
Every accounting firm stores some of its clients' most sensitive information, including tax returns, Social Security numbers, payroll records, banking details, and financial statements. That makes CPA firms a frequent target for cybercriminals.
The good news is that improving your firm's cybersecurity doesn't require guessing where to start. By implementing a core set of technology controls, you can significantly reduce your risk while improving operational resilience.
This checklist outlines 15 cybersecurity best practices every CPA firm should review, whether you have five employees or fifty.
Disclaimer: This checklist is intended for educational purposes only and is not legal or regulatory advice. Your firm should consult appropriate legal, regulatory, and compliance professionals regarding specific requirements.
Why CPA Firms Are Frequent Targets
Accounting firms manage highly valuable financial and personal information. A single compromised email account or infected workstation can expose client records, interrupt tax season, and damage your firm's reputation.
Common threats include:
- Phishing emails
- Ransomware
- Business Email Compromise (BEC)
- Stolen passwords
- Insider threats
- Unpatched software vulnerabilities
A layered cybersecurity strategy helps reduce these risks.
The 15-Point Cybersecurity Checklist
1. Enable Multi-Factor Authentication (MFA)
Protect every Microsoft 365 account, remote access connection, and administrator account with MFA.
Status: □ Complete □ Needs Improvement
2. Deploy Endpoint Detection & Response (EDR)
Traditional antivirus alone is no longer enough. Modern EDR solutions provide continuous monitoring and faster threat detection.
Status: □ Complete □ Needs Improvement
3. Secure Microsoft 365
Review:
- Conditional Access
- Email security
- Administrator accounts
- External sharing
- Legacy authentication
- User permissions
Status: □ Complete □ Needs Improvement
4. Verify Backup and Disaster Recovery
Ask yourself:
- Are backups encrypted?
- Are they stored off-site?
- Have they been tested?
- How quickly can we recover?
Status: □ Complete □ Needs Improvement
5. Patch Operating Systems and Applications
Keep Windows, Microsoft 365, browsers, tax software, and line-of-business applications up to date.
Status: □ Complete □ Needs Improvement
6. Perform Vulnerability Scanning
Regularly identify and remediate security weaknesses before attackers can exploit them.
Status: □ Complete □ Needs Improvement
7. Encrypt Sensitive Data
Use encryption for laptops, mobile devices, backups, and stored client information.
Status: □ Complete □ Needs Improvement
8. Limit User Permissions
Apply the Principle of Least Privilege so employees only have access to the systems and data they need.
Status: □ Complete □ Needs Improvement
9. Secure Remote Access
Protect remote workers with secure access technologies, device management, and Multi-Factor Authentication.
Status: □ Complete □ Needs Improvement
10. Train Employees
Provide ongoing cybersecurity awareness training and phishing simulations throughout the year.
Status: □ Complete □ Needs Improvement
11. Protect Email
Implement advanced email filtering, malware protection, and anti-phishing controls.
Status: □ Complete □ Needs Improvement
12. Review Third-Party Vendors
Evaluate the security practices of software providers and cloud services used by your firm.
Examples include:
- QuickBooks Enterprise
- Lacerte
- UltraTax
- Drake Tax Software
- ShareFile
- Laserfiche
Status: □ Complete □ Needs Improvement
13. Monitor Your Network
Implement continuous monitoring for servers, workstations, firewalls, Microsoft 365, and backup systems.
Status: □ Complete □ Needs Improvement
14. Create an Incident Response Plan
Document how your firm will respond to ransomware, phishing attacks, and other cybersecurity incidents.
Status: □ Complete □ Needs Improvement
15. Meet with Your vCIO Regularly
Technology and cybersecurity should be reviewed throughout the year, not only when something goes wrong.
Regular planning meetings help ensure your IT strategy supports your firm's growth, security, and business objectives.
Status: □ Complete □ Needs Improvement
How Torch Networks Helps CPA Firms
Torch Networks works with accounting firms and other financial organizations to implement many of these cybersecurity controls.
Our managed IT services include:
- 24/7/365 Help Desk
- 15-minute response guarantee
- Microsoft 365 administration
- Endpoint Detection & Response
- Secure backups
- Vulnerability management
- Vendor coordination
- Strategic vCIO services
- Continuous monitoring
- Layered cybersecurity
We also support the technology infrastructure behind leading accounting applications, including QuickBooks Enterprise, Lacerte, UltraTax, Drake Tax Software, Laserfiche, ShareFile, and Microsoft 365.
Not sure how your firm measures up?
Schedule a complimentary cybersecurity assessment with Torch Networks. We'll review your current environment, identify potential security gaps, and provide practical recommendations to help strengthen your firm's security posture.


