Skip to content

Texas Accounting Firm IT in 2026: The FTC Safeguards Rule Playbook

By Donovan Brown
July 12, 2026
13 sections
Texas Accounting Firm IT in 2026: The FTC Safeguards Rule Playbook

CPA and tax firms hold the data criminals want most — and the FTC Safeguards Rule now legally requires you to protect it. Here is the 2026 IT and security playbook for Texas accounting practices.

01

Introduction

If you run a CPA firm, a bookkeeping practice, or a tax-preparation office in Texas, you are holding the most concentrated pile of sensitive data most criminals will ever find: Social Security numbers, bank account details, full financial histories, and the login credentials to your clients' payroll and banking portals. That combination makes accounting firms one of the highest-value targets in the SMB world — and since 2023 it also puts you squarely under the FTC Safeguards Rule, a federal regulation that many Texas firms still do not realize applies to them.

This guide explains what the Safeguards Rule requires, why accounting firms are targeted, and the specific IT and security controls a Texas practice needs in place before the next busy season — and before a client's stolen refund lands your firm in an IRS data-loss investigation.

02

Why the FTC Safeguards Rule Applies to Your Firm

The Safeguards Rule is part of the Gramm-Leach-Bliley Act, and its definition of a "financial institution" is far broader than banks. The FTC has explicitly stated that tax preparers, accountants, and CPA firms are covered financial institutions. The IRS reinforces this: every firm with a Preparer Tax Identification Number is required to maintain a written information security plan, and that requirement is now checked at the point of PTIN renewal.

The rule stopped being aspirational in June 2023, when the amended version took effect with concrete, technical mandates. If your "security plan" is a one-page document your prior IT vendor wrote and nobody has opened since, you are not compliant — and worse, you are not protected.

03

The Nine Elements You Are Required to Have

The Safeguards Rule spells out specific elements every covered firm must implement. In plain English:

  • A named Qualified Individual — one person accountable for your security program (they can be internal or a designated contact at your outsourced IT provider).
  • A written risk assessment — documented, not verbal, identifying where client data lives and what threatens it.
  • Access controls — least-privilege permissions so a seasonal preparer cannot reach the entire client database.
  • Encryption — of client data at rest and in transit, including on laptops and backups.
  • Multi-factor authentication — required for anyone accessing client information. This is non-negotiable and the single most common gap we find.
  • Data disposal — a defined process for securely destroying records you no longer need.
  • Change management and monitoring — logging and reviewing who accesses what.
  • Vendor oversight — holding your software and cloud providers to the same standard.
  • An incident response plan — a written plan for when, not if, something goes wrong.
04

Why Accounting Firms Get Hit Harder

Criminals target accounting firms for reasons unique to the profession:

  • Refund fraud at scale — one compromised firm yields hundreds of complete tax profiles, enough to file fraudulent returns before clients file their real ones.
  • Seasonal staffing — the flood of temporary preparers each spring expands the number of people with data access and shrinks the time available to vet and train them.
  • Business email compromise — attackers impersonate a partner or a client to redirect a wire or a refund. Accounting workflows revolve around exactly the kind of money-movement requests these scams exploit.
  • Client-portal credentials — your firm often holds logins to client banking, payroll, and QuickBooks environments, turning a breach of your office into a breach of every client.

The threat is compounded by increasingly convincing AI-powered phishing that mimics a partner's writing style and a real client's prior emails.

05

Multi-Factor Authentication: The Control You Cannot Skip

If you do one thing after reading this, enable MFA everywhere client data can be reached — email, your tax software, remote access, the client portal, and cloud storage. The Safeguards Rule requires it, cyber insurers now require it, and it single-handedly defeats the credential-theft attacks that cause most firm breaches. Push-based or app-based authenticators are strongly preferred over SMS codes, which can be intercepted. For your most privileged accounts — the admin logins and the partner accounts that can move money — layer on the tighter controls we describe in our guide to privileged access management.

