TL;DR
- Attacks on accounting firms are overwhelmingly social rather than technical, and they succeed by imitating work the firm already expected to do. The tool your provider uses to manage your devices is itself worth asking about.
- The risk curve moves during filing season. A control posture that is right in June is undersized in February, and the fix is a seasonal checklist, not a permanent upgrade.
- The IRS Security Six serves as a baseline, not a complete solution. It does not address vendor oversight, data retention, or incident response, areas where the next layer of the stack provides critical protection.
- Your firm’s security needs grow in stages tied to real triggers (your first remote hire, your first remote team member, your first enterprise client), not a generic size band.
In February 2026, Microsoft tracked a phishing campaign that targeted 29,000 users across 10,000 organizations, using IRS-themed emails to install remote monitoring and management (RMM) software such as ScreenConnect and SimpleHelp on victims’ machines.
The attackers were not exploiting a software flaw so much as the fact that an email about tax forms, during tax season, doesn’t look unusual enough to ignore.
That is the pattern behind most accounting firm cybersecurity failures, and it is why a stack built around firewalls and antivirus alone keeps missing.
This piece maps the threat model targeting your firm, the five-layer stack that addresses it, and why your controls should look different in February than in June.
The Threat Model: What Is Actually Attacking Accounting Firms
Phishing against accounting firms rarely needs technical sophistication. The IRS Security Summit calls the most common way in “new client” spear phishing.
It starts with a message that looks like ordinary business, a prospective client emailing to ask if your firm has the capacity to take on new work. Because responding to that kind of inquiry is exactly what you’re in business to do, you reply, and the thread continues from there.
The malicious payload doesn’t show up until the second or third message, once the thread has already felt established and legitimate. Cruder versions still carry a tell, stiff phrasing, or a request that doesn’t quite add up.
The versions worth worrying about ride in through an email account the attacker already compromised, with no telltale signs at all. Quishing (QR code phishing) and voice-cloned callback requests use the same trick through a different channel, exploiting a form of contact your firm already trusts rather than a gap in your firewall.
Successfully managing financial operations while maintaining robust security is a hallmark of strategic finance.
This is also why your stack should be led by identity rather than the network perimeter. A single compromised preparer account exposes every client that the preparer touches, not just one file. That is why one successful phishing attempt against an accounting firm pays off far more than the same attempt against a similarly sized business in most other industries.
Proofpoint has tracked tax-themed campaigns delivering RMM tools such as Datto, N-Able, and ScreenConnect as their final payload, and Microsoft’s February data confirms the same pattern at scale. RMM access is also how a lot of ransomware ends up on accounting firm networks in the first place, since remote-access software gives an attacker the same reach as a legitimate provider.
Attackers want an RMM tool running on your machine for the same reason your IT provider wants one there: it provides privileged, often invisible access to every device it manages.
This dual purpose makes your provider’s remote access tool a high-value target, whether an attacker compromises the legitimate software or creates a convincing fake that your team installs themselves. Every firm evaluating a managed IT provider should ask how that provider secures its own privileged access, and most never do.
Filing Season Changes the Risk Curve, So the Controls Should Move Too
Tax season cyberattacks compound for three reasons between January and April. Attackers time campaigns to the calendar, since a tax-themed message only lands when tax season is genuinely underway.
Your staff is working longer hours under deadline pressure, which measurably degrades the scrutiny of unfamiliar emails or unusual requests. And the volume of legitimate inbound documents from unfamiliar senders sits at its annual peak, so a malicious attachment has nowhere to stand out against the noise.
A static control posture is wrong twice a year. Going into filing season, tighten approval thresholds for banking and wire changes, require out-of-band verification (a phone call, not a reply-all) for new client onboarding, and increase the cadence of phishing simulations.
Coming out of it, those controls can relax, but the identity and access layer underneath them should not. Treat this like a seasonal staffing plan for your security posture, not a permanent hardening exercise.
The Stack, Layer by Layer
Even as seasonal protocols expand and contract with the filing calendar, your security foundation requires a permanent architecture.
