Texas Accounting & CPA Firm Cybersecurity · 2026

Texas CPA Firms
Are Under
Active Attack

Whitley Penn. Lane Gorman Trubitt. BST & Co. Orrick's $8M settlement. The accounting sector saw more named ransomware and MFT incidents in 2023–2025 than any prior two-year window. Tax returns, audit workpapers, and client financial records are the highest-value identity theft packages available.

2024–2025 CPA Firm Incident Wave: Cl0p MOVEit campaign hit Whitley Penn (TX, Oct 2023), ALPHV/BlackCat hit Lane Gorman Trubitt (TX, Jan 2024), BST & Co. (NY) faced regulatory action under HIPAA after client PHI exposure, and Orrick Herrington paid $8M to settle breach claims. IRS has flagged tax preparer identity theft as a "Dirty Dozen" priority. FTC Safeguards Rule enforcement against accounting firms began in 2024.
Get Free Security Assessment Download Threat Brief (PDF)
$8M
Orrick breach settlement — professional services precedent
900+
Whitley Penn personnel affected — TX's largest CPA breach
$10.22M
US avg breach cost — +9% YoY (IBM CODB 2025)
30 min
CoreRecon IR SLA vs 241-day industry avg dwell
01 — Named incidents

Four Incidents That
Changed the Liability Calculus

These aren't generic ransomware statistics. These are documented incidents at named accounting and professional services firms — each with regulatory, legal, and reputational consequences that reshaped how clients, bar associations, and federal regulators view CPA firm cybersecurity.

Whitley Penn LLP — Dallas / Houston / Fort Worth / Austin
October 2023 · Cl0p Ransomware · MOVEit CVE-2023-34362

What happened: Whitley Penn — one of Texas's largest regional CPA firms, 900+ personnel — was hit by Cl0p ransomware through the MOVEit managed file transfer vulnerability. Client financial records, tax workpapers, and audit engagement letters were exfiltrated. Cl0p's MOVEit campaign hit 2,000+ organizations globally in 60 days.

Why it matters for TX CPA firms: MOVEit and GoAnywhere are the standard file transfer tools for transmitting tax returns, audit deliverables, and client financial statements. Every CPA firm that processes client data via MFT platform was in scope for the same CVE. The vulnerability existed in every unpatched MOVEit installation — patch timing was the only differentiator.

IRS implication: Exfiltrated tax data triggers IRS Safeguards Program notification requirements and potential suspension of e-file privileges during investigation. Client notification obligations under TDPSA apply to any Texas resident whose data was involved.

MOVEit MFT exploitation Cl0p ransomware 900+ personnel affected TX largest CPA breach 2023
Lane Gorman Trubitt LLC — Dallas, TX
January 2024 · ALPHV/BlackCat Ransomware · Data Exfiltration

What happened: Lane Gorman Trubitt, a Dallas-based CPA firm serving closely held businesses and high-net-worth individuals, was claimed by ALPHV/BlackCat in January 2024. The firm's client roster — private equity-backed companies, real estate investors, and family offices — made their audit workpapers and tax returns exceptionally high-value targets. Double-extortion: data exfiltrated before encryption deployed.

The double-extortion model: ALPHV/BlackCat does not just encrypt — they exfiltrate first, then threaten to publish on their leak site. For a CPA firm, "published data" means client tax returns, ownership structures, financial account information, and business valuation workpapers — all publicly accessible. Client relationships are permanently damaged even if the firm pays and systems are restored.

ALPHV/BlackCat double-extortion Dallas TX firm High-net-worth client exposure Private equity & family office data
BST & Co. CPAs LLP — Albany, NY (National Precedent)
2023–2024 · HIPAA Regulatory Action · Healthcare Client PHI

What happened: BST & Co., a CPA firm that performed accounting services for healthcare clients, faced regulatory action after client PHI exposure. CPA firms that process financial records for covered entities — hospitals, physician groups, home health agencies — are Business Associates under HIPAA and subject to the same breach notification and security rule obligations as the healthcare organizations themselves.

