Security guidance only helps when it leads to assigned, trackable work. In a tax office, threats may affect account credentials, client information, filing identifiers, devices, and remote access. The IRS says tax preparers must create and implement security plans to help protect taxpayer data (IRS: Protect Your Clients; Protect Yourself).
A small office can organize that work around the six functions of the NIST Cybersecurity Framework 2.0: Govern, Identify, Protect, Detect, Respond, and Recover. The framework is not a certification, and using it does not establish compliance. It offers a practical structure for deciding who is responsible, what needs to happen next, and when the work will be reviewed.
For each function, record at least:
- A named owner
- A specific next action
- A current status
- A due date, review date, or supporting record
When useful, add the relevant risk area, an escalation contact, and a note about evidence or review findings.
1. Govern: make responsibility visible
Governance connects the written security plan to everyday decisions. Name the person who coordinates the plan, then document who handles vendor questions, staff training, technology decisions, and escalation during a possible incident.
Useful actions may include:
- Scheduling recurring reviews of the written security plan
- Assigning open decisions to specific people
- Keeping contact information current for vendors and outside advisers
- Setting dates to review important vendor relationships
The owner of a task does not have to complete every part personally. That person makes sure the task has a clear status, a next step, and an appropriate route for escalation.
2. Identify: maintain a current operating picture
The office needs an up-to-date view of the information, accounts, devices, people, vendors, and locations involved in handling client data. This should be a working record, not an inventory created once and forgotten.
Possible actions include:
- Listing systems and locations that store client information or provide access to it
- Reviewing access and removing permissions that are no longer needed
- Identifying important vendors and operational dependencies
- Recording material risks that require a decision or follow-up
Use a level of detail appropriate for the office. Do not place passwords or other sensitive secrets in a general workflow tracker.
3. Protect: follow preventive work through
IRS and FTC guidance addresses safeguards such as access limits, multifactor authentication, encryption, backups, staff awareness, and secure remote access. The right measures depend on the office’s systems and circumstances; this article does not prescribe a technical configuration.
The workflow might include:
- Reviewing multifactor authentication coverage for relevant accounts
- Tracking backup and restoration checks
- Scheduling training on phishing and the handling of client data
- Referring technical, legal, compliance, or cybersecurity questions to qualified professionals
A workflow can document responsibility and follow-up. It does not provide encryption, access controls, backups, training, or any other security control.
4. Detect: establish a review and reporting path
Staff should know where to report suspicious messages, unexpected access, or unusual account activity. The office can also assign reviews of relevant account or audit activity and, when applicable, EFIN or PTIN activity.
For each review, record who performs it, how often it occurs, what status is reported, and where appropriate records are kept. Sensitive investigative details should not be placed in a task list with broad access.
A workflow can show that a review is assigned, complete, or overdue. It cannot monitor a network, identify malicious activity, or determine that an event is harmless.
5. Respond: decide who does what before an incident
A response plan should identify who handles containment, escalation, documentation, and decisions about outside reporting. Notification and reporting obligations may vary. The office should consult current official guidance and qualified professionals for its circumstances.
Practical preparation may include:
- Maintaining an accessible incident contact list
- Naming the people responsible for operational and external-reporting decisions
- Documenting where staff should report a suspected incident
- Running a tabletop exercise based on phishing or an account-compromise scenario
An exercise can expose unanswered questions that belong in the plan. It does not replace incident-response expertise during an actual event.
6. Recover: prepare for restoration and follow-up
Recovery covers restoration responsibilities, continuity planning, lessons learned, and updates after an incident or exercise.
Possible actions include:
- Assigning responsibility for restoration and continuity decisions
- Scheduling reviews or tests of recovery procedures
- Recording lessons from an exercise or incident
- Updating the written plan and related tasks when decisions change
Recording a recovery task does not guarantee that data or operations can be restored. Technical validation and professional guidance may be necessary.
A coordination tool is not a security control
A complementary workflow layer may give a team one place to see owners, next actions, statuses, review dates, and supporting notes. It is not cybersecurity software, tax-preparation software, a security control, or a substitute for qualified advice. It cannot detect, block, contain, or remediate a threat. Its use does not demonstrate compliance or prevent a breach.
No specific Intaxion feature, interface, or integration is claimed here. Any statement about the product would need to be verified against approved product sources before use.
Start with six rows
Create one row for each function: Govern, Identify, Protect, Detect, Respond, and Recover. Give every row one named owner, one next action, and one review date. Then compare the workflow with current guidance from the IRS, the NIST Cybersecurity Framework resources for small businesses, and the FTC’s cybersecurity guidance for small businesses.
This article provides educational information only. It is not tax, legal, compliance, or cybersecurity advice.
Get our free Tax Preparer Compliance Checklist
A practical checklist to help you review whether your process addresses IRS due-diligence requirements. Your office remains responsible for applying the rules. Download instantly.
We respect your privacy. Unsubscribe at any time.
