Accounting
Cybersecurity best practices as 2025 tax season kicks off
Published
1 year agoon

Every year during tax season, finance professionals handle an influx of sensitive financial and personal information passed along by their clients. Although most CPAs and accountants excel at processing this information, as well as other data related to their field, they’re typically not experts in cybersecurity.
As our technology-driven world grows increasingly complex and evolves more rapidly over time, the more important it becomes for financial institutions to take precautions that safeguard their clients’ sensitive information (and also their own). Bad actors are always working to get a step ahead of protection tech and services, and take advantage of the habits of employees who may not be aware of the latest cyber threats.
The best CPAs and accountants tend to be naturally inquisitive, perhaps to the point of skepticism — and their clients should thank them for it. Because when it comes to finances or cybersecurity, speaking as someone with professional experience in both spaces, those characteristics are superpowers. As cyberattacks become increasingly frequent and sophisticated, financial professionals should be encouraged to maintain a healthy dose of suspicion and lean into hypervigilance. From small accounting operations to large, enterprise-level firms, organizations and their employees must understand and embrace the importance of cybersecurity and its best practices.
Tax season is busy and a potential cybersecurity weakness
It’s critical for financial organizations to observe and maintain cybersecurity best practices, even (and perhaps especially) during tax season. Increased workloads during the busy season may push cybersecurity and network infrastructure down the list of priorities, but bad actors often look for such openings to exploit.
CPAs handle an influx of sensitive financial information and personal information during tax season, which could make them a more attractive target for cybercriminals. Failing to strengthen and maintain cybersecurity technology and protocols could lead to even more chaos and stress during what can already be a nerve-wracking time of year for the industry.
Building client and firm cybersecurity protocols
There is no one-size-fits-all approach to cybersecurity and instituting best-practice protocols, but one of the best methods in the financial services space is to separate cybersecurity into a two-pronged issue: client information and firm information.
Because clients — like CPAs — are rarely cybersecurity experts themselves and, in fact, often operate under the expectation that a financial firm has the proper tools and protocols in place to protect their information, it’s vitally important that nothing be taken for granted on this side.
Key areas of focus for client information
- Email: Email is inherently insecure for the exchange of sensitive financial documents. Once an email is sent, a firm has little to no control over where it ends up — possibly forwarded, intercepted or left in an insecure inbox. Email is also a primary attack vector for phishing. Clients might accidentally open malicious attachments or click on links in phishing emails disguised as legitimate requests. It can be clunky, too, as some email providers block certain file types that could be necessary for tax preparation, and size limits may prompt clients to use insecure methods, such as unencrypted file-sharing services or breaking files into multiple emails — a significant data security risk.
- Secure portal: The best antidote to publicly available email is a secure portal. A private, secure portal provides a financial firm with a controlled, encrypted environment for file sharing, minimizing the risk of breaches. Encryption protects data in transit and at rest, and access controls allow a firm to decide who gets access to which files and set permissions (view, download or edit) for further guardrails. Additionally, portals often log activity and provide an audit trail of who has accessed and modified files.
- Guest Wi-Fi networks: Guest networks are essential for accountants and CPAs in order to protect client data and their own systems. Strong passwords, encryption and network segmentation are crucial components of a secure Wi-Fi network. For extra layers of security, consider hiding your guest network’s SSID (network name), restricting guest network access to internet-only (blocking access printers and file shares) and creating a separate access point, further segregating it from your main network.
Internally, protecting firm information requires a multilayered approach that encompasses technology, policies and ongoing employee training. Strong access controls, encryption and data backups are fundamental security measures, but accounting firms should also partner with cybersecurity experts to create a comprehensive security program that accounts for employee awareness training and builds a strong security culture.
Key areas of focus for firm information
- Device security: All company devices and storage media, including hard drives and USB drives, should be encrypted to prevent data loss and theft. Install robust endpoint security software (antivirus, anti-malware and intrusion detection) on all company devices that access firm networks and client data. Implement mobile device management solutions to secure company-issued mobile devices and enforce security policies.
- Data security: Firms should use data loss prevention tools to prevent sensitive data from leaving the network without authorization. Secure file-sharing platforms and encrypted email for internal and external communication protect sensitive data. Meanwhile, a comprehensive data backup and recovery plan helps ensure business continuity in the case of adverse events such as a ransomware attack or even a natural disaster.
- Employee training and awareness: In addition to new employee training, regular security awareness training for all employees should be conducted to educate a firm’s workforce about cybersecurity threats, company security policies and best practices (including recognizing phishing emails and following strong password habits). Run simulated phishing attacks to test employee awareness and reinforce their training, and develop and regularly practice an incident response plan so that, if all else fails, employees know how to react in case of a security incident. This can significantly mitigate lost time, revenue and reputational impact in the event of a cyber attack.
