Why Accounting Firms Face Elevated Cybersecurity Risk

CPA and accounting firms hold exceptionally sensitive financial data: tax returns, financial statements, payroll information, trust accounts, and in many cases M&A details for clients. This data is valuable both for identity theft and for targeted fraud. Attackers who compromise an accounting firm can use the data to file fraudulent tax returns, conduct payroll diversion, or launch highly-targeted BEC attacks against the firm's clients using knowledge of their financial situation.

The GLBA Safeguards Rule

The Gramm-Leach-Bliley Act (GLBA) applies to accounting firms that provide financial services to individual clients. The FTC's updated Safeguards Rule, which took effect in 2023, requires covered financial institutions — including many accounting firms — to implement a written information security program with specific elements:

  • Risk assessment identifying foreseeable risks to client data
  • Technical safeguards including access controls, encryption, and MFA
  • Regular monitoring and testing of safeguards — including penetration testing
  • Oversight of service providers handling customer information
  • Incident response planning

The Referral Opportunity

CPA and accounting firms are well-positioned to refer their business clients for cybersecurity services. Many accounting clients navigating SOC 2, SOX, PCI DSS, or GLBA compliance need independent penetration testing as part of their compliance program. Grid32's referral partner program pays fees for introduced engagements with zero work required on the CPA firm's part. Many partners find that their clients view the referral as an extension of their advisory relationship — a trusted advisor connecting them with a trusted specialist. Learn about our partner program →

Serving accounting firms and their clients since 2009.

Grid32 provides penetration testing for CPA firms and offers a referral partner program for firms whose clients need security testing. Contact us to learn more.

Talk to an Expert →