IRS Pub 4557 + FTC Safeguards-aligned cybersecurity for the firm, not the brochure.
Managed cybersecurity for CPA, tax, and accounting firms that run Lacerte, Drake, CCH Axcess, UltraTax, Microsoft 365, or Google Workspace. We operate MDR, ITDR, and Security Awareness Training, then package the WISP and FTC Safeguards evidence your IRS Stakeholder Liaison and cyber-insurance carrier expect.
Obsidian Ridge is a CISSP-led managed security provider serving CPA, tax, and accounting firms in the Research Triangle and across the United States; managed detection and response starts at $25 per person per month on Ridge Core, month-to-month with no minimum and no contract, with 24/7 monitoring of every computer and email login and human-led containment, and it maps to IRS Publication 4557, the FTC Safeguards Rule, and a written information security plan (WISP).
We operate managed detection and response, ITDR, and Security Awareness Training for your firm end-to-end. The 24/7 SOC watches every endpoint and your Microsoft 365 or Google Workspace tenant for the attack patterns documented across the accounting vertical:
Ransomware against the tax software server during tax season
Refund-redirect BEC
Wire-fraud aimed at client trust funds
Obsidian Ridge adds the security-operations side: an IRS Pub 4557 + FTC Safeguards Rule § 314.4-aligned Written Information Security Plan, the AICPA SSTS § 1.3 documentation, the IRS Stakeholder Liaison-ready incident response runbook, cyber-insurance readiness, and the quarterly managing-partner briefing.
Pricing, per month:
Ridge Core, $25 per person: every computer and every email login watched 24/7.
Ridge Plus, $50 per person: adds the awareness program, email protection and a secure browser for your work apps. This is the tier to look at: it covers the controls cyber insurance applications ask about, including business email compromise.
Ridge Reserve, $70 per person: adds the incident response plan, access reviews and patch reporting carriers ask about.
Log collection is Ridge Log, an add-on on any tier.
To see which AI apps and agents can reach client information, start with an AI security assessment and review the findings and fixes with a CISSP.
Not ready for the full program yet? Ridge Watch ($15 per device per month, monitoring only) is an honest first step — real protection now, though a firm handling client financial data will want the controls above before a renewal or a WISP review.
A staff member downloads a client's tax return to a home laptop.
Set the rule for each app: allow, watermark or block the action.
01Copy
02Paste
03Download
04Upload
05Print
06Screenshot
Illustrative controls. Rules are configured for your work apps.
What's included
Everything we operate for a CPA firm
Managed detection and response on every endpoint and tax software server
Preparer laptops, partner workstations, the Lacerte / Drake / CCH Axcess / UltraTax server, the firm's M365 / Workspace box. The 24/7 SOC watching for ransomware canaries, credential theft, and the lateral-movement patterns documented in accounting-vertical attacks.
Managed ITDR on Microsoft 365 / Google Workspace
On either platform it catches stolen session tokens replayed from somewhere new and the inbox rules used to hide refund-redirect and wire-fraud activity. On Microsoft 365 it also catches the adversary-in-the-middle kits that bypass MFA (EvilProxy, Tycoon) and the OAuth-consent attacks against firm tenants.
Managed Security Awareness Training
Tax-season-tuned phishing simulations: IRS notice impersonation, EFIN suspension threats, ADP/Gusto payroll lookalikes, refund-redirect themes for preparers and seasonal contractors.
WISP + FTC Safeguards Rule evidence package
The Written Information Security Plan the FTC Safeguards Rule requires, built on the IRS Publication 5708 outline, the FTC Safeguards Rule § 314.4 documented program, the AICPA SSTS § 1.3-aligned procedures, and the audit-control logs the IRS Stakeholder Liaison wants to see.
Security settings review
We review MFA, admin separation, user access, former staff (including last season's contractors), external sharing and audit logging in the firm's tax, practice-management and document-management systems (Lacerte, Drake Tax, CCH Axcess, UltraTax CS, ATX, ProConnect and the like), and deliver a list of fixes the firm or its IT vendor applies.
