Practice Management 4 cyber essentials every tax firm needs Read the Article Open Share Drawer Share this: Share on X (Opens in new window) X Share on Facebook (Opens in new window) Facebook Share on LinkedIn (Opens in new window) LinkedIn Written by Luke Kiely Published Jul 8, 2026 5 min read Every business, including a tax firm, must have foundational technologies in place. Some of these are inherited in that they are built into the platforms and devices you already use, while others require a deliberate decision and action on your part. As threats evolve and your firm changes, nothing is set and forget. Every tool, setting, and platform needs to be reviewed and updated. Knowing what those foundations are, and taking ownership of them, is where security for all firms starts. Encryption must follow the data Think of encryption as a sealed envelope. The moment client data leaves that envelope, anyone who intercepts it can read it. It does not matter whether it is sitting on an unprotected drive, traveling through a standard email, or stored in a cloud folder with open permissions; it is your responsibility to make sure that envelope is never opened without authorization. What this means: You should have full-disk encryption on every device, so if a laptop is stolen, you’ll have a hardware loss and nothing more. The fir should have encrypted removable storage; no client data should ever move on a USB drive that is not protected. Using your practice management platform’s secure sharing function instead of email attachments, because plain email passes through an infrastructure you do not own. Periodically auditing your cloud data hosting platforms because access permissions drift, integrations accumulate, and data ends up in places nobody intended. Default settings at sign-up are not permanent guarantees. A stronger solution to passwords A stolen password alone should never be enough to access your accounts. Two-factor authentication (2FA) adds an essential second verification step, but not all second factors carry equal weight. SMS and email-based codes are inherently weak. Both of these rely on channels that can be intercepted or redirected. SIM-swapping attacks, where a criminal convinces a mobile carrier to transfer your number to a device they control, are well documented and increasingly common. Email-based codes carry the same flaw: If your email account is compromised, so is the code sitting in your inbox. Authenticator apps, which generate codes locally on your device without touching a network, are meaningfully more secure and should be the minimum standard for any business-critical account. The more significant development is the passkey, something you probably are used to by now, but not sure what it does. Supported by Microsoft, Google, and Apple, passkeys eliminate the password and 2FA. You authenticate using your device through fingerprint, face recognition, or a PIN, with verification happening cryptographically in the background. There is nothing to steal, intercept, or phish. Where platforms support passkeys, you should use them. Also worth noting is Single Sign-On. Many firms have unknowingly configured multiple tools to sign in via a single Google or Microsoft account. If that account is compromised, every connected application falls simultaneously. SSO is not inherently insecure, but the account at its center demands the strongest available protection and a password that exists nowhere else. Password management Weak and reused passwords remain one of the leading causes of business account compromises. Automated tools can cycle through millions of common combinations in seconds, and billions of stolen credentials already circulate on criminal marketplaces that are routinely tested against other platforms the moment they appear. If your approach to storing login credentials is a sticky note on your monitor, then you should treat it as compromised and fix it immediately. Password managers solve this problem effectively by generating strong, unique passwords for every account, storing them in an encrypted vault and autofilling them at login. Several are particularly well suited to smaller firm environments: 1Password Business is one of the most widely used and trusted platforms in the market with strong team management tools that make it easy to control who has access to what. Bitwarden is one of the most cost-effective of the options without meaningful compromise on capability. Keeper Security is a long-standing platform with a strong reputation among businesses, offering good user experience across devices and robust controls for managing staff access. Dashlane Business includes built-in dark web monitoring that automatically alerts you if staff credentials surface in known breach data, adding a proactive layer most competitors charge extra to provide.. Any of these solutions provide immediate and significant benefits to your firm. Anti-malware and device protection: The days of McAfee are over The image many firm owners still carry of antivirus software is a Norton or McAfee subscription running in the background, occasionally flagging something suspicious. Traditional antivirus software worked by matching files against a list of known threats, but this is a fundamentally reactive approach that modern attackers have learned to bypass. That era is long gone. What has replaced it is Endpoint Detection and Response (EDR). Where legacy antivirus looked for known bad files, EDR monitors behavior across your devices in real time, identifying suspicious activity, isolating compromised machines, and providing visibility into exactly what happened and when it happened. It is the difference between a smoke alarm and a full sprinkler system with a monitoring service. The good news is that serious endpoint protection no longer requires an enterprise budget. EDR solutions are widely available at price points accessible to firms of any size, and many business productivity platforms your firm may already be paying for include capable endpoint protection as part of its package. This is worth checking before you spend any additional money. The same principle applies here as everywhere else: deploying a solution is not enough. Alerts need to be reviewed, policies maintained, and coverage verified as your team and devices change. Endpoint protection that nobody is watching is not the same thing as protection … and can amount to a false sense of security. The starting foundation None of this requires a significant investment. The threat landscape facing tax firms is not standing still, and the tools available to defend against it aren’t either. The controls covered here are not a finish line, but are a starting point. Start with the basics, get them right, and build from there. Previous Post Large firm sees ProConnect™ Tax as “table stakes” Next Post From throwing spaghetti on the wall to a 95% close… Written by Luke Kiely Luke Kiely is the founder of iComply Online and chief information security officer at SmartVault. His experience includes law enforcement positions where he was instrumental in covertly monitoring and apprehending perpetrators of data-based cybercrimes. In addition, Luke has held several key senior roles overseeing information security, cybersecurity, and data compliance for top SaaS companies. More from Luke Kiely Leave a Reply Cancel replyYour email address will not be published. Required fields are marked *Comment * Name * Email * Website Notify me of new posts by email. Δ Browse Related Articles Practice Management 5 questions every tax firm needs to ask before moving online Practice Management 5 Ways Intuit® Link Will Transform Data Collection This Tax Season Practice Management How Can You Implement a Firm of the Future Workflow? Advisory Services TaxProTalk: A firm transitions tax software to grow, move to the cloud Advisory Services Creating an advisory workflow in the cloud Advisory Services Benefits of the cloud for tax professionals Workflow tools Benefits of cloud-native software Workflow tools Guide to switching software and migrating data Advisory Services How to prepare your firm for online transformation Practice Management 5 unexpected benefits of moving your tax firm to the cloud