IT and cybersecurity for accounting firms

Your client portal is locked. Is everything else in the firm?

Clients hand your firm their returns, Social Security numbers, and bank account details. A portal guards the files stored inside it. Droptine protects the inboxes, laptops, and people that handle those files everywhere else.
​
Book a consultation
Get your risk assessment
30 minutes. A strategic conversation. Clear next steps.
Financial documents and calculator representing client data protection

How firms come to believe they are covered

At some point the firm purchased software described as secure: a document portal, an encrypted vault, a protected file-sharing tool. The vendor promised safety, and the partners reasonably took that to mean the firm was safe.

That promise applies only to the product.

The mailbox where portal alerts arrive, and where a portal password can be reset, sits outside it. So does the notebook computer a preparer carries home and connects to coffee-shop Wi-Fi. So does the return saved to a desktop folder and never deleted. Firms that suffer a breach are seldom reckless. They locked the one entrance a vendor told them about and trusted the others to luck.
Get your risk assessment
Man in blue shirt and tie working at desk with laptop, papers, and notebook near a bright window.

Three places client data is at risk, and most firms protect one

1. Portal and tax software

You have paid for this one, and it does its job. Its strength still depends on what surrounds it. If a preparer opens the portal from a hijacked mailbox or an unmanaged home computer, the portal's own safeguards no longer count for much.

2. Email & cloud platforms

Criminals try the inbox before anything else. It contains reset links, client correspondence, and alerts that lead into your other systems. Once a partner's mailbox is taken over, the intruder seldom has to break into anything further.

3. Computers and phones

Client records end up on whatever machine a preparer uses, in the office or on the couch. An unprotected personal laptop on an open network, with returns saved locally, is an incident in the making.

A weakness in one undoes the other two. Droptine secures all three together.

A six-question self-check

Set software and contracts aside for a moment. Can your firm answer each of these with confidence?
​
Which people can open client tax and financial records, and on which computers and phones?

​
When a laptop or phone goes missing, is its drive encrypted and can you erase it remotely?

​
Does every mailbox, tax application, and cloud folder demand multi-factor authentication (MFA) with no exceptions?

​
Suppose ransomware locked every file this morning. How many days until you are working again, and when did someone last restore from backup?

​
What step confirms a client's identity before you release documents or act on a payment request?

​
Does the firm satisfy the FTC Safeguards Rule, and is its written information security plan (WISP) built on the guidance in IRS Publication 4557?

Tally the ones you hesitated on. Two or three is typical. That gives you a to-do list, and a to-do list can be finished.
Get a plan — book a consultation
Entrance of the Federal Trade Commission building with metal doors featuring ship and airplane designs.

Several parties now set your security requirements

A firm seldom answers to a single authority. The cyber insurance carrier will not renew without MFA, managed computers, and proven backups. Bigger clients send a security form ahead of sharing files. The FTC Safeguards Rule classifies tax preparers as financial institutions and requires a written information security plan (WISP). State breach-notification statutes apply on top of those.

What rarely gets explained is how much these demands overlap. Nearly all of them come down to a short list of basics: which people have access, on what equipment, under what safeguards, and what evidence you can show.

Droptine sets up a single program that satisfies the whole list, with working safeguards, monitoring, and paperwork that reflects your real setup. By the time a renewal form, client questionnaire, or examiner arrives, the answers are on file.

Warning signs inside an accounting firm


Staff or seasonal contractors prepare returns on computers they own.

You trust the portal, yet no one could confirm the mailboxes are protected.

Returns and source documents are saved to local drives, and there is no rule about it.

A few applications demand MFA while others skip it, and there is no record of which.

The firm's WISP began as a downloaded form and still reads like one.

The last insurance application included security items you answered by guesswork.

Common Questions

Yes. Hackers intentionally target smaller accounting firms because they hold the exact same high-value taxpayer data as large firms, but usually lack corporate-grade defenses. We specifically build custom, streamlined security programs tailored for 5 to 20-person CPA firms that need enterprise-grade compliance without enterprise-grade overhead.
A portal protects what is stored in it. Break-ins tend to start elsewhere: a mailbox lacking MFA, a preparer's own notebook computer, a return saved to a desktop last April. The portal company was never hired to guard those, so someone else has to.
Your IT person handles working computers and current software. Writing the WISP, watching for intrusions, and answering the insurer call for a separate skill set. Droptine covers those duties and coordinates with your IT person, who keeps doing daily support.
Yes to both. The FTC Safeguards Rule is the legal source of the requirement, since it treats tax preparers as financial institutions. IRS Publication 4557 gives the guidance, Publication 5708 offers a sample plan, and your PTIN renewal asks you to confirm a plan exists. We write a WISP around the way your firm really operates, put its safeguards in place, and update it each year.
Yes. We complete those questionnaires for you, bridge any compliance gaps they expose, and provide the exact documentation your enterprise or institutional clients need to feel confident keeping their business with you.

Give client data the protection your clients believe it already has.

They handed you their financial lives. A 30-minute conversation will tell you whether the systems holding that trust deserve it.
Book A consultation
Get your risk assessment