
If you run a CPA or tax preparation firm in Phoenix, you are operating under two overlapping compliance layers at the same time. One is IRS guidance. The other is federal law. They share common ground, but they are not the same thing, and treating one as a substitute for the other leaves real gaps.
The short answer: IRS Publication 4557 and its "Security Six" checklist describe the minimum technical practices the IRS expects you to follow to protect taxpayer data and your e-filing credentials. The FTC Safeguards Rule (16 CFR Part 314), rooted in the Gramm-Leach-Bliley Act (GLBA), is a broader legal requirement that adds a written information security program, a designated security coordinator, vendor oversight, and a 30-day breach notification duty. Meeting the Security Six is a solid technical floor. It is not a ceiling, and it is not enough on its own to satisfy the Safeguards Rule.
This post breaks down both frameworks, shows where they overlap, and explains which responsibilities belong to your firm versus which technical controls a Managed Service Provider (MSP) can implement and operate on your behalf.
Framework 1: IRS Publication 4557 and the Security Six
IRS Publication 4557 ("Safeguarding Taxpayer Data") is guidance published by the IRS and its Security Summit partners. It is not a statute, but non-compliance creates real exposure: an IRS data theft incident that traces back to poor security practices can trigger professional consequences and liability, and it damages the clients whose returns you filed.
The publication's most practical output is the Security Six, a checklist of six baseline technical controls every tax professional should have in place:
Antivirus protection. Up-to-date antivirus on every device that touches taxpayer data, catching the high volume of known commodity threats.
Firewall. A network-level firewall that controls what traffic enters and leaves your office environment.
Multi-factor authentication (MFA). Required for access to IRS e-services, your tax software, and any system holding taxpayer data. A stolen password alone should not be enough to get in.
Backup and recovery. Regular, protected backups of client files and firm data. If ransomware hits during tax season, backup is what determines whether you lose a day or a month.
Drive encryption. Full-disk encryption on laptops and workstations so that a lost or stolen device does not become a data breach.
Virtual Private Network (VPN). Encrypted connections when accessing firm systems remotely or over public Wi-Fi.
Publication 4557 also asks firms to maintain a Written Information Security Plan (WISP), which is where it begins to overlap with the Safeguards Rule. However, the IRS version of a WISP is less formally specified than what the FTC requires.
Framework 2: The FTC Safeguards Rule (16 CFR Part 314)
The FTC Safeguards Rule is a legal requirement under GLBA that applies to any "financial institution" handling consumer financial information. Tax preparers qualify. The rule was significantly updated in 2023, and the current version goes well beyond the Security Six.
Key requirements that go beyond IRS guidance:
Written Information Security Program (WISP). The Safeguards Rule requires a formal, documented WISP that is more specifically structured than the IRS recommendation. It must be based on a risk assessment, address identified risks, and be reviewed and updated regularly.
Designated qualified individual (security coordinator). Your firm must designate a specific person, whether internal staff or a service provider, who is responsible for overseeing the information security program. This person must report to your board or senior leadership at least annually.
Risk assessment. You must conduct and document a risk assessment that identifies reasonably foreseeable threats to the security of customer information, evaluates current safeguards, and informs your WISP.
Vendor oversight. You must select and oversee service providers (including your IT vendor) by contract, requiring them to implement appropriate safeguards.
30-day breach notification. If a breach affects 500 or more customers, you must notify the FTC within 30 days. This is a hard legal deadline with enforcement teeth.
Testing and monitoring. The rule requires continuous monitoring or periodic penetration testing and vulnerability assessments to evaluate the effectiveness of your controls.
Access controls and multi-factor authentication. MFA is explicitly required for accessing customer financial information, consistent with the Security Six but now a legal mandate rather than a recommendation.
Encryption of customer data. Both in transit and at rest, covering the same ground as the IRS encryption guidance but as a regulatory requirement.
