If you run an accounting firm, you may already have a basic cybersecurity program, but a more specific question may be harder to answer: Does GLBA apply to our firm?
For many accounting and tax preparation businesses, the answer may be yes.
The Gramm-Leach-Bliley Act (GLBA) applies beyond traditional banks and financial institutions. The Federal Trade Commission (FTC) identifies tax preparers, accountants, and other financial advisers among businesses that may qualify as financial institutions based on the activities they perform. For firms subject to the FTC's jurisdiction, the GLBA Safeguards Rule requires a written information security program designed to protect customer information.
That makes GLBA compliance for accounting firms more than a privacy policy exercise. It can affect how your firm manages customer information, controls access, secures Microsoft 365 and other cloud systems, evaluates service providers, trains employees, tests security controls, and responds to incidents.
The first step is determining whether GLBA applies to your firm. The second is understanding what the Safeguards Rule actually requires. The third is comparing those requirements with how your firm operates today.
GLBA applies to certain businesses that are significantly engaged in financial activities and fall within the jurisdiction of the applicable regulator.
For firms regulated by the FTC, the FTC's guidance specifically identifies tax preparers and accountants as examples of businesses that may qualify as financial institutions because they provide financial, investment, or economic advisory services. The definition is broader than the organizations people typically associate with the term "financial institution."
However, being an accounting firm does not automatically answer every question about GLBA coverage. The nature of the services your firm provides, who receives those services, and which regulator has jurisdiction can affect the analysis.
Your firm should establish:
If there is uncertainty about whether the law applies to your specific business model, have qualified legal or compliance counsel make the determination. Your IT provider can help assess security controls, but determining the firm's legal obligations is a separate question.
Once you determine that GLBA applies, the next question is what information needs to be protected.
The Safeguards Rule focuses on customer information, including records containing nonpublic personal information that are handled or maintained by or on behalf of the financial institution or its affiliates.
For an accounting firm, that information can exist across much more than a tax or accounting application.
It may include:
The practical question is not simply, "Where are our client files?"
It is:
Where does customer information exist, how does it move through the firm, and who can access it?
An accounting firm may have customer information distributed across:
A GLBA risk assessment should account for this broader information ecosystem.
For covered financial institutions under FTC jurisdiction, the Safeguards Rule requires a written information security program with administrative, technical, and physical safeguards designed to protect customer information. The program must be appropriate to the firm's size and complexity, the nature and scope of its activities, and the sensitivity of the information it handles.
The rule is risk-based. It does not mean every accounting firm needs the same technology stack.
It means the firm needs to identify reasonably foreseeable risks and implement safeguards appropriate to those risks.
The FTC's Safeguards Rule identifies specific elements that covered organizations must address.
The firm must designate a Qualified Individual to implement and supervise its information security program.
That individual can be an employee, affiliate, or service provider. However, outsourcing the technical work does not outsource the firm's responsibility. The FTC specifically states that when a service provider performs this role, the company still needs a senior employee to supervise that person.
For a smaller accounting firm, this distinction is important.
An MSP or managed security provider may operate security tools, monitor systems, perform assessments, and help maintain the program. Firm leadership still needs clear ownership of the overall information security program.
The information security program must be based on a written risk assessment.
The assessment should identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information and establish criteria for evaluating those risks. The firm must also periodically reassess those risks as its business and threat environment change.
A useful assessment should answer:
The output should be more than a risk score. It should establish a prioritized list of risks and the controls needed to reduce them.
The firm must design and implement safeguards that address the risks identified in the assessment.
The FTC identifies controls including access management, data inventory, encryption, application security, multifactor authentication, secure disposal, change management, and monitoring.
For an accounting firm operating primarily in Microsoft 365, that can translate into controls such as:
The technology should follow the risk assessment.
Buying another security product does not demonstrate that the underlying risk has been addressed.
The Safeguards Rule provides the regulatory framework. The firm's risk assessment should determine how those requirements translate into specific controls.
For most Microsoft 365 accounting environments, several areas deserve particular attention.
