Accountant working at dual monitors beside an April calendar

Why Tax Season Is the Riskiest Time of Year for CPA Firm IT

Tax season does not create new IT vulnerabilities. It amplifies the ones that already exist. Staff work longer hours under deadline pressure. Remote access increases. Client data volumes spike. And attackers know that a CPA firm facing an April 15 deadline is more likely to pay a ransom, click a suspicious link, or skip a software update than a firm that has twelve months to recover from a mistake.

For Phoenix CPA firms, the stakes are not abstract. A breach during peak season can mean suspended e-filing privileges, mandatory notifications to affected clients, IRS scrutiny of your firm's Electronic Filing Identification Number (EFIN), and a filing deadline that arrives whether your systems are working or not.

The five risks below are ranked by their operational consequences, not by how technically sophisticated the threat is. Each one maps to a real outcome your firm could face before April 15.

Risk 1: Ransomware That Targets Tax Software and Client Files

Ransomware operators track peak seasons across industries, and tax season is one of the most predictable windows they target. Tax preparation software, client document portals, and shared file repositories become the highest-value targets in your environment during the filing window. When ransomware encrypts these files, it does not merely cause data loss. It can halt your firm's ability to prepare or file returns entirely.

The operational consequence is immediate and compounding. If your tax software database is encrypted on March 15, your staff cannot prepare returns while recovery is underway. Clients miss deadlines. Extensions must be filed. And depending on the scope of the breach and the data involved, you may have a separate compliance obligation to address before you can focus on recovery.

What reduces this risk in practice:

  • Endpoint Detection and Response (EDR) that watches for the behavioral signals of ransomware (mass file encryption, attempts to delete or overwrite backups) rather than relying only on known-signature antivirus.
  • Application allowlisting so that only approved executables can run on workstations. Ransomware payloads typically arrive as unknown executables that an allowlist blocks by default.
  • Tested, isolated backups that cannot be reached and encrypted by the same attack that hit your production environment. A backup on the same network share as your client files is not a recovery plan.

Ransomware protection is not a single product. It requires detection capability, application control, and a verified recovery path working together. Onsite Technical Services builds each of these as distinct, accountable layers under the Layered Cybersecurity and Threat Defense service, rather than listing tools without defining who operates them.

Risk 2: EFIN and PTIN Exposure from a Credential Breach

Your firm's Electronic Filing Identification Number (EFIN) and your preparers' Preparer Tax Identification Numbers (PTINs) are the credentials the IRS uses to authenticate that returns are coming from a legitimate, authorized source. If a breach exposes the login credentials that access your e-filing systems, or if an attacker uses stolen credentials to file fraudulent returns under your EFIN, the IRS can suspend your e-filing authorization.

An EFIN suspension during filing season is not a minor inconvenience. It means your firm cannot electronically file returns for any client until the IRS investigates and restores your authorization. Paper filing is slower and in many cases practically impossible at the volumes a CPA practice handles. Client relationships suffer. The firm may face IRS questions about returns already filed under the compromised EFIN.

The IRS requires e-file providers to protect their EFINs and to report unauthorized use. The firm, not the software vendor, carries that responsibility.

What reduces this risk in practice:

  • Multi-factor authentication on every system that touches e-filing credentials, including tax software portals, Microsoft 365 accounts used for client communication, and remote access tools.
  • Identity Threat Detection and Response (ITDR) that monitors Microsoft 365 accounts for compromised logins, impossible-travel sign-ins, and unauthorized changes before an attacker can establish persistence.
  • Privileged access management so that EFIN-associated credentials are not stored in a browser or used from general-purpose workstations without additional controls.
  • Dark-web credential monitoring to surface exposed firm credentials before an attacker uses them.

Risk 3: Phishing Campaigns Impersonating IRS e-Services

Each tax season, the IRS publishes updated warnings about phishing campaigns that impersonate IRS e-Services, the Secure Object Repository (SOR), and related IRS communications platforms. These campaigns target tax professionals specifically, not just individual taxpayers. A convincing fake IRS e-Services login page captures the preparer's credentials and, in some cases, client information that the preparer believes they are securely transmitting to the IRS.

The IRS's own guidance on this category of threat is worth reading directly at irs.gov, and the agency updates it each season. The underlying pattern is consistent: attackers create urgency (a rejected return, an EFIN verification request, a security alert) and a plausible-looking portal to capture credentials under time pressure.

Tax season amplifies this risk because staff are under deadline pressure and processing a high volume of IRS-related messages. The probability that someone clicks before carefully verifying the sender and URL goes up when the inbox is full and the clock is running.

