The Quick Answer

Meeting the FTC Safeguards Rule is important for accounting and tax firms that are subject to it.

But meeting a requirement is not the same thing as knowing your business is protected.

A firm can have policies, security controls, written plans, training, and documentation in place while still carrying meaningful Operational, Legal, Reputational, and Regulatory Cyber Liability.

That is why MTS Consulting Group approaches the FTC Safeguards Rule as a starting point, not the finish line.

The better leadership questions are:

  • Are the safeguards actually working?
  • Can we prove they are working?
  • Do our documented policies match what employees really do?
  • Can the firm continue operating if an important system fails?
  • Does leadership understand the risks that remain?
  • Are important decisions documented?
  • What happens when the business changes?

At MTS, our position is simple:

Compliance is the minimum. Cyber Liability is the truth.

The goal is not simply to satisfy a requirement.

The goal is to build a business that understands its exposure and is better prepared before something goes wrong.

Five-step FTC Safeguards Rule infographic for cyber liability management

Compliance is the minimum. Cyber Liability is the truth.

The goal is to build a business that understands its exposure and is better prepared before something goes wrong.

Why the FTC Safeguards Rule Matters to Accounting and Tax Firms

Accounting and tax firms routinely work with information that clients consider extremely sensitive.

Depending on the services a firm provides, that may include:

  • Tax records
  • Social Security numbers
  • Bank information
  • Payroll information
  • Business financial statements
  • Personally identifiable information
  • Employee records
  • Client documents
  • Authentication information
  • Other confidential financial data

For firms subject to the FTC Safeguards Rule, protecting customer information is not simply a technology preference.

It is a business responsibility.

But there is an important distinction.

The Rule can tell leadership that safeguards need to exist.

It cannot make those safeguards effective simply because someone documented them.

That still requires leadership, technology, people, processes, evidence, verification, and ongoing attention.

The MTS Perspective: A Requirement Is a Baseline, Not a Business Strategy

Organizations sometimes approach cybersecurity requirements like a school assignment.

Complete the required items.

Save the documents.

Check the boxes.

Move on.

That approach can create false confidence.

Leadership begins thinking:

“We completed the requirement, so we must be protected.”

But the business may have changed since the paperwork was completed.

A new cloud application may have been introduced.

A new employee may have been given access.

A former employee’s access may not have been fully removed.

A vendor may now connect to sensitive systems.

Remote-work practices may have changed.

AI tools may be used with client information.

A backup process may exist but never have been tested.

A policy may describe one process while employees follow another.

That is why a requirement cannot be the end of the conversation.

The real question is:

What Cyber Liability is the organization still carrying?

The Five Gaps Between “We Have It” and “We Know It Works”

For leadership, one of the most useful ways to think about the FTC Safeguards Rule is to look for five gaps.

Gap #1: The Documentation Gap

The organization has written policies.

But do the policies describe what actually happens?

A document may say:

“Access is removed when an employee leaves.”

That sounds good.

Now ask:

  • Who performs that task?
  • How quickly?
  • Which systems are included?
  • How is completion verified?
  • What happens with cloud applications outside the normal IT environment?
  • Is there evidence showing the access was removed?

A written process and an operational process are not automatically the same thing.

Good documentation should reflect reality.

If reality changes, the documentation should change with it.

Gap #2: The Implementation Gap

Leadership may approve a safeguard.

That does not prove the safeguard was completely implemented.

For example:

“We require multifactor authentication.”

The next questions should be:

  • On which systems?
  • For which users?
  • Are privileged accounts included?
  • Are there applications where MFA is unavailable or disabled?
  • Who verifies the configuration?
  • What exceptions exist?

The point is not that MFA is ineffective.

The point is that the statement “we have MFA” is less useful than evidence showing where it is actually protecting the organization.

Implementation should be verified.

Gap #3: The Evidence Gap

This is one of the most important distinctions in the MTS operating model.

Leadership often hears statements such as:

  • “We have backups.”
  • “Everything is patched.”
  • “The antivirus is running.”
  • “The vendor handles that.”
  • “The policy is complete.”

Those statements may be correct.

