Accounting firms handle some of the most sensitive information their clients entrust to them, including tax records, Social Security numbers, financial statements, account information, payroll data, and other nonpublic personal information. For firms covered by the Gramm-Leach-Bliley Act (GLBA), protecting that information is not simply a matter of good IT hygiene. It is a regulatory obligation.
GLBA compliance for accounting firms centers on two related responsibilities: protecting customers' nonpublic personal information and maintaining an information security program designed to address the risks associated with that information.
The Federal Trade Commission (FTC) specifically identifies tax preparers, accountants, and other financial advisers among businesses that may qualify as financial institutions under GLBA. The FTC's GLBA guidance for businesses explains that coverage depends on the activities a business performs, not simply how the business describes itself.
For accounting firms using Microsoft 365, GLBA compliance also has a practical technology dimension. Identity controls, multifactor authentication, endpoint security, email protection, data access, encryption, monitoring, employee training, and incident response all contribute to the safeguards protecting customer information.
The Gramm-Leach-Bliley Act is a federal law focused on the privacy and security of consumers' financial information.
GLBA requires covered financial institutions to explain their information-sharing practices to customers and safeguard sensitive customer information. The law is implemented through regulations including the FTC's Privacy Rule and Safeguards Rule.
For accounting firms, the important distinction is that GLBA is not simply a requirement to keep files confidential. It creates expectations around how customer financial information is collected, used, shared, stored, protected, and ultimately disposed of.
Accounting firms routinely handle information that can fall within GLBA's definition of nonpublic personal information, particularly when providing services to individuals.
The FTC identifies providing financial, investment, or economic advisory services as financial activities and specifically lists accountants and tax preparers among examples of businesses that may be covered. Whether a particular firm is subject to the rules depends on its activities and applicable regulatory jurisdiction.
That makes GLBA relevant to many accounting and tax practices, including firms that may not think of themselves as financial institutions in the traditional sense.
GLBA uses a broader definition of "financial institution" than the term might suggest.
Under the FTC's Safeguards Rule, a financial institution is generally an entity engaged in an activity that is financial in nature or incidental to such financial activities, subject to the rule's jurisdiction and other provisions. The FTC specifically identifies tax preparation firms and certain financial advisers among examples of covered businesses.
Coverage is determined by the nature of the firm's activities rather than its industry label alone.
For an accounting firm, the first compliance question should therefore be:
Does our firm perform activities that bring us within the scope of GLBA and the FTC rules?
A qualified legal or compliance professional can help determine the firm's specific obligations, particularly if the firm operates across multiple regulatory jurisdictions.
The Safeguards Rule protects "customer information," which includes records containing nonpublic personal information about a customer that are handled or maintained by or on behalf of the financial institution or its affiliates.
The Privacy Rule uses the related concept of nonpublic personal information, or NPI.
The FTC explains that NPI can include information an individual provides to obtain a financial product or service, information obtained through a transaction, and information obtained in connection with providing a financial product or service. Examples can include names, addresses, income information, Social Security numbers, account numbers, payment history, balances, and other financial information.
For an accounting firm, that can translate into a broad information environment.
Examples may include:
The important security question is not simply where the firm's "financial files" are stored.
It is:
Where does customer information exist across the firm's entire technology environment, and who can access it?
GLBA's Privacy Rule addresses how covered financial institutions disclose and share consumers' nonpublic personal information.
Covered institutions generally must provide privacy notices explaining their information-sharing practices and, in certain circumstances, give consumers the ability to opt out of certain information sharing with nonaffiliated third parties.
The Privacy Rule is therefore broader than cybersecurity.
It addresses questions such as:
An accounting firm's privacy obligations should be evaluated alongside, rather than substituted for, its information security program.
For accounting firms, the Safeguards Rule is where GLBA becomes particularly relevant to cybersecurity.
The FTC's Safeguards Rule requires covered financial institutions under its jurisdiction to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information.
The program must be appropriate to the firm's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information it handles.
The objective is not to implement every available security technology.
It is to identify reasonably foreseeable risks and establish safeguards appropriate to those risks.
