Cybersecurity for CPA & Tax Firms

A secure portal is not the same as a secure firm.

Your clients trust you with their tax returns, Social Security numbers, and bank accounts — the raw material of their financial lives. The portal protects one room. Droptine secures the building.
Book a consultation
Check your exposure
30 minutes. A strategic conversation. Clear next steps.
Financial documents and calculator representing client data protection

Where "we're secure" comes from

Somewhere along the way, your company bought a product with "secure" in the name. A portal. A vault. Encrypted file sharing. The sales rep said "secure", so the firm feels secure.

Here's what that promise of security actually covers: itself.

It doesn't secure the email account that receives the portal notifications — the same account that can reset its password.

It doesn't manage the laptop a preparer takes home or the public wifi used in a coffee shop.

It doesn't stop a client file from being downloaded to a desktop and forgotten there.

The firms that get hurt aren't careless. They just protected the door the brochure called secure, and left the rest on the honor system.
Audit Your Risk in 2 Minutes
Man in blue shirt and tie working at desk with laptop, papers, and notebook near a bright window.

Client data lives behind three layers. Most firms have only secured the first.

Layer 1 — The portal and the data behind it

The layer you already bought. It matters — and it inherits the weaknesses of the two layers around it. A secure portal opened from a compromised inbox on an unmanaged laptop is not secure. It's just expensive.

Layer 2 — Email

The outermost layer and the first one tested by bad actors. Email holds password resets, client conversations, and notification links into everything else. An attacker who owns a partner's inbox rarely needs to "hack" anything more.

Layer 3 — Devices

Every laptop, desktop, and phone that touches client data — at the office, at home, at a kid's soccer game. A personal device with downloaded client files connecting to unsecure WiFi is a breach waiting to happen.

All three layers have to hold. Droptine makes sure you're secured from every angle.

Schedule a Consultation

Six questions worth answering honestly

Before any tools, any contracts, any spend — a financial firm should be able to answer these:
Who can access client tax and financial data, and from what devices?

If a laptop or phone is lost, stolen, or taken home, is the data on it fully encrypted and remotely wipeable?

Is Multi-Factor Authentication (MFA) strictly required to log into every email, tax portal, and cloud drive?

If ransomware encrypted our entire system today, how fast could we recover—and when was our backup last tested?

How do we verify client identity before sending sensitive documents or executing wire transfers?

Are our security practices compliant with the FTC Safeguards Rule, IRS Publication 4557 mandates, and WISP requirements?

Count the answers you weren't sure about. Most firms find two or three. That's not a crisis but it is a starting list, and lists can be worked.
Get a plan — book a consultation
Entrance of the Federal Trade Commission building with metal doors featuring ship and airplane designs.

CPAs and Tax preparers answer to more than one rulebook

You rarely have just one security requirement to satisfy. Your cyber insurer wants MFA, managed devices, and tested backups before it renews. Larger clients send security questionnaires before they'll share another file.

Firms that prepare tax returns are expected to keep a written information security plan; firms that provide financial services fall under the FTC Safeguards Rule. And every state has a data-breach law sitting behind all of it.

Here's the part nobody spells out: these requirements are mostly asking about the same handful of fundamentals — who can get in, from what devices, with what protection, and whether you can prove it.

Droptine builds one security program that answers all of them: the actual controls, the monitoring, and documentation that matches what's really running. When the insurance renewal, the client questionnaire, or the auditor shows up, the work is already done and the proof already exists.

Schedule a Consultation

What working with Droptine covers


MFA and access controls on email and every system that touches client data

Managed, monitored firm devices — and a plan for the personal ones

Portal permissions and download policies that match how the firm actually works

Backups that are protected, tested, and ready for your busiest week

Security policies and documentation that describe real controls — including a WISP if your firm needs one — kept current

Answers for insurers, regulators, and the occasional client who asks hard questions

Monitoring and maintenance after setup — because firms change, and security drifts

The Droptine plan, for CPA firms

01

Find the exposure

The first step is tracing where client data actually goes: inboxes, downloads, home offices, and the seasonal hire from two busy seasons ago. The paths nobody mentions in the brochure are usually the ones that matter.
02

Lock down what matters

Email and access first; they're what attackers test first. Then devices, downloads, backups, and the policies that hold it together.
03

Maintain the program

The program you set up this year won't match the firm you're running in three years. We keep the controls, monitoring, and documentation current, so the answer to "are we secure?" doesn't quietly expire.
Schedule a Consultation
Check your Exposure
Sunset over foggy mountains with dark silhouettes and a cloudy sky.

Signs it's time to secure your firm


Preparers or contractors at the firm work from personal devices.

The portal is solid, but nobody can vouch for email security.

Client files get downloaded locally with no policy on where they land.

MFA is on for some tools, not all. Nobody is sure which.

Your security documentation is a template with the firm's name pasted in.

Your cyber insurance renewal asked questions you had to guess at.

Two or more sound familiar? That's exactly the firm this work is for.

Common Questions

The portal is one room. The breach usually comes through the hallway: an inbox without MFA, a personal laptop, a downloaded file nobody remembered. None of that is the portal vendor's job — which is exactly the problem.
Yes. We complete those questionnaires for you, bridge any compliance gaps they expose, and provide the exact documentation your enterprise or institutional clients need to feel confident keeping their business with you.
Yes—a Written Information Security Plan (WISP) is legally required by IRS Publication 4557 and the FTC Safeguards Rule for tax preparers. We don't just hand you a generic template; we build, implement, and maintain a custom WISP that matches how your firm actually operates.
General IT keeps your computers running and software updated, but specialized cybersecurity protects you from sophisticated attacks, regulatory fines, and data theft. We partner directly with your IT person to handle compliance, threat monitoring, and advanced security so they can focus on daily support.
Zero disruption. We handle initial onboarding and heavy lifting outside of tax season, and maintain strict "change freezes" during peak deadlines so your team stays 100% focused on tax work.
Absolutely. You won't get jargon or 50-page reports—you'll get a clear, executive dashboard showing your security posture, active protections, and exactly how we're keeping your firm compliant and safe.
Yes—hackers intentionally target smaller accounting firms because they hold the exact same high-value taxpayer data as large firms, but usually lack corporate-grade defenses.
Not at all. We specifically build custom, streamlined security programs tailored for 5 to 20-person CPA firms that need enterprise-grade compliance without enterprise-grade overhead.
Website content, self-assessment results, and consultation materials are for general informational purposes only. They are not legal advice, certification, audit findings, or a guarantee of compliance or security. Final requirements depend on your contracts, systems, data, and applicable laws and frameworks.

Protect the firm the way your clients assume you already do.

They handed you their financial lives. A 30-minute conversation will tell you whether the systems holding that trust deserve it.
Book A consultation
Check your exposure