Back to Article List

The security plan the IRS expects you to already have

A half-open desk drawer in a small office after hours, papers and a folder inside, a key left in the lock.

Every summer the IRS and its Security Summit partners run a five-week series aimed at tax professionals, and they run it in July and August for an obvious reason. It is the only stretch of the year when a practice has time to read anything. Most of what the series covers is sensible advice you can take or leave on your own timetable. Two things in it are not advice at all. One is a document you are legally required to have, and the other is a list of contacts that is almost impossible to assemble on the day you need it. We'll look at both, and at what a small firm can realistically get done before the autumn.

Most of the campaign is guidance. One part of it is an obligation.

The 2026 series runs for five weeks and marks the Security Summit's eleventh year, working through new scams, phishing, building a security plan, the tools available, and how to spot and report a theft. Four of those five weeks are education. The third is not.

A tax or accounting practice counts as a financial institution under the Gramm-Leach-Bliley Act, which means it is required to maintain a written data security plan. Not a folder of good intentions, and not an understanding between the two people who run the place. A document. The IRS repeats this every year because the compliance rate is poor, and the compliance rate is poor because writing one from nothing is genuinely daunting when you have four staff and a filing deadline.

The IRS publishes the template, which removes most of the excuse

The part firms tend not to know is that the IRS wrote the plan for you. Publication 5709, How to Create a Written Information Security Plan for Data Safety, exists specifically so a small practice does not have to commission one. It walks through what the plan has to cover. Who is responsible for it, what data you hold and where, how you assess risk, how you vet the outside services that touch client data, and what you do if something goes wrong.

That last element is worth noticing, because it is the one that gets left blank. A plan describing your firewalls is easy to write. A plan describing what happens on the morning you discover a problem requires decisions nobody enjoys making in advance, which is exactly why they have to be made in advance.

One honest caveat. A plan written once, saved to a shared drive and never opened again satisfies the letter of the requirement and none of the point of it. The publication asks for periodic review, and the practical version of that is a calendar entry in a quiet month rather than a promise.

The list you cannot assemble on the day

Week five of the campaign covers reporting, and this is the part worth reading even if you skip everything else. The IRS's guidance for tax professionals who suffer a data theft is unusually direct about why timing matters, stating that speed is critical, because a quick report lets the IRS block fraudulent returns filed with the stolen information. The first call is not to a lawyer or an insurer. It is to your local IRS Stakeholder Liaison, who notifies IRS Criminal Investigation.

The wider list is longer than most firms expect. State tax agencies and state attorneys general, the local FBI office, your insurer, the credit bureaus, and eventually the clients themselves, in wording timed with law enforcement rather than sent the moment you find out.

There is also a federal deadline that arrived quietly. Since 13 May 2024, a covered financial institution that suffers a breach involving the information of at least 500 consumers must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery. Thirty days sounds generous until you picture the first week of it — most of which will be spent establishing what actually happened. The firms that meet it comfortably are the ones who wrote the phone numbers down in advance.

What a four-person practice can actually do before the autumn

Start by finding out whether you have a plan at all, which sounds facetious and is not — plenty of firms have one written by a departed staff member and stored somewhere nobody can name. If there isn't one, the template turns it into an afternoon. If there is, the useful test is whether it names a person, a date, and a phone number, or whether it only names technologies.

Then write down the reporting chain and keep a copy somewhere that does not depend on your own network being available. Printed and in a drawer isn't old-fashioned here. It is the point. Alongside that, it is worth knowing what your own systems would show you if something were wrong, since the signs of a compromised machine are rarely dramatic and are usually noticed by someone who already knew what normal looked like.

The technical baseline underneath all of it — multi-factor authentication, encryption of client data at rest, access that gets removed when someone leaves — is the same set of obligations that follows from how your tax software is deployed in the first place. Those two conversations are really one conversation, and firms tend to have them separately.

If you'd like a hand getting the plan written

The reason this campaign runs every summer is not that the advice changes much. It is that the work is unglamorous, never urgent until it is, and easy to move to next month eleven times in a row. That is a scheduling problem rather than a security problem. Scheduling problems are solvable.

If you'd like someone to sit down with the template, work out what your practice actually holds and where, and leave you with a plan and a contact list you could use under pressure, we're glad to help with that. August is a much better month for it than February.

Sources

IRS, Security Summit launch summer series to help tax pros protect clients from identity theft, Internal Revenue Service. Publication 5709, How to Create a Written Information Security Plan for Data Safety, Internal Revenue Service. Data theft information for tax professionals, Internal Revenue Service. Safeguards Rule notification requirement now in effect, Federal Trade Commission.