Las Vegas accounting professional working on a laptop with cybersecurity shield and lock icons in a modern office.

If your Las Vegas accounting firm handles tax returns, Social Security numbers, payroll records, financial statements, banking information, or other sensitive client data, cybersecurity isn't just an IT issue.

For accounting and tax firms subject to the FTC Safeguards Rule, protecting customer information requires a documented information security program supported by appropriate administrative, technical, and physical safeguards.

That can include controls such as multi-factor authentication, encryption, access management, security monitoring, employee training, vendor oversight, and incident response.

For CPA firms in the Las Vegas Valley, the challenge is putting those protections in place without creating unnecessary friction or downtimeโ€”especially during tax season.

The Federal Trade Commission specifically identifies tax preparation firms as an example of a financial institution that may fall under the Safeguards Rule. However, applicability depends on the activities a business performs rather than simply whether it calls itself a CPA or accounting firm.

๐Ÿ‘‰ Official FTC Safeguards Rule:
https://www.ftc.gov/legal-library/browse/rules/safeguards-rule

๐Ÿ‘‰ FTC Safeguards Rule compliance guidance:
https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know

Here is a practical FTC Safeguards Rule IT checklist for Las Vegas accounting firms.

1. Identify Where Your Accounting Firm Stores Sensitive Data

You can't protect information if you don't know where it lives.

A covered financial institution's security program should account for the customer information it collects, stores, transmits, and processes. That begins with understanding the systems containing sensitive information and assessing the risks associated with them.

For a Las Vegas CPA firm, that review may include:

  • Tax preparation software
  • Accounting and bookkeeping applications
  • Payroll systems
  • Client portals
  • Document-management systems
  • Microsoft 365 and email
  • Employee laptops and workstations
  • Local servers
  • Cloud-hosted applications
  • Backup systems
  • Remote-access tools
  • Mobile devices with access to business systems

Accounting firms commonly rely on platforms such as QuickBooks, Lacerte, ProSeries, Drake, UltraTax CS, CCH Axcess, Canopy, Karbon, and similar accounting or practice-management applications.

The exact environment will be different for every firm.

Why Remote Work Changes the Security Boundary

Consider a 25-person CPA firm in the Las Vegas Valley.

Some employees work primarily from the office. Others work remotely. Partners may access email and client files while traveling. Tax applications might run in one environment while supporting documents live somewhere else.

In that environment, cybersecurity can't stop at the office firewall.

Your security review may also need to consider:

  • Remote laptops
  • Microsoft 365 accounts
  • Cloud applications
  • Client portals
  • VPNs or remote desktops
  • Third-party integrations
  • Backup locations
  • Privileged administrator accounts

The goal is to understand where customer information enters the organization, where it moves, who can access it, and where it eventually leaves or is disposed of.

2. Control Access to Client and Taxpayer Information

Not every employee needs access to every client record.

The Safeguards Rule includes requirements involving access controls designed to limit access to customer information to authorized users who have a legitimate business need.

For an accounting firm, that can mean reviewing:

  • Individual employee accounts
  • Administrator permissions
  • Folder and application access
  • Remote-access privileges
  • Former employee accounts
  • Seasonal staff accounts
  • Temporary employee permissions
  • Third-party vendor access

CPA Firm Access-Control Checklist

Your IT team should evaluate whether the firm:

  • Gives every employee a unique login
  • Restricts administrator privileges
  • Applies least-privilege access
  • Reviews permissions periodically
  • Secures remote access
  • Disables former employee accounts promptly
  • Reviews access for temporary and seasonal employees
  • Uses appropriate multi-factor authentication

This becomes especially important around tax season.

CPA firms frequently add seasonal employees or temporary staff before filing deadlines. Those employees may need access to sensitive systems for several months.

When their work ends, unnecessary accounts and permissions shouldn't remain active indefinitely.

Does the FTC Safeguards Rule Require MFA?

For covered financial institutions subject to the applicable provision, the Safeguards Rule requires multi-factor authentication for people accessing customer information on the firm's systems.

MFA uses more than one authentication factor. Those factors may include:

  • Something the user knows, such as a password
  • Something the user has, such as an authenticator app or security key
  • Something inherent to the user, such as a biometric identifier

The Rule also provides for an alternative form of secure access control that offers equivalent protection when the Qualified Individual approves it in writing.