What reduces this risk in practice:

  • Advanced email protection that identifies impersonation attempts, spoofed sender domains, and malicious links before a message reaches an employee's inbox.
  • Security awareness training that includes realistic simulated phishing campaigns using IRS-themed lures, not just generic phishing scenarios. Staff who have seen a convincing fake IRS email in a training context are better equipped to recognize one in production.
  • Web content filtering that blocks known phishing domains at the DNS or proxy layer, so that even if a staff member clicks a malicious link, the connection is blocked before credentials can be entered.
  • A clear internal process for staff to report suspicious IRS-related communications before acting on them, with a short escalation path that does not add significant delay during busy periods.

Risk 4: Unpatched Endpoints Used for Remote Tax Preparation

Remote work during tax season is common for CPA firms. Partners review returns from home. Preparers access client files from personal laptops. Staff connect to the office network using a mix of firm-managed and personally-owned devices. Each unpatched endpoint in that picture is a potential entry point.

Attackers routinely exploit known vulnerabilities that already have patches available. The Cybersecurity and Infrastructure Security Agency (CISA) maintains a catalog of Known Exploited Vulnerabilities. A significant portion of successful intrusions use weaknesses that were publicly disclosed and patched months or years before the attack, because the target organization had not yet applied the fix.

For a CPA firm, the specific exposure is this: a preparer connects to your tax software environment from a laptop running an unpatched version of Windows or a browser plugin with a known remote code execution vulnerability. An attacker who has already compromised that endpoint can ride the remote access session into your firm's environment, where the client files and e-filing credentials live.

What reduces this risk in practice:

  • Centralized endpoint patching with verified deployment, so that a managed workstation receives and confirms patches rather than relying on a user to approve and install updates manually.
  • A company-managed-device-only policy for access to tax software and client data. Personal devices that the firm cannot patch, monitor, or manage should not have direct access to the environment that holds client tax files.
  • Remote monitoring that surfaces unpatched or out-of-compliance devices before they connect, rather than discovering the gap during an incident investigation.
  • Full-disk encryption on all endpoints so that a lost or stolen device does not become a data breach in addition to an asset loss.

Endpoint patching is one of the clearest examples of where operational responsibility matters more than having the right tool. A patching tool that generates reports but does not have a defined owner who verifies deployment and exceptions is not patch management. It is patch reporting.

Risk 5: No Tested Backup and Recovery Plan When the Filing Deadline Cannot Move

April 15 does not move because your server failed. The IRS grants extensions on request, but extensions still require a filing, and they do not relieve the underlying obligation. A firm that cannot access client records, tax software history, or prior-year return data on April 14 faces a category of problem that cannot be solved by working harder.

Many CPA firms have a backup. Fewer have a tested backup. The distinction is significant. A backup that has not been restored and verified in a realistic scenario is an assumption, not a recovery plan. Common failure modes include: backup jobs that have been silently failing for weeks, backups stored in the same physical location as the primary system (or on the same network share), and recovery procedures that exist on paper but have never been practiced under time pressure.

The FTC Safeguards Rule, which applies to tax return preparers as financial institutions under the Gramm-Leach-Bliley Act (GLBA), requires a written information security program that includes an incident response plan. A firm that suffers a breach affecting 500 or more consumers faces a 30-day notification requirement to the FTC under the amended Safeguards Rule. That notification obligation runs concurrently with your recovery effort. A firm without a practiced incident response and recovery plan is trying to handle both at the same time, for the first time, during filing season.

What reduces this risk in practice:

  • Separate, protected backups of both local systems and Microsoft 365 content (email, OneDrive, SharePoint) that are stored independently from the primary environment and cannot be reached by a ransomware attack affecting the primary network.
  • Documented recovery procedures with defined recovery time and recovery point targets. These targets should reflect the actual business consequence of being down during filing season, not generic defaults.
  • Scheduled restoration tests, not just backup-job verification. Testing that files can be written to a backup location is not the same as testing that a system can be restored and operational within an acceptable window.
  • An incident response plan that addresses the FTC notification timeline so that the compliance obligation does not arrive as a surprise while the technical recovery is still underway.

How These Five Risks Connect to FTC Safeguards Rule Obligations

Tax return preparers are financial institutions under GLBA and are subject to the FTC Safeguards Rule. The 2023 amendments to that rule added specific requirements including: a written information security program, a designated information security officer, annual risk assessments, multi-factor authentication for systems containing customer financial information, and an incident response plan.

The 30-day breach notification requirement applies when a breach affects 500 or more consumers. For a CPA firm that handles a few hundred or a few thousand client tax files, a ransomware incident or credential breach during filing season could easily reach that threshold. The notification goes to the FTC and the firm must provide it within 30 days of discovering the breach, regardless of where the recovery effort stands.

