Cybersecurity for Colorado Accounting Firms: What Your MSP Must Do


CYBERSECURITY  ·  COLORADO ACCOUNTING FIRMS  ·  IRS & FTC COMPLIANCE

Cybersecurity for Colorado Accounting Firms:
What Your IT Provider Should Be Doing in 2026

The FTC can fine your firm $53,088 per violation with no cap. The IRS can revoke your EFIN. And every tax preparer — including solo practitioners — is legally required to have a Written Information Security Plan. Here’s what that actually means for your Colorado firm and what your IT provider must be doing.

$53,088

FTC Per-Violation Fine

74%

Breaches Involve Human Error

All Preparers

WISP Required — No Minimum

Get a Free Security Assessment →
303-778-0600

Free assessment  ·  No obligation  ·  Denver  ·  Colorado Springs  ·  Westminster

WHAT THIS GUIDE COVERS

✓  Why every Colorado accounting firm — including solo practitioners — must have a WISP under IRS Publication 4557

✓  How the FTC Safeguards Rule, IRS Pub. 4557, and GLBA create overlapping legal obligations

✓  Why filing season is your highest-risk window — and how attackers exploit it

✓  The six IRS Security Six controls your firm must have documented

✓  What a compliant WISP actually contains — and who builds it

✓  7 questions to audit your current IT provider’s compliance readiness

Read time: ~10 minutes  ·  Published: June 10, 2026  ·  Author: Wendy Campbell, Director of Marketing, ABT

Colorado accounting firms hold a concentration of client data that is extraordinarily valuable to cybercriminals: Social Security numbers, EINs, bank routing information, investment account details, and years of income history for hundreds or thousands of clients. That is not a risk profile that warrants a general-purpose IT provider who treats your firm like any other small business.

In 2026, the compliance landscape for accounting firms has hardened significantly. The FTC Safeguards Rule and IRS Publication 4557 create layered legal obligations — and non-compliance is not just a risk management issue. The FTC’s current maximum civil penalty is $53,088 per violation, updated effective January 2025 under the Federal Civil Penalties Inflation Adjustment Act. The IRS can revoke your EFIN and PTIN. And Colorado’s breach notification statute adds state-level penalties on top of federal exposure.

This guide is for Colorado CPA firm owners, managing partners, and office administrators who want a clear picture of what their IT provider should actually be doing — and a practical way to evaluate whether they are.

Quick Answer

What cybersecurity does a Colorado accounting firm need from its IT provider in 2026?

Every Colorado accounting firm must have a Written Information Security Plan aligned to IRS Publication 4557 and the FTC Safeguards Rule (16 CFR Part 314), regardless of firm size or return volume. The WISP must document real controls — not a downloaded template — including MFA enforcement on all tax software and email, EDR on every endpoint, immutable backup with tested recovery, security awareness training with completion records, a designated security officer, vendor management for QuickBooks/Drake/Lacerte and cloud storage, and a written incident response plan covering IRS Form 14039B notification and Colorado breach statute procedures. If your IT provider cannot produce this documentation package on demand, your firm carries the compliance risk.

1. The Compliance Framework — FTC Safeguards Rule, IRS Pub. 4557 & WISP

Most Colorado accounting firms know they’re supposed to have security measures in place. Fewer understand that three overlapping federal frameworks create specific, documented, enforceable obligations — not general best-practice guidance. Here’s how they relate and where the obligations are distinct:

