What Is the FTC Safeguards Rule? A 2026 Compliance Checklist for CPA & Accounting Firms

If your accounting firm collects, stores, or processes sensitive financial information, cybersecurity is no longer just an IT issue—it’s a business requirement. The FTC Safeguards Rule requires many financial institutions, including CPA and accounting firms, to develop, implement, and maintain a comprehensive information security program designed to protect customer information.

For most CPA firms with 20–200 employees, compliance means implementing approximately 10–12 core security controls, documenting policies, assigning responsibility for cybersecurity, and regularly reviewing the effectiveness of your security program.

Whether you’re preparing for a cyber insurance renewal, responding to client security questionnaires, or simply strengthening your firm’s defenses, understanding the FTC Safeguards Rule is an important step toward protecting your business and your clients.

This guide explains the rule in plain English, outlines a practical compliance checklist, and highlights common mistakes that accounting firms should avoid.

What Is the FTC Safeguards Rule?

The FTC Safeguards Rule is part of the Gramm-Leach-Bliley Act (GLBA) and establishes standards for protecting customer financial information.

Rather than prescribing a single technology solution, the rule requires organizations to develop a security program that is appropriate for their size, complexity, and the sensitivity of the information they handle.

For CPA firms, this means taking a proactive approach to cybersecurity—not simply reacting when something goes wrong.

A strong safeguards program helps reduce the risk of:

  • Data breaches
  • Ransomware attacks
  • Business email compromise
  • Unauthorized access
  • Client trust issues
  • Regulatory scrutiny

The goal is simple: protect client information throughout its entire lifecycle.

Does the FTC Safeguards Rule Apply to CPA Firms?

Many accounting firms are surprised to learn that the answer is often yes.

If your firm provides financial services or handles nonpublic personal financial information on behalf of clients, you should understand how the Safeguards Rule applies to your business.

Requirements can vary depending on your firm’s services and circumstances. Because compliance obligations are ultimately legal matters, firms should consult qualified legal counsel regarding how the rule applies to their specific situation.

From an IT perspective, however, most accounting firms benefit from implementing the security controls outlined in this guide regardless of their regulatory obligations.

A Practical FTC Safeguards Rule Checklist

The following checklist summarizes the foundational cybersecurity practices many CPA firms should have in place.

1. Designate a Qualified Individual

Assign someone to oversee your information security program.

This person should be responsible for coordinating security efforts, evaluating risks, and reporting to leadership.

2. Perform a Written Risk Assessment

Document:

  • Critical systems
  • Sensitive data
  • Potential threats
  • Existing security controls
  • Areas requiring improvement

Risk assessments should be reviewed whenever major technology changes occur and periodically as part of your security program.

3. Enable Multi-Factor Authentication (MFA)

Passwords alone are no longer enough.

MFA should protect:

  • Microsoft 365
  • VPN access
  • Remote desktop
  • Administrative accounts
  • Cloud applications

4. Protect Every Endpoint

Every workstation, laptop, and server should include:

  • Endpoint Detection & Response (EDR)
  • Antivirus
  • Continuous monitoring
  • Automated updates

Attackers frequently target employee devices because they’re often the easiest point of entry.

5. Encrypt Sensitive Data

Encryption should protect:

  • Files stored on laptops
  • Backup data
  • Email when appropriate
  • Data transmitted across networks

Encryption helps reduce the impact if devices are lost or stolen.

6. Secure Microsoft 365

Most CPA firms rely heavily on Microsoft 365.

Important security measures include:

  • Conditional Access
  • MFA
  • Email protection
  • Secure SharePoint permissions
  • Defender policies
  • Administrative controls

7. Train Employees Regularly

Your staff is one of your strongest security defenses.

Provide recurring training covering:

  • Phishing emails
  • Password security
  • Social engineering
  • Safe browsing
  • Incident reporting

Quarterly reinforcement is often more effective than a single annual session.

8. Monitor Your Environment

Continuous monitoring helps identify unusual activity before it becomes a serious incident.

Monitoring should include:

  • Login attempts
  • Security alerts
  • Device health
  • Backup status
  • Patch compliance

9. Maintain Secure Backups

Backups should be:

  • Encrypted
  • Tested regularly
  • Stored securely
  • Protected from ransomware

A backup that hasn’t been tested isn’t a recovery strategy.

10. Review Your Security Program Every Year

Cyber threats continue to evolve.

Your policies, procedures, and security technologies should evolve as well.

Annual reviews help identify new risks and improve existing controls.

Common Compliance Gaps We See

Many accounting firms believe they’re adequately protected until a security assessment uncovers unexpected vulnerabilities.

Some of the most common issues include:

  • Shared administrator accounts
  • Missing MFA
  • Unsupported Windows devices
  • Weak password policies
  • Inconsistent patch management
  • No documented security policies
  • Untested backups
  • Former employees retaining system access
  • Limited employee cybersecurity training

Most of these issues can be corrected with a structured improvement plan.

Building a Practical Compliance Roadmap

Rather than trying to implement everything at once, focus on manageable phases.

First 30 Days

  • Complete a risk assessment
  • Enable MFA
  • Verify backups
  • Deploy endpoint protection

Next 60–90 Days

  • Develop written policies
  • Launch employee security awareness training
  • Review administrative privileges
  • Strengthen Microsoft 365 security

Ongoing

  • Quarterly security reviews
  • Annual risk assessments
  • Backup testing
  • Incident response exercises
  • Continuous vulnerability management

Breaking improvements into phases makes compliance more achievable while steadily reducing risk.

Example: Strengthening Security Before Renewal

Consider a regional CPA firm preparing for its annual cyber insurance renewal.

During an internal review, the firm discovered inconsistent MFA deployment, outdated security documentation, and several unsupported workstations.

By implementing a structured security improvement plan, the firm:

  • Standardized MFA across all users
  • Updated endpoint protection
  • Improved documentation
  • Completed backup testing
  • Strengthened overall cybersecurity

The result was a stronger security posture and greater confidence during client and insurance security reviews.

Frequently Asked Questions

Is the FTC Safeguards Rule mandatory?

For organizations covered by the rule, compliance is required. Because applicability depends on your firm’s activities and legal obligations, consult qualified legal counsel regarding your specific circumstances.

Is Microsoft 365 enough for compliance?

Microsoft 365 is an excellent platform, but compliance depends on how it’s configured and managed. Security settings, policies, monitoring, and user training all play important roles.

How often should a risk assessment be performed?

Most firms should review their risks at least annually and whenever significant changes occur within the technology environment.

Does employee cybersecurity training matter?

Absolutely. Human error remains one of the leading causes of cybersecurity incidents. Ongoing training helps employees recognize and respond to potential threats.

What happens if we discover gaps?

Finding gaps is normal. The important step is creating a documented plan to address them based on business priorities and risk.

Why CPA Firms Choose CW IT Support

At CW IT Support, cybersecurity isn’t an add-on—it’s a core part of how we help organizations operate securely.

We work with businesses to strengthen their security posture through proactive monitoring, risk assessments, technology planning, and practical cybersecurity guidance.

Our goal is to help clients reduce risk, improve resilience, and build technology environments that support long-term business success.

Ready to Strengthen Your Security Program?

Whether you’re preparing for a compliance review, renewing cyber insurance, or simply looking to improve your firm’s cybersecurity, a structured assessment is the best place to start.

CW IT Support can help you evaluate your current environment, identify security gaps, and develop a practical roadmap for protecting your business and your clients.

Contact CW IT Support to schedule a cybersecurity assessment and learn how your firm can build a stronger security foundation.

To top