GLBA Cybersecurity: 7 Questions for Your IT Provider | Sourcepass
Sep 25, 2026 Robert Villano Security & Compliance | Governance, Risk & Compliance | Industry - Professional Services 11 min read
For accounting firms subject to the Gramm-Leach-Bliley Act (GLBA), cybersecurity is not simply an IT responsibility. The GLBA Safeguards Rule requires covered financial institutions under the Federal Trade Commission's jurisdiction to maintain a written information security program designed to protect customer information.
That makes the relationship with your IT provider an important part of your GLBA cybersecurity strategy.
Your provider may manage Microsoft 365, endpoints, identity security, backups, security monitoring, or other systems containing customer information. But outsourcing technology does not outsource the firm's responsibility for its information security program. The FTC specifically states that a company using a service provider to implement or supervise its security program remains responsible for overseeing that relationship.
So instead of asking only, "Are we GLBA compliant?", accounting firm leadership should ask a more practical question:
Can our IT provider demonstrate that the technology environment, security controls, and processes supporting our firm address the risks identified in our GLBA information security program?
The following seven questions can help.
GLBA and Cybersecurity: 7 Questions to Ask Your IT Provider
A strong IT provider should be able to answer these questions clearly, provide evidence where appropriate, and explain how identified gaps are being addressed.
- Do we have a documented risk assessment?
- Is MFA protecting all appropriate access points?
- How is client financial data protected?
- How are privileged accounts controlled?
- How do you monitor for suspicious activity?
- What happens if our firm experiences a security incident?
- How do you verify that our technology vendors and service providers protect our data?
The goal is not to test your provider with technical terminology. It is to determine whether the provider can connect its day-to-day IT and cybersecurity activities to the firm's broader information security obligations.
1. Do We Have a Documented Risk Assessment?
The Safeguards Rule requires a covered firm's information security program to be based on a written risk assessment.
The assessment should identify reasonably foreseeable internal and external risks to customer information, evaluate existing safeguards, and be periodically reassessed as the firm's operations and risks change.
Your IT provider may contribute significantly to that assessment, but leadership should understand what it actually contains.
Ask your provider:
- When was our most recent risk assessment completed?
- What customer information and systems were included?
- Where does customer information exist across our environment?
- Which risks were identified?
- Which safeguards currently address those risks?
- What gaps remain?
- Who owns each remediation item?
- When will the assessment be updated?
A useful risk assessment should go beyond a generic cybersecurity score.
For an accounting firm, it should consider the actual environment, including:
- Microsoft 365 and identity systems
- Endpoints and laptops
- SharePoint and OneDrive
- Tax and accounting applications
- Document management platforms
- Remote access
- Backup systems
- Third-party applications
- Managed service providers
- Employees and contractors
What good looks like
You should be able to see a clear connection between:
Risk → Control → Evidence → Remediation
For example, if compromised credentials are identified as a significant risk, the provider should be able to explain which identity controls mitigate that risk, how those controls are monitored, where exceptions exist, and what is being done to address them.
A risk assessment that produces no measurable remediation is difficult to use as an ongoing management tool.
2. Is MFA Protecting All Appropriate Access Points?
Multifactor authentication is a core Safeguards Rule requirement for individuals accessing customer information on information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.
For accounting firms, the question should not be limited to whether MFA is enabled for Microsoft 365 email.
Ask where users, administrators, vendors, and applications can access systems containing customer information.
That may include:
- Microsoft 365
- Tax applications
- Accounting platforms
- Remote access tools
- Cloud applications
- Backup systems
- Administrative portals
- Customer portals
- Third-party applications
Ask your provider:
- What percentage of applicable accounts are protected by MFA?
- Are there any exceptions?
- Why do those exceptions exist?
- Who approved them?
- Are privileged accounts subject to stronger controls?
- Are third-party administrators required to use MFA?
- How are MFA exceptions monitored?
- What happens when a user changes roles or leaves the firm?
What good looks like
Instead of hearing:
"MFA is enabled."
You should be able to hear:
"MFA is enforced for all applicable accounts. We have two documented exceptions, both with defined remediation dates."
That is a much more useful security metric because it measures coverage and identifies residual risk.
3. How Is Client Financial Data Protected?
The Safeguards Rule requires covered organizations to understand what customer information they have and where it is stored, collected, or transmitted. It also requires encryption of customer information on systems and while in transit, unless encryption is not feasible and effective alternative controls are approved by the Qualified Individual.
Your IT provider should therefore be able to explain how customer information moves through your technology environment.
Ask your provider:
- Where is customer information stored?
