Tax season concentrates every risk factor an accounting firm has into a few months. Volume rises, temporary staff arrive, clients send sensitive documents through whatever channel is convenient, deadlines make everyone hurry, and attackers know all of this.
The compliance obligations do not pause for the season, and the practical difficulty is that the season is exactly when firms have least capacity to think about them.
Why the season is the risk
- Volume. More documents, more email, more new client relationships, and less time to scrutinise any of them.
- Seasonal staff. Temporary preparers and administrative help need rapid access to highly sensitive data, often with abbreviated onboarding.
- Deadline pressure. The reliable enabler of social engineering. A request marked urgent gets less scrutiny in March than in September.
- Client behaviour. Clients email tax documents as attachments, from personal accounts, on personal devices, because it is convenient.
- Targeted attacks. Phishing campaigns impersonating the IRS, tax software vendors, and clients rise sharply in the season. Attackers know the calendar.
The consequence of a compromise is also unusually severe. A firm holding Social Security numbers, income data, bank details and dependants' information for hundreds of clients is holding everything needed for identity theft and fraudulent return filing at scale.
What the Safeguards Rule requires
Firms performing tax work are financial institutions under the FTC Safeguards Rule and must maintain a written information security plan. The IRS reinforces this through Publication 4557, and PTIN renewal now includes an acknowledgement that preparers are required by law to maintain a written information security plan.
That acknowledgement deserves emphasis. False statements on that form are a criminal offence, and once the requirement has been formally acknowledged, a missing plan is a known compliance gap rather than an oversight — something considerably more serious than a compliance gap.
The requirements most relevant during the season:
- MFA for anyone accessing systems holding client information — explicitly required, not addressable
- Access controls limiting information to those who need it, which is where seasonal staff arrangements most often fail
- Encryption of client information at rest and in transit
- Monitoring of authorised user activity
- Secure disposal of information no longer needed, generally within two years of last use
- A written incident response plan
- Security awareness training for all staff, including temporary staff
| Requirement | What the rule says |
|---|---|
| Multi-factor authentication | For any individual accessing any information system |
| Encryption | Customer information at rest and in transit over external networks |
| Monitoring | Log and monitor authorised users' activity |
| Disposal | No later than two years after the information was last used, with limited exceptions |
| Incident response | A written incident response plan |
| Training | Security awareness training for staff |
| Breach reporting | Notify the FTC within 30 days of discovering an event affecting 500 or more consumers |
Seasonal staff, handled properly
This is where most firms have their real gap, because the pressure to get people productive quickly is enormous.
- Create individual accounts. Never shared logins, however temporary the role. Shared accounts destroy the audit trail the rule requires you to maintain.
- Set expiry dates at creation. A seasonal account should expire automatically rather than depending on someone remembering in May.
- Grant access by role and by client assignment. A preparer handling twenty returns does not need the full client database.
- Deliver and document security training before access is granted, not as a formality afterwards.
- Offboard on the last day. Disable accounts, terminate sessions, recover devices, revoke portal access.
- Run an access review in May. Every year, without exception. It reliably finds accounts that should have gone.
Client document exchange
Clients will email tax documents as attachments unless you make an easier alternative available. Email is a poor channel for this — it is frequently unencrypted in transit, it lands in mailboxes that may lack MFA, and it leaves sensitive material sitting in inboxes indefinitely.
The workable answer is a secure client portal, combined with a firm rule that documents are not accepted by email. That rule holds only if the portal is genuinely easy to use, so the choice of portal matters more than the policy statement.
It is worth communicating this to clients before the season rather than during it, and worth explaining that the firm will never ask them to email sensitive documents — which also inoculates them against the phishing that impersonates you.
The attacks that actually land
- Preparer account compromise, used to file fraudulent returns or to harvest the entire client database. The highest-consequence outcome.
- Client impersonation — an email apparently from a client asking for a copy of their return, or for a refund to be redirected.
- Fake IRS or software vendor communications, particularly account verification requests timed to the season.
- Payment redirection targeting the firm's own receivables.
- Ransomware timed for maximum leverage. A firm encrypted in late March faces different pressure than one encrypted in July, and attackers understand this.
The last point is worth planning for explicitly. Your recovery capability should be tested before the season, because the season is when you will most need it and least be able to afford a slow restore.
Preparation, by month
The realistic approach is to front-load the work outside the season.
- Autumn — review and update the WISP, run the risk assessment, test backup restores, review vendor agreements, confirm cyber insurance renewal requirements are met.
- Before the season — provision seasonal accounts with expiry dates, deliver and document training, confirm MFA coverage, communicate the portal process to clients.
- During — monitor for unusual access patterns, particularly out-of-hours activity on preparer accounts. Resist the temptation to grant broad access for speed.
- May — offboard every seasonal account, run the access review, and document what was done.
The IRS also expects prompt reporting of data theft to a Stakeholder Liaison, separate from the FTC notification obligation for events affecting 500 or more consumers. Both should be in the incident response plan with contact details already filled in.
| When | What to do |
|---|---|
| Autumn | Update the WISP, run the risk assessment, test restores, review vendor agreements, confirm cyber insurance requirements |
| Before the season | Provision seasonal accounts with expiry dates, deliver and document training, confirm MFA, tell clients about the portal |
| During the season | Watch for unusual access, especially out-of-hours activity on preparer accounts; resist granting broad access |
| May | Offboard every seasonal account, run the access review, document what was done |
Sources
- Federal Trade Commission — FTC Safeguards Rule: What Your Business Needs to Know
- Legal Information Institute, Cornell Law School (text of the FTC Safeguards Rule) — 16 CFR § 314.4 - Elements
- Internal Revenue Service — IRS, Security Summit remind tax pros they need a Written Information Security Plan to protect client data (IR-2026-92)
- Internal Revenue Service — Protect your clients; protect yourself
- Internal Revenue Service — Data theft information for tax professionals


