💙 Love us or your money back — first 3 months of service

NEWSROOM

Every Tax Preparer Is a Financial Institution Under Federal Law. Many Have No Written Security Plan.

The IRS is in the final week of its summer campaign telling tax professionals to write one. Industry data says the firms it applies to are mostly two-person shops.

KANSAS CITY, Mo., August 6, 2026. If you prepare tax returns for a living, federal law counts you as a financial institution. Same category as a bank. That classification carries an obligation most small firm owners have never heard of: a written information security plan (WISP), on paper, kept current.

The Gramm-Leach-Bliley Act is what does it. Under GLBA, tax and accounting professionals are considered financial institutions and must implement a data security plan, which puts them under the Federal Trade Commission's Safeguards Rule. The IRS said it plainly in July 2025: tax professionals are legally required to have a written, accessible plan, and should review, test and update it regularly.

The agency is in the middle of saying it again. On July 7 the IRS and its Security Summit partners launched "Protect Your Clients; Protect Yourself," a five-week campaign for tax professionals now in its final week. The same guidance is being delivered in person at the 2026 IRS Nationwide Tax Forums, which continue in New York City Aug. 18-20, Orlando Sept. 1-3, and San Diego Sept. 15-17.

"Most preparers I talk to have no idea this applies to them, and I don't blame them one bit. Nobody ever told them," said Sam Sapp of Lockbaud. "Many of these smaller firms would be lucky to have a cybersecurity plan at all, let alone a written one."

The size of the gap follows from the shape of the profession. Research published in The CPA Journal in January, drawn from IRS preparer and e-filing datasets for the 2024 tax year, found 89% of all e-filers handle fewer than 1,000 filings a year, and 48% of preparers matched to a firm are solo practitioners. Intuit, H&R Block, and TaxHawk together account for only about a third of e-filing submissions. Most of the rest of the profession is small businesses.

Those firms hold exactly what an attacker wants. Social Security numbers, bank account details, income records, and dependent information for every client on the list, usually going back years.

The Safeguards Rule doesn't ask for a security operations center. The FTC asks firms to designate someone to coordinate the program, identify and assess risks to customer information, and create, implement and regularly test safeguards. The IRS publishes Publication 5708, a 28-page template built for smaller practices, and Publication 4557 covers safeguarding taxpayer data more broadly. Both are free.

A plan on paper isn't really the point either. The protections have to actually be in place, and that's where a lot of firms get caught. They assume somebody else has it handled, usually the tax software vendor or whoever set the office up. Those companies secure their own platform. They don't secure your email, your laptops, your backups, or the person who clicks the wrong link.

Somebody has to own that, and in a two-person office nobody has room for one more job. That's why these plans get started in February and forgotten by March. A lot of firms hand it off instead, which is a good chunk of what IT support for accounting firms means in practice. And it's not just tax firms. Any small business sitting on customer data runs into the same thing, which is most of why outsourced IT for small businesses is a category at all.

Two things any tax or accounting firm can check this week:

  • Find out whether your firm has a written plan at all, and who is named in it as responsible. If nobody is named, you don't have one.
  • Ask your tax software vendor and your IT provider, in writing, exactly what each one secures. The gap between those two answers is yours to cover.

"That's what we try to help with, and honestly what we want to make a push to help more with," Sapp said. "If a firm gets one page written and puts a name on it, that's a real win. We'll take it."

Through Oct. 31, Lockbaud is offering a free written information security plan review to tax and accounting firms. Lockbaud will read an existing plan against Publication 5708 and the Safeguards Rule and say plainly what's missing, or confirm a firm doesn't have one yet. Requests go to connect@lockbaud.com or 816-208-2888.


Why a rule written for banks lands on a two-person practice

The phrase financial institution does most of the damage here. It sounds like it describes an industry, so people who are not in that industry stop reading. What it actually describes in this context is an activity: handling nonpublic personal financial information as part of your business. Preparing a return means collecting Social Security numbers, wage records, and bank details. That is the activity, so the classification follows, and the firm's size never enters into it.

This catches more small businesses than most owners expect. The obligation does not scale with headcount, revenue, or the number of returns filed. A sole practitioner working from a spare bedroom carries the same written plan requirement as a regional firm with an IT department, which is precisely the asymmetry that leaves the smallest firms most exposed.

What the plan is actually supposed to contain

A written information security plan is not a technical document and it is not something a firm buys. It names a person responsible for the program. It writes down what client information the firm holds, where that information lives, and what could realistically go wrong with it. Then it records the specific safeguards in place against those risks, and it commits to testing whether they still work.

Kept current is the part that gets skipped. A plan written once and filed away satisfies nobody, because the rule asks firms to review, test and update it. In practice that means a recurring calendar entry, not a folder. If the plan still names software the firm stopped using two years ago, or a staff member who left, it is not a current plan and it will not read as one to anybody who asks.

Starting it doesn't take technical skill. It takes one person agreeing it's theirs, and a date on the calendar to look at it again.

The timing is better than it looks

August is the quietest stretch on an accounting calendar, which makes it the only realistic window to do this. A written plan drafted in August is a document. The same plan attempted in February is a distraction during the busiest weeks of the year, which is why it does not get done then and why it has not been done yet.

That seasonal logic is not unique to security work. It is the same reason the stretch after filing season is when firms tend to reconsider vendors, revisit what broke, and fix the things they tolerated under deadline. We wrote about that pattern in more detail in our guide to switching IT providers after tax season.

Primary sources

Every claim above traces to a federal publication or to peer-reviewed industry research. The originals are worth reading if you prepare returns for a living.

  • IRS news release IR-2026-81, July 7, 2026, launching the five-week "Protect Your Clients; Protect Yourself" campaign and listing the 2026 Nationwide Tax Forum dates
  • IRS news release IR-2025-79, July 29, 2025, on the federal mandate for a written information security plan and the FTC requirements under GLBA
  • IRS Publication 5708, the 28-page template for creating a written information security plan, written for smaller practices
  • IRS Publication 4557, Safeguarding Taxpayer Data
  • The CPA Journal, January 2026, Garrett and Donnelly, on tax firm size drawn from IRS PTIN and e-filing datasets for the 2024 tax year

What this connects to

IT support for accounting firms: ongoing ownership of the security plan, the testing schedule, and the documentation, so it exists before a client or a regulator asks.

Managed IT for CPA firms: what changes operationally when a practice stops treating technology as whoever is least busy that week.

Cybersecurity for accounting firms: the safeguards the written plan is supposed to describe, actually implemented and monitored.

Outsourced IT for small businesses: the same argument without the tax framing, for any small business holding customer data it cannot afford to lose.

Free security plan review through October 31

For tax and accounting firms. Send us the plan you have and we will read it against IRS Publication 5708 and the FTC Safeguards Rule, then tell you plainly what is missing. If you do not have one yet, say so and we will start there instead.

Request a plan review

About Lockbaud

Lockbaud is a managed IT and cybersecurity provider based in Kansas City, Missouri, serving small and mid-sized businesses across the United States. Lockbaud works most often with accounting firms, law firms, and chambers of commerce, and backs its work with same-day support, zero-downtime onboarding, and a money-back guarantee. Founded and owned by Sam Sapp. More at lockbaud.com.

Media contact

Lockbaud Media Relations
media@lockbaud.com
(816) 264-1337

📞 Call now