By Yiddy Lemmer, CEO – CompuConnect, Inc.
CPA and accounting firms handle some of the most sensitive information a client can provide.
Tax records. Social Security numbers. Banking information. Payroll records. Financial statements. Business information. Personally identifiable financial information.
Protecting that information is not only good business practice. Depending on the services your firm provides and whether it qualifies as a covered financial institution, the FTC Safeguards Rule may establish specific requirements for how customer information must be protected.
For CPA firm leaders, the challenge is that cybersecurity requirements can quickly become technical.
What does the Safeguards Rule actually require?
What technology should your firm have in place?
And how can you determine whether your current IT and cybersecurity environment is meeting those requirements?
Let's break down some of the most important technology-related requirements in practical terms.
Important: This article is intended for general educational purposes and is not legal or compliance advice. Applicability of the FTC Safeguards Rule depends on your firm's activities and circumstances. CPA firms should consult qualified legal or compliance professionals regarding their specific obligations.
First, Does the FTC Safeguards Rule Apply to CPA Firms?
The FTC Safeguards Rule requires covered financial institutions under FTC jurisdiction to maintain safeguards designed to protect customer information.
The important distinction is that being a CPA or accounting firm does not, by itself, necessarily determine whether your organization is covered.
The FTC's definition of a financial institution focuses on whether a business is significantly engaged in certain financial activities. Firms should evaluate the services they provide and obtain appropriate legal or compliance guidance when determining whether the Rule applies.
For organizations that are covered, the Safeguards Rule requires a written information security program containing administrative, technical, and physical safeguards appropriate to the organization's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information involved.
From an IT perspective, several requirements deserve particular attention.
1. Multi-Factor Authentication
Passwords alone are not enough.
The Safeguards Rule requires covered organizations to implement multi-factor authentication for individuals accessing information systems, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.
Multi-factor authentication, commonly called MFA, requires more than one type of authentication factor.
For a CPA firm, MFA may be relevant across systems such as:
- Microsoft 365
- Cloud applications
- Remote access
- Systems containing customer information
- Administrative accounts
This is particularly important when employees work remotely or access sensitive information from multiple locations.
But simply turning on MFA somewhere in your organization is not the same as having a properly designed access strategy.
Your firm should understand which systems contain or provide access to customer information and how access to those systems is protected.
2. Encryption of Customer Information
Covered organizations are required to protect customer information using encryption both when the information is stored and when it is transmitted over external networks.
If encryption is not feasible, the Rule allows effective alternative controls that have been reviewed and approved by the Qualified Individual responsible for the information security program.
For CPA firms, customer information may exist in many different places:
- Servers
- Employee computers
- Laptops
- Cloud platforms
- File-sharing systems
- Accounting and tax applications
- Backups
- Portable devices
This is why protecting client information requires more than securing a single application.
Your firm needs to understand where sensitive information lives, how it moves, and who can access it.
3. Access Controls
Not every employee needs access to every piece of information.
The Safeguards Rule requires covered organizations to implement and periodically review access controls.
In practical terms, your firm should be able to answer questions such as:
Who has access to sensitive client information?
Does each employee need that access?
Who has administrative privileges?
What happens when an employee changes roles?
How quickly is access removed when someone leaves the firm?
Are outside vendors able to access your systems?
Access management can become especially challenging as accounting firms grow, add employees, use outside contractors, open additional locations, or adopt more cloud applications.
Permissions that made sense two years ago may no longer make sense today.
That is why access should be reviewed periodically rather than simply granted and forgotten.
4. Inventory Your Data, Devices, and Systems
You cannot adequately protect information if you do not know where it is.
The FTC's guidance emphasizes maintaining an understanding of your information ecosystem, including where customer information is collected, stored, and transmitted.
That means having visibility into the systems, devices, platforms, and people involved.
For a CPA firm, that could include:
- Desktop computers
- Laptops
- Servers
- Microsoft 365
- Cloud storage
- Tax applications
- Accounting software
- Client portals
- Backup systems
- Remote access tools
- Mobile devices
- Third-party applications
This inventory helps your firm understand its potential exposure and determine where safeguards need to be applied.
5. Logging and Monitoring
Cybersecurity is not simply about installing security software.
You also need visibility into what is happening inside your technology environment.
The Safeguards Rule requires covered organizations to implement procedures and controls designed to monitor authorized users' activity and detect unauthorized access or use of customer information.
Monitoring can help identify unusual activity that may otherwise go unnoticed.
For example, suspicious login activity, unusual access patterns, or unauthorized attempts to reach sensitive information may warrant investigation.
The goal is not simply to collect logs.
Your firm needs processes for identifying activity that may indicate a security problem and responding appropriately.
6. Vulnerability Assessments and Security Testing
Technology changes constantly.
New vulnerabilities are discovered. Software is updated. Employees come and go. New applications are installed. Cloud environments change.
That means cybersecurity cannot be treated as a one-time project.
The Safeguards Rule requires covered organizations to regularly monitor and test the effectiveness of their safeguards.
The FTC explains that organizations can satisfy certain testing requirements through continuous monitoring of information systems.
If continuous monitoring is not used, the Rule calls for annual penetration testing and vulnerability assessments, including system-wide scans at least every six months, along with additional testing when circumstances warrant it.
For CPA firms, the bigger lesson is simple:
Security needs to be continuously evaluated.
A cybersecurity assessment performed several years ago does not necessarily tell you whether your environment is adequately protected today.
7. Secure Disposal of Customer Information
CPA firms tend to accumulate data.