But MTS believes important Cyber Liability decisions should be based on evidence before assumption.

For example:

Instead of:

“We have backups.”

ask:

“When was the last successful recovery test, what was restored, and what did we learn?”

Instead of:

“Security software is installed.”

ask:

“Which systems are reporting correctly, and where are the gaps?”

Evidence changes the quality of the leadership conversation.

Gap #4: The Business-Impact Gap

A security requirement generally focuses on protecting information.

Leadership must also understand what happens to the organization when a control fails.

Suppose a tax preparation system becomes unavailable during a critical filing period.

The technical problem matters.

But leadership is dealing with something larger:

Operational Risk

Can staff continue working?

Legal Risk

Does the event create responsibilities that require professional guidance?

Reputational Risk

What happens to client confidence?

Regulatory Risk

What responsibilities may be triggered or exposed?

That is why MTS uses the four areas of Cyber Liability.

They force leadership to look beyond the technical issue.

Gap #5: The Ownership Gap

One of the most dangerous phrases in cybersecurity is:

“I thought somebody else handled that.”

Leadership may assume:

  • The IT provider owns it.
  • The software vendor owns it.
  • The office administrator owns it.
  • The outside consultant owns it.
  • The employee owns it.

Meanwhile, everyone involved may have a different understanding.

Requirements do not eliminate shared responsibility.

They make clarity more important.

For every meaningful safeguard, leadership should understand:

Who owns implementation?

Who verifies it?

Who maintains it?

Who receives evidence?

Who makes the business decision when a gap is identified?

Unclear ownership creates hidden Cyber Liability.

The FTC Safeguards Rule Is the Starting Line: Not the Finish Line

Five-step FTC Safeguards Rule infographic for cyber liability management

Requirements establish the baseline. Leadership manages the risk.

Your WISP Should Be a Living Business Document

For many accounting and tax firms, the Written Information Security Plan (or WISP) becomes a central part of the security conversation.

The danger is treating it as a document that exists simply to prove a document exists.

A useful WISP should connect to the real organization.

If the firm changes:

  • technology,
  • vendors,
  • locations,
  • employees,
  • work practices,
  • applications,
  • data flows,
  • or business processes,

the risk picture can change as well.

That means leadership should periodically ask:

“Does our written plan still describe the organization we actually operate?”

A beautiful document that describes a business from three years ago may offer less protection than leadership assumes.

The document should support the system.

It should not replace the system.

Policies Have to Match Behavior

This is another place false confidence develops.

Imagine a policy says:

“Sensitive client information may only be stored in approved systems.”

Good.

Now ask employees how they actually work.

Do they:

  • Email files to themselves?
  • Save information locally?
  • Use personal cloud-storage accounts?
  • Put client information into unsanctioned AI tools?
  • Share documents through unapproved services?
  • Create operational workarounds when deadlines are tight?

The question is not whether employees are bad people.

Most workarounds happen because people are trying to get work done.

That is why Teach Before We Act matters.

Security guidance needs to make sense to the people expected to follow it.

If the only thing standing between your written policy and risky employee behavior is a document nobody remembers reading, leadership does not have enough evidence.

A Policy Is Not Proof

Six step policy cycle infographic showing document, implement, verify, interpret, decide, document again

Evidence Before Assumption

Requirements tell you what should exist. Evidence tells you what actually exists.

A Safeguard Should Have Four Things Attached to It

A simple MTS framework is to look at every meaningful safeguard through four questions.

1. Owner

Who is responsible?

2. Evidence

How do we know it exists and works?

3. Business Impact

What could happen if it fails?

4. Review

When will we look at it again?

Those four items turn a control into an ongoing management process.

Without them, leadership may know what was supposed to happen but have very little visibility into what is actually happening.

Cyber Liability Does Not Disappear When a Recommendation Is Deferred

Accounting firms have budgets.

Not every improvement can happen immediately.

That is normal.

The MTS standard is not:

Every recommendation must be approved today.

The standard is:

Every meaningful decision should be understood.

When a risk is identified, leadership can choose to:

Accept

Proceed with the recommendation.

Defer

Recognize the issue but intentionally schedule action for later.

