
What Client Data Security Actually Requires for a Growing Law or Accounting Firm
A managing partner at a 70-person accounting firm gets a renewal questionnaire from the firm's cyber insurance carrier asking for a written information security program, proof of multi-factor authentication on every system that touches client data, and the name of the person accountable for the firm's security posture. A litigation partner at a 90-person law firm gets a client's outside counsel guideline that requires encryption at rest, a documented incident response plan, and evidence of employee security training before the client will send another matter. Neither partner has a clear answer, because "we take security seriously" was never a specific enough commitment to produce documentation for. Client data security for a law or accounting firm is not a vague best practice. It is a set of named obligations, and knowing exactly what they require is the first step to actually meeting them.
What counts as client data at these firms
The phrase "client data" undersells what a law or accounting firm actually holds. A law firm's files can include attorney-client privileged communications, medical records and financial disclosures produced in discovery, Social Security numbers and bank account details from estate and family law matters, and trust account records governed by state IOLTA rules, where mishandling funds is a bar discipline issue, not just a bookkeeping error. An accounting or tax firm holds completed tax returns with SSNs and full financial pictures, payroll data, bank account and routing numbers for direct deposit and electronic filing, and often access to a client's accounting software with live transaction history. This is a materially higher-risk data set than the typical vendor or HR records most companies think of when they hear "data security," and it is why the rules that apply to these two professions are more specific than general business best practice.
The rules that actually apply
The obligations split along professional lines, and it matters which ones apply to your firm.
For law firms, the duty comes from the rules of professional conduct. Model Rule 1.6(c), added to the ABA Model Rules in 2012 and adopted in some form by the large majority of states, requires a lawyer to "make reasonable efforts to prevent the unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." The ABA's Formal Opinion 483, issued in 2018, goes further and lays out what happens after a breach: lawyers must act reasonably and promptly to stop it, assess what was accessed, and notify current clients under Rule 1.4 when a breach involves or is likely to involve their confidential information. State bar ethics opinions layer additional guidance about cloud storage, encryption, and vendor use on top of these baseline rules.
For accounting and tax firms, the obligations are more codified. The FTC Safeguards Rule (16 CFR Part 314) explicitly names "an accountant or other tax preparation service" as a covered financial institution, regardless of firm size, and has required a written, risk-assessment-based information security program since June 2023. Since May 2024, firms covered by the rule must report certain security events affecting 500 or more consumers to the FTC within 30 days. Separately, the IRS requires every paid tax preparer to follow Publication 4557's "Security Six": antivirus and endpoint protection, a firewall, multi-factor authentication, encrypted backups, drive encryption, and a VPN for remote access. The AICPA's Statements on Standards for Tax Services added Section 1.3 effective January 1, 2024, requiring members to make "reasonable efforts to safeguard taxpayer data," on top of the existing Confidential Client Information Rule that already restricted disclosure without client consent.
Layered on top of both professions are state data breach notification laws, which generally require notice when unencrypted personal information is unauthorized-acquired, regardless of firm size or whether a client complained first.
| Rule or framework | Applies to | Core requirement |
|---|---|---|
| ABA Model Rule 1.6(c) | Lawyers | Reasonable efforts against unauthorized access or disclosure |
| ABA Formal Opinion 483 | Lawyers | Investigate, stop, and notify clients after a breach |
| FTC Safeguards Rule | Accountants, tax preparers | Written information security program, breach reporting |
| IRS Publication 4557 | Paid tax preparers | The "Security Six" technical controls |
| AICPA SSTS 1.3 | CPAs, tax professionals | Reasonable efforts to safeguard taxpayer data |
What "reasonable efforts" actually means in practice
None of these rules hand you a checklist with a single correct answer, which is exactly why firms struggle to demonstrate compliance even when they are doing most of the right things informally. In practice, what satisfies a regulator, an insurer, or a client's outside counsel guideline comes down to the same core set of controls, documented rather than assumed.