- Which systems have access to it?
- How is it encrypted?
- How is information protected when transmitted?
- Who has access?
- How are permissions reviewed?
- How is customer information protected on employee devices?
- How are backups protected?
- What happens to data when a device or system is retired?
- Which third-party applications receive customer information?
For Microsoft 365 environments, the conversation should extend beyond email.
Consider:
- SharePoint permissions
- OneDrive sharing
- Microsoft 365 identity
- Endpoint security
- Administrative access
- Third-party application permissions
- Data stored in connected applications
- Email and file-sharing controls
What good looks like
Your provider should be able to map the firm's major customer information repositories and explain the controls protecting each one.
You should also be able to identify exceptions.
If a particular system cannot support a required security control, that should be a documented risk decision rather than an unknown gap.
4. How Are Privileged Accounts Controlled?
Not every user account presents the same level of risk.
Administrative accounts can change configurations, create or disable users, access sensitive systems, modify security controls, and potentially access large amounts of customer information.
That makes privileged access an important part of any accounting firm's identity security strategy.
Ask your provider:
- How many privileged accounts exist?
- Who has administrative access?
- Why does each person need it?
- Are administrative accounts separate from normal user accounts?
- Is MFA enforced?
- Are privileged activities logged?
- Are administrative permissions reviewed regularly?
- Are former employees and contractors removed promptly?
- Does our IT provider have direct administrative access to our environment?
- How is your own administrative access controlled and monitored?
That last question is particularly important.
If an IT provider has administrative access to the firm's Microsoft 365 tenant, endpoints, network, backup systems, or other platforms containing customer information, that access should be incorporated into the firm's risk assessment and service-provider oversight process.
What good looks like
The firm can identify:
- Who has privileged access
- Why they have it
- What systems they can access
- How that access is protected
- How activity is monitored
- When access was last reviewed
A low number of administrators is not the objective by itself. The objective is controlled, justified, monitored privileged access.
5. How Do You Monitor for Suspicious Activity?
Security tools only reduce risk when someone can identify and respond to meaningful events.
The Safeguards Rule requires covered organizations to regularly monitor and test the effectiveness of safeguards. Depending on the firm's approach, this can involve continuous monitoring or the testing and vulnerability assessment requirements specified by the rule.
Your IT provider should be able to explain what happens after a security alert occurs.
Ask your provider:
- What security events are we monitoring?
- Which systems are covered?
- Who reviews alerts?
- Is monitoring performed continuously?
- What types of events trigger investigation?
- How are suspicious Microsoft 365 sign-ins identified?
- How are endpoint threats investigated?
- How are high-severity alerts escalated?
- What is the expected response time?
- How are incidents documented?
- What security metrics do you report to leadership?
What good looks like
A provider should be able to show more than a dashboard full of alerts.
Ask for operational measures such as:
- Number of high-severity events
- Alerts investigated
- Mean time to investigate
- Mean time to contain
- Unresolved high-risk alerts
- Systems covered by monitoring
- Significant trends over time
The objective is to understand whether monitoring is producing meaningful action.
6. What Happens If Our Firm Experiences a Security Incident?
Every accounting firm should know what happens when something goes wrong before an incident occurs.
The Safeguards Rule requires a written incident response plan that addresses how the firm will respond to and recover from security incidents affecting the confidentiality, integrity, or availability of customer information. The plan should establish roles, responsibilities, decision-making authority, communications, remediation, documentation, and reporting procedures.
Your IT provider may be responsible for significant portions of the technical response, but the firm's leadership still needs to understand the overall process.
Ask your provider:
- How will we know if a security incident occurs?
- Who contacts our firm?
- Who is responsible for containing the incident?
- Who investigates what happened?
- How do you determine whether customer information was accessed?
- Who coordinates with legal counsel?
- Who determines whether regulatory notification requirements apply?
- How are affected systems restored?
- How is the incident documented?
- Do you conduct post-incident reviews?
- When was the incident response plan last tested?
The GLBA Safeguards Rule also contains a specific FTC notification requirement for certain security events involving at least 500 consumers' information. Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event involving unauthorized acquisition of unencrypted customer information.
The specific facts of an incident determine whether that requirement applies, and other federal, state, contractual, or professional obligations may also be relevant.
What good looks like
Your firm should know:
Who → Does What → When → With What Authority → Using What Process
An incident response plan that exists only as a document is less useful than one that has been exercised and updated based on what the firm learned.
7. How Do You Verify That Our Technology Vendors and Service Providers Protect Our Data?
Your IT provider is not necessarily the only third party with access to customer information.