The five layers detailed below establish that critical baseline, evolving from basic perimeter shielding to the identity-led framework your firm needs as it scales:
| Layer | Defends against | Minimum for a small firm | What changes for a distributed firm |
| Identity | Account takeover, credential phishing | MFA on every account | Single sign-on, engagement-scoped access instead of blanket role access |
| Endpoint | Malware, device compromise | Managed antivirus and encryption | Enforced patch cadence, endpoint detection, and response (EDR) across every device |
| Data | Data theft, improper retention | Encryption at rest and in transit | A documented retention schedule and secure disposal process |
| Monitoring and response | Undetected or slow-contained incidents | Alerting that a person actually reads | A written incident response plan naming who calls the client |
| Human | Social engineering | Annual security awareness training | Ongoing phishing simulation and a culture where reporting a mistake beats hiding it |
Identity carries the most weight in this stack because it’s where the dominant attack pattern actually lands. Leveraging cloud accounting technology effectively requires not just accessibility but a secure infrastructure to protect data.
Multi-factor authentication (MFA) on every account, single sign-on where your tools support it, and access scoped to the engagement rather than handed out by blanket role all shrink the blast radius when one account gets compromised.
Endpoint protection means managed devices, enforced encryption, and a patch cadence you can actually defend if an auditor asks. Nimbl Tech’s remote device management guide walks through the provisioning, monitoring, onboarding, and offboarding flow for this layer in full.
Data protection is encryption at rest and in transit, a retention schedule you could defend to an auditor, and a real disposal process once a record’s retention window closes.
Monitoring and response come down to two things: alerting that a human actually reads, and a written incident response plan that names who calls the client. A plan nobody has rehearsed is documentation, not capability.
The human layer earns the highest return per dollar spent, since the threat model here is social rather than technical. Phishing simulation, verification steps for banking changes, and a culture where reporting a mistake beats covering it up all live in this layer.
The IRS Security Six Is the Floor, Not the Finish Line
The IRS calls its baseline the “Security Six,” a term it introduced in 2019 and restates in current form in Publication 4557. The six controls are anti-virus software, firewalls, backup, drive encryption, multi-factor authentication, and a virtual private network (VPN). It is a genuinely useful floor and an authoritative one to point to when a client or an auditor asks what your firm has in place.
It is still a floor. The Security Six is device and perimeter-oriented. It predates the identity-first threat model described above, and it says nothing about vendor oversight, data retention schedules, monitoring, or incident response.
A firm that stops at these six controls meets the baseline but remains exposed to the actual threats targeting firms like yours. The layers above the Security Six, not the six items themselves, are what close that gap.
Which Layers Your Firm Needs Now
Security needs grow in stages, and each stage has a real trigger, not a vague size band. Scaling your firm effectively demands strong financial leadership to oversee both technology adoption and security standards.
A single office with a small team needs the Security Six plus real MFA discipline and a written information security plan (WISP) that actually exists rather than sitting half-finished. The trigger to move past this stage is your first fully remote hire.
A distributed team needs managed endpoints, centrally enforced encryption, and formal onboarding and offboarding procedures. In Nimbl Tech’s experience, this stage typically begins with about 15 employees who have access to client financial data.
Offshore capacity raises the bar again. It calls for engagement-scoped access, written vendor oversight, and evidence capture that would hold up in an insurance review. The trigger here is the first remote team member your firm will never meet in person.
Above 5,000 consumer records, a firm loses several Safeguards Rule exemptions it may have relied on at a smaller size. Enterprise clients or real-world organizations also require penetration testing, a qualified information security officer, SOC reporting readiness, and SOC documentation, regardless of your headcount.
Build It or Buy It
Whether you are looking to adopt a finance-as-a-service model, implement comprehensive strategic finance solutions, or choose outsourced financial management, coverage determines your success, not just cost. A single internal hire cannot cover a risk curve that spikes every filing season, has no depth during the exact weeks your firm is busiest, and leaves you exposed the moment that person takes a vacation or leaves.
Managed IT services solve the coverage problem by design, though the cost comparison usually favors them as well once you account for the fully loaded cost of one generalist hire. A firm with a genuine internal security capability should keep it. Most firms in the 10 to 50 employee range do not have that capability yet, which is why outsourced IT support has entered the conversation for so many of them.
