ACH payment incentive available · Multi-year prepay discounts up to 15% · View reference pricing
2026-07-08Compliance

FTC Safeguards Rule for Accounting Firms: What You Need to Have in Place

The FTC Safeguards Rule requires financial institutions — including accounting firms and tax practitioners — to implement specific security controls. This article covers the key requirements.

The Federal Trade Commission (FTC) Safeguards Rule requires financial institutions to implement a written information security program with specific technical controls. Under the Rule's expanded definition, 'financial institution' includes accountants, tax preparers, and many financial advisors.

If your firm prepares tax returns, manages financial records, or handles nonpublic personal information for clients, the Rule likely applies to you. This article summarizes the main technical requirements. Review your specific obligations with a qualified attorney or compliance advisor.

1. Written information security program

The Rule requires a documented information security program that identifies the risks to client information and the controls in place to address them. This is not optional documentation — it is the foundation regulators and auditors will look for. The program must be reviewed and updated regularly.

2. Multi-factor authentication (MFA)

The Rule requires MFA for any system that accesses customer financial information. This means MFA must be enabled on your tax software logins, email accounts, cloud storage, and any remote access tools. Standard username and password alone does not satisfy this requirement.

3. Endpoint detection and response (EDR)

Basic antivirus is not sufficient. The Rule's requirement for monitoring and testing your systems is most commonly satisfied with behavior-based EDR software. EDR monitors device activity in real time and can isolate a device from the network if suspicious encryption or ransomware activity is detected.

4. Encryption

Client data must be encrypted both when stored (at rest) and when transmitted. For most accounting firms, this means enabling full-disk encryption on all workstations and laptops (Windows BitLocker or macOS FileVault), and ensuring file transfers containing client data are sent securely.

5. Access controls and least privilege

Staff should only have access to the client data they need for their role. Admin accounts should be limited to people who genuinely need them. When an employee leaves, their access should be removed promptly.

6. Incident response plan

You need a written plan for what happens if there is a data breach or security incident: who gets notified, what steps are taken, who is responsible. The plan does not have to be complex, but it needs to exist and staff need to know where to find it.

When to Request Second-Opinion Triage

If your firm does not currently have these controls in place, a managed security assessment can identify the gaps and implement the technical requirements. Contact our team to discuss your environment. Note that Nanicto assists with technical implementation — legal compliance questions should be directed to a qualified attorney.

Related Guides
Hands-On Support

Have questions about what you have seen on your screen?

If you need a second opinion on an alert or want help putting proper zero-trust protection in place, our team is available to assist.

1 Business-Day Response· Written SOW Before Billing· Zero Hardware Lock-in