What Happens If a Houston CPA Firm Suffers a Data Breach During Tax Season?

If a Houston CPA firm suffers a data breach during tax season, the technical problem is only the beginning.

The firm may need to determine what information was accessed, contain the attack, preserve evidence, restore affected systems, notify regulators and potentially notify clients — all while trying to keep tax returns moving toward filing deadlines.

Under the FTC Safeguards Rule, covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovering a qualifying breach involving the unauthorized acquisition of unencrypted information belonging to at least 500 consumers.

Texas law adds another set of requirements. Businesses generally must notify affected Texas residents without unreasonable delay and no later than 60 days after determining that a breach occurred. If at least 250 Texas residents are affected, the Texas Attorney General must also be notified as soon as practicable and no later than 30 days after the breach is determined.

And for tax professionals, the IRS advises firms experiencing client data theft to contact their local IRS Stakeholder Liaison immediately.

Those notification deadlines matter.

But during February, March and April, another problem can become just as damaging: keeping the CPA firm operational while the incident is being investigated.

The First 72 Hours: What a CPA Firm Data Breach Can Actually Look Like

Most cyberattacks against CPA firms don't begin with a dramatic message announcing that someone has hacked the network.

They often begin with an email.

An employee receives what appears to be a Microsoft 365 login request, client document notification, tax software message, password reset, shared file, vendor invoice or even communication appearing to come from the IRS.

The employee clicks the link and enters a password.

Nothing obvious happens.

That is what makes these attacks dangerous.

Hours or days later, the firm may discover unusual email activity, suspicious Microsoft 365 logins, messages being sent from an employee's account, files being accessed unexpectedly or a workstation behaving abnormally.

If ransomware is involved, the first obvious indication could be encrypted files or computers that employees can no longer use.

What should happen next?

Contain the affected system or account.
The compromised computer, user account or cloud session needs to be isolated quickly so the attacker cannot continue moving through the environment.

Determine the scope.
A compromised Microsoft 365 account and a compromised network are very different incidents. The investigation needs to determine what the attacker accessed and whether client information may have been exposed.

Preserve evidence.
Security logs, Microsoft 365 audit information, endpoint telemetry, firewall logs and other evidence can become extremely important when determining what happened and what reporting obligations may apply.

Document the response.
The firm should maintain a timeline showing when the incident was discovered, what was found and what actions were taken.

Bring in the right resources.
Depending on the severity of the incident, that may include the firm's managed IT provider, cybersecurity specialists, cyber-insurance carrier, legal counsel and other incident-response professionals.

For a small CPA firm, this is where valuable time can disappear.

The challenge isn't simply removing malware or resetting a password. It is figuring out what happened, how far it went, what information was affected and who needs to know about it — while the tax-season clock keeps moving.

Who Does a CPA Firm Need to Notify After a Data Breach?

A CPA firm handling taxpayer information isn't dealing with only an IT issue after a breach. Depending on what happened, federal and state notification requirements may apply.

FTC Safeguards Rule

Tax preparation and accounting firms can fall under the FTC Safeguards Rule as financial institutions.

For a qualifying notification event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers, the FTC requires notification as soon as possible and no later than 30 days after discovery.

The FTC also treats encrypted information as unencrypted for this purpose if the encryption key was accessed by an unauthorized party.

Texas Data Breach Law

Under Texas Business and Commerce Code §521.053, affected Texas residents generally must be notified without unreasonable delay and no later than 60 days after the business determines that a breach occurred, subject to certain exceptions.

If the breach involves at least 250 Texas residents, the organization must also notify the Texas Attorney General as soon as practicable and no later than 30 days after determining that the breach occurred.

IRS

The IRS recommends that tax professionals report client data theft to their local IRS Stakeholder Liaison immediately.

The IRS notes that speed matters because early notification can allow the agency to take steps designed to prevent criminals from filing fraudulent tax returns using stolen client information.

Clients

Depending on the facts of the incident and applicable notification requirements, affected clients may also need to be notified.

For a CPA firm, this can be one of the most difficult parts of the incident.

Clients have entrusted the firm with Social Security numbers, income information, banking information, tax returns and other highly sensitive financial records.

How the firm responds can have a lasting impact on that relationship.

What Does a Data Breach Cost a Small CPA Firm?