Framework Who It Applies To Enforcement Consequence
FTC Safeguards Rule
16 CFR Part 314
Non-bank financial institutions under GLBA — including tax preparers who file 11+ federal returns annually, CPAs, bookkeepers, and financial advisors. Requires a written nine-element information security program with designated security officer, risk assessment, technical controls, vendor oversight, incident response. Civil penalties up to $53,088 per violation (current Federal Register figure, effective Jan 17, 2025). No maximum cap. FTC also now requires breach notification within 30 days for incidents affecting 500+ customers — and that notification is public.
IRS Publication 4557
Safeguarding Taxpayer Data
All tax preparers regardless of firm size or return volume. The IRS has no minimum threshold. A solo practitioner filing a single return for compensation has the same WISP obligation as a 50-person firm. This is the most widely misunderstood aspect of the compliance framework. EFIN and PTIN revocation. State-level breach notification obligations under C.R.S. § 6-1-716. Reputational damage that takes years to recover from in a referral-driven profession.
WISP
Written Information Security Plan
The single document that satisfies both frameworks. Must reflect your firm’s actual systems, actual vendors, actual staff roles, and be reviewed annually. A template downloaded from the internet and never updated is not compliant. A WISP that doesn’t reference your actual systems is not a compliant WISP. “We have one on file” is not sufficient when the IRS or a cyber insurer asks to review it.

⚠ The Size Misconception — Corrected

Many Colorado solo practitioners and two-partner firms assume WISP requirements only apply to larger enterprises. They don’t. IRS Publication 4557 applies to every tax preparer, period — there is no minimum return threshold. The FTC Safeguards Rule’s 11-return threshold applies specifically to FTC jurisdiction; the IRS applies Pub 4557 more broadly. If you prepare returns professionally, you need a WISP that reflects your actual security posture.

2. Filing Season: Why January–April Is Your Highest-Risk Window

Tax season creates a predictable attack window that cybercriminals actively exploit. Your staff is under maximum pressure, working longer hours with less bandwidth for careful scrutiny. Client data volume is at its peak. The likelihood of clicking a phishing link or approving an unusual financial request without a second look increases with every hour of deadline pressure.

The IRS Security Summit — a coalition of the IRS, state tax agencies, and software industry partners — has documented consistent spikes in tax-professional data theft incidents during filing season. In one reported period they identified nearly 300 data breaches at tax professional practices in a single half-year window, with downstream impact on hundreds of thousands of taxpayers.

Three Filing Season Attack Patterns Your IT Provider Should Be Monitoring

January phishing spikes. Threat actors send targeted emails impersonating the IRS, Drake, Intuit, Thomson Reuters, and payroll providers in the weeks before filing season opens. Staff conditioned to receive high volumes of tax-related communications are more likely to click.

AI-powered deepfake attacks. Generative AI tools now make it practical for attackers to clone a partner’s voice and leave a convincing voicemail requesting a rush wire transfer. Deepfake audio and synthetic email impersonation are not theoretical in 2026 — they are documented attack tools. Multi-step verification for all financial approvals is a compliance requirement, not a suggestion.

Ransomware during extension season. The August and October extension deadlines create secondary attack windows when firms are under a second pressure surge. Ransomware deployed during a busy week creates maximum leverage — firms are more likely to pay when deadline-critical data is locked.

Your IT provider should have a documented filing season security protocol — a heightened-alert posture during January–April and August–October that includes increased monitoring sensitivity, phishing simulation reminders, and a rapid-response procedure for suspicious financial requests. Ask them for it in writing.

3. The IRS Security Six — What Must Be Documented and Implemented

The IRS Security Summit publishes six foundational controls — the “Security Six” — that represent the baseline security posture the IRS expects to find. These are not optional. They map directly to WISP documentation requirements and are what both the IRS and cyber insurers ask for during review.

1  ·  Antivirus / EDR Software

Modern endpoint detection and response (EDR) — not legacy antivirus — on every device that accesses client data or tax software. EDR detects behavioral anomalies that signature-based antivirus misses.

MSP deliverable: EDR deployment report covering every endpoint, with management console record and update frequency documentation.

2  ·  Firewall & Network Security

Properly configured firewall with DNS filtering, network segmentation separating client data systems from general office use, and documented review procedures. Guest Wi-Fi should never share a segment with systems processing client tax data.

MSP deliverable: Network diagram with segmentation documentation, firewall ruleset review record, DNS filtering log.

