← All Compliance Insights

CPA & Accounting

What Happens When a CPA Firm Doesn't Maintain a Real Security Program?

For a CPA firm, cybersecurity can look like a technology issue right up until something goes wrong.

Then the questions change. A regulator may want to know whether the firm had a functioning information-security program before the incident: where sensitive information was stored, what safeguards were in place, how employees were trained, whether vulnerabilities were being addressed, and what procedures existed for responding to an incident and notifying affected clients.

Real enforcement actions show that the consequence is not always simply a fine. In some cases, regulators have required businesses to build the security program they should already have had—under legally binding settlements, formal orders and continuing outside oversight.

Wojeski & Company CPAs: $60,000 Plus a Mandated Security Overhaul

Wojeski & Company is a certified public accounting firm in New York with roughly 35 to 40 employees. The firm experienced a ransomware attack in 2023 and a separate unauthorized-access incident in 2024. Together, the incidents exposed personal information, including Social Security numbers, belonging to more than 4,700 people. The New York Attorney General also found substantial delay in notifying affected individuals.

The settlement required Wojeski to pay $60,000 in penalties. But the penalty was only part of the consequence.

The firm was also required to implement substantial security measures, including:

  • a comprehensive information-security program;
  • encryption of personal information;
  • stronger account and access controls;
  • an inventory of where personal information is stored;
  • a vulnerability-management program;
  • a written incident-response plan designed to support timely notification; and
  • cybersecurity training for employees.
$60,000 PENALTY — PLUS A MANDATED SECURITY PROGRAM

The important point is not that Wojeski suffered a breach. Security incidents can happen even in organizations that take security seriously.

The important point is what the regulator required after examining the firm's security practices. Many of the required measures were the same kinds of safeguards, processes and documentation that a functioning security program should have addressed before the incidents occurred.

TaxSlayer: A 20-Year FTC Order

The FTC's enforcement action against TaxSlayer demonstrates how much longer the regulatory consequences can last. The FTC alleged that the tax-preparation company failed to maintain an adequate written information-security program, failed to conduct an adequate risk assessment, and failed to implement appropriate safeguards.

Following the enforcement action, the FTC entered a final order prohibiting TaxSlayer from violating the Safeguards Rule and Privacy Rule for 20 years.

The order also required independent third-party assessments of TaxSlayer's security program every two years for 10 years.

20-YEAR FTC ORDER
10 YEARS OF INDEPENDENT ASSESSMENTS

The underlying cyber incident lasted a relatively short period. The federal compliance obligations lasted decades.

That is why terms such as “FTC order” or “barred from violations” should not be read as regulatory boilerplate. They represent continuing, enforceable obligations long after the original incident is over.

TradeSource: $230,000 and a WISP Required by the State

TradeSource, Inc. was not a CPA firm, but its Massachusetts enforcement case demonstrates another important point. After a phishing-related breach exposed names and Social Security numbers belonging to more than 3,000 Massachusetts residents, the Massachusetts Attorney General found that TradeSource had no Written Information Security Plan in place before or during the breach.

The resulting settlement included $230,000 in penalties. The company was also required to:

  • create and maintain a WISP;
  • provide the written program as required under the settlement;
  • obtain an independent third-party assessment of its security program; and
  • maintain continuing employee information-security training.

These requirements became part of a state enforcement settlement rather than measures the company could implement voluntarily on its own timetable.

$230,000 PENALTY
REQUIRED WISP
INDEPENDENT ASSESSMENT
STATE OVERSIGHT

The absence of the written security program was not merely an administrative detail discovered after the breach. It was part of the enforcement problem.

The Fine Is Often Not the Biggest Consequence

These three cases involve different organizations, laws and regulators. But the pattern is difficult to miss.

The consequences included:

  • mandatory security programs;
  • required written policies;
  • employee training;
  • vulnerability management;
  • encryption and access controls;
  • independent third-party assessments;
  • incident-response requirements; and
  • years of continuing regulatory obligations.

The dollar penalty is easy to put in a headline. The longer-term cost may be management time, legal expense, mandatory remediation, independent assessments, documentation requirements, reputational damage and operating under requirements imposed through an enforcement agreement or order.

What Should a CPA Firm Have Before an Incident?

A practical security program should answer basic questions such as:

  • What sensitive information does the firm maintain?
  • Where is that information stored?
  • What reasonably foreseeable risks threaten it?
  • What administrative and technical safeguards are in place?
  • Who is responsible for overseeing the program?
  • How are employees trained?
  • How are vulnerabilities identified and addressed?
  • How are service providers evaluated?
  • What happens when a security incident is discovered?
  • Who handles breach-notification escalation?
  • How does the firm document that the program is actually being maintained?

For CPA and tax firms, these questions overlap directly with the FTC Safeguards Rule, IRS safeguarding guidance and the firm's Written Information Security Plan.

A deeper explanation of the WISP is available in:

What Does a CPA Firm's WISP Actually Need to Include?

A practical explanation of the FTC requirements is available in:

The FTC Safeguards Rule for CPA Firms: What It Means in Practice

Build the Program Before Someone Else Defines It for You

A breach does not automatically mean that a firm failed to maintain reasonable security. That is not the lesson from these cases. The more useful lesson is what regulators required once significant security shortcomings became part of an investigation.

Wojeski was required to overhaul its security program. TaxSlayer entered a federal order lasting 20 years. TradeSource was required to create the WISP it did not have and subject the program to independent assessment.

CPA firms have a better option: identify the gaps, prioritize them and build the security program deliberately—before an incident, insurer or regulator is setting the timetable.

How GO InfoTek Can Help

GO InfoTek helps CPA and accounting firms turn security and compliance requirements into a practical operating program. That can include:

  • security risk assessments;
  • Written Information Security Plan development and maintenance;
  • FTC Safeguards Rule support;
  • implementation and review of technical safeguards;
  • vulnerability management;
  • incident-response planning;
  • breach-notification planning;
  • security-awareness training and testing;
  • vendor-security oversight;
  • policy and documentation development; and
  • ongoing vCISO support.

The objective is not simply to produce a compliance document. It is to make sure the firm's policies, technology and actual day-to-day security practices describe the same security environment—and that the firm can demonstrate what it has put in place.

Because the best time to discover that the security program has gaps is before someone else requires the firm to fix them.

This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.

Sources and Further Reading

A practical next step

Discuss Your Environment with GO InfoTek

Start with the systems, safeguards, documentation and questions your organization has today.

Schedule a Conversation