Intelligence Report · Texas Accounting & CPA Firms · 2026

Texas CPA Firms
Cyber Threat
Brief 2026

Whitley Penn. Lane Gorman Trubitt. BST & Co. Orrick's $8M settlement. Four incidents that changed the IRS WISP, FTC Safeguards, and class action liability calculus for every Texas accounting practice. 38 verified sources.

4
named incidents
2023–2024
$8M
Orrick settlement
precedent
4
overlapping
mandates enforced
38
verified
sources
Download Full Brief (PDF) Get Free Security Assessment
Sources: IRS Pub 4557 · FTC 16 CFR Part 314 · TDPSA TX AG · IBM CODB 2025 · FBI IC3 2024 · AICPA Rule 301 · Cl0p MOVEit advisories · ALPHV/BlackCat FBI advisory

The CPA Sector Threat
Landscape in Numbers

MetricValueSource
Orrick class action settlement (professional services precedent)$8MOrrick settlement reporting, 2025
FTC civil penalty per violation per day$50,120FTC 16 CFR Part 314 (enforced Jun 2023)
TDPSA civil penalty per violation (TX AG)$7,500TX Data Privacy and Security Act, eff. Jul 1 2024
US average breach cost (all sectors)$10.22MIBM Cost of Data Breach Report 2025 (+9% YoY)
Average breach dwell time (industry avg)241 daysIBM Cost of Data Breach Report 2025
CoreRecon IR SLA (critical incidents)30 minCoreRecon SLA — Sentinel/Fortress/Command
Cl0p MOVEit organizations compromised (2023)2,000+CISA/FBI joint advisory + Emsisoft tracker
TX CPA firms serving as HIPAA Business Associates (est.)~400AICPA PCPS survey + CoreRecon analysis

Four Incidents That Changed
the Liability Calculus

Entity Date Attack Vector Impact Relevance
Whitley Penn LLP
Dallas / Houston / FW / Austin, TX
Oct 2023 Cl0p — MOVEit CVE-2023-34362 Client tax returns, audit workpapers, engagement letters exfiltrated. 900+ personnel affected. TX largest CPA breach 2023
Lane Gorman Trubitt LLC
Dallas, TX
Jan 2024 ALPHV/BlackCat double-extortion PE-backed company K-1s, high-net-worth tax returns, ownership structures exfiltrated before encryption. Leak site claim. Double-extortion — data published
BST & Co. CPAs LLP
Albany, NY (national precedent)
2023–2024 Healthcare client PHI in accounting records HIPAA Business Associate regulatory action. OCR enforcement against CPA firm directly — not just the healthcare client. HIPAA BA liability precedent
Orrick, Herrington & Sutcliffe
Global (professional svcs precedent)
2023 breach / 2025 settlement Client confidential record exfiltration $8M class action settlement. Breach of fiduciary duty + malpractice + contract theory applies identically to CPA firms. $8M — class action precedent

Four Mandates —
Simultaneously Enforced

FrameworkAuthorityKey RequirementsPenalty
IRS Pub 4557 — WISP IRS Safeguards Program Written ISP, designated coordinator, risk assessment, technical safeguards, vendor oversight, IR plan, annual training PTIN revocation, e-file suspension during investigation
FTC Safeguards Rule — 16 CFR 314 FTC Qualified Individual, written ISP, MFA, encryption, annual pen test, vendor oversight, 30-day FTC breach notification (500+ records) $50,120/violation/day civil penalty
TDPSA — TX Data Privacy Act TX Attorney General Data Protection Assessments, 45-day consumer requests, breach notification. GLBA-regulated data partially exempt; marketing/CRM data not exempt. $7,500/violation civil penalty
HIPAA — BA obligations HHS Office for Civil Rights Security Rule compliance for CPA firms serving as Business Associates to covered entities. Breach notification to covered entity within 60 days. OCR enforcement direct against BA. $100–$50,000/violation; $1.9M/year max per category

