Tax Season Ransomware: Why CPA Firms Get Hit Between February and April
Why ransomware operators target accounting firms during tax season, the attack chains that work, the recovery timelines firms cannot afford.
Read articleCompliance
What cyber insurance for CPA and tax firms actually covers in 2026, the underwriting questionnaire controls carriers review.
Accounting firms have become a high-value target for ransomware operators, BEC crews, and tax-refund redirect scammers.
CPA and tax firms hold concentrated client financial data — SSNs, bank routing details, prior-year returns, K-1s, active wire instructions — in environments small enough for defenses to be inconsistent. Downtime hurts because IRS deadlines do not move.
Cyber insurance sits next to accountants professional liability on the renewal checklist.
What has changed in 2026 is not whether a firm needs it, but what carriers will underwrite, at what price, and which questionnaire answers quietly turn into coverage conditions on the day a claim is filed.
This article is for managing partners, firm administrators, and IT-responsible CPAs filling out a renewal application. Obsidian Ridge does not sell insurance. We help firms pass underwriting honestly and operate the controls behind the answers.
Many partners assume their existing policies cover cyber events. They do not. Accountants professional liability — E&O — responds to errors and omissions in accounting and tax: a missed Section 754 election, an incorrect depreciation schedule, alleged audit negligence.
General liability covers slip-and-fall. Neither responds to forensics, ransomware, an FTC inquiry, or a wire redirected by a compromised vendor email.
A cyber liability policy is a separate contract. In 2026, coverage parts on a typical accounting policy include:
Some carriers bundle. Some sell endorsements. Read the declarations and schedule of endorsements, not the brochure.
Do not size an accounting-firm cyber policy from a blog post — but walk into the broker conversation with the right anchors. Most small firms carry $1 million in aggregate cover; firms in the 50-to-250-employee range commonly carry $2 million to $5 million. A $1 million policy with documented controls typically prices around $1,000 to $3,000 per year.
Use partner count, revenue, client-data volume, payroll or refund authority, contract requirements, and prior-incident history to refine it.
The aggregate is half the conversation. Sublimits decide what the firm actually collects:
For a firm that processes client refunds, manages payroll, or holds funds in trust, the crime sublimit may be the single most important number on the page.
The controls below appear repeatedly across current accounting-firm and general SMB cyber applications. They are the controls most likely to affect eligibility, sublimits, exclusions, and price.
MFA on email, tax software, remote access, and admin accounts. Carriers ask separately about MFA on Microsoft 365 or Google Workspace, on the tax platform (Lacerte, Drake, UltraTax, ProSeries, CCH Axcess), on RDP, VPN, RMM, and on every privileged admin account.
Misrepresenting MFA is a top cause of denied claims.
24/7 EDR or MDR on every endpoint and server. A real 24/7 SOC watching the EDR, not "we will check the dashboard Monday."
Identity threat detection on the M365 or Google Workspace tenant. Token theft, impossible travel, anomalous mailbox rules, OAuth consent abuse — where most BEC events begin.
Immutable offsite backup with documented restore tests. Separated from production credentials, with a monthly or quarterly restore test that produces a log.
Written information security program. A WISP meeting both IRS Publication 4557 and the FTC Safeguards Rule, named qualified individual, current within 12 months.
We cover the build in IRS Publication 4557 and the FTC Safeguards Rule for CPA Firms in 2026.
IR plan plus a tabletop in the last 12 months. Short, usable, with evidence the firm has run through it.
Security awareness training with phishing simulations. Recurring cadence, not a once-a-year video. Tax-season simulations carry weight.
DMARC at quarantine or reject. Plus link protection and attachment sandboxing.
Vendor risk inventory with breach notification clauses. Tax software, e-signature, cloud storage, document portal, payroll service, bank file transfer.
Encryption at rest and in transit. Workstations, backups, file shares, email, client portal.
Documented adherence to AICPA SSTS Section 1.3. Newer questionnaires now include this — the SSTS addressing data privacy is a professional standard, and carriers ask whether the firm has written policies aligned with it.
This is the control stack current applications keep asking firms to prove, and it lines up closely with the IRS Security Six.
The most common cyber loss in accounting is not ransomware. It is wire fraud through BEC.
An attacker compromises an email account — the firm's, a vendor's, or a client's — and inserts altered payment instructions into a routine transaction. FBI IC3 reporting continues to show BEC driving the largest dollar losses in cybercrime, and tax-season patterns intensify the exposure.