There isn't one reliable number that applies to every small accounting firm.

A compromised email account discovered quickly may look very different from a ransomware incident involving dozens of computers and thousands of client records.

However, once outside incident-response services become necessary, costs can accumulate quickly.

For a small firm, $25,000 to $100,000+ in breach-response costs is a reasonable planning range, while a serious ransomware event, extensive data exposure or prolonged business interruption can cost considerably more.

Those costs can include:

  • Digital forensic investigation
  • Cybersecurity incident-response services
  • Specialized privacy or cybersecurity legal counsel
  • Client notification
  • Credit or identity monitoring
  • Data and system recovery
  • Emergency IT work
  • Cyber-insurance deductibles
  • Lost productivity
  • Business interruption

And during tax season, the indirect costs can become especially significant.

Lost Production

Every hour partners, managers and employees spend working through a security incident is an hour they aren't preparing returns, communicating with clients or completing other billable work.

During February through April, that time is difficult to recover.

Client Trust

A data breach at a company that sells ordinary consumer products is serious.

A breach at a CPA firm is different.

Accounting firms may hold Social Security numbers, W-2s, K-1s, bank information, payroll records, financial statements and complete tax returns.

Clients understand how valuable that information is.

Filing Deadline Risk

If employees cannot access files, email, tax software or other systems, the cybersecurity incident quickly becomes a business-continuity issue.

Now the firm isn't just responding to an attack.

It may also be explaining why client work has been delayed while an IRS filing deadline continues approaching.

How One Houston CPA Firm Reduces Its Risk During Tax Season

One Houston CPA firm supported by Scorpion Technology operates under a fully managed IT and cybersecurity model.

That matters throughout the year, but it becomes particularly important as tax season approaches.

During filing season, accountants naturally receive more email.

Clients send documents. Employees exchange tax information. Vendors send notifications. Tax software generates messages. Microsoft 365 produces legitimate security alerts.

Attackers understand that.

We also see suspicious and phishing email activity targeting the types of communications accounting firms expect to receive — including Microsoft 365 alerts, document-sharing requests, password resets and messages designed to appear as though they came from clients or trusted organizations.

For this Houston CPA firm, security doesn't depend on one employee recognizing every bad email.

It starts before the message reaches the employee.

Layer 1: Managed Email Security

The firm's Microsoft 365 email is protected by Proofpoint managed email security.

Potential phishing messages, malicious links and other suspicious email can be analyzed and blocked before reaching an employee's mailbox.

That distinction is important.

If a malicious message never reaches the Microsoft 365 mailbox, the protection isn't limited to the employee's office computer.

It also reduces exposure when that employee checks the same mailbox from a smartphone, tablet or another device outside the CPA firm's office.

But email filtering alone is not enough.

Layer 2: Fully Managed Endpoint Detection and Response

Company computers are protected by a managed endpoint detection and response platform, or EDR.

EDR monitors endpoints for behavior that may indicate malware, ransomware, suspicious processes or other malicious activity.

Instead of relying solely on traditional antivirus signatures, endpoint detection looks for activity happening on the computer that may require investigation or containment.

Layer 3: Firewall, Web and DNS Protection

The firm's network is also protected by a managed firewall with content filtering and DNS security.

DNS filtering provides another opportunity to stop a connection when an employee or device attempts to reach a known malicious destination.

This matters because no security layer is perfect.

If a phishing message, malicious advertisement or compromised website gets past one control, another layer has an opportunity to stop the attack.

Layer 4: 24/7 Identity Threat Detection and Response

Modern attacks increasingly target identities rather than computers.

A criminal doesn't necessarily need to infect a workstation if they can steal an employee's Microsoft 365 credentials.

That's why this firm's security program also includes 24/7 identity threat detection and response, or ITDR.

Identity monitoring looks for suspicious activity associated with cloud accounts and Microsoft 365 — giving the security team another opportunity to identify an account takeover or unusual authentication activity.

The Result: Security Doesn't Depend on One Perfect Click

No cybersecurity company can credibly promise that every attack will be stopped.

And no employee — regardless of training — will recognize every sophisticated phishing message.

That's why the objective is layered security.

Email security tries to stop the attack before it reaches the employee.

DNS and firewall security provide another control if someone attempts to reach a malicious destination.