Side-by-Side Comparison
| Requirement | IRS Pub 4557 / Security Six | FTC Safeguards Rule |
|---|---|---|
| Legal authority | IRS guidance (not statute) | Federal law (16 CFR Part 314 / GLBA) |
| Who enforces it | IRS / Security Summit | FTC (with civil penalty authority) |
| Antivirus | Required (Security Six) | Required (part of safeguards) |
| Firewall | Required (Security Six) | Required (part of safeguards) |
| MFA | Required (Security Six) | Explicitly required by rule |
| Backup and recovery | Required (Security Six) | Required (part of safeguards) |
| Encryption (devices and transit) | Required (Security Six) | Explicitly required by rule |
| VPN / secure remote access | Required (Security Six) | Addressed under access controls |
| Written Information Security Program | Recommended | Required, formally structured |
| Designated security coordinator | Not specified | Required (qualified individual) |
| Formal risk assessment | Not specified | Required, must be documented |
| Vendor / MSP oversight by contract | Not specified | Required |
| Penetration testing or continuous monitoring | Not specified | Required |
| Breach notification (30-day FTC notice) | Not specified | Required for 500+ affected customers |
| Annual report to board / senior leadership | Not specified | Required |
The Security Six Is the Floor. The Safeguards Rule Is the Ceiling.
A common mistake among tax preparers is treating the IRS Security Six as a complete compliance program. It covers the foundational technical controls well. But the Safeguards Rule layers governance, documentation, testing, and legal accountability on top of those same technical controls.
Think of it this way: a firm that has antivirus, a firewall, MFA, backups, encryption, and a VPN is in much better shape technically than one that has none of those. But if that same firm has no documented WISP, no designated security coordinator, no formal risk assessment, no vendor oversight agreement, and no breach notification plan, it is not in compliance with the Safeguards Rule regardless of how good its technical stack is.
The technical controls and the governance program have to exist together.
What an MSP Owns vs. What Your Firm Owns
This is the division of responsibility that most tax preparers get wrong when they hire an IT provider. An MSP can implement and operate the technical controls. The governance obligations belong to your firm.
What Onsite Technical Services implements and operates on your behalf:
Antivirus and endpoint protection on every device (covering the Security Six antivirus requirement and the Safeguards Rule safeguards requirement)
Managed Detection and Response: a 24/7 Security Operations Center that triages alerts and responds to genuine threats, so a breach at midnight does not wait until morning
Identity Threat Detection and Response: monitoring Microsoft 365 accounts for compromised logins, impossible-travel sign-ins, and unauthorized account changes
Multi-factor authentication enforcement across Microsoft 365 and other systems
Full-disk encryption on laptops and workstations (covering the Security Six encryption requirement)
Backup of both computer data and Microsoft 365 content, independent of what Microsoft retains by default
Firewall and network management (billed as a separate line item, not bundled into the per-user rate)
Secure remote access and endpoint controls covering the VPN requirement
Web content filtering and advanced email protection, blocking phishing pages and business-email-compromise attempts before they reach a staff member's inbox
Security awareness training and phishing simulations, because staff are the most-targeted point in any tax firm's security posture
Endpoint patching and updates, closing the known vulnerabilities that most breaches exploit
Security event logging and monitoring to support incident investigation and evidence collection
Data Loss Prevention controls to keep taxpayer data from leaving your environment improperly
These controls address the technical requirements in both the Security Six and the Safeguards Rule. Onsite Technical Services can also serve as the designated qualified individual under the Safeguards Rule if your firm does not have a qualified internal candidate, though that arrangement should be documented in your service agreement. Your compliance advisor can help you structure that properly.
What your firm owns:
The WISP itself. Your IT provider can help document what controls exist and how they operate, but the WISP is a firm-level governance document that your leadership must own, approve, and keep current.
The formal designation of a security coordinator (whether internal or your MSP, the designation is a firm decision).
The risk assessment process and documentation. An MSP can provide technical input, but the assessment must be directed and owned by the firm.
Vendor oversight, including the contractual requirement that your IT provider maintain appropriate safeguards. That means your engagement with Onsite Technical Services should include a written agreement that addresses security obligations.
The breach notification decision and execution. If an incident crosses the 500-customer threshold, your firm makes the notification to the FTC within 30 days. Your IT provider supports the investigation; your firm makes the legal call.
Annual reporting to your board or senior leadership on the state of your information security program.
No IT provider can take these governance responsibilities off your plate by simply deploying tools. That is the distinction that matters most when evaluating whether your firm is actually operating a compliant program versus simply having a decent security stack.
A Practical Example: What Happens When a Laptop Is Lost
Suppose a staff member leaves a laptop at a client's office over a weekend. Here is how the two frameworks map to that incident:
Security Six / IRS guidance: Drive encryption means the data on that device is unreadable without credentials. The laptop is a hardware loss, not a data breach. The IRS guidance is satisfied on the technical side.
