04/30/2025
For Tax Professional,
Increasingly, there has been a lot of discussion and messaging around the importance of data and information security. Cybercriminals are constantly evolving their tactics, targeting tax professionals like you to steal taxpayer information for fraudulent refunds and identity theft. Protecting client data is not just an ethical responsibility – it’s a legal requirement under the Safeguards Rule of the Federal Trade Commission (FTC).
To strengthen your cybersecurity defenses, here are some keys steps to follow:
Use strong passwords and multi-factor authentication (MFA). Ensure that all systems, software, and accounts related to your tax practice use complex passwords and enable MFA when possible.
Keep systems updated. Regularly update software, operating systems, and security programs to patch vulnerabilities that can be exploited by hackers.
Encrypt and back-up sensitive data. Secure taxpayer data using encryption and store backup copies in a separate and protected location.
Implement network security measures. Use firewalls, anti-virus software, and virtual private networks (VPNs) to protect data from unauthorized access.
Be cautious with emails and links. Phishing scams are one of the most common ways criminals gain access to tax data. Never click on unexpected links or open attachments without verifying the sender.
Limit data access. Only grant access to client information to those with a need to know. Review access controls regularly.
Taxpayer data security is a shared responsibility and failure to protect it can have serious consequences including, identity theft, legal liability, and loss of professional reputation.
For more details on ways to protect clients and yourself, visit: IRS.gov.