06

Securing the Seasonal Surge

The busy season is your highest-risk window. More people, more data movement, more fatigue, and more urgency for attackers to exploit. Prepare before January:

  • Provision access on a least-privilege basis — seasonal staff get exactly the clients and systems they need, and access is revoked the day the engagement ends.
  • Secure remote work — preparers working from home need encrypted, authenticated connections, not a shared password. Our comparison of secure remote access options covers the practical choices.
  • Run a phishing refresher — a fifteen-minute training and a simulated phishing email before tax season catches the mistakes before a criminal does.
  • Lock down data disposal — the temporary files, printouts, and scratch copies that pile up in March need a defined destruction path.
07

Encryption and Backups That Survive an Attack

Encryption is explicitly required, and it is also your last line of defense: an encrypted laptop stolen from a car is a lost asset, not a reportable breach. Encrypt endpoints, encrypt backups, and encrypt data in transit to and from your tax software. Then make sure your backups are immutable and tested — ransomware crews specifically target accounting firms in the weeks before a filing deadline because the pressure to pay is highest. A backup you have never restored from is a hope, not a plan.

08

Cloud Accounting Software Doesn't Make You Compliant

Moving to QuickBooks Online, a hosted tax package, or a cloud document portal shifts where the data lives, but it does not shift the Safeguards obligation off your firm. Under the rule you remain responsible for vendor oversight — you must confirm your providers protect the data you entrust to them, and you must configure their security features rather than assuming the defaults are enough.

  • Read the shared-responsibility model — the vendor secures the platform; you secure the accounts, the access, and the configuration. A misconfigured sharing setting on a cloud folder is your breach, not theirs.
  • Turn on the security features you are paying for — MFA, audit logging, and role-based access are usually available and usually off by default.
  • Keep a vendor inventory — a simple list of every service that touches client data, what it holds, and its security posture. This is also the foundation of the SaaS-integration hygiene we cover elsewhere.
  • Watch for credential sprawl — every cloud tool is another login that can be phished or stuffed, which is why dark web monitoring for exposed firm credentials belongs in your program.

Consolidating this oversight is one of the clearest arguments for a single managed IT partner who can hold every vendor to one standard rather than leaving each software choice to police itself.

09

Your Written Information Security Plan (WISP)

The IRS provides a WISP template, but a template is a starting point, not a finished program. Your WISP has to reflect how your firm actually handles data: which software you use, where files are stored, who has access, and how you respond to an incident. It must be a living document, reviewed at least annually and updated when your systems change. Firms pursuing broader assurance often align their WISP with a recognized framework — our guide to SOC 2 readiness and our SOC 2 compliance resources show how a formal control framework maps onto these requirements and reassures larger clients.

10

When Something Goes Wrong: The Reporting Clock

The amended Safeguards Rule added a breach-notification requirement: certain incidents involving 500 or more consumers must be reported to the FTC within 30 days. Texas has its own breach-notification statute on top of that. The practical takeaway is that you need a written, rehearsed incident response plan before an incident, because the clock starts the moment you discover the problem — not the moment you finish investigating it. Rehearse it the way we describe in our guide to tabletop exercises, and remember that adopting a recognized framework can also provide an affirmative defense under Texas SB 2610.

12

Where to Start

Begin with an honest gap assessment against the nine Safeguards elements: do you have MFA everywhere, a current written risk assessment, least-privilege access, tested encrypted backups, and an incident response plan? Most Texas firms find three or four gaps, and the highest-impact fix — turning on MFA across every client-data system — can be done in days, not months. LayerLogix helps accounting and tax practices build and operate a compliant program through our compliance-focused cybersecurity and managed IT services. Start with a free IT assessment that measures your firm against the Safeguards Rule and the threats aimed at your profession, or review our full compliance services to see how the pieces fit together.

13

Geographic Coverage

LayerLogix provides FTC Safeguards support, WISP development, and managed security for accounting and tax firms across Texas, with local, Texas-based teams. We serve CPA and bookkeeping practices in Houston, Austin, Dallas, Fort Worth, and Sugar Land. With 20+ years of experience and 100% Texas-based support, we help firms protect client data through tax season and every season after it.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call