Resources & News

11 Remote-Work Cybersecurity Tips for Tax and Accounting Firms

A man wearing headphones taking part in a virtual meeting on his laptop, with several other participants visible on screen

11 Remote-Work Cybersecurity Tips for Tax and Accounting Firms

I wish there were not numerous examples of bad players hacking into systems. Moreover, I wish I did not have personal examples to share, like:

  1. The employee who fell victim to a phishing request and purchased $500 Amazon gift cards. I found out when he wanted me to sign off on his expense report.
  2. The employee who received a personal text telling them to update one of the apps on their phone. The thief then read her login remotely and locked her phone. Then they remoted into her work computer, locking it out. Thankfully, a quick-thinking team member unplugged her computer. What would have happened if this team member was working remotely?
  3. The mysterious emails we started to see on one of our remote servers from somewhere in Hungary.

With an introduction like this, you might think: How are you going to help protect me and my virtual team? All of these examples occurred many years ago and we learned the hard way. No one can guarantee you won’t have something bad happen to you or the Personally Identifiable Information (PII) you are legally required to protect; however, there are things we can do to improve our security.

Tip 1: Utilize virtual private networks (VPN).

This effectively creates a single domain name system (DNS) entry to and from your office from each remote worker via an encrypted network tunnel. Employees need to log in to access the network.

Tip 2: Secure access to both entry points.

This is done with strong password management and multi-factor authentication (MFA). Password management means using a password management system or using long passwords with a mixture of numbers, lower and upper case alpha characters, plus other characters. The longer the better (14 or more characters) and the passwords should change frequently.

An MFA, or an equivalent, is now legally required for all accounting firms on any device that may have access to PII. MFA typically requires additional verification from the worker’s phone or a physical token.

Tip 3: Employ proper data encryption.

Any information transmitted over your VPN must be encrypted and the remote workstations must have their data encrypted as well. If a laptop is stolen, the thieves can easily get data from the hard drives without needing the password to get into your computer.

Tip 4: Conduct regular and automated software updates.

This is true for every system in the firm, your website and remote workstations. The third example given at the beginning of the article occurred because one of our servers had not been updated by our IT vendor. While we often rely on external consultants to handle these services, it makes sense to periodically perform an independent audit of their work. Thankfully, the bad players wanted the server power, not our data, so we isolated the server and recovered with clean backups.

Tip 5: Demand dedicated remote hardware.

Your remote workers cannot conduct personal business on your remote workstations. This includes personal email, checking their social media accounts or shopping. The workstation must be dedicated to work.

Tip 6: Focus on endpoint security.

Install security software on each remote workstation. Have the virtual office be at home in a secure, unshared space. Put timers on everything, including a timed shutdown of the workstation and a timed shut down of the VPN. Remember, while a VPN is a single point of entrance into your hub, if the thief gets into the remote workstation, and the VPN is open, they can access all the data you allow the remote user to see.

Tip 7: Secure the hub.

A firewall is a piece of hardware that will create direct access points to each virtual workstation and will limit access to your firm from others. Your office should have a firewall and you should consider installing a firewall at the remote location. Be very conscious what is inside your firewall and what is outside your firewall. For instance, if clients want access to the internet, set up a separate connection outside your firewall.

Tip 8: The principle of least privilege.

Your remote worker should only have access to the data needed to conduct their work, no more. So to the degree possible, segregate what each remote worker can see on your server. If a remote workstation is breached and the thief is in your central network, you want to be alerted and you want to limit the damage that can be caused.

Tip 9: Develop strong policies and procedures.

Write up a remote worker policy and have the employee sign acknowledgement of understanding and receipt of the policy. Review this at least once per year.

The policy should include that no PII may remain on the remote workstation, as a way to limit your risks. Consider the inclusion of this policy into your Written Information Security Plan (WISP). Then, ensure each worker reviews and acknowledges your WISP. Ensure you also have contemporaneous proof of that acknowledgement.

Tip 10: Make timely, secure backups.

Your backups must be created regularly, encrypted and stored offsite. It is also important to keep timely backups disconnected from your network. Create and regularly update a disaster recovery plan. This plan is a roadmap of your network, hardware, software, vendors, password management and is a critical part of any recovery from your backups. Remember disaster usually comes in the form of hackers, but it could be a fire or other natural disaster. Plus sophisticated hackers will go through your entire network and may destroy your networked backups, so plan accordingly.

Tip 11: Train, test and monitor.

Your best defense is creating and maintaining an active WISP. Move beyond what is dictated by the FTC and the IRS regulations, and focus on creating a document that actually works for your firm. This includes training all your staff and putting tests in place to see how well you and your employees are doing. Consider periodic penetration testing and data testing of your remote workers to ensure no PII is accidentally stored or accessible remotely.

When creating and managing a remote workforce, security starts with awareness. This is something we learned the hard way. Now we have regularly scheduled sessions on email security. We also conduct annual training and review the annual IRS dirty dozen scams. We test our backups and send fake emails to all staff to ensure everyone is on guard for the next bad player.

With all the new tools and the reality of intense workloads in short periods of time, working remotely is now a fact in your firm’s worklife. But it doesn’t need to mean it creates unreasonable security risks, if managed correctly.


Steve Enzler is a more than 30-year veteran running businesses providing services to tax and accounting firms throughout the United States. He holds a B.A. in accounting and an MBA and has extensive experience researching and writing client-oriented content for accountants and tax professionals. You can reach him at senzler@tangiblevalues.com or via LinkedIn.

Ready to Get Compliant?

Create your IRS WISP in minutes with WISP Builder's all-in-one compliance tool.

View Plans