
UpTrajectory Review
The FTC Safeguards Rule and IRS Publication 4557 have been looming over tax and accounting firms for years, yet many practitioners still treat compliance as a checkbox exercise rather than a fundamental shift in how they handle client data. Jason Bramwell's piece in CPA Practice Advisor cuts through the regulatory fog with a plain-language breakdown of what these rules actually demand, not what firms wish they demanded. This is not theoretical guidance. The Safeguards Rule, originally aimed at financial institutions, now explicitly covers tax preparers and accounting firms as 'financial institutions' because they handle consumer financial data. The rule requires a written information security plan, risk assessments, access controls, encryption, employee training, and oversight of service providers. Bramwell's contribution is translating this legalese into operational reality for firms that are still running their IT on hope and a prayer.
For small and mid-sized accounting practices, this is not optional. The FTC has made clear that tax preparers fall under its enforcement umbrella, and the penalties for noncompliance are severe—fines up to $100,000 per violation, plus potential personal liability for firm owners. But the real cost is not the fine. It is the reputational damage when a data breach exposes client Social Security numbers, bank accounts, and financial histories. Clients do not distinguish between a hacker and a negligent firm; they see a professional who failed to protect their most sensitive information. Bramwell's piece matters because it frames compliance not as a legal burden but as a client trust imperative, which is exactly how small firms should think about it.
What is genuinely useful here is the emphasis on IRS Publication 4557 as a practical companion to the Safeguards Rule. Too many firms treat these as separate, overlapping mandates when they are actually complementary. Publication 4557 provides the 'how'—specific safeguards for protecting taxpayer data—while the FTC rule provides the 'why' and the enforcement teeth. Bramwell correctly identifies that the biggest gap in most firms is not technology but governance: no written plan, no assigned responsibility, no incident response protocol. The piece is skeptical of the common excuse that 'we are too small to be a target.' That is precisely backwards. Small firms are targeted because they are soft targets, and the data they hold is just as valuable as what big banks hold.
The second-order effects are significant. Compliance costs money upfront—encryption tools, secure portals, staff training, possibly a fractional CISO or managed security provider. But the downstream costs of a breach are catastrophic: client attrition, professional liability claims, regulatory scrutiny, and the time sink of managing an incident instead of serving clients. There is also a competitive angle. Firms that can credibly demonstrate robust data security will win clients from firms that cannot. In an era of remote work and cloud-based everything, security is no longer a back-office concern. It is a client-facing differentiator. Bramwell's piece hints at this but could go further in connecting compliance to business development.
What to watch next is enforcement. The FTC has been relatively restrained so far, but that will not last. State attorneys general are also getting into the act, and the IRS is increasingly focused on data security as part of its broader taxpayer protection efforts. Firms should not wait for a breach or an audit to get serious. The practical move is to start with a risk assessment, document everything, and assign one person—owner, office manager, or external advisor—to own the security plan. Review it annually. Train staff quarterly. And treat client data with the same care you treat client money. Bramwell's piece is a solid starting point, but it is only a starting point. The real work is operational, ongoing, and non-negotiable.
Takeaway: Assign one person to own your written security plan, train staff quarterly, and treat client data like client money—because regulators and clients now do.
Excerpt from the original — CPA Practice Advisor
A plain-language breakdown of what the FTC Safeguards Rule and IRS Publication 4557 mean for tax and accounting firms.