The Safeguards Rule establishes specific elements that covered organizations must address in their information security programs. These requirements provide a useful framework for accounting firms evaluating their cybersecurity maturity.
A covered firm must designate a Qualified Individual to implement and supervise its information security program.
That person can be an employee, affiliate, or service provider. However, using an outside IT or security provider does not transfer the firm's responsibility for compliance. The firm must retain responsibility and designate a senior member of its personnel to oversee the relationship.
For a small or midsize accounting firm, this distinction matters.
An outsourced IT provider may operate security tools and perform technical functions, but firm leadership still needs clear ownership of the information security program.
The information security program must be based on a written risk assessment.
The assessment should identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information and establish criteria for evaluating those risks. The firm must also periodically reassess risks as its operations and threat environment change.
A useful accounting-firm risk assessment should answer:
The Safeguards Rule requires organizations to implement safeguards that address the risks identified through their assessment.
The FTC identifies specific controls including access management, data inventory, encryption, application security, multifactor authentication, secure disposal, change management, and monitoring of user activity.
For a Microsoft 365 environment, these requirements can translate into practical controls such as:
The specific technology should follow the firm's risk assessment rather than the other way around.
Security controls need to be tested to determine whether they are actually working.
The Safeguards Rule requires covered institutions to regularly monitor and test the effectiveness of their safeguards. The FTC notes that continuous monitoring can satisfy the testing requirement for information systems; otherwise, the rule specifies annual penetration testing and vulnerability assessments, including system-wide scans every six months for publicly known vulnerabilities, along with additional testing in certain circumstances.
This is an important distinction between having security tools and operating a security program.
A firm should be able to demonstrate not only that a control exists, but that it is being monitored, reviewed, and improved.
Employees are part of the information security program.
The Safeguards Rule requires security awareness training and specialized training for personnel with hands-on responsibility for implementing the information security program.
For accounting firms, training should address behaviors employees encounter in their normal work, including:
The objective should be measurable behavior change, not simply completion of an annual training module.
Useful measures can include training completion, phishing-reporting behavior, repeat failures, MFA adoption, and time to report suspected incidents.
A GLBA information security program should not be a policy document that sits untouched in a compliance folder.
It should describe how the firm actually manages information security.
The Safeguards Rule addresses:
The Qualified Individual must also provide a written report to the firm's board or governing body, or an appropriate senior officer if there is no board or equivalent body, at least annually. The report must address the overall status of the program and material matters such as risk assessments, control decisions, service providers, testing, security events, and recommended changes.
For executive leadership, this creates an opportunity to turn cybersecurity from a collection of technical activities into a measurable risk-management program.
Accounting firms rarely operate entirely on their own infrastructure.
Customer information may pass through:
The Safeguards Rule requires covered institutions to select service providers capable of maintaining appropriate safeguards, require appropriate safeguards through contracts, monitor their performance, and periodically reassess their suitability.
This means vendor management is part of GLBA cybersecurity compliance.
A practical service-provider review should consider:
The goal is not to collect security questionnaires for their own sake.
The goal is to understand where responsibility sits across the firm's technology ecosystem.
A GLBA information security program must include a written incident response plan.
The plan should establish the firm's response objectives, internal processes, roles and decision-making authority, communication procedures, remediation processes, documentation and reporting requirements, and post-incident review.
That plan should be practical enough to use during an actual security event.
For example, if an employee's Microsoft 365 credentials are compromised, the firm should already know:
The Safeguards Rule includes a specific notification requirement for certain security breaches.
Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a notification event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
This requirement took effect in May 2024.
The FTC's notification requirement is only one part of an incident response process. Accounting firms may also have obligations under other federal, state, contractual, or professional requirements depending on the circumstances.
A GLBA assessment should begin with information and risk, not with a list of security products.
A practical review can be organized into six areas.
| Area | Questions to evaluate | Example measure |
|---|---|---|
| Identity | Who can access customer information? Is MFA enforced? | MFA coverage and privileged-account coverage |
| Data | Where is customer information stored and shared? | Known data repositories and access paths |
| Endpoints | Are devices protected and managed? | Managed-device coverage and unresolved critical findings |
| Monitoring | Can the firm detect suspicious activity? | Alert coverage and response time |
| People | Do employees recognize and report threats? | Training completion, reporting rate, repeat failures |
| Response | Can the firm contain and investigate an incident? | Time to detect, contain, and document incidents |
For Microsoft 365 environments, the review should extend beyond the Microsoft 365 admin center.