Decline

Consciously decide not to proceed.

Those are business decisions.

But there is another category that creates trouble:

Forget

The recommendation gets discussed.

Nobody owns it.

Nothing is documented.

Six months later, everyone assumes somebody handled it.

Cyber Liability did not disappear.

The decision trail did.

That is why MTS treats documentation as part of the protection system.

The Three-Finding Rule Applies Here Too

Security and regulatory assessments can generate long reports.

That does not mean leadership should try to fix everything at once.

MTS believes a leadership conversation should usually begin with one to three meaningful findings.

For each one:

What did we find?

State the evidence.

Why does it matter?

Translate it into business language.

Which Cyber Liability areas could it affect?

Operational?

Legal?

Reputational?

Regulatory?

What do we recommend?

Make the next step clear.

What happens if we wait?

Explain the consequence without using fear.

What does leadership need to decide?

Create ownership.

A 70-page report may contain useful information.

Three clear decisions are more likely to produce meaningful action.

Illustrative Accounting-Firm Scenario

Consider a 30-person accounting and tax firm.

The firm has:

  • A WISP
  • Multifactor authentication
  • Endpoint protection
  • Backups
  • Annual employee training
  • An outsourced IT provider

Leadership reasonably believes the firm’s security program is in good shape.

Then an independent review discovers:

  1. Two important cloud applications are outside the firm’s normal MFA standard.
  2. Backup jobs are running, but no one can produce evidence of a recent recovery test.
  3. Several seasonal users retained access beyond the period when they needed it.

The lesson is not:

“The firm failed.”

The lesson is:

The organization had safeguards, but verification identified areas where reality did not completely match leadership’s expectation.

Now leadership has three clear decisions.

That is progress.

Why Independent Verification Matters

Organizations should be willing to test their own assumptions.

That includes MTS.

This is why we established an important principle:

If independent evidence identifies something we missed, the goal is not to defend our pride.

The goal is to protect the client.

That means a healthy security program should include opportunities for outside evidence to challenge what leadership and the technology provider believe to be true.

An independent assessment may confirm:

“You are in better shape than you thought.”

That is valuable.

It may also reveal:

“There are three areas you believed were covered that deserve additional attention.”

That is valuable too.

The goal is not to manufacture bad news.

The goal is clarity.

From Requirement to Evidence

FTC Safeguards Rule five step process infographic for accounting firms

A policy is not proof. Evidence creates clarity.

The FTC Safeguards Rule and the Four Areas of Cyber Liability

The MTS Cyber Liability Framework helps leadership put safeguards into business context.

Operational Risk

Ask: Can we continue operating?

Security controls should support the firm’s ability to remain productive and recover from disruptions.

Legal Risk

Ask: What responsibilities could this create?

Technology providers should not replace qualified legal counsel.

But they should be able to provide clear technical facts, evidence, and documentation when leadership needs appropriate professional guidance.

Reputational Risk

Ask: Will clients continue trusting us?

A client may never ask which endpoint-security product you use.

They may care deeply about how their sensitive information is protected and how your firm responds when something goes wrong.

Trust is a business asset.

Regulatory Risk

Ask: Are we meeting the responsibilities expected of us?

This is where the FTC Safeguards Rule directly enters the conversation.

But remember:

A requirement identifies responsibility.

Leadership still needs to make sure the organization is actually prepared.

What Leadership Should Ask Instead of “Are We Compliant?”

Because MTS intentionally avoids making compliance the destination, consider replacing that question.

Instead of:

“Are we compliant?”

ask:

1. What responsibilities apply to our firm?

Get clarity first.

2. What safeguards have we actually implemented?

Separate intention from action.

3. What evidence proves those safeguards are working?

Separate belief from verification.

4. What Cyber Liability remains?

See the whole risk.

5. What decisions are still open?

Create accountability.

Those five questions create a more useful leadership conversation.

What Changes Should Trigger Another Look?

Cyber Liability is not static.

A firm should consider reviewing its risk position when meaningful changes occur.