TX relevance: Approximately 400 CPA firms in Texas serve as Business Associates to HIPAA-covered entities. Any firm that touches payroll, billing, or cost-accounting data for a hospital or physician practice is in scope. The BST precedent confirms OCR will pursue CPA firms — not just healthcare providers — for HIPAA violations.

HIPAA BA liability PHI in accounting records OCR enforcement precedent ~400 TX CPA/healthcare BA firms
Orrick, Herrington & Sutcliffe — $8M Settlement (National Precedent)
2023 Breach · 2024–2025 Class Action · $8M Settlement

What happened: Orrick — a global law firm that handles M&A, PE, and corporate transactions — suffered a breach of client confidential records. The $8M class action settlement (2025) established a significant liability precedent for professional services firms: breach of client data is actionable as breach of fiduciary duty, malpractice, and contract — not just a regulatory event.

Why CPA firms should care: Orrick is a law firm, not an accounting firm — but the liability theory is identical. CPA firms hold client data under engagement letter confidentiality obligations. Post-Orrick, any CPA firm breach is a potential class action, not just an insurance claim. The $8M settlement came from a firm with substantial professional liability coverage. Smaller TX CPA firms with $1–$5M policy limits face existential exposure.

$8M class action settlement Fiduciary duty breach theory Professional liability precedent Class action risk for all prof. services
02 — Regulatory framework

Four Overlapping Mandates —
All Enforced, All Apply

Texas CPA firms face a compliance stack that grew significantly in 2023–2024. Most firms are aware of IRS WISP requirements. Fewer understand that FTC Safeguards, TDPSA, and GLBA create independent obligations — with separate enforcement authorities and penalty structures.

IRS Publication 4557 — WISP Requirement

Every PTIN holder must maintain a Written Information Security Plan. Designate a coordinator, conduct risk assessment, implement safeguards, oversee service providers, incident response plan. IRS can revoke e-file privileges during breach investigation. Non-compliance is also cited in AICPA ethics rules under the confidentiality standard.

PTIN revocation + e-file suspension

Source: IRS Pub 4557; IRS Dirty Dozen 2025 (tax preparer identity theft)

FTC Safeguards Rule — 16 CFR Part 314

CPA firms are classified as financial institutions under GLBA. Full enforcement since June 2023. 8 requirements: written ISP, Qualified Individual, risk assessment, MFA, encryption, IR plan, vendor oversight, annual pen test. 30-day FTC breach notification for 500+ customer records. FTC enforcement actions against accountants began 2024.

FTC civil penalties — $50,120/violation/day

Source: 16 CFR Part 314 (FTC, enforced since Jun 2023)

TDPSA — Texas Data Privacy & Security Act

Effective July 1, 2024. $7,500/violation civil penalties. Any CPA firm doing business in Texas that processes personal data of Texas residents is in scope. 45-day consumer data request response. Data Protection Assessment required for high-risk processing. GLBA-regulated data partially exempt but marketing/analytics databases are not.

$7,500/violation — TX AG enforcement

Source: TX Data Privacy and Security Act; TX Attorney General

SOC 2 — Client Contractual Requirement

Enterprise clients, PE sponsors, and government contractors increasingly require SOC 2 Type II certification from their CPA firms. SOC 2 Trust Service Criteria (Security, Availability, Confidentiality) map directly to IRS WISP and FTC Safeguards requirements — a single compliance program can satisfy all three. Without SOC 2, firms may lose RFP eligibility for enterprise audit engagements.

Client loss — enterprise RFP disqualification

Source: AICPA SOC 2 Trust Service Criteria (2017 update)

Key insight most TX CPA firms miss: IRS WISP, FTC Safeguards, and TDPSA have three separate enforcement authorities (IRS, FTC, TX AG) with three separate penalty structures. A single breach triggers all three simultaneously. A 500-record breach can result in: PTIN revocation during investigation, FTC civil penalty ($50,120/day per violation), TX AG civil penalty ($7,500/violation), and class action liability post-Orrick. Most TX CPA firms carry $1M–$3M in professional liability coverage — insufficient against simultaneous multi-regulator enforcement.
03 — 8 controls

