The eight weeks between mid-February and April 15 change the entire calculus of an IT-versus-security conversation for a CPA firm. Attackers know when tax data is concentrated, when preparers are tired, and when a firm cannot spare an afternoon to think about a phishing email. The IRS knows it too — the Stakeholder Liaison program exists specifically because preparer breaches during filing season have a mandatory reporting path built around them. Nothing about that shape maps to a normal IT help-desk relationship.
This article is written for the managing partner or firm administrator asking whether the current IT arrangement is enough, or whether a separate security function is what the practice actually needs. The framing is not adversarial; the specialist you already work with probably does the operations layer well. It is that a specific set of tasks, defined by IRS Publication 4557, IRS Publication 5708, the FTC Safeguards Rule, and the practical reality of a preparer's filing-season calendar, belongs to a different discipline than the one that keeps Lacerte licensed and the printer online.
Filing season concentrates risk, and it changes what the split has to cover
The rest of the year, IT and security look like distinguishable functions that could plausibly be handled by one provider under a well-scoped agreement. From roughly February 10 through April 15, that stops being true. Three things compress into the same window: (1) the firm holds concentrated client SSNs, bank routing details, prior-year returns, K-1s, and active refund and estimated-payment instructions; (2) preparer working hours push into the 60- and 70-hour range and mistakes multiply; (3) the attacker calendar knows this and the volume of tax-themed phishing rises accordingly.
The single most useful reframing is that a security operation for a tax firm is not a year-round monitoring service with a spike in April. It is a monitoring service that has to be provably present during the eight weeks when a missed detection is unrecoverable in schedule terms, and quietly effective during the rest of the year. Whether the IT firm can be that presence is the question below.
What your accounting IT firm was built to run
Accounting IT is its own trade. A good firm handles a specific and complicated stack:
- The tax platform itself — Lacerte, Drake, CCH Axcess, UltraTax CS, ATX, ProConnect. Service packs, form-year updates, network-share configuration, license true-ups before season, the vendor's tax-year rollover in the last week of January.
- E-file infrastructure — the EFIN account plumbing, the acknowledgment retrieval loop, the correction workflow for a rejected return, the coordination with the state e-file portals that behave differently.
- E-signature and delivery — DocuSign or Adobe Sign integration for engagement letters, SmartVault or TaxDome for document exchange, portal provisioning for new clients who arrive January 15 with paperwork.
- Hardware and workstation lifecycle across a headcount that doubles between February and April — the seasonal-contractor laptop provisioning cycle, the printer-and-scanner refresh, the partner laptop that follows them home.
- Microsoft 365 or Google Workspace administration — mailbox provisioning for seasonal staff, distribution lists for the tax teams, delegation to admins.
- Backups and restore procedures for the tax software's database and document store, run against a schedule that changes seasonally.
- Wi-Fi and firewall management for a footprint that expands with seasonal desks and often a temporary conference-room overflow.
- Vendor coordination — the tax platform vendor's implementation and support teams, the practice-management-system vendor, the ISP.
None of that is a security operation, and none of it should be asked to be. It is the layer the firm cannot function without on ordinary days and the layer that gets stress-tested every March.
What actually breaks in the eight weeks around April 15
The concrete incident shapes that turn a filing-season IT problem into a filing-season security event share a family resemblance: attacker inside identity, quiet, until the moment the numbers move.
Preparer identity compromise on a Tuesday in March. An adversary-in-the-middle phishing kit lands on a preparer working past midnight. MFA is defeated at the session-token layer. The attacker sets an inbox rule that routes messages containing the words "IRS," "refund," or the client's name into a hidden folder. Over the next three business days the attacker replies from inside legitimate threads with modified direct-deposit routing on a handful of client returns filed that week. The preparer does not notice — they are looking at K-1s, not their sent items. The refunds land in the attacker's account. The client, and then the IRS, discovers this in April when the reported refund does not match the received refund.
Tax software server ransomware, staged from an operatory workstation, detonated on the last weekend of March. The intrusion begins on a workstation that got a malicious attachment, dwells for several days, moves laterally to the tax software server. The encryptor lands Saturday afternoon. Monday morning the firm cannot prepare, file, or bill. There is no way to move April 15 for the firm's clients, and the firm is now negotiating extension filings and communicating with clients simultaneously.
EFIN and PTIN compromise via a seasonal contractor account that was never deprovisioned. The contractor left in April 2025. Their credentials still work in the tax platform's admin console the following January. An attacker with access to that account can file fraudulent returns against clients on file, or exfiltrate the full client roster with prior-year SSNs.
