Compliance

Skip the Data Security Plan for Carroll County Accounting Firms and the Breach Letter Writes Itself

September 30, 2026 · 10 minutes

Skip the Data Security Plan for Carroll County Accounting Firms and the Breach Letter Writes Itself

Outside attackers with a financial motive were behind 100% of confirmed breaches at small and medium-sized businesses in Verizon's 2026 Data Breach Investigations Report. That makes a data security plan for Carroll County accounting firms a front-line control, because every return on file carries the Social Security numbers, bank details, and income history those attackers want.

Tax Season Ends. The Target Stays

Once the mid-October extension deadline passes, most small practices settle into a slower rhythm. Client files do not. The returns, W-2s, and scanned IDs collected since January still sit on laptops, in cloud portals, and in old email threads.

Extension clients add another layer. Their files often stay open well into fall, with documents still moving between the office and the client by portal, email, and scanner.

Attackers count on that. Verizon's 2026 findings for small and medium-sized businesses show how breaches at smaller organizations unfold:

  • System Intrusion, Basic Web Application Attacks, and Social Engineering represent 100% of breaches
  • Exploitation of vulnerabilities was the initial access vector in 26% of breaches, followed by credential abuse at 13% and phishing at 9%
  • Credentials were compromised in 31% of breaches
  • Third-party involvement appeared in 55% of breaches
  • The human element was present in 45% of breaches

None of those patterns depends on headcount. They follow opportunity: an unpatched device, a reused password, a vendor with loose access. A six-person office in Westminster or Eldersburg presents the same openings as a larger organization, often with fewer resources to spot them, a point Verizon makes directly about smaller businesses.

The credential figure matters most for a practice that runs on email and cloud portals. One stolen login can expose every document shared through that account. The owner may not hear about it until a client calls about a return they never filed.

The Law Already Asked for This Plan

Many owners are surprised to learn that federal law treats their practice as a financial institution. Under the Gramm-Leach-Bliley Act, the FTC's Safeguards Rule lists tax preparation firms by name among the businesses it covers. The FTC's test turns on the activities a business performs, not on how the business describes itself.

Put in plainer terms by the IRS, tax and accounting professionals are considered financial institutions under this law. The Rule requires covered businesses to develop, implement, and maintain an information security program, and the FTC is explicit that the program must be written.

A Yearly Reminder and the Size Question

The IRS repeats the point every summer. In its August 2026 reminder, the agency and its Security Summit partners stated that tax and accounting professionals are legally required to have a written, accessible plan. They added that firms should review, test, and update that plan regularly. The same release points practices to IRS templates and guides built to make that work manageable.

Size shapes the plan without erasing it. The FTC exempts financial institutions holding information on fewer than 5,000 consumers from certain provisions of the Rule. The program still has to fit the size and complexity of the business, the nature of its work, and the sensitivity of the data involved. For a small practice, a data security plan for Carroll County accounting firms is a legal baseline, not an optional upgrade.

What Happens the Week After a Breach

When a practice has no plan, the first written document it produces about security is often the notice explaining what went wrong. Federal and Maryland law both dictate what comes next.

Under the Safeguards Rule, a breach involving at least 500 consumers' unencrypted information must be reported to the FTC as soon as possible. The deadline is no later than 30 days after discovery, and the FTC notes that these reports may be made public. Encrypted data counts as unencrypted if the attacker also reached the encryption key.

Maryland adds its own sequence. The state's breach notification statute requires a business to notify the Office of the Attorney General before it notifies affected residents. That notice must describe when and how the breach occurred and what steps the business has taken. Residents must then hear from the business as soon as reasonably practicable, and no later than 45 days after discovery.

The statute also spells out what the letter to clients must contain:

  • The categories of personal information taken, or reasonably believed to have been taken
  • The business's address and telephone number
  • Toll-free numbers and addresses for the major consumer reporting agencies
  • Contact details for the FTC and the Maryland Office of the Attorney General
  • A statement that clients can get guidance from those sources on avoiding identity theft

Every item on that list is a question a written plan answers in advance. Without one, the owner drafts those answers under a legal deadline while clients wait for an explanation.

What Belongs in the Plan

The FTC's small-business compliance guide breaks the Safeguards Rule into nine required elements. For a small accounting office, they group naturally into three questions.