Identity is a critical control point because compromised credentials can provide access to email, documents, applications, and customer information.
Review:
A useful measurement is not "MFA is enabled."
It is what percentage of relevant accounts are actually protected by MFA, including privileged accounts?
Customer information may be accessed from laptops, desktops, mobile devices, and other endpoints.
Evaluate whether:
Email remains a major pathway into an organization's information environment.
A practical assessment should examine:
For Microsoft 365 users, these controls should be evaluated as part of the firm's broader identity and security architecture rather than as isolated email settings.
The firm should know where customer information is stored and how it is protected.
Review:
Security controls are more useful when the firm can determine whether they are working.
Review whether the firm can:
The goal is to reduce the time between a security event occurring and the firm identifying and responding to it.
GLBA compliance should be supported by evidence.
A firm should be able to demonstrate not only that it has security policies, but that it operates the controls those policies describe.
The FTC's Safeguards Rule requires covered organizations to maintain a written information security program and documentation around key elements of that program.
Depending on the firm's environment, documentation may include:
One of the most useful practices is to document why a security decision was made.
For example:
Risk: Former employees may retain access to cloud applications after termination.
Control: Automated identity deprovisioning and termination checklist.
Measure: Percentage of terminated users whose access is disabled within the firm's defined target.
Owner: IT or security administrator.
Review: Monthly.
That creates a direct connection between the risk assessment, the control, and measurable risk reduction.
An accounting firm's security program extends beyond systems it owns directly.
Cloud applications, managed IT providers, security providers, tax platforms, payroll systems, document management platforms, and other vendors may have access to customer information.
The Safeguards Rule requires covered institutions to select service providers capable of maintaining appropriate safeguards, require appropriate safeguards through contractual provisions, monitor providers, and periodically reassess their ability to meet security obligations.
For each provider with access to customer information, document:
This turns vendor management into an active part of the firm's security program rather than an annual questionnaire exercise.
The Safeguards Rule requires a written incident response plan.
The plan should establish how the firm identifies, responds to, and recovers from security events, including roles, responsibilities, communication, remediation, documentation, reporting, and post-incident review.
For an accounting firm, consider a compromised Microsoft 365 account.
The incident response process should establish:
Certain security incidents trigger a specific FTC notification requirement.
Under the Safeguards Rule, covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovering a notification event involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
The FTC describes a notification event as the unauthorized acquisition of unencrypted customer information. The rule also addresses circumstances involving access to an encryption key.
This is not the only notification requirement an accounting firm may face. State breach-notification laws, contractual requirements, professional obligations, and other regulations may also apply depending on the circumstances.
The most useful assessment is not simply a list of yes-or-no compliance questions.
It should connect requirements → current controls → gaps → actions → measurable outcomes.
A practical assessment can use the following framework:
| Area | What to evaluate | Example measure |
|---|---|---|
| GLBA scope | Whether the firm and relevant activities are covered | Documented coverage determination |
| Governance | Qualified Individual and program ownership | Named owner and annual reporting |
| Risk | Written risk assessment and reassessment | Open high-risk items and remediation status |
| Identity | MFA, privileged access, account lifecycle | MFA and privileged-account coverage |
| Data | Customer information inventory and protection | Known repositories and access paths |
| Endpoints | Device management and protection | Managed-device coverage |
| Monitoring | Detection and investigation capabilities | Alert coverage and response time |
| People | Training and security behavior | Completion and reporting rates |
| Vendors | Third-party access and oversight | Critical providers reviewed |
| Response | Incident response readiness | Time to detect, contain, and document |
This gives leadership a way to see whether the firm's security program is improving rather than simply whether a policy exists.
Use this as a starting point for evaluating your current program.
A gap does not have to become an all-or-nothing compliance exercise.
Start with the risks that could have the greatest impact on customer information and the controls that can materially reduce those risks.
For many firms, that means establishing a reliable baseline around identity, privileged access, endpoint security, email, data protection, vulnerability management, monitoring, employee behavior, and incident response.