Each of these is a security operation's job to stop or bound. None of it is what an IT helpdesk queue is designed to catch in real time.
The WISP is often treated as a compliance artifact — a document that lives in a shared drive until someone asks about it. It is that, but it is also a legally operative attestation about what the firm actually does. IRS Publication 4557 has required any preparer with a PTIN to maintain a WISP since well before it became fashionable. IRS Publication 5708 provides a sample template. The FTC Safeguards Rule at 16 CFR Part 314, authorized under the Gramm-Leach-Bliley Act, makes the substantive requirements binding on non-bank financial institutions — which explicitly includes tax preparers and CPAs providing tax and financial services.
The 2023 Safeguards amendments enumerate the components: a designated Qualified Individual, a written risk assessment, access controls, encryption, MFA (§ 314.4(c)(5)), an incident-response plan, service-provider oversight (§ 314.4(f)), and annual reporting to the firm's leadership (§ 314.4(i)). The § 314.4(j) notification amendment that took effect May 13, 2024 adds a 30-day duty to notify the FTC of a notification event involving unencrypted customer information of 500 or more consumers.
A WISP that describes controls the firm is not actually operating is worse than no WISP at all, because it is a written attestation that becomes inaccurate on the day of an incident. This is the artifact that a security operation produces and maintains — not because an IT firm cannot produce a document, but because the document is only true if the underlying operations are being run.
The reporting path the IRS walks after a preparer discovers a breach
This is the part most partners have never mapped end-to-end until they are already inside it. The IRS asks tax professionals to report suspected or confirmed data theft immediately to the local IRS Stakeholder Liaison. The Liaison coordinates with the Return Preparer Office and Criminal Investigation, and helps flag fraudulently filed returns associated with the affected PTINs and client SSNs.
That reporting to the IRS is not a substitute for anything else. In parallel:
- The FTC notification under § 314.4(j) at the 500-consumer threshold runs on the 30-day clock from discovery.
- State breach-notification statutes each have their own timing and content requirements, keyed on residency of affected individuals — Massachusetts, New York, California, Texas, and Illinois all have specific mechanics.
- Client-notification duties may exist under state law and under the firm's professional-responsibility framework, and may need to distinguish current from former clients.
- Cyber-insurance carrier notification typically runs on a "reasonably practicable" or 30-to-60-day timing, and late notification is one of the most common reasons a paid policy does not pay.
That is a lot of parallel clocks with different starting times, different information requirements, and different addressees. Coordinating them is incident-response work. It is not an IT-helpdesk function. It is what a security operation is supposed to have rehearsed in a tabletop, written into an incident-response plan, and paper-trailed on the day of the event.
FTC Safeguards § 314.4(f) puts service-provider oversight in writing
The subsection most CPA firms have not read: § 314.4(f) requires the firm to select service providers that are capable of maintaining appropriate safeguards, to require them by contract to implement and maintain those safeguards, and to periodically assess them based on the risk they present.
The practical translation for the IT relationship is a written engagement that goes beyond a services agreement. It needs to specify the security safeguards the IT firm operates, obligate them to maintain those safeguards, provide the firm with the evidence necessary for periodic risk-based assessment, and require breach-notification back to the firm on a defined clock.
An IT firm with credential access into the tax platform, the tenant, and the workstations that touch client tax data is a service provider under § 314.4(f). "We have worked with them for years, they are fine" is not the shape of the record the FTC will ask for during a program-review examination.
What a security operation covers for a CPA firm
The specific list, distinguished from what an IT firm typically covers:
- Managed detection and response on every preparer laptop, every partner workstation, the seasonal-contractor devices during their active window, and the tax software server. Coverage of the workstations without coverage of the server is not coverage of the server.
- Identity threat detection on the Microsoft 365 or Google Workspace tenant — session-token replay, adversary-in-the-middle sign-ins, malicious inbox rules, OAuth consent, MFA fatigue — distinct from spam filtering. This is where refund-redirect and EFIN-compromise chains are supposed to break early.
- A documented seasonal-contractor identity lifecycle — provisioning on start date, credential and MFA enrollment before first login, deprovisioning of tax platform access and Microsoft 365 access at April 16, verified rather than assumed.
- Awareness training tuned to the accounting attack surface: IRS-impersonation drills, EFIN-suspension threats, payroll-lookalike lures for the office admin, refund-redirect scenarios for preparers, wire-fraud scenarios for anyone touching client funds.
