Tax season delivers two certainties for CPA firms and accounting practices: a surge in client work and a matching surge in cyberattacks targeting them.
It's not a coincidence. Cybercriminals know your firm holds tax returns, payroll records, Social Security numbers, and complete financial histories for hundreds of clients. During busy season, staff are moving fast and inboxes are flooded — exactly the conditions that make phishing attacks succeed.
For accounting firms in Toledo and across Northwest Ohio, the regulatory stakes are equally serious. The FTC Safeguards Rule (16 CFR Part 314) and IRS Publication 4557 impose specific, enforceable requirements on tax professionals and financial firms. Failing to meet them isn't just a security risk — it's a liability that can end a practice.
Why Accounting Firms Are Prime Cybercrime Targets
A single client tax file contains everything needed for identity theft, fraudulent loan applications, and synthetic identity fraud. A 200-client practice holds enough data to keep a criminal operation running for years — and attackers know it.
Three attack patterns dominate the threat landscape for Toledo-area CPA firms:
Tax Season Phishing: From January through April, attackers send emails impersonating the IRS, state tax authorities, Drake Tax support, or Intuit/QuickBooks. The urgency of tax season creates exactly the pressure that makes people click without thinking.
W-2 and Payroll Diversion Fraud: A Business Email Compromise (BEC) attacker gains access to an email account, monitors communications, then impersonates a client or employee to redirect direct deposit or payroll funds to a criminal-controlled account.
Fake Client Portal Scams: Spoofed emails claim a client has uploaded a document for your review. The link leads to a credential-harvesting page that captures logins to QuickBooks, Thomson Reuters Onvio, or your practice management system — giving the attacker access to every client file you manage.
The FTC Safeguards Rule: What It Requires of Your Firm
The FTC Safeguards Rule (16 CFR Part 314) covers accounting firms, tax preparers, and CPA practices that provide financial services. Updated in 2023, it now mandates specific technical controls — not just vague "reasonable security."
Written Information Security Plan (WISP): Every covered firm must maintain a documented WISP describing how it identifies risks, safeguards customer information, and responds to incidents. The IRS independently requires a WISP for all tax professionals. If your firm doesn't have one, this is your most urgent gap.
Multi-Factor Authentication (MFA): MFA is explicitly required on any system accessing customer financial data — tax software, accounting platforms, document portals, and email.
Encryption: Client data must be encrypted in transit and at rest. Unencrypted files on a shared drive or sent as email attachments are a compliance violation.
Access Controls and Least Privilege: Staff should only access the client files their role requires. When someone leaves, access must be revoked promptly.
Designated Qualified Individual: Covered firms must assign someone responsible for overseeing the information security program — a role many small CPA practices fill through a managed IT partner.
IRS Publication 4557: Core Requirements for Tax Professionals
IRS Publication 4557 (Safeguards for Tax Professionals) sets security expectations for all tax preparers and CPA firms. Failure to meet them can result in loss of e-filing privileges, civil liability, or referral to law enforcement.
Key Publication 4557 requirements include: maintaining a WISP; running anti-virus, anti-malware, and firewall software; keeping tax software and operating systems patched and current; encrypting all client data transmitted electronically; enabling MFA on all systems; and providing annual staff security awareness training.
If your firm suffers a data breach involving taxpayer information, IRS guidance directs tax professionals to contact the IRS e-Services help desk immediately and report to the appropriate state tax agency and the Federation of Tax Administrators (taxadmin.org). Having a documented incident response plan is not optional under either IRS guidance or the FTC Safeguards Rule.
Accounting Software Security: Drake, QuickBooks, and Thomson Reuters
The platforms your firm relies on daily are high-value targets. Here's what Toledo-area CPA firms need to know about the most common tax and accounting platforms.
Drake Tax
Drake requires an active internet connection for licensing and e-filing, which means your network perimeter matters. Enable MFA on your Drake account, keep the software current, and never allow remote desktop access to Drake machines without VPN and MFA. Drake Hosted provides better isolation but demands the same access-control discipline.
QuickBooks Desktop and Online
QuickBooks Desktop stores files locally — they must be encrypted, backed up offsite, and accessible only to authorized staff. QuickBooks Online is cloud-hosted, but your credentials and accountant access are still your responsibility to protect. MFA is non-negotiable on every account, and staff should be trained to spot fake QuickBooks support phishing attempts.
Thomson Reuters Onvio and Accounting CS
Thomson Reuters cloud platforms have strong built-in security, but your access management practices determine whether it actually protects you. Audit user access regularly, disable accounts when staff leave, and require MFA for all Onvio logins. Attackers routinely spoof Onvio document-sharing emails to harvest your credentials.
Is Your Firm FTC Safeguards Rule Compliant?
Use this self-assessment to identify gaps before a regulator or plaintiff does.
☐ A Written Information Security Plan (WISP) exists and has been reviewed in the past 12 months
☐ A designated Qualified Individual oversees your information security program
☐ MFA is enabled on all systems touching client financial data — tax software, QuickBooks, document portals, email, and remote access
☐ Client data is encrypted in transit and at rest
☐ Access controls limit staff to only the client files their role requires
☐ All software and operating systems are current — no end-of-life Windows or unpatched tax software
☐ Automated, offsite backups run regularly and have been tested with an actual restore in the past six months
☐ Staff have completed security awareness training in the past 12 months covering phishing, BEC, and fake portal attacks
☐ A written incident response plan exists with IRS and state notification procedures documented
☐ Third-party vendors and cloud platforms handling client data have been evaluated for their own security practices
FTC Safeguards Rule enforcement is active. If you checked "no" on three or more items, the time to act is now — not after a breach.
What a Compliant IT Setup Looks Like for a 5–25 Person CPA Firm
A properly secured CPA practice doesn't require enterprise spending. It requires intentional design and consistent execution.
For a 5–25 person firm, a compliant environment includes: business-grade endpoint detection and response (EDR) on every device; centrally enforced MFA across all accounts; business email security with advanced threat protection to block phishing and BEC before it reaches staff; encrypted automated backups with tested restore procedures; a managed firewall; documented acceptable-use and remote-work policies; and a managed IT partner who handles patching, monitoring, and security awareness training — and can serve as your WISP's Qualified Individual.
Flyght works with accounting firms across Toledo and Northwest Ohio on exactly this stack. We know Drake Tax, QuickBooks, and Thomson Reuters. We understand IRS and FTC compliance requirements. And we build security around your workflows — not the other way around. The Northwest Ohio accounting community is closely connected through the Toledo CPA Society and Ohio Society of CPAs. A breach at one firm ripples fast, and the reputational damage often outlasts the financial one.
Request a Free Cybersecurity Assessment for Your Accounting Firm
Flyght works with CPA firms and accounting practices across Toledo and Northwest Ohio to build IT environments that meet FTC Safeguards Rule and IRS Publication 4557 requirements — without disrupting the workflows your team depends on during busy season.
We'll review your setup, identify compliance gaps, and give you a clear roadmap for closing them. No scare tactics, no upselling — just an honest look at where you stand and what it takes to protect your clients and your practice.