3  ·  Multi-Factor Authentication

MFA enforced on every access point where client data can be reached: email, tax software (Drake, Lacerte, ProConnect, ProSeries), cloud storage, and remote access tools. The FTC Safeguards Rule explicitly requires MFA for systems accessing customer information — it is not user-optional.

MSP deliverable: MFA enforcement documentation via Microsoft Entra ID or equivalent. Policy screenshots confirming MFA cannot be bypassed by users.

4  ·  Backup & Recovery

Encrypted, immutable backup isolated from the primary network, with documented recovery testing. For a firm hit by ransomware during filing season, your recovery time objective (RTO) is the difference between a bad week and a catastrophic one. “Our data is backed up” without a tested restoration procedure is not a disaster recovery plan.

MSP deliverable: Backup architecture documentation, quarterly restore test results with RTO/RPO measurements, isolation verification from primary network.

5  ·  Encrypted Email & File Transfer

Client tax documents and financial data transmitted over unencrypted email are an IRS Publication 4557 violation. This requires encrypted email transport, secure file transfer for document exchange, and DLP policies preventing sensitive data from leaving firm-approved channels.

MSP deliverable: Email encryption policy in Microsoft 365 or equivalent, DLP rule documentation, secure client portal configuration.

6  ·  Security Awareness Training

Annual security training for all staff with documented completion records and simulated phishing tests. For Colorado accounting firms this training must be calibrated to accounting-specific scenarios — wire fraud, tax-season phishing, payroll diversion, IRS impersonation — not generic “don’t click links” content.

MSP deliverable: Training platform enrollment records, simulated phishing test reports with click-rate data, annual completion certificates for all staff.

FREE SECURITY ASSESSMENT  ·  COLORADO ACCOUNTING FIRMS  ·  NO OBLIGATION

Is Your Firm IRS Publication 4557 and FTC Safeguards Compliant?

ABT’s free security assessment covers your WISP status, Security Six documentation gaps, cyber insurance readiness, and tax software security configuration. Written report. No obligation.

Schedule My Free Assessment →
303-778-0600

4. Building a Compliant WISP — What It Must Actually Contain

The single biggest WISP mistake Colorado accounting firms make is downloading a template from the internet, filling in the firm name, and filing it away. A WISP that doesn’t reference your specific systems, actual staff roles, current vendors, and real incident response procedures is not compliant. When the IRS or FTC asks to review it, they’re looking for evidence that it reflects your actual security program.

WISP Section What It Must Include Common Gaps
Designated Security Officer A named individual responsible for implementing and reviewing the security program. Can be a partner, office manager, or your MSP in a vCISO capacity. No named individual. “The IT company handles it” is not a compliant designation.
Risk Assessment Annual documented assessment of risks to client data. Must identify specific threat vectors relevant to accounting operations, including filing-season-specific exposure. Generic language not specific to accounting operations. Missing filing-season threat assessment.
Technical Safeguards Named security controls with implementation status: EDR solution, MFA platform, backup system, encryption standard, patch management process. Describing MFA as “in place” without specifying which systems it covers.
Vendor Management Inventory of every third-party vendor with access to client data: tax software, cloud storage, payroll, IT provider. Written contracts defining security obligations for each. No vendor inventory. No data security agreement with IT provider. Missing contracts for cloud storage.
Incident Response Plan Written procedures for breach detection, containment, notification, and recovery. Named contacts for legal counsel, cyber insurer, IRS identity theft notification (Form 14039B), and Colorado breach reporting (C.R.S. § 6-1-716). No IRS Form 14039B procedure. Missing Colorado state notification reference. No evidence preservation procedure.

Who Builds Your WISP?

Your WISP should be built collaboratively between your firm’s management and your IT provider — your MSP supplying the technical documentation (controls in place, how they’re managed, evidence of function) and firm leadership supplying the administrative components (designated officer, access policies, staff training records). A WISP that your IT provider has never seen is not a WISP that reflects your actual security posture.