Exposures by service line:
The base cyber policy generally does not cover the loss. The crime or social-engineering rider does. Two things to verify:
A rider that covers only direct funds-transfer fraud is nearly useless for the accounting BEC pattern. Insist on social-engineering language.
Ransomware endorsements commonly carry coinsurance — typically a 10 to 25 percent insured share, though some policies use 50 percent — plus sublimits below the aggregate and controls-warranty language.
A clause may condition or reduce coverage if the insured cannot demonstrate MFA, EDR or MDR, immutable backups, and a tested IR plan were operating at the time of loss.
The result is simple: the headline limit is not the whole payout story. If the policy includes a controls warranty, every answer on the application is a coverage condition.
After the 2023 Lloyd's war exclusion guidance, most cyber policies exclude nation-state attacks. Wording varies.
For accounting firms, watch the supply-chain language. If a breach travels through the tax software vendor, document portal, e-signature platform, or RMM, some policies treat that as a systemic event and exclude it.
Ask whether the policy responds if a tax software vendor breach affects this firm, and whether there is a separate sublimit for systemic events. Get it in writing.
Prior-acts matters too. If a tax-season incident happened in the prior policy period and was never disclosed at renewal, the carrier can deny on the next policy. Disclose known incidents.
Many carriers now ask whether the firm has cybersecurity gaps during tax season — specifically, whether seasonal contractors and per-diem preparers are brought into the same control set as full-time staff. The honest answer is often "no."
A firm that runs tight MFA, MDR, and offboarding for full-time staff often loosens all three when it brings on seasonal preparers from January through April.
Be ready to answer:
Things that look like security but do not change underwriting much in 2026:
Carriers score operating controls and evidence, not invoices.
The sequence that works in practical order:
Enable MFA on Microsoft 365 or Google Workspace, on Lacerte, Drake, UltraTax, ProSeries, or CCH Axcess admin accounts, and on every RDP, VPN, and RMM path. This is usually one of the cheapest control moves and one of the most important underwriting answers.
A managed detection and response service with a real 24/7 SOC checks the EDR and 24/7 monitoring boxes at once.
Identity threat detection on top covers the cloud productivity suite controls and MFA-bypass detection. Our Managed Detection and Response and Managed ITDR services are designed against this control set.
Pick a product that supports immutability natively, include tax software databases and the document management system in the test scope, schedule a monthly restore, and keep the log.
A WISP satisfying IRS Publication 4557 and the FTC Safeguards Rule, paired with a one-page IR plan naming:
A 60-minute tabletop with managing partner, administrator, and IT vendor satisfies the tabletop requirement.
Refund-redirect emails, vendor banking changes, IRS-impersonation lures, payroll change requests. Our Managed Security Awareness Training handles the cadence and tunes simulations to the tax calendar.
That covers the main underwriting control categories on a 2026 questionnaire.
A firm with repeated claims or no demonstrable program improvement should expect a harder renewal conversation and may need to shop excess and surplus markets. The key is not a better narrative. It is evidence that the controls changed after the incident.
If a claim was paid in a prior period, expect the next application to ask what changed. "We are more careful now" does not pass.
"We moved to a 24/7 MDR provider, added MFA on the tax software admin accounts, rewrote the WISP to meet the Safeguards Rule amendments, and ran a tabletop in March" does.
Misrepresentation is a coverage defense. If the questionnaire said MFA was enabled and forensics shows it was not, the carrier may rescind. Answer honestly. If a control is partial, say so.
A partner cannot use cyber insurance to "transfer" the obligation to safeguard client data. AICPA SSTS Section 1.3 addresses use and protection of client information, and Code of Professional Conduct provisions on confidentiality and due care apply regardless of what the policy pays.
Insurance covers financial consequences. It does not cover a state board finding that controls were unreasonable, an IRS EFIN suspension, or a Safeguards Rule enforcement action. The firm remains the data steward; the carrier is a backstop.
We are not an insurance broker. We do not sell policies and we do not collect commissions. We help firms operate the controls underwriters score and produce the evidence the application asks for.
The control set that appears most often on 2026 applications (24/7 MDR, identity threat detection, MFA enforcement, and workforce training) lines up with our Ridge Core and Ridge Plus tiers.