Safeguards Rule: Your firm still needs to document the incident, evaluate whether it constitutes a reportable breach under your WISP's incident response procedures, determine whether any data was actually accessible (encryption status, login attempts, remote wipe capability), and confirm whether the 30-day FTC notification clock applies. All of that is a governance process, not a technical one.
The technical control (encryption) does the protective work. The governance program determines whether you handled the incident correctly and can demonstrate it to a regulator.
What This Costs and How to Think About It
For a Phoenix CPA or tax preparation firm, properly managed IT and security that supports both frameworks runs approximately $200-$250 per user per month as a planning benchmark. That range reflects the scope of operational responsibility required: endpoint management, security stack, Microsoft 365 security and administration, and the monitoring and response layers that turn tools into actual protection.
Network management, covering your firewall, switches, and wireless, is always a separate line item from the per-user rate. The range for network management runs approximately $50-$200 per month per location if you own the hardware and $150-$400 per month per site if the hardware and subscriptions are provided. Both ranges scale with network size and complexity.
Microsoft 365 licensing is billed separately on Microsoft's terms and is never included in the per-user managed services rate.
These are planning figures, not a quote. Your actual investment depends on user count, locations, existing infrastructure, and the specific scope of services engaged. Your compliance advisor may also add fees for WISP development, risk assessment documentation, and Safeguards Rule program support. Those are separate from the IT managed services engagement.
What should not be in your budget: a provider whose sole compliance claim is "we check the Security Six boxes." That covers the technical floor. It does not cover the legal program.
Who This Article Is For
This breakdown is most useful for:
Phoenix-area CPA firms and tax preparation businesses with 2-50 staff who have handled the Security Six basics but have not built a formal Safeguards Rule program.
Firm owners who assumed their IT provider "handles compliance" and want to understand exactly where that responsibility boundary sits.
Office managers or operations leads who have been handed the WISP project and are trying to understand what the IT side versus the policy side actually involves.
If your firm has fewer than 5,000 accounts in total, some Safeguards Rule provisions scale accordingly, but the core requirements, including the WISP, coordinator designation, risk assessment, and breach notification duty, still apply. Size does not remove the obligation; it may affect certain technical implementation thresholds.
For managed IT and security support that addresses the technical layer of both frameworks, Onsite Technical Services works with Phoenix-area financial services firms. Visit our small and mid-sized business services page to learn more about how we structure that engagement.
Frequently Asked Questions
Does the FTC Safeguards Rule apply to my small tax preparation firm in Phoenix?
Yes. The Safeguards Rule applies to any financial institution that handles consumer financial information, and tax preparers meet that definition regardless of firm size. The rule does not have a minimum revenue or employee threshold that exempts small practices. Some technical implementation thresholds scale with the number of customer records you hold, but the core obligations, including the WISP, security coordinator, risk assessment, and breach notification duty, apply to your firm.
Can my IT provider write our WISP for us?
Your IT provider can document what technical controls exist and how they operate, which is essential input for a WISP. However, the WISP is a firm-level governance document. It must reflect your firm's specific risk environment, be approved by firm leadership, and be owned by your designated security coordinator. Your compliance advisor or attorney is the right resource for drafting and formalizing the WISP itself. An IT provider that claims to make you Safeguards-Rule-compliant by deploying tools alone is describing the technical floor, not the full program.
What is the 30-day FTC breach notification requirement?
Under the updated Safeguards Rule, if a breach affects 500 or more customers, your firm must notify the FTC within 30 days of discovering the breach. This is a legal deadline. Your IT provider supports the technical investigation and helps determine the scope of what was accessed, but the notification decision and execution belong to your firm. This is one of the Safeguards Rule obligations that has no equivalent in IRS Publication 4557.
Is MFA enough to satisfy the Safeguards Rule's access control requirements?
MFA is explicitly required by the Safeguards Rule and is a meaningful control, but it is not sufficient on its own. The rule also requires access controls that limit who can reach customer information, monitoring of those access controls, and periodic review. MFA addresses authentication. The broader access control requirement addresses authorization, monitoring, and governance around who has access, under what conditions, and whether that access is being reviewed.
How is network management billed differently from per-user managed IT services?
Network management, covering your firewall, switches, and wireless access points, is always a separate line item and is never bundled into the per-user managed services rate. The cost depends on who owns the hardware and whether compliance monitoring is included. For client-owned hardware with OTS providing maintenance and monitoring, the range runs approximately $50-$200 per month per location. For OTS-provided hardware plus subscriptions, the range runs approximately $150-$400 per month per site, scaling with network size and complexity.