Then establish measurable remediation targets.
For example:
Instead of: "Improve Microsoft 365 security."
Use: "Reach 100% MFA coverage for all users with access to customer information, review privileged accounts monthly, and remediate identified high-risk identity findings within the defined target."
Instead of: "Improve employee security awareness."
Use: "Complete required training for all personnel and increase the percentage of employees who report simulated phishing messages over the next two quarters."
Instead of: "Improve incident response."
Use: "Document and test the incident response process, assign response owners, and establish target times for detection, containment, investigation, and escalation."
The difference is measurable behavior and control effectiveness rather than simply having a policy on file.
For an accounting firm, determining whether GLBA applies is the starting point, not the finish line.
If the firm is covered, the Safeguards Rule provides a framework for building an information security program around the information the firm handles and the risks it faces.
That means knowing what customer information exists, controlling who can access it, protecting the systems that process it, evaluating third-party providers, training employees, monitoring security controls, and maintaining an incident response process.
For firms operating in Microsoft 365, identity is often a particularly important part of that environment. But Microsoft 365 security controls are only one component of the broader program. Customer information can move through tax applications, document platforms, endpoints, email, cloud services, and external providers.
The practical test is therefore not whether the firm owns the right security tools.
It is whether the firm can demonstrate:
What information do we need to protect?
What risks have we identified?
What safeguards address those risks?
How do we know those safeguards are working?
Who is responsible for fixing gaps?
What happens when something goes wrong?
That is the foundation of a GLBA information security program that can be managed, measured, and improved over time.
GLBA can apply to accounting firms, particularly firms providing services that qualify as financial activities under the law. The FTC specifically identifies accountants and tax preparers among businesses that may qualify as financial institutions. Whether a specific firm is covered depends on its activities and applicable regulatory jurisdiction.
Start by determining whether the firm's activities fall within GLBA's definition of financial activities and which regulator has jurisdiction. The FTC identifies tax preparation firms and accountants among businesses that may fall within the scope of the rules it enforces. Firms with uncertainty about their legal coverage should consult qualified legal or compliance counsel.
The GLBA Safeguards Rule requires covered financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information.
Requirements include designating a Qualified Individual, conducting a written risk assessment, implementing appropriate safeguards, monitoring and testing controls, training employees, overseeing service providers, maintaining an incident response plan, and providing required leadership reporting.
The FTC Safeguards Rule requires covered organizations to implement multifactor authentication for individuals accessing customer information on their information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.
The Safeguards Rule protects customer information, including records containing nonpublic personal information handled or maintained by or on behalf of a covered financial institution. For accounting firms, this can include tax information, Social Security numbers, financial statements, account information, and other sensitive client financial information.
Yes. Covered organizations subject to the FTC Safeguards Rule must develop, implement, and maintain a written information security program appropriate to their size and complexity, activities, and the sensitivity of customer information.
Yes. The Safeguards Rule requires a written risk assessment that identifies reasonably foreseeable internal and external risks to customer information and evaluates the safeguards used to address those risks. The assessment must be periodically reassessed as circumstances change.
Yes. Covered organizations must maintain a written incident response plan addressing how the organization will respond to security events, including roles, communications, remediation, documentation, and reporting.
Certain security incidents require notification to the FTC. A covered financial institution must notify the FTC as soon as possible and no later than 30 days after discovering a qualifying notification event involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
No. Microsoft 365 can provide security capabilities that support GLBA safeguards, including identity protection, multifactor authentication, access controls, encryption, endpoint management, and monitoring. However, GLBA compliance depends on the firm's overall information security program, including its people, processes, applications, service providers, risk assessment, and incident response capabilities.
First determine whether the firm is covered and identify the customer information subject to the applicable requirements. Then conduct a written risk assessment, document existing safeguards, identify gaps, and prioritize remediation based on the risks to customer information. A legal or compliance professional can help establish the firm's regulatory obligations, while IT and security professionals can assess the technical and operational controls.