For a Las Vegas accounting firm, MFA may need to be evaluated across systems such as:

  • Microsoft 365
  • Remote access
  • Cloud applications
  • Client-data platforms
  • Accounting systems
  • Other applications containing customer information

Turning MFA on for email is valuable, but it may not address every system through which customer information can be accessed.

3. Protect the Systems Your CPA Firm Depends On

Cybersecurity controls have to protect sensitive information without preventing accountants from doing their jobs.

That matters even more during March and April.

A security change that unexpectedly disrupts tax software, document workflows, remote access, or client portals can create its own business problem.

The Safeguards Rule addresses multiple technical safeguards that covered firms may need to implement.

Accounting Firm Cybersecurity Checklist

Depending on the firm's applicable requirements and risk assessment, its technology environment may need to address:

  • Encryption
  • Endpoint security
  • Operating-system patching
  • Application patching
  • Microsoft 365 security
  • Wireless-network security
  • Remote-access protection
  • Secure backups
  • Logging and monitoring
  • Vulnerability management
  • Secure data disposal
  • Application security
  • Change-management procedures

Does the FTC Safeguards Rule Require Encryption?

The FTC's guidance states that covered institutions subject to this requirement must encrypt customer information both at rest and in transit.

If encryption isn't feasible, effective alternative controls may be used when appropriately reviewed and approved by the Qualified Individual.

For accounting firms, encryption shouldn't be viewed as a single checkbox.

Sensitive information may exist across:

  • Employee laptops
  • Servers
  • Cloud platforms
  • Email systems
  • Backup systems
  • Document-management platforms
  • Client portals
  • Accounting applications

It may also travel between clients, employees, vendors, and cloud services.

A better question than โ€œDo we have encryption?โ€ is:

Where does customer information live or travel, and how is it protected at each point?

4. Maintain Secure Backups and Business Continuity

A cybersecurity incident isn't the only threat to an accounting firm.

Hardware failures, software problems, accidental deletion, ransomware, and other disruptions can also make critical systems unavailable.

For CPA firms facing fixed filing deadlines, recovery time matters.

A backup strategy should consider:

  • What information is backed up
  • How frequently backups occur
  • Where backups are stored
  • How backups are protected
  • Who can access them
  • Whether recovery has been tested
  • How quickly critical systems can be restored

Backing up data is important.

Being able to restore it reliably when the firm is under pressure is what makes those backups useful.

For Las Vegas accounting firms, backup and recovery planning should be coordinated with the firm's broader information security and incident-response processes.

5. Train Employees to Recognize Phishing and Cyber Threats

Technology alone can't protect taxpayer information.

Employees remain an important part of the security program.

The Safeguards Rule includes employee security-awareness training requirements for covered organizations.

That training should reflect the threats employees actually encounter.

A Tax-Season Phishing Example

Imagine an employee receives this message during a busy afternoon:

โ€œHere are the documents you requested. I need this filed today.โ€

The sender's name looks familiar.

There is an attachment.

The employee already has multiple deadlines competing for attention.

That combination of familiarity and urgency is exactly what can make phishing effective.

5 Things Employees Should Check Before Clicking

Before opening an unexpected attachment or following a link, employees should check:

  1. The actual email address.
    Does it match the address the client normally uses?
  2. Whether the request makes sense.
    Was the employee expecting these files or this message?
  3. Where the link really goes.
    Does the destination match the organization or service mentioned in the email?
  4. Whether unusual urgency is being used.
    Is the sender pressuring the employee to bypass the firm's normal procedures?
  5. Whether the request can be independently verified.
    If something seems unusual, contact the client using a known phone number or established communication method.

A few seconds of verification can prevent a much larger disruption.

6. Test Security and Manage Vulnerabilities

Security controls shouldn't simply be installed and forgotten.

The FTC Safeguards Rule includes requirements addressing monitoring and testing of safeguards.

Depending on the organization and applicable provisions, this may involve activities such as:

  • Vulnerability assessments
  • Penetration testing
  • Continuous monitoring
  • Security-event review
  • Patch management
  • Remediation tracking

Testing helps answer an important question:

Are the safeguards working the way the firm believes they're working?

Finding a weakness through a planned security review is generally preferable to discovering it during an active incident.

7. Review Vendors That Handle Customer Information

Your accounting firm may rely on outside companies for:

  • Cloud hosting
  • Software
  • IT support
  • Document management
  • Email
  • File sharing
  • Backup
  • Payment processing
  • Other technology services

Those vendors can become part of your cybersecurity risk.