An accounting firm's technology ecosystem may include:
- Microsoft 365
- Tax software
- Accounting applications
- Document management systems
- Payroll platforms
- Cloud storage
- Backup providers
- Managed security providers
- E-signature platforms
- Customer portals
- Other specialized applications
The Safeguards Rule requires covered financial institutions to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, establish appropriate security requirements through contracts, monitor provider performance, and periodically reassess their suitability.
Ask your provider:
- Which vendors have access to customer information?
- Which vendors have direct access to our network or systems?
- How are those vendors evaluated?
- What security requirements are included in their contracts?
- How often are high-risk vendors reassessed?
- How are vendor security incidents communicated?
- What happens when a vendor relationship ends?
- Does our IT provider maintain its own vendor risk management process?
This is particularly important when an IT provider recommends or manages third-party technology on the firm's behalf.
What good looks like
Your firm should maintain a current inventory of important service providers and understand:
- What data each provider handles
- What access each provider has
- The provider's security requirements
- When the provider was last reviewed
- Any unresolved security concerns
- What happens when the relationship ends
Not every vendor requires the same level of scrutiny. Risk-based oversight should focus more attention on providers with access to sensitive customer information or critical systems.
What Should an IT Provider Be Able to Show an Accounting Firm?
The seven questions above are useful because they shift the conversation from claims to evidence.
When evaluating your IT provider, ask for documentation or reporting that demonstrates how the program operates.
Examples include:
| Area | Evidence to request |
|---|---|
| Risk management | Current written risk assessment and remediation plan |
| Identity | MFA coverage and privileged-account review |
| Data protection | Data inventory, encryption coverage, access reviews |
| Endpoint security | Device coverage, security status, vulnerability reporting |
| Monitoring | Security event and response reporting |
| Incident response | Current plan and most recent exercise or review |
| Employee security | Training completion and relevant behavior metrics |
| Vendor oversight | Critical vendor inventory and review status |
| Testing | Vulnerability assessments, penetration testing, or monitoring evidence |
| Governance | Security reporting provided to leadership |
The specific documentation will vary based on the firm's environment and the provider's responsibilities.
The underlying principle is simple:
If a security control matters, the firm should be able to determine whether it exists, whether it is working, and whether exceptions are being managed.
What Should Accounting Firm Leadership Measure?
Cybersecurity reporting becomes more useful when it focuses on outcomes rather than the number of tools deployed.
Instead of reporting:
"We have endpoint protection."
Consider measuring:
Percentage of active endpoints protected and managed.
Instead of:
"We conduct security awareness training."
Measure:
Training completion, phishing reporting behavior, and repeat failures.
Instead of:
"We monitor security events."
Measure:
Coverage of critical systems, high-severity events investigated, and response times.
Instead of:
"We have a risk assessment."
Measure:
Number of high-risk findings, remediation status, and time to address identified gaps.
A practical cybersecurity scorecard for leadership might include:
- MFA coverage
- Privileged-account coverage and review status
- Managed endpoint coverage
- Critical vulnerability count
- Vulnerability remediation time
- Security awareness completion
- Phishing reporting rate
- High-severity security events
- Mean time to investigate
- Mean time to contain
- Critical vendor review completion
- Open remediation items
- Incident response exercise date
These measures help leadership understand whether security controls are producing measurable improvements.
What If Your IT Provider Cannot Answer These Questions?
The purpose of these questions is not to create an adversarial relationship with an IT provider.
It is to establish whether the provider's services align with the firm's risk-management responsibilities.
If your provider cannot answer a question, start by determining why.
The issue may be:
- The provider does not own that responsibility
- Another vendor manages the relevant system
- The information exists but is not being reported to leadership
- The control has not been implemented
- The control exists but is not being measured
- The firm has not clearly assigned ownership
Each situation calls for a different response.
The important thing is to make the gap visible and assign an owner.
A useful discussion with an IT provider should ultimately produce:
Gap → Risk → Owner → Action → Deadline → Evidence
That creates accountability without turning cybersecurity into a checklist exercise.
How Microsoft 365 Fits Into the Conversation
For accounting firms operating primarily in Microsoft 365, identity and cloud security should be a central part of the discussion with the IT provider.
Ask how the provider manages:
- Microsoft 365 identity
- MFA
- Privileged administrator accounts
- Conditional access
- Endpoint security
- Email security
- SharePoint and OneDrive permissions
- Third-party application access
- Security logging
- Suspicious sign-in detection
- Device management
- Data protection
- Backup and recovery
Microsoft 365 provides security capabilities that can support an accounting firm's GLBA information security program, but the platform itself does not establish compliance.