Over time, that can mean years of client files, former employee information, old computers, archived emails, cloud files, and other records.
But keeping information indefinitely can create additional risk.
The Safeguards Rule requires covered financial institutions to develop and maintain procedures for securely disposing of customer information generally no later than two years after the most recent use of that information in connection with providing a product or service.
There are exceptions, including situations involving legitimate business needs, legal requirements, or circumstances where targeted disposal is not reasonably feasible.
This means data retention should be intentional.
Your firm should understand what information it maintains, why it is being retained, where it is stored, and how it will eventually be securely disposed of.
8. A Written Incident Response Plan
One of the worst times to decide how to respond to a cybersecurity incident is after one has already started.
The Safeguards Rule requires covered organizations to establish a written incident response plan designed to promptly respond to and recover from security events that materially affect the confidentiality, integrity, or availability of customer information.
An effective plan should address issues such as:
- Who is responsible for making decisions?
- Who needs to be contacted?
- How will the incident be contained?
- How will systems be recovered?
- How will information be communicated internally and externally?
- How will weaknesses identified during the incident be corrected?
- How will the incident and response be documented?
Your incident response plan should also coordinate appropriately with legal counsel, cyber insurance providers, forensic specialists, law enforcement, and other professionals when circumstances require them.
CompuConnect has completed Certified Incident Response Training, which strengthens how we help businesses prepare for and coordinate technology response, continuity, containment, and recovery. That role does not replace the legal, forensic, insurance, regulatory, or law enforcement professionals who may need to be involved in an incident.
9. Monitor Your Technology Service Providers
Your firm's security does not end at your office door.
CPA firms often rely on outside organizations that may have access to systems or customer information.
The Safeguards Rule requires covered organizations to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, include security expectations in contracts, and periodically assess service providers based on the risks they present and the adequacy of their safeguards.
This can include technology providers and other third parties that receive, maintain, process, or otherwise have access to customer information.
For CPA firm leaders, this raises an important question:
10. Employee Security Awareness Training
Technology alone cannot protect your firm.
Employees interact with email, client documents, cloud applications, passwords, file-sharing systems, and sensitive information every day.
The Safeguards Rule requires security awareness training for personnel, along with specialized training for people responsible for implementing the information security program.
For CPA firms, training can help employees better recognize risks such as:
- Phishing emails
- Fake Microsoft 365 login pages
- Suspicious attachments
- Credential theft
- Social engineering
- Unusual requests for financial information
- Unsafe handling of sensitive information
Security awareness should not be treated as something employees complete once and forget.
Threats change, and training should be refreshed accordingly.
Technology Is Only One Part of the Safeguards Rule
One of the biggest mistakes a business can make is assuming that buying cybersecurity tools automatically equals compliance.
The Safeguards Rule is broader than technology.
Covered organizations must establish and maintain a written information security program. Among other requirements, the Rule addresses:
- Designating a Qualified Individual
- Conducting a written risk assessment
- Implementing safeguards based on identified risks
- Monitoring and testing those safeguards
- Training personnel
- Overseeing service providers
- Keeping the information security program current
- Maintaining a written incident response plan
- Reporting to the organization's board or governing body
Technology supports many of these responsibilities, but technology alone does not establish compliance.
What Should CPA Firm Leaders Ask Their IT Provider?
You do not necessarily need to become a cybersecurity expert.
But you should be able to ask good questions.
Consider asking your IT provider:
Do we have MFA implemented everywhere it should be?
Is sensitive customer information appropriately encrypted?
Who has access to our systems and client information?
How often are user permissions reviewed?
Do we maintain an accurate inventory of our devices and systems?
How are our systems monitored for suspicious activity?
Are vulnerability assessments and required security tests being performed?
How are backups protected and recovery tested?
Do we have a written incident response plan?
How quickly can former employee access be removed?
How are third-party technology providers evaluated?
Are employees receiving ongoing cybersecurity awareness training?
If your IT provider cannot clearly explain how these areas are being addressed, that may be a sign that a deeper technology and cybersecurity review is needed.
Cybersecurity Should Protect Client Trust
For CPA firms, cybersecurity is about more than checking boxes.
Your clients are trusting your firm with information they would not give to most businesses.
Protecting that information helps protect the client relationship, your firm's reputation, and your ability to continue operating when something goes wrong.
The FTC Safeguards Rule gives covered organizations a framework for establishing an information security program, but the practical work happens in your technology environment every day.
Access needs to be controlled.
Systems need to be monitored.
Data needs to be protected.
Employees need to be trained.
Backups and recovery need attention.
Security needs to evolve as your firm changes.
And someone needs to make sure it is actually happening.
At CompuConnect, we work with CPA and accounting firms throughout New York and New Jersey, helping them manage the technology and cybersecurity behind their businesses.
Because many of our clients are CPA firms, we understand the importance of protecting confidential client information while keeping employees productive and technology dependable throughout the year.
If you are unsure whether your current technology environment supports your firm's security and compliance requirements, schedule a Discovery Call with CompuConnect.
We can help you understand your current technology environment, identify areas that may need attention, and build a practical roadmap for strengthening your firm's cybersecurity.
About the Author
Yiddy Lemmer is the Founder and CEO of CompuConnect IT, a leading IT support and cybersecurity firm serving small and midsize businesses across New York and New Jersey. With over 18 years of hands-on experience, multiple Microsoft and CompTIA certifications, and deep roots in Brooklyn, Yiddy leads with a passion for technology, service excellence, and helping businesses thrive through secure and efficient IT systems.