The Safeguards Rule requires covered institutions to take steps to select appropriate service providers, require relevant safeguards through contracts, and periodically assess service providers based on the risk they present.

Questions to Ask Technology Vendors

Consider asking:

  • What customer information can the vendor access?
  • How is that information protected?
  • Does the vendor use MFA?
  • How is privileged access controlled?
  • What happens if the vendor experiences a security incident?
  • What cybersecurity obligations are included in the contract?
  • Does the vendor use subcontractors that can access your information?
  • How does the vendor handle data when the relationship ends?

Vendor oversight isn't simply a purchasing exercise.

It is part of protecting the information your clients have trusted you to safeguard.

8. Create a Written Incident-Response Plan

There is never a convenient time for a cyber incident.

For an accounting firm, February, March, or April may be especially disruptive.

The Safeguards Rule requires applicable covered institutions to maintain a written incident-response plan designed to help the organization respond to and recover from security events.

Your plan should establish key responsibilities before an incident happens.

Your Incident-Response Plan Should Address

  • Who employees contact first
  • Who is responsible for incident decisions
  • How compromised devices are isolated
  • How compromised accounts are secured
  • How logs and evidence are preserved
  • How backup and recovery procedures work
  • Who communicates internally
  • Who communicates externally
  • How weaknesses identified during the incident are corrected
  • How the incident is documented and reviewed afterward

The middle of a ransomware incident is not the ideal time to decide who is in charge.

5 Steps for Responding to a Cybersecurity Incident

A practical accounting-firm response framework is:

1. Contain the incident.
Isolate affected systems, devices, or accounts when appropriate.

2. Determine what was affected.
Identify the users, accounts, systems, and information involved.

3. Preserve evidence and investigate.
Retain relevant logs and information needed to understand the incident.

4. Restore systems safely.
Recover clean systems while addressing the weaknesses that contributed to the incident.

5. Evaluate notification obligations.
Work with appropriate legal, compliance, insurance, technical, and other professionals to determine what reporting or notifications may be required.

FTC Safeguards Rule 500-Consumer Notification Requirement

The Safeguards Rule also contains an FTC notification requirement for certain security events.

Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event.

The requirement generally concerns the unauthorized acquisition of unencrypted customer information involving at least 500 consumers.

For purposes of the requirement, encrypted information may be treated as unencrypted when an unauthorized person also obtained access to the encryption key.

๐Ÿ‘‰ FTC Safeguards Rule notification form:
https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act/safeguards-rule-form

Accounting firms should consult qualified legal or compliance counsel when determining whether an incident triggers FTC or other notification obligations.

FTC Safeguards Rule IT Checklist for Las Vegas Accounting Firms

Use this checklist as a starting point for reviewing your firm's cybersecurity environment:

  • โœ… Written information security program
  • โœ… Qualified Individual designated
  • โœ… Written risk assessment, when applicable
  • โœ… Inventory of systems and customer information
  • โœ… Access controls
  • โœ… Multi-factor authentication
  • โœ… Encryption or permitted alternative safeguards
  • โœ… Endpoint security
  • โœ… Application security
  • โœ… Patching and vulnerability management
  • โœ… Logging and security monitoring
  • โœ… Security testing
  • โœ… Employee cybersecurity training
  • โœ… Service-provider oversight
  • โœ… Secure data disposal procedures
  • โœ… Change-management procedures
  • โœ… Protected backup and recovery
  • โœ… Written incident-response plan, when applicable
  • โœ… Applicable FTC notification procedures
  • โœ… Regular security-program review and updates

A Note About Smaller Financial Institutions

Financial institutions that maintain customer information concerning fewer than 5,000 consumers are exempt from certain Safeguards Rule provisions.

That does not mean every business below that threshold is automatically exempt from the entire Safeguards Rule.

Because applicability depends on the firm's activities and circumstances, accounting firms should evaluate the Rule itself and obtain appropriate legal or compliance guidance.

How IRS Publication 4557 Fits With the FTC Safeguards Rule

Tax professionals should also be familiar with IRS Publication 4557, Safeguarding Taxpayer Data.

Publication 4557 provides guidance specifically for tax professionals on protecting taxpayer information and discusses areas including security planning and the FTC Safeguards Rule.