- WISP maintenance as a living document, with the Qualified Individual annual report to firm leadership produced from operating evidence rather than assembled from memory before the meeting.
- Incident-response coordination that already knows the Stakeholder Liaison contact for the region, the § 314.4(j) trigger, the state breach-notification clocks by state, and the cyber-insurance carrier's notification path.
- The evidence packet a Safeguards program review, an IRS Stakeholder Liaison conversation, or a cyber-insurance underwriter will ask for — produced continuously rather than assembled on request.
When your accounting IT firm already covers it
A minority of accounting IT firms have built a security practice around their operations one. Whether the one on retainer is that firm is a question with specific answers:
- Managed EDR they operate, not just resell, on every workstation, every partner and preparer laptop, seasonal-contractor devices during their active window, and the tax software server — with a security operations center staffed around the clock.
- A written engagement with the firm covering FTC Safeguards § 314.4(f) — meaning the IT firm can produce, on request, evidence of their own information-security program and the safeguards they operate on the firm's behalf.
- A signed incident-response plan specific to the firm, with the Stakeholder Liaison contact for the region on file, the § 314.4(j) trigger criteria documented, and the state breach-notification clocks summarized.
- An MFA coverage export, an audit-control log sample from the last month, and identity-anomaly evidence from the last week, produced on the day of the request.
- A signed WISP with a Qualified Individual named, an annual report from the last twelve months, and a documented seasonal-contractor lifecycle including the deprovisioning check for the last April 16.
Missing items are not accusations. They are unowned functions to hand to someone before March, not after.
Six questions to bring to the March review
Bring these to the vendor review scheduled for early March, before filing season fully closes the calendar for the conversation.
- "Do you operate a security operations center reading our endpoint and identity alerts around the clock, and can you name the team?"
- "If a preparer's mailbox gets phished on a Tuesday night in March, what does your automated response do in the first ninety seconds, and what does a human do next?"
- "Under FTC Safeguards § 314.4(f), do we have a written vendor engagement covering your operating safeguards, and can you produce today the evidence of your own information-security program?"
- "If we have a data-theft event this filing season, what is your written procedure for the Stakeholder Liaison notification, the § 314.4(j) 30-day FTC notification if we cross 500 consumers, and the state breach-notification clocks?"
- "Do you monitor our Microsoft 365 or Google Workspace tenant for identity-layer attacks — token replay, adversary-in-the-middle sign-ins, malicious inbox rules — separately from spam filtering, and can you show a report from last week?"
- "Do you have a documented seasonal-contractor identity lifecycle with a verified deprovisioning check that ran against the last April 16?"
Where the answers are hesitant, the March conversation is when to assign the function — while there is still time.
Co-managed is the only shape that survives filing season
The single-vendor default arrangement is the shape a small firm accumulates when it grows without pausing to reconsider. It is not the shape that stays coherent when the workload triples for eight weeks and the attacker calendar knows it.
The co-managed shape splits the two functions to the specialists that operate them. The accounting IT firm keeps the tax platform, the e-file infrastructure, the seasonal hardware ramp, and the vendor coordination running. The security operation runs detection, response, identity monitoring, awareness training, the WISP, the FTC Safeguards program artifacts, the § 314.4(f) evidence chain, and the incident-response coordination. Total spend is closer than partners expect to a generalist charging for equivalent depth, because each specialist runs its own layer more efficiently.
What Obsidian Ridge operates for CPA and tax firms
We are a CISSP-led managed security practice. We do not compete with the firm's accounting IT provider — we operate the security layer next to them. The program is managed detection and response, identity threat detection, and security awareness training, with the WISP maintenance, the FTC Safeguards § 314.4(f) evidence chain, the seasonal-contractor identity lifecycle, and cyber-insurance readiness attached. The vertical deep dive lives on the CPA and accounting cybersecurity page.
If the pressure point is a cyber-insurance renewal, an IRS Stakeholder Liaison conversation, or a Safeguards program review already on the calendar, the Cyber Insurance Readiness Sprint is the fixed-scope engagement — from $1,500, delivered in seven business days — that turns the questionnaire into a paperwork step.
Next step
If this article named a gap the firm already suspected, the practical starting move is either the free carrier questionnaire to score the firm before an underwriter does, or the Readiness Sprint if a renewal, a Safeguards program review, or a Stakeholder Liaison conversation is already on the calendar. For the broader tool-and-service-model taxonomy, the MDR vs EDR vs MSSP vs SOC-as-a-service decision tree is the buyer-side companion piece.