FTC Safeguards Rule for Accounting Firms: What You Need to Have in Place
The FTC Safeguards Rule requires financial institutions — including accounting firms and tax practitioners — to implement specific security controls. This article covers the key requirements.
The Federal Trade Commission (FTC) Safeguards Rule requires financial institutions to implement a written information security program with specific technical controls. Under the Rule's expanded definition, 'financial institution' includes accountants, tax preparers, and many financial advisors.
If your firm prepares tax returns, manages financial records, or handles nonpublic personal information for clients, the Rule likely applies to you. This article summarizes the main technical requirements. Review your specific obligations with a qualified attorney or compliance advisor.
1. Written information security program
The Rule requires a documented information security program that identifies the risks to client information and the controls in place to address them. This is not optional documentation — it is the foundation regulators and auditors will look for. The program must be reviewed and updated regularly.
2. Multi-factor authentication (MFA)
The Rule requires MFA for any system that accesses customer financial information. This means MFA must be enabled on your tax software logins, email accounts, cloud storage, and any remote access tools. Standard username and password alone does not satisfy this requirement.
3. Endpoint detection and response (EDR)
Basic antivirus is not sufficient. The Rule's requirement for monitoring and testing your systems is most commonly satisfied with behavior-based EDR software. EDR monitors device activity in real time and can isolate a device from the network if suspicious encryption or ransomware activity is detected.
4. Encryption
Client data must be encrypted both when stored (at rest) and when transmitted. For most accounting firms, this means enabling full-disk encryption on all workstations and laptops (Windows BitLocker or macOS FileVault), and ensuring file transfers containing client data are sent securely.
5. Access controls and least privilege
Staff should only have access to the client data they need for their role. Admin accounts should be limited to people who genuinely need them. When an employee leaves, their access should be removed promptly.
6. Incident response plan
You need a written plan for what happens if there is a data breach or security incident: who gets notified, what steps are taken, who is responsible. The plan does not have to be complex, but it needs to exist and staff need to know where to find it.
When to Request Second-Opinion Triage
If your firm does not currently have these controls in place, a managed security assessment can identify the gaps and implement the technical requirements. Contact our team to discuss your environment. Note that Nanicto assists with technical implementation — legal compliance questions should be directed to a qualified attorney.