๐Ÿ‘‰ IRS Publication 4557:
https://www.irs.gov/pub/irs-pdf/p4557.pdf

These resources fit together rather than competing with one another:

FTC Safeguards Rule โ†’ Requirements applicable to covered financial institutions

IRS Publication 4557 โ†’ Taxpayer-data security guidance for tax professionals

Your firm's cybersecurity program โ†’ The technology, people, policies, monitoring, and response processes used to protect information

Recommended internal link:
IRS Publication 4557: Cybersecurity Checklist for Las Vegas CPA and Tax Firms

Frequently Asked Questions About the FTC Safeguards Rule for CPA Firms

Does the FTC Safeguards Rule apply to CPA firms in Las Vegas?

Potential applicability isn't based on the firm's Las Vegas location. The FTC identifies tax preparation firms as an example of a financial institution, but coverage depends on the activities the organization performs.

CPA and accounting firms should evaluate their specific operations rather than assuming every accounting firm has identical obligations.

What cybersecurity protections should a Las Vegas CPA firm have?

A CPA firm should begin with its applicable legal and regulatory requirements and its risk assessment.

Depending on the firm's circumstances, cybersecurity controls may include:

  • Access controls
  • MFA
  • Encryption
  • Endpoint security
  • System monitoring
  • Protected backups
  • Employee training
  • Vendor management
  • Vulnerability management
  • Incident response

The appropriate safeguards depend on the firm's risks, systems, size, complexity, and the sensitivity of the information it maintains.

Does the FTC Safeguards Rule require multi-factor authentication?

For covered financial institutions subject to the applicable requirement, yes. The Rule requires MFA for people accessing customer information unless an equivalent form of secure access control is approved in writing by the Qualified Individual as provided by the Rule.

Does the FTC Safeguards Rule require encryption?

The Rule requires applicable covered institutions to encrypt customer information on their systems and while it is being transmitted.

When encryption isn't feasible, effective alternative safeguards may be used under the conditions established by the Rule.

Does a CPA firm need an incident-response plan?

Applicable covered financial institutions are required to establish a written incident-response plan addressing security events.

The plan should establish responsibilities, response procedures, communications, remediation, documentation, and post-incident review before an actual emergency occurs.

What should a Las Vegas accounting firm do after a cybersecurity incident?

A firm should contain the incident, determine what systems and information were affected, preserve evidence, investigate the event, restore systems securely, and evaluate applicable reporting or notification requirements.

The firm's actual response should follow its documented incident-response plan and involve appropriate legal, compliance, cybersecurity, insurance, and other professionals when necessary.

Can an MSP make a CPA firm FTC compliant?

An MSP can help implement, document, monitor, and maintain many of the technical safeguards that support an accounting firm's security and compliance program.

An MSP cannot simply guarantee FTC compliance.

Responsibility for complying with applicable requirements remains with the covered financial institution, and questions about legal applicability should be addressed with appropriate legal or compliance professionals.

Why Accounting-Firm IT Experience Matters

CPA firms have technology requirements that look different from many other businesses.

Your firm may be managing:

  • Highly sensitive taxpayer information
  • Specialized accounting and tax software
  • Fixed filing deadlines
  • Seasonal employees
  • Remote users
  • Client portals
  • Large document workflows
  • Little tolerance for downtime during tax season

Security controls need to account for all of those realities.

A provider supporting CPA firms should understand that the objective isn't simply to make systems more secure.

The objective is to make them secure, reliable, supportable, and usable when deadlines are tight.

For firms evaluating Las Vegas accounting IT support, useful questions include:

  • Does the provider understand our accounting applications?
  • Can it support both office and remote users?
  • How does it handle cybersecurity monitoring?
  • How are backups tested?
  • How quickly can it respond during tax season?
  • Does it understand the technical controls relevant to the Safeguards Rule?
  • Can it clearly document what it manages and what remains our responsibility?

Your accountants shouldn't have to become IT experts simply to understand whether basic security controls are working.

Is Your Las Vegas Accounting Firm Ready for a Security Review?

For a 10โ€“50 employee CPA or accounting firm in the Las Vegas Valley, cybersecurity has to accomplish two things at the same time:

Protect the information clients have trusted you with.

And:

Keep the systems your accountants rely on available when the pressure is highest.

Stimulus Technologies can help evaluate and manage technical controls that support your firm's cybersecurity and compliance program, including areas such as access, endpoint protection, Microsoft 365 security, backups, monitoring, and IT support.

Schedule an IT Security Review for Your Las Vegas Accounting Firm

Find out where your firm's technology controls are strong, where gaps may exist, and which improvements should be prioritized before the next busy season.

Contact Stimulus Technologies for an IT Security Review: Book your free 15-minute consult now.ย