The firm's security program still needs to identify risks, implement appropriate controls, monitor those controls, test their effectiveness, manage service providers, respond to incidents, and maintain appropriate governance.
Turn the IT Relationship Into a Security Operating Model
For accounting firm leadership, the most important shift is moving from asking whether the IT provider is "taking care of security" to establishing who is responsible for each part of the security program.
A practical operating model looks like:
Firm leadership → Risk ownership and governance
Qualified Individual → Information security program oversight
IT/security provider → Technical implementation and operations
Employees → Secure behaviors and incident reporting
Technology vendors → Protection of data within their services
That model creates clearer accountability.
The IT provider can operate the technology. Leadership can make risk decisions. Employees can follow security requirements. Vendors can be held to defined security expectations.
Together, those responsibilities form a functioning information security program.
The Right Question Is Not "Are We Secure?"
No IT provider can reduce cybersecurity to a simple yes-or-no answer.
For an accounting firm subject to GLBA, the more useful conversation is whether the firm's security program is appropriately designed, consistently implemented, monitored, tested, and improved.
That means asking:
- Do we understand our customer information?
- Do we understand the risks?
- Are the right controls in place?
- Are those controls actually working?
- Can we demonstrate that?
- What gaps remain?
- Who owns those gaps?
- What happens when something goes wrong?
The answers should become part of an ongoing operating rhythm between firm leadership and the IT provider.
GLBA establishes the obligation to protect customer information. Your IT provider should help turn that obligation into a security program that can be measured, managed, and improved.
FAQ
Does GLBA apply to accounting firms?
GLBA can apply to accounting firms because the FTC identifies tax preparation firms, accountants, and other financial advisers among businesses that may qualify as financial institutions depending on their activities. Whether a specific firm is covered depends on its activities and applicable regulatory jurisdiction.
What should an accounting firm ask its IT provider about GLBA compliance?
Accounting firms should ask their IT provider about the firm's risk assessment, MFA coverage, data protection, privileged access, security monitoring, incident response, and service-provider oversight. These questions help determine whether the technology environment supports the firm's GLBA information security program.
Does an IT provider make an accounting firm GLBA compliant?
No. An IT provider can implement and operate security controls, but the accounting firm remains responsible for its information security program. The FTC specifically states that using a service provider does not eliminate the firm's responsibility for overseeing its security program.
What should a GLBA risk assessment include?
A GLBA risk assessment should identify reasonably foreseeable internal and external risks to customer information, evaluate existing safeguards, and establish how identified risks will be addressed. It should be written and periodically reassessed as the firm's operations and risk environment change.
Does GLBA require MFA for accounting firms?
The Safeguards Rule requires multifactor authentication for individuals accessing customer information on an information system, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.
What should an IT provider monitor for GLBA cybersecurity?
An IT provider should monitor security events relevant to the firm's customer information and information systems. Depending on the environment, that can include suspicious Microsoft 365 sign-ins, privileged account activity, endpoint threats, authentication anomalies, unusual data access, and other security events.
How should an accounting firm evaluate its IT provider?
Evaluate whether the provider can demonstrate effective risk management, identity security, data protection, monitoring, incident response, vulnerability management, security testing, and service-provider oversight. Ask for measurable evidence and documentation rather than relying only on descriptions of the provider's services.
Does GLBA require accounting firms to encrypt customer information?
Yes. The Safeguards Rule requires covered organizations to encrypt customer information on their systems and in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.
Does GLBA require an incident response plan?
Yes. Covered financial institutions under the Safeguards Rule must maintain a written incident response plan addressing how the firm will respond to and recover from security incidents affecting customer information.
Does a GLBA-covered accounting firm have to report every security incident to the FTC?
No. The FTC notification requirement applies to specific qualifying notification events. Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a notification event involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
How does Microsoft 365 support GLBA cybersecurity?
Microsoft 365 can provide capabilities relevant to GLBA security controls, including MFA, identity and access management, endpoint security, email protection, encryption, logging, and security monitoring. However, using Microsoft 365 does not by itself establish GLBA compliance. The firm still needs a risk-based information security program and appropriate governance, processes, controls, testing, and oversight.
What is the most important thing to ask an IT provider about GLBA?
Ask the provider to demonstrate how its services address the risks identified in the firm's written risk assessment. The strongest conversation connects each significant risk to a specific control, an owner, measurable evidence that the control is working, and a documented plan for addressing exceptions or gaps.
Subscribe To
Sourcepass Insights
Sourcepass Insights
Stay in the loop and never miss out on the latest updates by subscribing to our newsletter today!