Accounting firms had a strange kind of luck for a few years. The FTC Safeguards Rule was on the books, but enforcement stayed quiet enough that plenty of firms treated their written information security plan as a document to file away, not something to actually run. That quiet stretch is over. Regulators are now checking whether firms can produce real evidence, not just a policy binder that hasn't been touched since it was written.
For a mid-sized firm juggling tax season staffing, client portals and a pile of sensitive financial data, this shift lands at the worst possible time. The busy season is already stretched thin. Adding compliance scrutiny on top of it exposes gaps that managed IT support should have closed long before the first extension deadline hit.
The Safeguards Rule requires a written information security plan but regulators are increasingly asking firms to prove the plan reflects what's actually happening on their network. That means access logs, evidence of employee training, documented incident response steps and proof that seasonal staff accounts were properly provisioned and shut off. A binder with good intentions doesn't hold up if the firm can't show the plan in action.
This shift matters because a lot of firms built their original WISP with outside help years ago, checked the box and moved on. Regulators aren't asking whether a plan exists anymore, they're asking whether someone can walk through it and show it's being followed today.
Tax season brings a wave of temporary preparers, interns and contractors who need access to client files for a few months and then disappear. Firms that manage this manually lose track of who still has login credentials in June. Managed IT support built around a firm's actual hiring calendar closes accounts the moment a contract ends, instead of relying on someone remembering to do it weeks later.
A written information security plan that describes tools the firm stopped using two years ago is worse than having no plan because it signals the document was never reviewed. You should treat the WISP as a living record, updated whenever software changes, new staff join, or a client portal gets replaced, so what's on paper matches what's protecting client data. Even small changes, like switching file-sharing tools or adding a new remote access method, need to show up in the plan the same week they happen, not months later during an annual review.
Busy season traffic spikes put real strain on servers, VPNs and client portals right when firms can least afford downtime. Capacity planning tied to the tax calendar, not a generic annual review, is part of what keeps a firm both operational and compliant when volume triples in a matter of weeks. A portal that slows to a crawl in late March isn't just an inconvenience, it's also a sign that the systems handling sensitive client data weren't sized for the load they're actually carrying.
Two firms can run nearly identical security setups and land in very different positions during an audit. The one with documented access reviews, training records and incident response logs walks through a Safeguards Rule check with confidence. The one relying on informal habits and tribal knowledge is left explaining gaps it didn't know it had. Managed IT support that builds documentation into everyday operations, not a scramble before an audit, is what separates the two.
We work with accounting firms to build managed IT support around the actual shape of their busy season, not a generic template pulled off a shelf. That means onboarding and offboarding tied to hiring cycles, helping with a WISP that gets reviewed on a real schedule, and access logs that are ready before a regulator ever asks for them. Compliance stops being a scramble in March and becomes something the firm can show off, not just survive.
The firms getting caught off guard aren't ignoring the Safeguards Rule, they're treating it as a one-time project instead of an ongoing responsibility. A short internal audit now, checking who has access to what and whether the WISP still matches reality, catches most of the obvious gaps before they turn into findings.
Enforcement pressure isn't going away and neither is the seasonal staffing churn that makes accounting firms harder to secure than most industries. Firms that pair real managed IT support with a WISP that's maintained walk into next tax season with far less to worry about. The ones still treating compliance as paperwork are the ones regulators are most likely to notice.