- Physical security: Implement physical security measures to protect office space and equipment, including old-school and analog methods. That may include security cameras, visitor logs and physical locks that limit access to control systems. Be sure to shred and securely dispose of sensitive documents to prevent data breaches.
Cyber attacks, no matter the time of year, can have significant financial and reputational costs. Organizations that lack the time or resources to bolster or sustain their cybersecurity and network infrastructures — again, especially during the upcoming busy season — should consider partnering with external cybersecurity specialists to ensure their clients’ personal information and network security stay protected. As always, better safe — and secure — than sorry.
You may like

The Financial Accounting Standards Board met this week to discuss its projects on accounting for transfers of cryptocurrency assets and enhancing the disclosures around certain digital assets, such as stablecoins.
Processing Content
During Wednesday’s meeting, FASB’s board made certain tentative decisions, according to a
At a future meeting, the board plans to consider clarifying the derecognition guidance for crypto transfer arrangements to assess whether the control of a crypto asset has been transferred.
FASB also began deliberations on the
The board decided to provide illustrative examples in Topic 230, Statement of Cash Flows, to clarify whether certain digital assets such as stablecoins can meet the definition of cash equivalents. It also decided to include the following concepts in the illustrative examples:
- Interpretive explanations that link to the current cash equivalents definition;
- The amount and composition of reserve assets; and,
- The nature of qualifying on-demand, contractual cash redemption rights directly with the issuer.
FASB plans to clarify that an entity should consider compliance with relevant laws and regulations when it’s creating a policy concerning which assets that satisfy the Master Glossary definition of the term “cash equivalents“ will be treated as cash equivalents.
“I agree with the staff suggestion to look at examples,” said FASB vice chair Hillary Salo. “From my perspective, I think that is going to help level the playing field. People have been making reasonable judgments. I agree with that. And I think that this is really going to help show those goalposts or guardrails of what types of stablecoins would be in the scope of cash equivalents, and which ones would not be in the scope of cash equivalents. I certainly appreciate that approach, and I think it has the least potential impact of unintended consequences, because I do agree with my fellow board members that we shouldn’t be changing the definition of cash equivalents, and it’s a high bar to get into the cash equivalent definition.”
“I’m definitely supportive of not changing the definition of cash equivalents,” said FASB chair Richard Jones. “I believe that’s settled GAAP in a way, and we’re not really seeing a call to change it for broader issues. I am supportive of the example-based approach. The challenge with examples, though, is everybody’s going to want their exact pattern, but that’s not what we’re doing.”
The examples will explain the rationale for how digital assets such as stablecoins do or do not qualify as cash equivalents and give a roadmap for other types of digital assets with varying fact patterns to be able to apply.
“We really don’t want to be as a board facing a situation where something was a cash equivalent and then no longer is at a later date,” said Jones. “That’s not good for anyone, so keeping it as a high bar with certain rigid criteria, I think, is fine.”
Stablecoins are supposed to be pegged to fiat currencies such as U.S. dollars and thus provide more stability to investors. “In my view, while a stablecoin may meet the accounting definition established for cash equivalents, not every one of those stablecoins in the cash equivalent classification represents the same level of risk,” said FASB member Joyce Joseph.
She noted that the capital markets recognize the distinctions and have established a Stablecoin Stability Assessment Framework to evaluate a stablecoin’s ability to maintain its peg to a fiat currency. Such assessments look at the legal and regulatory framework associated with the stablecoin, and provide investors with information that could enable them to do forward-looking assessments about the stability of the stablecoin.
“However, for an investor to consider and utilize such information for a company analysis the financial statement disclosures would need to include information about the stablecoin itself,” Joseph added. “In outreach, the staff learned that investors supported classifying certain stablecoins as cash equivalents when transparent information is available about the entities at which the reserve assets are held. Therefore, in my view, taking all of this into consideration a relevant and informative company disclosure would include providing investors with the name of the stablecoin and the amount of the stablecoin that is classified as a cash equivalent, so investors can independently assess the liquidity risks more meaningfully and more comprehensively by utilizing broader information that is available in the capital markets and its emerging information.”
Such information could include the issuer, reserves, governance and management, she noted, so investors would get a more holistic look at the risks that holding the stablecoin would entail for a given company.
The board decided to require all entities to disclose the significant classes and related amounts of cash equivalents on an annual basis for each period that a statement of financial position is presented.
Entities should apply the amendments related to the classification of certain digital assets as cash equivalents on a modified prospective basis as of the beginning of the annual reporting period in the year of adoption.
FASB decided that entities should apply the amendments related to the disclosure of the significant classes and amounts of cash equivalents on a prospective basis as of the date of the most recent statement of financial position presented in the period of adoption.