5. Tax & Accounting Software — What Your MSP Needs to Know

A general MSP treats Drake, Lacerte, QuickBooks, and ProConnect like any other software application. A compliance-grade MSP understands that these platforms are the primary surface area for client data exposure — and that misconfiguration in any of them is a direct compliance gap.

Platform Security Configuration Your MSP Must Address WISP Documentation Required
Drake Tax Password policy enforcement, MFA on Drake portals, data location verification (local vs. cloud), e-file PIN management, audit log review. Named vendor, data handling agreement reference, MFA configuration screenshot, backup coverage confirmation.
Lacerte / ProSeries Intuit account MFA enforcement, user access review (former staff removal), Intuit Link portal security, data synchronization security for cloud features. Intuit named as vendor, access control policy reference, MFA enforcement documentation, annual access review log.
QuickBooks Online Accountant access management, client permission levels, MFA on Intuit account, audit log monitoring for unusual access patterns, bank feed security. Intuit named as vendor, access delegation policy, permission level documentation, audit log review frequency.
Microsoft 365 Purview DLP policies for tax data, SharePoint/OneDrive external sharing restrictions, Entra ID conditional access, Teams external access controls for client communications. Microsoft named as cloud provider in WISP, DLP policy documentation, external sharing restriction screenshots, conditional access policy record.

6. 7 Questions to Audit Your Current IT Provider

Put these questions to your current IT provider. The answers will tell you whether they are equipped to support your compliance obligations — or whether you are carrying that risk alone.

# Question What a Qualified Answer Sounds Like
1 Have you built or reviewed a WISP for an accounting firm? Can you help us build one aligned to IRS Publication 4557? A specific yes with named client experience. “We help with compliance documentation” is not the same as knowing IRS 4557 structure.
2 Do you have a filing-season security protocol — a documented heightened monitoring posture during January–April? A specific documented procedure. “We monitor year-round” is not a filing-season protocol.
3 Can you configure and support Drake, Lacerte, QuickBooks, or our specific platform? Named experience with your specific platform. “We support all software” is not the same as knowing Drake’s MFA configuration.
4 Can you produce our WISP technical documentation — Security Six implementation evidence — within 48 hours if the IRS or an insurer asks? “Yes — we maintain a documentation package as part of your managed service.” Any version of “we’d need to compile that” is not adequate.
5 When did you last test our backup recovery, and what was the documented RTO? Specific date and documented result. “Our backups run nightly” is a backup policy — not a recovery test.
6 Do you have a procedure specifically for IRS identity theft notification (Form 14039B) and Colorado state breach notification? A specific yes referencing IRS Form 14039B and C.R.S. § 6-1-716. Generic “we have an IRP” is not the same thing.
7 Can I speak with another Colorado accounting firm reference of similar size? Specific references with firm type and size match. Any hesitation is meaningful data.

7. How ABT Supports Colorado Accounting Firms

ABT has served Colorado businesses in regulated industries since 2005. We’re not a national MSP with a Colorado branch — we’re a Colorado company with three Front Range offices serving the accounting and professional services firms that have operated here for decades.

When we onboard a Colorado accounting firm, the engagement is built around the specific deliverables the IRS, FTC, and cyber insurers actually ask for:

Onboarding Assessment — Month 1

Security gap assessment against IRS Pub. 4557 and FTC Safeguards Rule  ·  Security Six documentation review  ·  WISP gap analysis  ·  MFA deployment  ·  Backup verification with documented RTO  ·  Tax software security configuration review  ·  Written IT environment inventory.

Ongoing Managed Services

24/7 SIEM monitoring with filing-season heightened alert posture  ·  Patch management with tax software compatibility testing  ·  Quarterly backup restore tests  ·  Annual WISP review and update  ·  Security awareness training with accounting-specific phishing simulations  ·  Compliance documentation package maintained for IRS and insurance review.