8 Controls Every
TX CPA Firm Needs Now

The 8-Point CPA Firm Security Checklist
IRS WISP with designated coordinator, current risk assessment, and annual review. Covers all client data handling workflows. Required for e-file privileges.
MFA on all systems holding client tax data — tax prep software (Thomson Reuters, Drake, Intuit ProConnect, ProSystem fx), client portals, email, and practice management tools. GLBA 16 CFR 314.4(c)(5) requirement.
MFT platform monitoring — real-time anomaly detection on MOVEit, GoAnywhere, Cleo, or any file transfer platform used for client deliverable transmission. Whitley Penn lesson: unpatched MFT = open door.
GLBA Qualified Individual designation — vCISO satisfies the 16 CFR 314.4(a) requirement. Delivers WISP, annual risk assessment, annual board/management report, vendor oversight, and incident response plan.
Annual penetration testing — scoped to client portal, tax software integrations, MFT platform, and internal lateral movement paths. Required under FTC Safeguards Rule and IRS WISP framework.
BEC controls on engagement wire flows — attorney trust account wire fraud is the analog for CPA firms. Floor plan similar: month-end/quarter-end tax payment wires are high-value targets. Dual authorization, out-of-band verification on all wires above $25K.
Vendor oversight program for tax software, document management (iManage, NetDocuments, ShareFile), and client portal platforms. FTC requires documented service provider oversight. Thomson Reuters breach (2024) shows risk.
TDPSA + FTC Safeguards dual compliance mapping. One engagement delivers both — TDPSA AG notification workflows and FTC 30-day customer notification simultaneously. Avoids double remediation cost.
04 — Pricing

Flat-Rate SOC Coverage —
No Hidden Fees

Month-to-month. No long-term contracts. SDVOSB pricing. All tiers include 24/7 SOC monitoring, IRS WISP-compatible controls documentation, and FTC Safeguards technical control evidence.

Sentinel
$89
/endpoint/month
  • 24/7 SOC monitoring + EDR
  • IRS WISP technical controls baseline
  • MFT anomaly detection (MOVEit, GoAnywhere)
  • Security awareness training
  • TDPSA breach notification workflow
  • 4-hour IR SLA
Get Sentinel Pricing
Command
$2,500
/month + endpoint tier
  • Everything in Fortress
  • vCISO as GLBA Qualified Individual
  • IRS WISP authorship & annual updates
  • Annual risk assessment + board report
  • FTC Safeguards full program management
  • SOC 2 readiness coordination
  • 30-minute IR SLA
Get Command Pricing
05 — Why CoreRecon

SDVOSB · 30-Min SLA ·
Texas-Resident Data

SDVOSB Certified

Service-Disabled Veteran-Owned Small Business. Qualifies for GSA Schedule set-asides, SBA 8(a) program access, and state procurement preferences. TX state vendor via AT&T — active on TX Department of Information Resources (DIR) contracts.

30-Minute IR SLA

IBM CODB 2025: industry average breach identification = 241 days. A CPA firm breached in January (tax season) faces simultaneous client impact, IRS notification risk, and FTC 30-day clock. Our 30-minute SLA for critical incidents means detection happens in hours, not months.

Texas Residency — Client Data Stays in TX

Client tax data and financial records processed by a TX SOC staffed by TX-based engineers. No offshore SOC handling IRS client data. TX state residency for data processing is increasingly required by TX state agency and municipal contracts.

CPA-Sector Expertise

We understand Thomson Reuters UltraTax, Drake, ProSystem fx, Intuit ProConnect, and the MFT platforms that carry client deliverables. Our playbooks are built around tax season risk windows, month-end close, and engagement letter workflows — not generic enterprise security templates.

SDVOSB Certified
30-Min IR SLA
TX-Based SOC
IRS WISP Compliant
FTC Safeguards QI
SOC 2 Readiness
Free Security Assessment — $2,500 Value

30-minute call with a CPA firm security specialist. We map your IRS WISP compliance gaps, FTC Safeguards QI status, MFT platform exposure (MOVEit/GoAnywhere), and TDPSA notification readiness. Written report delivered in 14 days at no cost.

Book Free Assessment →

SDVOSB Certified  ·  30-Min SLA  ·  TX-Based Team  ·  No Long-Term Contracts