
October 2026 | IT Support for CPA Firms Salt Lake City | Cybersecurity Awareness Month | IRS Data Security
October is Cybersecurity Awareness Month — and for Salt Lake City CPA firms, it lands at a meaningful moment. The October 15 extension deadline is behind you, the pre-season window is opening, and it's a good time to take stock of what you actually know versus what you think you know about protecting client tax records. Not all of the advice circulating in the profession is accurate. Some has been repeated so long that it sounds like fact even when it's outdated or wrong.
When bad advice goes unchallenged, it creates blind spots. And blind spots are exactly what cybercriminals look for. For accounting firms, the stakes are unusually high: your systems hold Social Security numbers, bank account details and complete financial histories for every client you serve — some of the most valuable data a criminal can steal. Knowledge gaps and comfortable assumptions are what make firms easy targets, not their location or their client mix.
The good news is that these gaps are simple to close once you know where they are. Here are six myths we hear from CPA firm partners regularly, along with the truth behind each one.
Myth 1: "Hackers Only Care About Us During Tax Season"
It's tempting to believe the threat rises in March and April and fades once returns are filed. In reality, attackers target CPA firms year-round. The October 15 crunch is a prime window — your accounting staff is rushing extensions out the door and more likely to click without thinking. But the quiet weeks that follow are just as attractive, because attackers know firms relax, defer software updates and postpone security projects until January.
If your firm has exposed accounts, an unpatched server running UltraTax CS or Lacerte, or a client portal with weak authentication, bad actors will take advantage of it in November just as readily as in April. Every CPA firm offers something valuable: client SSNs, EFINs, banking details and direct pathways to hundreds of taxpayers.
Fact: Hackers choose targets based on opportunity, not the tax calendar.
Myth 2: "Our Staff Will Recognize a Phishing Email"
The days of obvious phishing emails full of typos from suspicious senders are gone. Today's emails are polished and personalized — and the ones aimed at accounting firms are crafted to look exactly like the messages your staff expects: fake IRS e-Services notices, spoofed EFIN verification requests, bogus alerts from your tax software vendor and fake client emails with "tax documents" attached.
Thanks to AI, it's become harder to catch a scam from the text alone. Instead, your accounting staff needs to think about sender behavior. Ask whether the supposed sender would:
- Make an unusual request, like re-verifying your e-Services credentials by email
- Change payment or refund deposit instructions
- Request sensitive information such as client SSNs or portal logins
- Send a new or unusual login link for your tax software or document portal
If anything seems off, verify before clicking or responding. The IRS does not initiate contact by email — a fact every person in the firm should know cold.
Fact: A convincing email can still be a scam, even one wearing an IRS logo.
Myth 3: "MFA Fully Protects Our Tax Software"
Multi-factor authentication (MFA) is essential — the IRS and the FTC Safeguards Rule effectively require it for systems holding taxpayer data. But it's not invulnerable. Hackers use MFA fatigue to their advantage, counting on staff approving requests out of habit or annoyance. "Prompt bombing," for example, floods a preparer's phone with requests during a busy day in hopes they'll approve access just to make them stop.
MFA is a tool, not a shield. Attackers are finding ways around weaker authentication methods, which is why the MFA on your UltraTax CS, CCH Axcess or client portal logins needs support from the security controls around it — monitoring, access reviews and alerting when something looks wrong.
Fact: MFA should be one layer in a broader security program, not the whole program.
Myth 4: "Our Backups Have Us Covered"
Ask yourself: if your firm was hit with ransomware tomorrow, could you actually restore your client tax records? Could you recover prior-year returns, the current-year files in Drake Tax or Lacerte, and the workpapers in your document management system? How long would it take — and could you do it in February?
A backup is great when you know it's going to work. An untested backup isn't something you can rely on during an incident. If you've never performed a test restore of a client return, you don't have a recovery plan — you have a hope. Knowing how long your firm would realistically be down can save you significant time, money and client relationships.
Fact: Having backups is not the same as being able to recover.
Myth 5: "Cybersecurity Is Only IT's Responsibility"
Your IT provider does a lot to keep your firm safe, but they can't control every click your accounting staff makes. And for CPA firms, this myth isn't just risky — it's contrary to your compliance obligations. IRS Publication 4557 and the FTC Safeguards Rule make data security the responsibility of the entire firm, with a designated individual accountable for the program. Security decisions happen at every desk, every day, and it takes only one bad click to expose every client file.
Employee security awareness training matters. When everyone in the firm knows what a fake IRS notice looks like and when to ask for help, they become part of your defenses instead of the gap in them.
Fact: Under IRS Publication 4557, protecting taxpayer data is the whole firm's obligation — and training your staff strengthens both security and compliance.
Myth 6: "We'd Know What to Do If Something Happens"
It's a Tuesday morning in early December. Several preparers suddenly can't access client files. Many firms discover in that exact moment that nobody has answered the basic questions:
- Should staff shut down their computers?
- Who calls IT?
- Who notifies the IRS Stakeholder Liaison, and when?
- When does the insurance company get involved?
- Who communicates with clients — and how?
Don't rely on memory in the moment. Your Written Information Security Plan (WISP) — which the IRS requires of every professional tax preparer — must include a documented incident response plan. Improvising during a breach isn't just chaotic; it means the plan you attested to having wasn't real.
Fact: Your recovery plan shouldn't debut during an incident — and your WISP requires it to exist long before one.
Frequently Asked Questions
Do you offer cybersecurity and IT support for CPA firms in Salt Lake City?
Yes. Qual IT provides IT support for CPA firms in Salt Lake City, including threat detection and response, email security, phishing protection, employee security awareness training, MFA implementation, secure client portal management and IRS data security compliance support — including WISP development aligned with Publication 4557.
What does IRS Publication 4557 require of accounting firms?
Publication 4557 outlines the safeguards tax professionals must have under the FTC Safeguards Rule: a Written Information Security Plan (WISP), a designated security coordinator, risk assessments, access controls, encryption, multi-factor authentication, employee training and a documented incident response plan. Every firm that prepares returns is expected to comply, and PTIN renewal now requires attesting to a data security plan.
How do I know if my firm's cybersecurity is actually working?
Through testing and review: verified restores of client tax records, simulated phishing exercises tailored to the scams aimed at preparers, and a periodic assessment of your tools, policies and WISP by a qualified IT partner who understands accounting firm IT services in Utah.
Cybersecurity Awareness Starts With the Facts
Cybersecurity Awareness Month is about making sure the assumptions guiding your firm's decisions are correct. Myths are comfortable — they let you feel covered without digging deeper. But security gaps rarely come from a missing product. They come from believing you've already got it handled when you don't.
If any of these myths sound familiar, the post-deadline window is the right time to take a closer look — before the pre-season rush begins. We work with Salt Lake City CPA firms to protect client data and keep systems running through tax season. Schedule a free 10-minute discovery call with Qual IT and we'll help you separate what's protecting your client tax records from what's only giving you peace of mind.