The board will allow early adoption in both interim and annual reporting periods in which financial statements have not been issued or made available for issuance.
FASB also decided to permit entities to adopt the amendments to be illustrated in the examples related to the classification of certain digital assets as cash equivalents without the need to perform a preferability assessment as described in Topic 250, Accounting Changes and Error Corrections.
The board directed the staff to draft a proposed accounting standards update to be voted on by written ballot. The proposed update will have a 90-day comment period.
Accounting
Lawmakers propose tax and IRS bills as filing season ends
Published
2 weeks agoon
April 17, 2026

Senators introduced several pieces of tax-related legislation this week, including measures aimed at improving customer service at the Internal Revenue Service, cracking down on tax evasion and curbing the carried interest tax break, in addition to efforts in the House to repeal the Corporate Transparency Act.
Processing Content
Senators Bill Cassidy, R-Louisiana, and Mark Warner, D-Virginia, teamed up on introducing a bipartisan bill, the
The bill would establish a dashboard to inform taxpayers of backlogs and wait times; expand electronic access to information and refunds; expand callback technology and online accounts; and inform individuals facing economic hardship about collection alternatives.
“Taxpayers deserve a simple, stress-free experience when dealing with the IRS,” Cassidy said in a statement Wednesday. “This bill makes the process quicker and easier for taxpayers to get the information they need.”
He also mentioned the bill during a
“I’m happy to meet with the team … and do all I can to make it as good as you want it to be,” said Bisignano.
“My bill would equip the IRS with the legislative mandate to create an online dashboard so that taxpayers can monitor average call wait time and budget time accordingly,” said Cassidy. He noted that the bill would allow a callback for taxpayers that might need to wait longer than five minutes to speak to a representative, and establish a program to identify and support taxpayers struggling to make ends meet by providing information about alternative payment methods, such as installments, partial payments and offers in compromise.
“I know people are kind of desperate and don’t know where to turn for cash, so I think this could really ease anxiety,” he added. “This legislation is bipartisan and is likely to pass this Congress.”
Cassidy and Warner
“Taxpayers shouldn’t have to jump through hoops to get basic answers from the IRS — and in the last year, those challenges have only gotten worse,” Warner said in a statement. “I am glad to reintroduce this bipartisan legislation on Tax Day to ease some of this frustration by increasing clear communication and making IRS resources more readily available.”
Stop CHEATERS Act
Also on Tax Day, a group of Senate Democrats and an independent who usually caucuses with Democrats teamed up to introduce the Stop Corporations and High Earners from Avoiding Taxes and Enforce the Rules Strictly (Stop CHEATERS) Act.
Senate Finance Committee ranking member Ron Wyden, D-Oregon, joined with Senators Angus King, I-Maine, Elizabeth Warren, D-Massachusetts, Tim Kaine, D-Virginia, and Sheldon Whitehouse, D-Rhode Island. The bill would provide additional funding for the IRS to strengthen and expand tax collection services and systems and crack down on tax cheating by the wealthy.
“Wealthy tax cheats and scofflaw corporations are stealing billions and billions from the American people by refusing to pay what they legally owe, and far too many of them are getting a free pass because Republicans gutted the enforcement capacity of the IRS,” Wyden said in a statement. “A rich tax cheat who shelters mountains of cash among a web of shell companies and passthroughs is likelier to be struck by lightning than face an IRS audit, and Republicans want to keep it that way. This bill is about making sure the IRS has the resources it needs to go after wealthy tax cheats while improving customer service for the vast majority of American taxpayers who follow the law every year.”
Earlier this week. Wyden also
The Stop CHEATERS Act would provide the IRS with additional funding for tax enforcement focused upon high-income tax evasion, technology operations support, systems modernization, and taxpayer services like free tax-payer assistance.
“As Congress seeks ways to fund much-needed policy priorities and address our growing national debt, there is one common sense solution that should have unanimous bipartisan support: let’s enforce the tax laws already on the books,” said King in a statement. “Our legislation will make sure the IRS has the resources it needs to confront the gap between taxes owed and taxes paid – while ensuring that our tax enforcement professionals are focused on the high-income earners who account for the most tax evasion. This is a serious problem with an easy solution; let’s pass this legislation and make sure every American pays what they owe in taxes.”
Carried interest
Wyden, King and Whitehouse also teamed up on another bill Thursday to close the carried interest tax break for hedge fund managers that
Carried interest is a form of compensation received by a fund manager in exchange for investment management services, according to a
Under the bill, the
“Our tax code is rigged to favor ultra-wealthy investors who know how to game the system to dodge paying a fair share, and there is no better example of how it works in practice than the carried interest loophole,” Wyden said in a statement. “For several decades now we’ve had a tax system that rewards the accumulation of wealth by the rich while punishing middle-class wage earners, and the effect of that system has been the strangulation of prosperity and opportunity for everybody but the ultra-wealthy. There are a lot of problems to fix to restore fairness and common sense to our tax code, and closing the carried interest loophole is a great place to start.”
