that failing to create and enact a plan may lead to an FTC investigation.

The FTC has exempted businesses that keep information on fewer than 5,000 consumers from certain provisions of the rule, but not from the rule as a whole. This is general information, not legal advice; ask an attorney which parts apply to your practice.

Use multi-factor authentication everywhere

Multi-factor authentication (MFA) means signing in with something beyond a password, such as a code from an app on your phone. It protects an account even when the password has been stolen.

  • The FTC Safeguards Rule requires MFA for anyone accessing customer information on your system, using at least two of: something you know (a password), something you have (a token or phone), or something you are (a fingerprint).
  • The IRS tells tax professionals to use the most secure MFA option available, not only for tax software but for email and storage accounts too.
  • Start with email. Whoever controls your email can reset most of your other passwords.

The IRS "Security Six"

The IRS recommends six basic protections for every tax professional:

  1. Anti-virus software, to catch malicious software on your computers.
  2. Firewalls, to shield computers and networks from malicious or unnecessary web traffic.
  3. Two-factor authentication, an extra layer of protection beyond a password.
  4. Backup software or services, so critical files are routinely copied to an external source.
  5. Drive encryption, which makes the data on a lost or stolen computer unreadable.
  6. A virtual private network (VPN), an encrypted tunnel between a remote worker and the firm's network.

Devices and email

These come from the IRS's own checklist in Publication 4557:

  • Keep security software and web browsers set to update automatically.
  • Use strong, unique passwords: at least eight characters, and the IRS suggests considering sixteen for administrator accounts. Never reuse or share them. A password manager helps.
  • Keep business and personal email separate, and do not read business email or sensitive files on public wi-fi.
  • Back up client data in encrypted form to a source that is not connected to your network full time. The IRS calls this your best protection against ransomware.
  • Encrypt sensitive files and devices, and wipe or destroy old drives, phones and printers before you get rid of them.
  • Keep an inventory of the devices and software that store or process client data.
  • Change default passwords on routers, printers and new accounts.

Train your staff

People are the target, so people are the defense. The FTC requires covered businesses to give their staff security awareness training and to schedule regular refreshers. The IRS says every employee, professional and administrative, should be educated about security threats and phishing.

Keep it practical: walk through the red flags, agree on which requests always get a call back, and make sure everyone knows who to tell when something looks wrong.

Least privilege

  • Give each person access only to what their job needs. The IRS advises limiting access to taxpayer data to those who need to know.
  • Give everyone their own login. No shared accounts or passwords.
  • Remove access the day someone leaves. The IRS guide says to deactivate a departing employee's usernames and passwords immediately.
  • Name one person as responsible for your security program. The FTC requires a designated "qualified individual" to oversee it.

Watch for misuse

  • Check your EFIN status in e-Services every week for the number of returns filed under it, and contact the IRS e-Help Desk if it is higher than you filed. Eligible preparers can also view returns filed per PTIN in their online PTIN account.
  • Remove Centralized Authorization File (CAF) authorizations for people who are no longer clients.
  • Keep audit logs that record who did what and when. The IRS recommends them.

How Journey helps

  • MFA for every staff sign-in. Staff accounts must set up an authenticator app before using Journey, and each sign-in asks for its code. Recovery codes are available in Settings, under Your account, then Security.
  • A second-factor check for sensitive owner actions. Some owner and General Manager actions, such as changing the client sign-in setting, are refused by the server unless the session has completed the second factor.
  • An email sign-in code for clients. Journey can send clients a six-digit code by email each time they sign in to the portal. It is on by default, and firm owners and General Managers control it in Settings, under the firm's Security section. The portal asks for the code before it opens, and the portal's server actions check it too. If the portal can't confirm the code, it does not open.
  • Roles that limit access. Each staff member has a firm role that decides what they can see and do. See Role structure.
  • An audit log. Owners and General Managers can see changes to clients, returns and requests, invoices, staff and tasks, with who made each one and when.
  • A drafted WISP. Journey drafts a Written Information Security Plan from your firm's settings and tells you what is left for your firm to complete.

Sources

  • IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024): irs.gov/pub/irs-pdf/p4557.pdf
  • IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice (Rev. 8-2024): irs.gov/pub/irs-pdf/p5708.pdf
  • IRS, "Tax pros: Follow the 'Security Six' steps to help protect taxpayer data": irs.gov
  • FTC, "FTC Safeguards Rule: What your business needs to know": ftc.gov
Can't find what you need? .