Incident response coordination
If something happens, we coordinate forensics, prompt IRS Stakeholder Liaison notification, FTC notification for 500+ consumer breaches, state AG filings, cyber-insurance claim, and client-facing communication. The Qualified Individual remains the decision-maker; we operate every step.
How we work
Alongside your current IT company
Keep your IT company. They handle the help desk, the hardware and the everyday fixes. We run the security layer beside them: threat detection and response, and the evidence insurers and auditors ask for.
For the wider set of regulated-industry writeups — IRS Pub 5708, WISP templates, cyber-insurance controls, breach-notification law — browse the compliance blog.
The insurance wedge
Insurance renewal or new application? Start with the Readiness Sprint.
Maybe a cyber-insurance renewal just arrived, often mid tax season, with a 2026 questionnaire asking for:
A WISP
MFA coverage
A social-engineering-fraud control the firm can't yet evidence
In 7 business days the Cyber Insurance Readiness Sprint maps every question on your carrier's questionnaire to the control that answers it, closes the gaps we can, and hands you a signed evidence pack.
Flat fee, $1,500–$3,500 depending on office count and scope. Delivered, or we keep working at no additional cost until it is. We don't control underwriter decisions. We control whether you walk in with the evidence they ask for.
Obsidian Ridge is not an insurance producer, broker, or agent. We do not sell, place, or advise on insurance products.
Account hygiene, MFA on the tax software itself, seasonal-contractor lifecycle, audit-log review, e-signature integration tokens, and the on-prem server hardening checklist.
The 2026 underwriting questionnaire, the social-engineering rider that matters for tax-season wires, and the operational sequence that passes the application.
The role-distinction reframe for CPA firms. What your IT provider owns, what a security operation owns, the specific questions to ask to tell whether the layer is covered, and why co-managed is the healthy model.
Firms with seasonal-contractor surges that need a defensible identity lifecycle
Multi-office CPA groups consolidating after acquisitions or partner additions
Managing partners who want CISSP-led security expertise without staffing it internally
And who it is not for
Firms with no email, no tax software, and no cloud anything (rare in 2026)
Firms already operating an in-house 24/7 SOC with senior identity-security expertise
Firms looking for a one-time WISP template PDF with no ongoing service
How we start
From first call to operating program
01
Discovery call (30 minutes)
Tell us how the firm runs. Tax software, partner count, seasonal staffing model, current IT firm, cyber-insurance renewal date, any recent incidents, and what is driving the conversation. We tell you which tier fits and where the real risks are.
02
Scoped proposal (within 3 business days)
Endpoint and user counts, tier recommendation, the implementation schedule, and the WISP + FTC Safeguards deliverables. Fixed monthly pricing. Month-to-month or annual. No vendor markup games.
03
Deployment (5–10 business days)
Managed EDR agent on every endpoint and tax software server. Managed ITDR connected to your Microsoft 365 or Google Workspace tenant. Awareness program launched with a phishing simulation calibrated to your firm's practice areas. Written engagement agreement covering FTC § 314.4(f) vendor oversight signed before any access.
04
24/7 operation + 90-day check-in
The 24/7 SOC is watching from day one. Obsidian Ridge handles escalations, quarterly managing-partner briefings, the WISP maintenance, the FTC Safeguards Qualified Individual annual report support, the cyber-insurance renewal package, and the tabletop exercise every firm should be running annually.
FTC Safeguards Rule in plain English
What the rule actually requires.
The FTC Safeguards Rule at 16 CFR Part 314 applies to non-banking financial institutions under FTC jurisdiction — a definition the FTC treats as including tax preparers and many CPA firms. Two provisions come up most often on cyber applications and in enforcement:
§ 314.4(j) breach notification: as of May 13, 2024, notify the FTC no later than 30 days after discovery of a notification event involving unencrypted customer information of 500 or more consumers.