Repealing Corporate Transparency Act
The House Financial Services Committee is also planning to markup a bill next Tuesday that would fully repeal the Corporate Transparency Act, which has already been significantly
If enacted, the repeal would eliminate beneficial ownership reporting requirements, removing a transparency measure designed to help law enforcement and national security officials identify who is behind U.S. companies.
“This repeal would turn the United States back into one of the easiest places in the world to set up anonymous shell companies, something Congress worked for years to fix,” said Erica Hanichak, deputy director of the FACT Coalition, in a statement. “These entities are routinely used to facilitate corruption, financial crime, and abuse. Rolling back the CTA doesn’t just weaken transparency, it signals to bad actors around the world that the U.S. is once again open for illicit business.”
Accounting
IRS struggles against nonfilers with large foreign bank accounts
Published
3 weeks agoon
April 15, 2026

The Internal Revenue Service rarely penalizes taxpayers who have high balances in foreign bank accounts and fail to file the proper forms, according to a new report.
Processing Content
The
Taxpayers with specified foreign financial assets that meet a certain dollar threshold are also required to report the information to the IRS by filing Form 8938. Failure to file the form can result in penalties of up to $60,000. However, TIGTA’s previous reports have demonstrated that the IRS rarely enforces these penalties.
The IRS created an Offshore Private Banking Campaign initiative to address tax noncompliance related to taxpayers’ failure to file Form 8938 and information reporting associated with offshore banking accounts, but it’s had limited success.
Even though the initiative identified hundreds of individual taxpayers with significant foreign bank account deposits who failed to file Forms 8938, the campaign only resulted in relatively few taxpayer examinations and a small number of nonfiling penalties. The campaign identified 405 taxpayers with significant foreign account balances who appeared to be noncompliant with their FATCA reporting requirements.
The IRS used two ways to address the 405 noncompliant taxpayers: referral for examinations and the issuance of letters to them.
- 164 taxpayers (who had an average unreported foreign account balance of $1.3 billion) were referred for possible examination, but only 12 of the 164 were examined, with five having $39.7 million in additional tax and $80,000 in penalties assessed.
- 241 noncompliant taxpayers (who had an average unreported account balance of $377 million) received a combination of 225 educational letters (requiring no response from the taxpayers) and 16 soft letters (requiring taxpayers to respond). None of the 241 taxpayers were assessed the initial $10,000 FATCA nonfiling penalty.
“While taxpayers can hold offshore banking accounts for a number of legitimate reasons, some taxpayers have also used them to hide income and evade taxes,” said the report.
Significant assets and income are factors considered by the IRS when assessing whether taxpayers intentionally evaded their tax responsibilities, the report noted. Given the large size of the average unreported foreign account balances, these taxpayers probably have higher levels of sophistication and an awareness of their obligation to comply with the law.
TIGTA believes the IRS needs to establish specific performance measures to determine the effectiveness of the FATCA program. “If the IRS does not plan to enforce the FATCA provisions even where obvious noncompliance is identified, it should at least quantify the enforcement impact of its efforts,” said the report. “This will ensure that IRS decision makers have the information they need to determine if the FATCA program is worth the investment and improves taxpayer compliance.
TIGTA made three recommendations in the report, including revising Campaign 896 processes to include assessing FATCA failure to file penalties; assessing the viability of using Form 1099 data to identify Form 8938 nonfilers; and implementing additional performance measures to give decision makers comprehensive information about the effectiveness of the FATCA program. The IRS disagreed with two of TIGTA’s recommendations and partially agreed with the remaining recommendation. IRS officials didn’t agree to assess penalties in Campaign 896 or with implementing performance measures to assess the effectiveness of the FATCA program.
“From our perspective, TIGTA’s conclusions regarding IRS Campaign 896 are based, in part, on a misguided premise and overgeneralizations, including the treatment of ‘potential noncompliance’ as tantamount to ‘egregious noncompliance’ that warrants a monetary penalty without contemplating the variety of justifications that may exempt a taxpayer from having to file Form 8938,” wrote Mabeline Baldwin, acting commissioner of the IRS’s Large Business and International Division, in response to the report.
What that means for consumer loans
Checks and Balance newsletter: Of God and MAGA
Why software stocks, 2026’s market dogs, have joined the rally
Armanino adds Strategic Accounting Outsourced Solutions
New 2023 K-1 instructions stir the CAMT pot for partnerships and corporations