Three Front Range Offices — Local Dispatch

Denver / Centennial HQ: 11999 E. Caley Ave Suite A  ·  303-778-0600
Colorado Springs: 1047 Elkton Drive  ·  719-434-4080
Westminster / NoCO: 12000 N. Pecos St. Suite 330  ·  720-389-2460

Frequently Asked Questions

Is a WISP required for all Colorado accounting firms, even solo practitioners?

Yes. IRS Publication 4557 requires every tax preparer who handles taxpayer data to maintain a Written Information Security Plan, with no minimum threshold based on firm size or return volume. If you prepare returns for compensation, you are required to have a WISP that reflects your actual controls. The FTC Safeguards Rule adds a parallel obligation specifically for firms filing 11+ federal returns annually — but IRS Pub 4557 applies regardless.

What is the current FTC Safeguards Rule civil penalty for accounting firms in 2026?

The FTC’s current maximum civil penalty is $53,088 per violation, updated effective January 17, 2025 under the Federal Civil Penalties Inflation Adjustment Act (Federal Register, January 2025). There is no maximum cap on total penalties — violations that continue over time accumulate daily. The FTC also now requires breach notification within 30 days for incidents affecting 500 or more customers, and that notification becomes public.

What is the difference between IRS Publication 4557, the FTC Safeguards Rule, and a WISP?

These three frameworks describe the same compliance outcome from different angles. The FTC Safeguards Rule (16 CFR Part 314) is the federal regulation requiring a written security program for non-bank financial institutions including tax preparers. IRS Publication 4557 is the IRS’s specific guidance applying to all tax preparers on how to implement it. A WISP is the actual document your firm produces that demonstrates compliance with both. The key distinction: Pub 4557 applies to all preparers regardless of return volume; the FTC Safeguards Rule triggers at 11+ federal returns annually.

Why is filing season the highest cybersecurity risk window for Colorado accounting firms?

Filing season creates a predictable attack window: staff are under maximum deadline pressure, client data volume is at its peak, and the likelihood of a phishing click or unusual financial request going unscrutinized is higher. The IRS Security Summit has documented consistent spikes in tax professional data theft incidents during January–April. AI-powered deepfake attacks make partner impersonation practical in 2026, not theoretical. Your IT provider should have a documented filing-season security protocol — not just year-round baseline monitoring.

Does ABT serve Colorado accounting firms outside of Denver?

Yes. ABT operates three Front Range offices with local dispatch across the I-25 corridor. Colorado Springs (1047 Elkton Drive, 719-434-4080) serves Monument through Pueblo. Westminster/NoCO (12000 N. Pecos St. Suite 330, 720-389-2460) covers Fort Collins, Greeley, Loveland, and Boulder County. Denver/Centennial HQ (11999 E. Caley Ave Suite A, 303-778-0600) covers Metro Denver and the South Metro. We do not manage Colorado firms from another state or time zone.

COLORADO ACCOUNTING FIRM CYBERSECURITY ASSESSMENT  ·  FREE  ·  NO OBLIGATION

Know Whether Your Firm Is IRS and FTC Compliant Before the IRS Does

ABT’s free security assessment covers your WISP status, Security Six documentation gaps, tax software configuration, cyber insurance readiness, and filing-season security posture. Written report. Clear gap analysis. No sales pressure.

Schedule My Free Assessment
303-778-0600

Denver  ·  Colorado Springs  ·  Westminster/NoCO  ·  yourabt.com  ·  Colorado since 2005

WC

Wendy Campbell

Director of Marketing  ·  Automated Business Technologies  ·  yourabt.com

Published: June 10, 2026

Wendy oversees all digital marketing for ABT, a Colorado-owned B2B technology company serving the Front Range since 2005. ABT provides Managed IT Services, Cybersecurity, Managed Print, Access Control, and VoIP solutions to businesses across the I-25 corridor from Fort Collins to Pueblo.