§ 314.4(f) service-provider oversight: select service providers capable of maintaining appropriate safeguards, contract with them to do so, and periodically assess them based on the risk they present.
This is a general summary for educational purposes, not legal advice. Coverage and application depend on your specific circumstances and change over time. Consult qualified counsel and the official FTC guidance. Source: FTC Safeguards Rule (ftc.gov).
The WISP, from the IRS original
What IRS Publication 5708 says a WISP needs.
The IRS and the Security Summit wrote Publication 5708 to help tax professionals, particularly smaller practices, write a Written Information Security Plan.
It says that under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are financial institutions regardless of size, and that the Safeguards Rule requires a WISP: “Your WISP must be written and accessible.”
What the FTC requires of each firm, as the IRS lists it
A qualified individual who coordinates the information security program.
A risk assessment of customer information in each relevant area of the firm, and an evaluation of how well the current safeguards control those risks.
A safeguards program, designed and implemented, then regularly monitored and tested.
Service providers that can maintain appropriate safeguards, with contracts that require them to, and oversight of how they handle customer information.
Adjustments as the business changes, or as testing and monitoring turn up results.
Multi-factor authentication for anyone accessing any information system, unless the qualified individual approves reasonably equivalent or more secure access controls in writing.
A report to the FTC for a security event affecting 500 or more people, as soon as possible and no later than 30 days after discovery.
How the IRS says to build it
Size it to the firm: “a sole practitioner can use a more abbreviated and simplified plan than a 10-partner accounting firm.” Cover physical, technical and administrative safeguards.
The publication's outline runs, in order:
Objectives and scope
The qualified individual and authorized users
The risk assessment and a hardware inventory
The safety measures
An employee code of conduct
An implementation clause
The attachments
It suggests a signed employee and contractor acknowledgment, updated at annual training, and it calls the WISP an evergreen document to be regularly reviewed, tested and updated.
Where our services fit
The monitoring the program needs: managed detection and response on every computer and server, watched by Huntress's 24/7 SOC.
Multi-factor authentication evidence: a coverage report, and from Ridge Core, identity threat detection on the sign-ins MFA protects.
Training records: security awareness training with completion records on Ridge Plus and Ridge Reserve, to sit beside the signed acknowledgments.
The evidence: the Readiness Sprint maps your carrier's questionnaire to the control that answers each question and hands you a signed evidence pack.
Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States.
Help writing and evidencing your IRS WISP
A written information security plan needs to describe your actual practice: who coordinates security, where taxpayer information is held, what risks you identified and how safeguards are checked. The IRS provides Publication 4557 and a WISP template in Publication 5708. Use them to document decisions, rather than buying a template and treating it as proof of implementation.
Obsidian Ridge helps connect the controls we operate to the records you keep: endpoint and identity incidents, training completion, and separately scoped log evidence. The Readiness Sprint can organize control evidence and gaps. Your firm still owns its WISP, supplier decisions and legal obligations. Read the CPA WISP and FTC Safeguards guide. See the IRS WISP resources.
Questions managing partners ask
Frequently asked questions
Can you help our accounting firm write and evidence its WISP?
We can help document the security controls we operate and organize evidence and gaps for your firm's WISP. Start with IRS Publications 4557 and 5708. Your firm remains responsible for approving and maintaining its written plan, and for meeting the FTC Safeguards Rule obligations that apply to it.
Are you an IRS-authorized e-file provider or PTIN holder yourself?
No, and we don't claim to be.
We deliver the technical safeguards that IRS Publication 4557, the FTC Safeguards Rule, and AICPA SSTS § 1.3 require — audit controls, encryption, MFA, identity threat detection, integrity monitoring — and we package the evidence the IRS Stakeholder Liaison and FTC investigators expect to see.