How Nimbl Tech Builds This
Nimbl Tech was built as the internal IT function for a distributed accounting firm, which is why the stack in this piece is organized around filing season and access governance rather than a generic small business template.
Access Management is one of Nimbl Tech’s own core services, built on the same least-privilege principle described in the identity layer above. The right people get the right access, no more, and access gets reviewed and removed as people join and leave, rather than left to accumulate.
Start With the Threat, Not the Product
Firms that get this right start with the threat, not the product. They work out who is actually trying to get in before they buy anything. They size their stack based on how distributed their team is and how much client financial data they carry. And they treat a vendor’s own access into their systems as a question worth asking, not a box to check.
Firms that get it wrong do the opposite. They buy tools first and build a threat model later, if they ever do.
That is the order this piece followed. It’s worth applying the same order to your own setup, especially before your next renewal or your next hire changes what your firm actually needs to protect.
Review your security stack with our team, starting with the threats specific to your firm.
FAQs
What Kinds of Cyberattacks Actually Target Accounting Firms Most Often?
The dominant pattern is social engineering dressed up as ordinary business. The clearest example is the “new client” spear-phishing scheme, where an attacker poses as a prospective client to establish a thread before delivering malware or a credential-harvesting link.
Ransomware and business email compromise follow close behind, usually arriving through the same compromised-thread pattern rather than an obvious technical exploit such as a network intrusion. A newer variant delivers remote monitoring and management (RMM) software instead of a traditional payload, since that software hands an attacker the same privileged access to your devices your own IT provider relies on.
The common thread across all of them is that these attacks succeed by imitating work your firm already expected to do, not by breaking through a technical defense.
Why Do Attacks on Tax Preparers Spike Between January and April?
Three factors compound during filing season, each working in the attacker’s favor. Attackers time campaigns to the calendar since a tax-themed message only lands when tax season is genuinely underway. Staff are working long hours under deadline pressure, which measurably reduces how much scrutiny an unfamiliar email or an unusual request gets before someone acts on it.
And the volume of legitimate documents arriving from unfamiliar senders peaks at the exact same time, so a malicious attachment has nowhere to stand out against the noise. Firms that tighten verification procedures heading into the season, then relax them once it passes, are accounting for this pattern directly rather than maintaining the same posture year-round.
Is the IRS Security Six Enough on Its Own for a Distributed Firm?
No. The Security Six, meaning anti-virus software, firewalls, backup, drive encryption, multi-factor authentication, and a VPN, is a genuinely useful floor, but it’s device and perimeter-oriented by design.
It doesn’t address vendor oversight, data retention schedules, ongoing monitoring, or a written incident response plan. All four of those matter more once a firm has remote team members accessing client financial data from outside a single office. Treating the Security Six as a complete security program ignores the vendor oversight and incident response gaps that current threats exploit.
Should a 20-Person Firm Hire a Security Person or Use a Managed Provider?
For a 20-person firm, coverage matters more than the headline price tag. A single internal hire can’t staff after-hours monitoring and can’t absorb a risk curve that spikes every filing season. That coverage gap gets real the moment that person takes a vacation, gets sick, or leaves the firm entirely.
A managed provider fields a team with defined escalation paths, usually at a more predictable and often lower total cost than one fully loaded generalist salary. Firms with a genuine internal security capability already built out should keep it. Most firms at this size haven’t built that capability yet, which is the actual reason this decision keeps coming up.
Will Cyber Insurance Pay Out If Our WISP Was Out of Date When We Were Breached?
That depends on your specific policy language and your insurer’s underwriting requirements. This is a question for your broker and your actual policy documents, not a general answer anyone can give you in the abstract. What holds true across insurers, though, is that an outdated or nonexistent written information security plan (WISP) is one of the fastest ways to complicate a claim after a breach.
Insurers increasingly treat current WISP documentation as a condition of coverage rather than a formality. A claims adjuster who finds a stale or missing plan has real grounds to delay or dispute payout. Keeping the WISP current is part of what keeps the coverage you’re paying for actually usable when you need it.