Identity, endpoints, email, cloud applications, file storage, third-party integrations, privileged access, and security monitoring should be evaluated as one connected environment.
Use the following checklist as a starting point for an internal review:
A mature GLBA program is not simply a binder of policies or a list of cybersecurity products.
It should create a repeatable operating cycle:
Identify → Assess → Protect → Monitor → Respond → Improve
The firm's risk assessment identifies what needs protection. Security controls address those risks. Monitoring provides evidence that controls are working. Incident response establishes what happens when they are not. Leadership review then drives changes to the program.
That cycle also gives executives something more useful than a generic statement that the firm is "secure."
Leadership can instead track measurable indicators such as:
These measures help connect GLBA compliance to actual changes in security posture.
For accounting firms, the most useful GLBA assessment is often not a review of whether policies exist.
It is a comparison between what the firm's policies say should happen and what actually happens.
If the policy requires MFA, is MFA enforced for every relevant account?
If the firm says customer information is encrypted, where is that information stored and how is encryption verified?
If an employee leaves, how quickly is access removed?
If a security alert occurs, who investigates it?
If a service provider has access to client information, when was that provider last assessed?
If an incident occurs, can the firm demonstrate what happened, what information was affected, and how the response was managed?
Those questions turn GLBA from a compliance exercise into a practical cybersecurity framework.
For accounting firms using Microsoft 365 and cloud-based applications, that distinction is especially important. Customer information can move across identities, devices, email, applications, and external providers every day. Effective GLBA compliance therefore depends on understanding the entire information environment and continuously improving the controls that protect it.
GLBA can apply to accounting firms because the FTC identifies accountants and tax preparers among businesses that may qualify as financial institutions based on their financial activities. Whether a specific firm is covered depends on its activities, applicable jurisdiction, and other circumstances.
GLBA compliance for accounting firms involves protecting covered customer financial information and meeting applicable privacy and information security requirements. For firms subject to the FTC's Safeguards Rule, this includes maintaining a written information security program based on a risk assessment and implementing appropriate administrative, technical, and physical safeguards.
GLBA protects nonpublic personal information and, under the Safeguards Rule, customer information containing such information. Examples can include Social Security numbers, income information, account numbers, payment information, financial statements, and other information collected or maintained in connection with financial services.
The GLBA Safeguards Rule requires covered financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program designed to protect customer information. The program must address risks appropriate to the organization's size, complexity, activities, and the sensitivity of its information.
Yes. The FTC Safeguards Rule requires multifactor authentication for individuals accessing customer information on the organization's information system, unless the Qualified Individual has approved in writing an equivalent form of secure access control.
Yes. Covered organizations under the Safeguards Rule must maintain a written information security program appropriate to their size and complexity, activities, and the sensitivity of customer information.
Yes. The Safeguards Rule requires a written incident response plan covering areas such as response processes, roles and responsibilities, communications, remediation, documentation, reporting, and post-incident review.
Certain breaches trigger an FTC notification requirement. Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
Covered accounting firms remain responsible for overseeing service providers that handle customer information. The Safeguards Rule requires firms to select providers capable of maintaining appropriate safeguards, address security requirements contractually, monitor provider performance, and periodically reassess provider suitability.
Microsoft 365 can provide security capabilities that support a GLBA information security program, including identity controls, multifactor authentication, access management, encryption, endpoint management, and security monitoring. However, using Microsoft 365 does not by itself make an accounting firm GLBA compliant. The firm must evaluate its overall information security program, controls, processes, people, applications, and service providers against its risks and applicable requirements.
Start by identifying customer information and where it resides, conducting a documented risk assessment, reviewing identity and access controls, evaluating encryption and endpoint protection, testing security controls, reviewing service providers, assessing employee security behavior, and validating the firm's incident response capabilities. The assessment should result in prioritized remediation actions with measurable owners and deadlines.