We are not your Qualified Individual (FTC § 314.4(a) — that role lives with a designated firm partner) and we are not your tax practice's professional-standards interpreter.
Do you replace our IT company?
No. We are a managed cybersecurity firm, not an MSP. Your IT firm continues to handle help-desk, Wi-Fi, hardware procurement, and tax software upgrades.
We handle 24/7 monitoring, identity threat detection, security awareness training, incident response coordination, and the WISP + FTC Safeguards Rule evidence package. The two functions belong with different specialists.
What does this cost for a 4-preparer CPA firm?
Ridge Core starts at $25 per person per month, covering every workstation, the tax software server and partner laptops with 24/7 monitoring plus identity monitoring on the Microsoft 365 or Google Workspace accounts.
Ridge Plus at $50 per person per month adds the awareness-training program, email protection and a secure browser for your work apps.
Ridge Reserve at $70 per person per month adds the incident response plan, quarterly admin-access reviews and monthly patch reporting for practices with an upcoming insurance renewal or audit.
We use Lacerte / Drake on a local server. Can you protect it?
Yes. Our managed EDR runs on Windows Server. We deploy the agent on the tax software server, every preparer workstation, every staff laptop, and the front-desk machine.
The tax software server is usually the highest-value endpoint in the firm and the one most MSPs overlook on EDR coverage — we treat it as the priority.
What if we use CCH Axcess or UltraTax — cloud platforms?
Cloud tax software shifts the server burden to the vendor and the threat model toward account compromise.
That is where Managed ITDR matters most: monitoring sign-in anomalies, mailbox rules, and token-replay attacks on your M365 or Workspace tenant, plus OAuth consent on Microsoft 365 — the front door to the cloud tax software.
Endpoint coverage is still important because preparers' laptops still get phished, and Ridge Core already covers both sides, so it is the standard starting point for cloud-tax-software firms.
How long does deployment take?
Endpoint agent rollout typically completes within 5 business days of contract signing. Identity threat detection on Microsoft 365 or Google Workspace activates within 24–48 hours of tenant connection.
The awareness training program launches within the first two weeks. The WISP outline and incident response plan are drafted in the first 30 days and reviewed with the Qualified Individual before finalization.
What about seasonal contractors during tax season?
Seasonal contractors are the highest-risk identity surface in any accounting firm — provisioned in February, used for 10 weeks, often skipping training.
We deploy SAT modules and MFA enrollment as part of onboarding, document the deprovisioning date (April 16, no exceptions), and ensure their tax software access ends at the same time as their M365 access.
The contractor lifecycle is a documented part of the WISP we help maintain.
Do you help with cyber insurance renewals?
Yes. Our Cyber Insurance Readiness sprint maps the carrier questionnaire to the actual controls you have or need, packages the evidence the underwriter wants to see, and tells you honestly which gaps are worth closing before renewal.
The goal is to turn a declined, surcharged, or uncertain application into a cleaner underwriting conversation backed by evidence.
What happens if we have a breach during your service?
Huntress's 24/7 SOC acts on the alert around the clock. For an active incident, call your cyber insurance carrier's breach hotline first; there is no emergency line here.
Within one business day, Obsidian Ridge takes over everything past containment.
We coordinate forensics, walk through prompt IRS Stakeholder Liaison notification (the IRS asks preparers to report data theft immediately), the FTC 30-day notification for breaches affecting 500+ consumers, the state breach-notification clocks, the cyber-insurance claim, and the client-facing communication.
The firm's Qualified Individual remains the decision-maker for legal and client disclosures; we operate every technical and process step.
Two ways to start
See where you stand, or talk with us.
The 10-minute assessment scores your firm against the controls the IRS, FTC, and your carrier ask about — no email required to see your result.
The 30-minute accounting briefing goes deeper — tax software, partner count, seasonal staffing, insurance renewal, the threat model, and what your first 90 days would look like.
Both are free, both are no-obligation, and we tell you when you don't need us.