Encryption needs to cover client data both at rest and in transit, not just email in flight. Multi-factor authentication needs to sit on every system that touches client files: email, the practice management or tax preparation platform, remote access, and any cloud storage. Access needs to follow least privilege, so a paralegal or staff accountant only reaches the matters and clients they actually work on, and that access gets revoked the day someone leaves the firm, not weeks later. Every employee needs documented, recurring security training, because a five-minute phishing click bypasses every technical control a firm has. The firm needs a written incident response plan that names who does what in the first 24 hours of a suspected breach, not just a vague understanding that "IT will handle it." Every vendor that touches client data, from the e-discovery platform to the payroll processor to the cloud practice management tool, needs a documented review before onboarding, because a firm's obligations under Rule 1.6 or the Safeguards Rule do not stop at its own network perimeter. And closed files need a retention and secure-destruction schedule, so client data does not sit indefinitely on a server with no one accountable for it.
What it costs when none of this is documented
The gap rarely surfaces because something breaks. It surfaces during an insurance renewal, a bar audit, or a client's security questionnaire, when a firm is asked to produce evidence of controls it has never written down. The scale of the underlying risk is real: the ABA's most recent Cybersecurity TechReport found that roughly three in ten law firms have experienced a security breach, with mid-sized firms reporting some of the highest incident rates, up from lower figures in earlier survey years. Firms that cannot produce a written information security program, a named accountable individual, and evidence of specific controls at renewal time increasingly face higher premiums, added exclusions, or a declined policy outright. That conversation is far worse to have during a 30-day renewal window than in advance of one.
Who should actually own this
This is not a task for a general IT support contract. A managed service provider is built to keep systems running: patching, monitoring, help desk, backups. Writing a risk-assessment-based information security program, mapping it to the specific rules that apply to your firm, and maintaining the documentation an insurer or regulator will actually ask for is a different function entirely. At a small firm, a managing partner can sometimes hold this informally. Past roughly 75 to 100 employees, with multiple practice groups or service lines, informal ownership stops working reliably, and something usually falls through until an incident, an audit, or a renewal forces the question.
This is where fractional IT leadership fits. Elevaire Systems does not replace a firm's MSP or in-house IT staff. The MSP keeps the day-to-day environment running. Fractional IT leadership sits above that relationship: translating rules like ABA Rule 1.6, the FTC Safeguards Rule, and IRS Publication 4557 into an actual written program, reviewing vendors, and giving the partners one accountable person to point to when a client, an insurer, or a regulator asks hard questions.
Frequently Asked Questions
How much does it cost to build a compliant information security program?
Costs scale with firm size and complexity, but the comparison that matters is against the alternative. A full-time CIO or dedicated security lead at a firm this size typically commands a total compensation package well into six figures, which is difficult to justify when the actual workload is a matter of days per month, not a full-time role. Fractional IT leadership provides the same program-building and documentation work at a fraction of that fixed cost, scaled to what the firm actually needs.
Does this replace or overlap with our MSP or in-house IT person?
No. Your MSP or IT staff continues handling day-to-day support, monitoring, and technical implementation. Fractional IT leadership designs the information security program, maps it to the specific rules that apply to your firm, and manages the MSP relationship as part of that program, rather than duplicating the support work they already do.
Do we need this if we have never had a breach or a client complaint?
The absence of an incident is not evidence of a compliant program. ABA Rule 1.6, the FTC Safeguards Rule, and IRS Publication 4557 all apply regardless of loss history, and insurers and clients increasingly ask for documented proof of specific controls before binding a policy or sending new matters. Most firms discover the gap during a renewal questionnaire or a client audit, not because something already went wrong.
How do we get started?
It typically starts with an assessment of what client data the firm actually holds, which rules apply given the firm's practice mix, and where the current environment falls short of "reasonable efforts" as those rules define it, followed by a prioritized plan to close the gaps. Elevaire Systems offers a free consultation to walk through where a firm stands before any engagement begins.
Does this apply the same way to a 10-person firm as it does to a 150-person firm?
The underlying rules do not scale down with firm size. A two-partner tax practice is bound by the same IRS Security Six requirements as a 150-person firm, and a small firm typically has fewer internal resources to cover the gap, which makes dedicated oversight more valuable per dollar spent, not less. What changes with size is complexity: more practice groups, more vendors, and more people with access, all of which make an undocumented, informal approach break down sooner.
Ready to Put This Into Practice?
Schedule a free consultation and let's talk through what this means for your organization specifically.
Schedule a Free Consultation