The five risks above are not purely technical problems. Each one, if it materializes, can trigger a Safeguards Rule compliance consequence. Ransomware that encrypts client files is a breach. A credential theft that exposes client data is a breach. An unpatched endpoint that served as the entry point for an attacker who accessed client records is a breach. The absence of a tested incident response plan does not prevent the obligation from applying. It just means the firm has to meet the obligation without having practiced it.

What a Managed IT Program Addresses (and What It Does Not)

A managed IT and cybersecurity program can implement and operate the technical controls that reduce these five risks: endpoint protection and patching, email filtering, multi-factor authentication, identity monitoring, application control, and verified backup and recovery. Onsite Technical Services carries the operational responsibility for those controls under a documented, recurring process rather than a one-time configuration.

What a managed IT program does not do is serve as your firm's legal counsel, compliance consultant, or GLBA program officer. The FTC Safeguards Rule requires a written information security program, a designated information security officer, and documented risk assessments. Those are firm-level responsibilities. The technical controls OTS operates support that program. They do not replace the program itself.

If your firm does not yet have a written information security program under the Safeguards Rule, that is the right conversation to have with a qualified compliance or legal advisor. OTS can speak to what the technical environment looks like and what controls are in place. The compliance program that governs those controls is the firm's responsibility to establish and maintain.

Five Questions to Ask Before Tax Season Starts

  • Has your backup been tested with an actual restoration in the past 90 days, and do you have a documented recovery time target?
  • Is multi-factor authentication enforced on every system that touches client tax data, including your tax software portal and Microsoft 365?
  • Are all firm-managed endpoints on a current patch cycle, and do you have a policy prohibiting unmanaged personal devices from accessing the tax prep environment?
  • Has your staff seen a simulated IRS-themed phishing campaign in the past year, or is your security training using generic scenarios that do not reflect the actual lures targeting tax professionals?
  • Does your firm have a written incident response plan that addresses the FTC's 30-day breach notification requirement, and has anyone at the firm read it in the past twelve months?

If any of those answers is "no" or "I'm not sure," the gap is worth closing before February, not after.

Onsite Technical Services works with Phoenix-area professional service firms to implement and operate the technical controls that underpin a sound information security program. Learn more about how we support businesses like yours at onsite-tech.com/small-mid-sized-businesses.

Frequently Asked Questions

Does the FTC Safeguards Rule apply to CPA firms and tax preparers?

Yes. Tax return preparers are treated as financial institutions under the Gramm-Leach-Bliley Act (GLBA), which means the FTC Safeguards Rule applies. Requirements include a written information security program, a designated information security officer, annual risk assessments, multi-factor authentication on systems containing customer financial information, and an incident response plan. The 2023 amendments added a 30-day breach notification requirement to the FTC when a breach affects 500 or more consumers.

What happens to a CPA firm's EFIN if there is a credential breach?

If stolen credentials are used to file fraudulent returns under your firm's Electronic Filing Identification Number (EFIN), the IRS can suspend your e-filing authorization while it investigates. A suspended EFIN during filing season means your firm cannot electronically file returns for any client until the IRS restores authorization. The IRS places responsibility for protecting the EFIN on the e-file provider, meaning the firm.

Why is a backup that has never been tested a problem for a CPA firm?

A backup that has not been restored and verified in a realistic test is an assumption, not a recovery plan. Common failure modes include backup jobs that have been silently failing, backups stored on the same network as the primary system (reachable by the same ransomware attack), and recovery procedures that have never been practiced under time pressure. For a CPA firm, the filing deadline does not move because a recovery is in progress. Testing the restoration process before an incident is the only way to know whether your actual recovery time is acceptable.

What is the 30-day FTC breach notification requirement?

Under the amended FTC Safeguards Rule, financial institutions (including tax return preparers) that experience a breach affecting the unencrypted information of 500 or more consumers must notify the FTC within 30 days of discovering the breach. This obligation runs concurrently with the technical recovery effort and does not pause while systems are being restored. Firms without a practiced incident response plan often encounter this requirement for the first time while the recovery is still underway.

Should CPA firm staff be allowed to use personal laptops for remote tax preparation?

Allowing unmanaged personal devices to access tax software and client data significantly increases the firm's attack surface. A personally-owned laptop that the firm cannot patch, monitor, or enforce security policies on represents an endpoint the firm has no visibility into. If that device is compromised, an attacker can potentially ride the remote access session into the firm's environment where client files and e-filing credentials are stored. A company-managed-device-only policy for access to the tax preparation environment is a meaningful risk reduction measure.

Book a Consult