Examples include:

  • Adding a new office
  • Significant staff growth
  • Adding seasonal employees
  • Changing tax or accounting applications
  • Introducing new cloud platforms
  • Expanding remote work
  • Changing major vendors
  • Implementing AI tools
  • Handling new categories of sensitive information
  • Changing backup systems
  • Experiencing a significant security incident
  • Discovering a meaningful control gap

A plan that was appropriate yesterday may need adjustment tomorrow.

The objective is not constant panic.

It is intentional review.

Frequently Asked Questions

Does meeting the FTC Safeguards Rule mean our firm is secure?

No requirement can guarantee that an organization will never experience a security incident.

Meeting applicable responsibilities is important, but leadership should also evaluate implementation, evidence, recovery, changing business conditions, and remaining Cyber Liability.

Does the FTC Safeguards Rule apply to every accounting firm?

Applicability can depend on the activities performed by the organization and its status under the relevant law and rule.

Accounting and tax firms should confirm applicability with qualified legal or regulatory professionals rather than relying solely on an IT provider or an online article.

MTS can help explain the technology and Cyber Liability implications but does not replace legal counsel.

What is a WISP?

A Written Information Security Plan documents how an organization approaches protecting sensitive information.

The important MTS question is not merely whether the document exists.

It is whether the documented program reflects how the business actually operates and whether important safeguards can be verified.

How often should a WISP be reviewed?

The appropriate review cycle depends on the organization and its applicable responsibilities.

Leadership should also review the plan when meaningful business or technology changes occur rather than assuming the calendar alone determines when risk changes.

Is having MFA enough?

MFA is an important security control.

But leadership should understand where it is enabled, where it is not, which accounts are protected, what exceptions exist, and whether implementation has been verified.

If we have backups, are we prepared?

Not necessarily.

Backup is a technology function. Recovery is a business outcome.

Ask what can be recovered, how long recovery may take, and what has actually been tested.

Who should own the firm’s security program?

Leadership owns the business responsibility.

Technology providers, employees, vendors, and other professional advisors may each have defined roles.

The objective should be clear ownership rather than assuming one outside provider owns every responsibility.

Can our IT provider tell us whether we meet every legal requirement?

An IT provider can explain technical controls, provide evidence, identify gaps, and assist with implementation.

Questions requiring legal interpretation should be directed to qualified legal counsel.

Good advisors understand the boundary between their expertise and someone else’s.

The MTS Perspective

MTS does not want accounting-firm leaders memorizing regulations.

We want them making better decisions.

That means understanding:

What is required.

What has been implemented.

What has been verified.

What remains exposed.

What decision comes next.

The FTC Safeguards Rule can help create an important baseline.

But it should not become the ceiling.

A firm should not wait until a regulator, client, attorney, failed recovery, or cyber incident exposes the difference between what the organization thought it had and what actually existed.

That is why MTS looks beyond the first visible requirement.

Create Clarity Before Action.

Teach Before We Act.

Guide Through the Storm.

See the Whole Risk.

Because the objective is not simply completing the requirement.

The objective is a stronger organization.

Your Next Step

Take one safeguard your leadership team believes is already handled.

Do not buy anything.

Do not change anything yet.

Ask four questions:

Who owns it?

What evidence do we have?

What happens to the business if it fails?

When was it last reviewed?

You may discover that everything is exactly where it should be.

Good.

You may discover an assumption that needs investigation.

Also good.

Either way, leadership has replaced uncertainty with evidence.

That is the first step toward reducing Cyber Liability.

If your firm needs help seeing the larger picture, MTS’s 26-minute Cyber Liability Assessment is designed to begin that conversation in plain English.

The objective is not to overwhelm leadership with a technical audit.

It is to understand where you may be exposed, what matters most, and what deserves attention first.

Clarity first. Action second.

Continue Through the Cyber Liability Knowledge Center

Previous Chapter:
What Should Managed IT Actually Do to Reduce an Accounting Firm’s Business Risk?

Start Here:
What Is Cyber Liability, and How Is It Different from Cybersecurity?

Next Chapter:
What Should Tax Professionals Understand About IRS Publication 4557 Beyond the Checklist?

Related chapters:

Explore MTS services: