Intaxion
Operations

When a Security Incident Interrupts Client Work: A Response Map for Practice Owners

Published September 10, 2026
5 min read
Illustration of a practice owner organizing roles, evidence, access review, and communications while an incident remains under investigation.

A tax practice loses access to a key system during filing work. Someone on the team also notices unfamiliar activity. These facts establish an operational interruption and a reason to investigate. They do not, by themselves, prove unauthorized access, a confirmed compromise, or a legally reportable data breach.

Keeping those distinctions clear helps the practice respond without assigning a technical or legal label before the evidence supports it.

Put one person in charge of coordination

Designate an owner or senior leader to coordinate the response. This person does not need to conduct the technical investigation or decide which legal duties apply. The coordinator keeps track of responsibilities, decisions, dependencies, and unanswered questions.

Work may proceed across several areas at once:

  • cybersecurity investigation and operational stabilization;
  • preservation of evidence and decision records;
  • legal and reporting analysis;
  • review of system access and affected workflows;
  • internal and external communications.

The FTC’s Data Breach Response guide describes a response that may involve forensic, legal, information-security, operational, human-resources, communications, and management participants. The IRS guidance for tax professionals also directs practices to appropriate experts and reporting contacts.

Let qualified professionals direct technical decisions

Engage qualified cybersecurity professionals to assess the situation and direct technical actions. Preserve available logs, records, affected equipment, and other potentially relevant information. Avoid uncoordinated changes that could erase information needed for the investigation.

Whether to isolate systems, change credentials, restore data, or examine devices depends on the event and the technology involved. This article does not provide forensic or containment instructions. Those decisions require professionals who can evaluate the actual systems and evidence.

The FTC guide addresses securing operations, preserving evidence, and working with forensic specialists. It is general guidance, not proof that a particular response satisfies every applicable obligation.

Workflow diagram showing the office steps described in the English article.

Determine legal and reporting duties from confirmed facts

Seek incident-specific advice from qualified legal counsel. Notice or reporting duties may depend on the facts, applicable law, jurisdiction, contracts, insurance terms, and the information involved.

Possible channels for a tax practice may include the IRS, law enforcement, state authorities, insurers, contractual partners, and affected clients. Current official instructions and professional advice should determine which channels apply and when to use them. Do not present every interruption or suspicious indicator as a reportable breach.

The IRS maintains data-theft information for tax professionals. IRS Publication 5293, the Data Security Resource Guide for Tax Professionals, discusses safeguards, warning signs, and reporting categories, but the publication is dated May 2018. Verify current procedures before relying on an operational detail.

Separate operational impact from possible data exposure

Document which systems, accounts, client processes, and deadlines may be affected. Under the direction of cybersecurity professionals, review who had access to relevant systems and whether available records show unexpected activity.

Unfamiliar filing activity or unexpected activity involving an Electronic Filing Identification Number, or EFIN, can be a reason to investigate. An indicator is not proof of a specific compromise. Record confirmed operational effects separately from assumptions about data access or exposure.

Decision matrix comparing the workflow choices described in the English article.

Communicate with confirmed facts

Assign one communications lead. Maintain a shared record of confirmed facts, open questions, assigned decisions, and language cleared for use.

Coordinate communications with legal counsel, cybersecurity professionals, and law enforcement when applicable. If an update is appropriate, explain what is known, what remains under review, what useful steps recipients can take, and how authentic updates will arrive. Avoid speculation, premature attribution, guarantees, and unnecessary investigative detail.

A status update is not a legal conclusion. If the practice does not know whether information was accessed, say that the matter remains under investigation.

Operational checklist summarizing the readiness steps in the English article.

Carry the response map into preparedness

After immediate decisions are addressed, document response roles, contact paths, warning indicators, access responsibilities, and authoritative reporting sources in the practice’s written information security plan or operating runbook.

NIST’s Cybersecurity Framework 2.0 resources for small businesses provide a reference for organizing cybersecurity risk-management work. The framework does not guarantee that incidents will be prevented or determine the legal duties that apply to a specific event.

If client work is being interrupted now, seek situation-specific direction from qualified legal and cybersecurity professionals and verify current reporting instructions with the relevant authorities.

Sources

Open related Intaxion tool

Get our free Tax Preparer Compliance Checklist

A practical checklist to help you review whether your process addresses IRS due-diligence requirements. Your office remains responsible for applying the rules. Download instantly.

We respect your privacy. Unsubscribe at any time.