A busy CPA office cannot pause because an employee clicked the wrong attachment. During tax season, a few hours without access to tax software, client folders, email, or the phone system can create missed deadlines and anxious clients. This CPA firm cybersecurity case study shows how one suburban accounting firm reduced its exposure without making day-to-day work harder for its staff.

The firm in this example is a composite based on common conditions seen in small and midsize professional offices. Its challenges will be familiar to many CPA firms: confidential client data, remote staff, aging computers, vendor portals, tight deadlines, and a technology environment that had grown one quick fix at a time.

The Starting Point: High Risk Hidden Behind Normal Operations

The firm had 22 employees, two partners, and a mix of onsite and remote workers. It handled individual and business tax returns, payroll records, financial statements, bank information, and copies of client identification documents. Most files lived on a local server, with some documents stored in Microsoft 365 and others saved on individual desktops.

Nothing had failed dramatically yet. That was part of the problem. Because the office could still print returns, send email, and access its tax applications, technology was viewed as “working.” But a security review identified several issues that could turn a routine phishing email or stolen password into a serious business interruption.

Remote access was available through an older VPN configuration. Multifactor authentication was not consistently enforced. Several staff members used local administrator accounts because a past software update had required elevated permissions. Backups ran each night, but the office had not tested a full restore. The firewall was still operating, yet its security services, firmware, and alerting rules had not received regular attention.

The firm also had no current written inventory of users, computers, network equipment, shared passwords, or cloud subscriptions. When an employee left, access was usually removed, but there was no documented offboarding checklist to confirm it had happened everywhere.

For an accounting firm, these are not minor housekeeping issues. They create risk across client confidentiality, operations, insurance requirements, and compliance obligations. The FTC Safeguards Rule requires covered financial institutions, including many tax preparation and accounting businesses, to maintain an information security program appropriate to their size and complexity. A written information security plan, often called a WISP, is not a substitute for technical controls. It is the framework that makes those controls repeatable and accountable.

What Made the CPA Firm Vulnerable

The most immediate concern was email-based fraud. Attackers regularly impersonate clients, payroll providers, tax software vendors, and firm partners. A message asking someone to review a “2025 W-2 correction” or reset a Microsoft 365 password can look convincing when staff members are processing hundreds of requests.

The firm also faced a ransomware concern. If ransomware reached one workstation and spread through shared drives, the office could lose access to active returns, source documents, templates, and historical client records. A backup that exists but cannot be restored quickly does little to protect a deadline.

There was also an access-control issue. Too many people could reach too much information. Employees had access to shared folders that were useful years earlier but were no longer relevant to their roles. This is common in growing firms, especially when staff members cover multiple responsibilities during filing season. Still, broad access means one compromised account can expose far more data than necessary.

Finally, the firm had limited visibility. No one reviewed failed login attempts, unusual VPN activity, endpoint security alerts, or firewall events on a regular basis. The partners would likely learn about an incident from an employee or client, not from a security alert.

The Security Plan: Fix the Highest-Impact Gaps First

The right response was not to replace every device or force the firm into an expensive project during peak season. The priority was to reduce the most likely risks while protecting uptime.

The work began with a documented assessment of users, endpoints, servers, network equipment, applications, backups, and remote-access methods. This created a baseline for the firm’s WISP and identified which systems stored or processed sensitive information.

Securing Identity and Remote Access

Multifactor authentication was enforced for Microsoft 365, remote access, administrative accounts, and other systems that supported it. This was one of the fastest ways to reduce the impact of stolen passwords. A password from a phishing page may still be exposed, but it should not be enough by itself to open the firm’s email or network.

The VPN was reviewed and updated to use current security settings. Access was limited to approved users and managed devices where possible. Former employees were removed from all relevant systems, including cloud applications and remote access groups.

The firm also eliminated unnecessary local administrator privileges. Some specialized tax and accounting applications require exceptions, so this was handled carefully rather than applying a blanket restriction. Where elevated access was genuinely needed, it was documented and limited to the appropriate users.

Improving Email and Endpoint Protection

Email protections were configured to better identify suspicious attachments, spoofed senders, and malicious links. Staff received short, practical phishing training built around the emails they were most likely to see: client document requests, e-signature notices, payroll messages, and Microsoft 365 login prompts.

The goal was not to turn accountants into security analysts. It was to give them a clear response process: stop, verify through a known phone number or separate message, and report suspicious email before opening a link or attachment.

Managed endpoint protection was deployed across workstations and servers, with alerting for suspicious behavior. Devices were brought into a patching process so operating system and application updates were reviewed and installed consistently. Unsupported computers were identified for replacement rather than left connected to the network indefinitely.

Making Backups Useful During an Emergency

The firm’s existing nightly backup was retained, but the strategy changed. Critical data received protected backup copies that could not be easily altered or deleted by a compromised administrator account. Backup status was monitored, and the firm tested the restoration of selected files and a server image.

Testing mattered. A successful backup report only proves that data was copied somewhere. It does not prove the office can restore the right files, within the needed timeframe, while systems are under pressure.

For this firm, a full server recovery could take longer than restoring individual client folders. That led to a practical recovery plan: restore the most urgent tax-season data first, provide secure temporary access where feasible, and bring remaining systems back in a defined order. Recovery priorities were based on business function, not simply which server was easiest to restore.

The Result: Better Control Without Disrupting the Office

Within the first phase of work, the firm had consistent multifactor authentication, cleaner user access, improved firewall oversight, protected endpoint security, and a documented backup recovery process. It also had a current equipment and account inventory, which made support requests faster and reduced confusion when staff changed roles.

The most meaningful result was not a new dashboard or a stack of compliance paperwork. The firm could answer questions it previously could not answer with confidence: Who has remote access? Which devices hold client data? Are backups recoverable? What happens if a partner’s email account is compromised? Who is responsible for reviewing security controls?

There were trade-offs. Multifactor authentication added a few seconds to some logins. More restrictive email filtering occasionally required a legitimate message to be released. Access cleanup meant staff needed to request folders they had informally used before. Those small inconveniences were preferable to a week of downtime, a ransomware negotiation, or explaining a client data incident during filing season.

What Other CPA Firms Can Take From This Case Study

A CPA firm does not need enterprise-level complexity to make meaningful security improvements. It does need a clear view of its systems and a plan that connects technology decisions to business risk. For most firms, the highest-value starting points are identity protection, secure remote access, tested backups, endpoint security, patching, and employee phishing awareness.

A written WISP should reflect how the office actually operates, including remote employees, cloud applications, tax software, client document exchange, and vendor access. A document copied from a generic template will not help much if no one knows who reviews it or whether the listed controls are in place.

Local support also has value when a firm needs help quickly. During tax season, an unresolved server problem, failed internet connection, or suspicious login cannot wait for a ticket queue with no clear owner. A hands-on IT partner can assess the environment, document the gaps, and make changes in a sequence that protects both security and productivity.

The best time to test recovery, verify access, and close security gaps is before an employee reports a strange email or a shared drive becomes unavailable. A practical assessment now gives your firm options later, when the pressure is much higher.