Endpoint detection watches what happens on the computer.

Identity monitoring watches the user's cloud account.

And managed security provides people who can investigate when one of those systems identifies something suspicious.

For the CPA firm, the desired outcome is remarkably simple:

Employees keep preparing tax returns while the security systems and IT team work in the background to prevent security events from becoming business disruptions.

Why Layered Cybersecurity Matters for CPA Firms

The question isn't whether a CPA firm should use antivirus, a firewall or email filtering.

The better question is:

What happens when one of those controls fails?

That's where layered cybersecurity becomes important.

Consider a phishing attack.

An effective security model gives the firm several opportunities to stop it:

  1. Email filtering identifies and blocks the phishing message.
  2. If the message gets through, security awareness training helps the employee recognize it.
  3. If the employee clicks, DNS or web filtering may block the malicious destination.
  4. If malicious software reaches the computer, EDR can detect suspicious behavior.
  5. If credentials are stolen, multifactor authentication and identity monitoring provide additional protection.
  6. If an attacker gets into Microsoft 365, 24/7 monitoring can identify abnormal account behavior.
  7. If data is damaged or deleted, tested backups provide a recovery path.

That's the difference between simply installing security products and actually having a managed cybersecurity strategy.

What Cybersecurity Should a CPA Firm Have Before Tax Season?

For small and midsize CPA firms, we generally recommend building security around several core areas.

Advanced email security
Email remains one of the primary ways attackers target accounting employees, particularly with phishing, credential theft and impersonation attacks.

Multifactor authentication
A stolen password should not automatically give an attacker access to Microsoft 365 or other business systems.

Managed endpoint detection and response
Company computers should be continuously monitored for suspicious activity rather than relying only on traditional antivirus.

24/7 identity monitoring
Microsoft 365 and other cloud identities need monitoring because many modern attacks never require traditional malware.

Firewall and DNS filtering
Network and DNS controls create additional opportunities to block known malicious destinations.

Security awareness training and phishing simulations
Employees should regularly see realistic examples of the attacks they are likely to encounter.

Microsoft 365 backup
Microsoft provides a highly resilient cloud platform, but firms still need an independent strategy for recovering accidentally or maliciously deleted business information.

SPF, DKIM and DMARC management
Email authentication helps prevent criminals from impersonating the firm's domain when targeting clients or employees.

Written Information Security Plan
Tax professionals should maintain a Written Information Security Plan, or WISP, documenting how taxpayer information is protected and how the organization will respond to security incidents.

Incident-response planning
The first time a CPA firm decides who should call the insurance carrier, attorney, IRS and IT provider should not be the morning a breach is discovered.

The Best Time to Prepare Is Before Filing Season

The best cybersecurity incident is the one that never becomes an incident.

For CPA firms, the months before filing season are the time to review Microsoft 365 security, backups, endpoint protection, firewall configuration, employee access, phishing defenses and incident-response procedures.

Waiting until February or March creates a much harder problem.

At that point, employees are busy, client email volume is high, deadlines are approaching and even a small interruption becomes expensive.

A good managed IT and cybersecurity program doesn't eliminate every risk.

It reduces the number of opportunities attackers have, improves the chances of detecting suspicious activity early and gives the firm a defined response when something does happen.

For a CPA firm entrusted with taxpayer information, that's an important distinction.

Houston CPA IT Support and Cybersecurity

Scorpion Technology is a Houston-based managed IT and cybersecurity provider serving small and midsize businesses.

We've served businesses in the Houston area since 2007, with experience in the IT industry dating back to 1999.

For CPA firms and other professional-services organizations, our focus is straightforward: protect Microsoft 365, endpoints, identities, email, networks and business data while giving employees a responsive IT team they can call when they need help.

Our managed services are designed around proactive monitoring and layered cybersecurity — not simply waiting for something to break.

If you're reviewing your CPA firm's cybersecurity before the next tax season, we can help you identify where your current protections are strong, where gaps may exist and which improvements actually make sense for the size of your firm.

Scorpion Technology LLC
Houston Managed IT & Cybersecurity
713-623-1266
ScorpionITSupport.com

This article provides general information about cybersecurity and data-breach response and is not legal advice. Organizations should consult qualified legal counsel regarding the notification and regulatory requirements that apply to a specific incident.