Who Owns It

The Rule requires a Qualified Individual to implement and supervise the program. That person can be an employee or an outside service provider, and no particular degree or title is required. If the role is outsourced, the practice must still designate a senior employee to supervise it.

The Qualified Individual also reports in writing, at least annually. In a practice without a board, that report goes to the senior officer responsible for the program.

What You Have and Who Can Reach It

Everything starts with a written risk assessment, built on an inventory of what client data exists and where it lives. From there, the Rule names specific safeguards:

  • Access controls reviewed periodically, so each person reaches only the client data their job requires
  • Encryption of customer information on your systems and in transit
  • Multi-factor authentication for anyone accessing customer information
  • Secure disposal of customer information within two years of its last use, with limited exceptions
  • Change management, so a new server or software rollout does not quietly open a gap
  • Logging of authorized user activity, with procedures to detect unauthorized access

How You Would Know Something Went Wrong

Safeguards need testing. The Rule calls for continuous monitoring, or else annual penetration testing plus vulnerability scans every six months. It also requires a written incident response plan covering roles, decision-making authority, communication inside and outside the company, and a review afterward.

Staff training and service provider oversight round out the list. Training carries more weight than its place on the list suggests, since the human element appeared in 45% of small and medium-sized business breaches. Contracts with vendors who touch client data must spell out security expectations and give the practice a way to monitor their work.

Where the Gaps Tend to Hide

The weak spots worth checking first line up with the Verizon numbers above. A data security plan for Carroll County accounting firms turns each of these loose ends into an assigned task with an owner and a date:

  • Nobody can name the one person responsible for security decisions
  • Client documents still arrive and leave as ordinary email attachments
  • Seasonal preparers from last spring still have working logins
  • No one can list every vendor with access to client data, from tax software to the IT provider
  • Software and device updates depend on someone remembering to click install
  • The plan, if one exists, came from a template and was never edited

Two of those deserve extra weight. With third-party involvement in 55% of small and medium-sized business breaches, the vendor list is not a formality. With exploitation of vulnerabilities as the leading initial access vector, missed updates are an open door.

The email habit connects to the credential numbers. When compromised credentials show up in 31% of breaches, a mailbox holding years of attached returns becomes a ready-made archive for whoever gets in.

Turning a Template Into a Working Document

The IRS makes the starting point easy to find. Publication 5708 is a template built for tax professionals, especially smaller practices, and it walks owners through creating a plan and understanding their compliance duties. A companion guide, Publication 5709, covers how to create a plan for data safety. The IRS recommends focusing on three areas: employee management and training, information systems, and detecting and managing system failures.

A template only helps once it describes how the office runs. Useful plans name the specific software, devices, vendors, and people in the practice. They also change when those things change, which is why both the FTC and the IRS expect regular review.

Most of that work does not require new technology. It requires decisions written down: who approves access, how files move, which vendors are trusted, and who makes the call when something breaks. A plan the owner has never read will not guide anyone on the morning something goes wrong.

A practical sequence for the coming quarter looks like this:

  • Name the Qualified Individual and the senior employee who oversees that role
  • Inventory where client data lives, including portals, backups, and personal devices
  • Write the risk assessment and match each risk to a safeguard
  • Confirm multi-factor authentication and encryption on every system holding client files
  • Review vendor contracts for security language
  • Draft the incident response plan, including the FTC and Maryland notification steps
  • Put the first written annual report on the calendar

Once written, the plan earns its keep through practice. A short tabletop walk-through, where the team talks through a stolen laptop or a compromised mailbox, shows quickly whether the contacts and notification steps on paper still hold up. Each walk-through also produces the kind of documented test result that both the FTC and the IRS expect a plan to reflect.

Carroll County practices spend every spring shielding clients from unpleasant surprises at filing time. A data security plan for Carroll County accounting firms applies that same discipline to the data behind those returns. With the plan in place before an incident, a notification letter becomes one step in a process the practice has already rehearsed, rather than the opening page of a crisis.

Sources

  • Verizon, 2026 Data Breach Investigations Report, Executive Summary
  • Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know
  • Internal Revenue Service, IR-2026-92, IRS and Security Summit Remind Tax Pros They Need a Written Information Security Plan to Protect Client Data
  • Maryland General Assembly, Commercial Law Section 14-3504