Ridge Core covers endpoint, MDR and ITDR. Ridge Plus adds SAT, addressing the core control categories on many questionnaires. The accounting industry page lays out the mapping.
For firms renewing in the next 90 days, the two-week Cyber Insurance Readiness sprint:
Talk with us about how the program fits together.
Cyber insurance is not a substitute for controls. It is a backstop for residual risk. Firms that treat the policy as the plan tend to learn the expensive way that the controls warranty is doing more work than the declarations page.
If the questionnaire is making you nervous, that is the right instinct. The fix is operational. Start with:
Ready to map your firm's controls to the carrier questionnaire? Start the Cyber Insurance Readiness sprint.
Last updated
September 30, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Yes. Accountants professional liability (E&O) responds to errors and omissions in tax and accounting work — a missed election, an incorrect basis calculation, alleged negligence in audit work.
It does not respond to forensics, breach notification, ransomware, FTC Safeguards regulatory defense, or wire fraud. Those losses sit on a standalone cyber liability policy.
Most carriers and the AICPA now treat cyber as a separate, expected line of coverage for CPA and tax firms.
Most small firms carry $1 million in aggregate cover; firms in the 50-to-250-employee range commonly carry $2 million to $5 million, with larger firms moving to excess layers.
A $1 million policy with documented controls typically runs about $1,000 to $3,000 per year.
Sublimits decide what you actually collect — on a $1 million policy the social-engineering and crime sublimit commonly lands at $50,000 to $100,000, well below the headline aggregate, which matters most for a firm that processes refunds, payroll, or holds funds in trust.
Yes, and you need to read it carefully. The base cyber policy generally does not cover wire fraud.
The crime or social-engineering rider does, but only if the wording covers social engineering fraud — where a staff member was tricked into authorizing the transfer — and not only direct computer-funds-transfer fraud.
For firms that hold client funds, process refunds, or handle payroll on behalf of clients, this rider is often the most important coverage in the policy.
2026 questionnaires now ask about MFA on the tax preparation platform itself, whether the platform is cloud-hosted or on-premises, who has admin access, and whether the firm has a documented vendor inventory that includes the tax software publisher.
Carriers also ask whether IRS e-filing credentials and EFINs are protected with MFA and whether the firm has procedures for the IRS Security Six required by Publication 4557.
Yes.
After the 2023 FTC Safeguards Rule amendments and the § 314.4(j) breach notification amendment that took effect May 13, 2024 — requiring non-banking financial institutions under FTC jurisdiction, including tax preparers, to notify the FTC within 30 days of a notification event involving unencrypted customer information of 500 or more consumers — many current cyber applications for accounting firms ask whether the firm has a written information security program meeting Safeguards Rule requirements, has designated a qualified individual, and has a documented incident response plan.
A missing or out-of-date WISP can become a reason for declined or restricted terms.
Ransom payment is generally covered when it is legal under OFAC sanctions rules and the carrier's incident response panel approves the payment in advance.
Ransomware endorsements commonly carry coinsurance — typically a 10 to 25 percent insured share, though some policies use 50 percent — plus sublimits below the aggregate and controls-warranty language if the firm cannot demonstrate that named controls (MFA, EDR or MDR, immutable backups, and an incident response plan) were operating at the time of loss.
Read the ransomware endorsement, not just the declarations page.
Most policies require notice as soon as reasonably practicable, with a hard window — commonly 30 to 60 days — for written notice.
Late notification is one of the most common reasons coverage is denied even when the underlying loss is otherwise covered.
Build the carrier hotline into the firm's incident response plan, and remember that the IRS now requires tax preparers to report data theft incidents within specific timeframes that may be shorter than the carrier window.
A firm that suffered a covered loss without subsequent program improvement should expect harder renewal questions, weaker terms, or non-renewal risk.
Two-strike firms — those with claims in consecutive renewal periods — face the hardest market and may need to shop excess and surplus markets.
The fix is operational evidence: documented MDR, MFA, tested backups, WISP, and a tabletop completed since the incident.
Related reading
Why ransomware operators target accounting firms during tax season, the attack chains that work, the recovery timelines firms cannot afford.
Read articleHow BEC and wire-fraud unfold in CPA firms — refund redirect, payroll wire interception, vendor payment scams.
Read articleWhat IRS Publication 4557 and the FTC Safeguards Rule actually require of CPA firms in 2026 — the safeguards, the written program, and where firms slip.
Read article