8 Controls for
TX CPA Firms

01
IRS WISP + FTC Safeguards Integrated Program
One program satisfies both IRS Pub 4557 and FTC 16 CFR 314 requirements — written ISP, designated Information Security Coordinator / Qualified Individual, annual risk assessment, annual report to management. CoreRecon Command delivers WISP authorship and annual updates.
02
MFA on All Client Data Systems
MFA required on: Thomson Reuters UltraTax/CS, Drake, ProSystem fx, Intuit ProConnect, client portals, document management platforms, email. FTC 16 CFR 314.4(c)(5) requirement. IRS WISP technical safeguard. No exception for "small" or "legacy" platforms.
03
MFT Platform Monitoring + 72-Hr Patch SLA
Real-time anomaly detection on MOVEit, GoAnywhere, Cleo, ShareFile, or any file transfer platform transmitting client deliverables. Critical vulnerability patch SLA: 72 hours from disclosure. Whitley Penn was an unpatched MOVEit instance. The next campaign will target a different MFT.
04
Annual Penetration Test (FTC Required)
Annual pen test scoped to client portal, tax software integrations, MFT platform, email, and internal lateral movement paths. Required under FTC Safeguards Rule 16 CFR 314.4(g). Document results and remediation timeline for examiner readiness.
05
Vendor Oversight Program
Documented oversight for Thomson Reuters, Intuit, Drake, document management (iManage, NetDocuments, ShareFile), and any SaaS handling client data. FTC requires: written security requirements, annual review, breach notification contractual clauses, access monitoring. FTC 16 CFR 314.4(f).
06
BEC Controls on Client Fund Flows
Tax refund wire diversion, estimated tax payment fraud, and trust account BEC are documented against professional services firms. Out-of-band verbal verification for any wire instruction change exceeding $10K. MFA on controller and partner email accounts with wire transfer authority.
07
TDPSA + FTC Dual Notification Playbook
TDPSA TX AG notification ($7,500/violation) and FTC 30-day customer notification require parallel workflows. Pre-build both before a breach. Annual tabletop exercise simulating the Whitley Penn/Lane Gorman scenario: concurrent TDPSA + FTC + client notification + IRS Safeguards Program notification.
08
SOC 2 Evidence Collection
SOC 2 Trust Service Criteria (Security, Availability, Confidentiality) map to IRS WISP and FTC Safeguards — one compliance program satisfies all three. CoreRecon Command collects 12-month audit logs in auditor-ready format for SOC 2 engagements. Eliminates the "double remediation" cost of separate WISP + SOC 2 engagements.

SDVOSB · 30-Min SLA ·
TX Residency

30-Minute IR SLA
Industry average breach dwell time: 241 days (IBM CODB 2025). A CPA firm breached during January tax season faces concurrent IRS WISP failure, FTC 30-day clock, and client notification obligations. Our 30-minute critical incident SLA means detection happens in hours.
🏆
SDVOSB Certified
Service-Disabled Veteran-Owned Small Business. Qualifies for GSA Schedule set-asides and state procurement preferences. Active TX DIR vendor via AT&T — government contracting background means we understand documentation rigor.
🌵
TX Residency — Data Stays in TX
TX-based SOC staffed by TX-based engineers. Client tax data processed by Texas residents in Texas. No offshore SOC handling IRS client data. TX state residency increasingly required for TX state agency and municipal contracts.
📋
IRS WISP + FTC QI In Scope
Command tier vCISO serves as both IRS WISP Information Security Coordinator and FTC Safeguards Qualified Individual. WISP authorship, annual updates, risk assessment, annual board report, vendor oversight — all in scope. One engagement satisfies both mandates.
🔒
MFT Platform Expertise
We know MOVEit, GoAnywhere, Cleo, and ShareFile — the file transfer platforms that carry CPA firm client deliverables. Our monitoring playbooks are built around tax season risk windows, MFT anomaly detection, and 72-hour critical CVE patch enforcement.
🔗
SOC 2 Readiness Support
Command tier collects 12 months of audit logs in SOC 2 Trust Service Criteria format. Evidence collection supports your SOC 2 auditor without separate engagement scope. Satisfies IRS WISP, FTC Safeguards, and SOC 2 simultaneously — one compliance program.

Three ways to
protect your practice

🔍
Free Security Assessment
30-minute call with a CPA firm security specialist. We review your WISP compliance gaps, FTC Safeguards QI status, MFT platform exposure, and TDPSA notification readiness — at no cost. Written report in 14 days.
Get Free Assessment →
📊
Breach Cost Calculator
Enter your firm size, endpoint count, and security controls. Get an estimate of what a Whitley Penn-scale or Lane Gorman Trubitt-scale incident would cost your practice — including concurrent FTC penalty, TDPSA, and post-Orrick class action exposure.
Calculate My Exposure →
📞
IR Hotline — On Call Now
Active incident? Suspected breach? Call (800) 955-2596. 24/7 SOC with CPA firm incident response experience. We handle forensics and IRS/FTC notification support so you can protect your clients and your practice.
Call (800) 955-2596 →
Sources (38): IRS Publication 4557: Safeguarding Taxpayer Data (rev. 2024) • IRS FY2025 "Dirty Dozen" — Tax Preparer Identity Theft • FTC Safeguards Rule, 16 CFR Part 314 (enforced since June 9, 2023) • Gramm-Leach-Bliley Act, 15 USC §6801 • Texas Data Privacy and Security Act (eff. July 1, 2024) — TX Attorney General • AICPA Code of Professional Conduct Rule 301 (confidentiality) • AICPA SOC 2 Trust Service Criteria (2017, updated 2022) • 45 CFR Part 164 HIPAA Security Rule (Business Associate obligations) • Progress Software MOVEit Transfer CVE-2023-34362 security advisory (May 2023) • CISA/FBI joint advisory on Cl0p MOVEit campaign (AA23-158A) • Emsisoft: MOVEit breach impact tracker (2023) • KrebsOnSecurity: Cl0p MOVEit campaign reporting (2023) • Bleeping Computer: Cl0p MOVEit reporting (2023) • Reuters: MOVEit breach scope reporting (2023) • Whitley Penn LLP MOVEit incident — TX media coverage (Oct 2023) • Lane Gorman Trubitt ALPHV/BlackCat claim — ALPHV leak site (Jan 2024) • CISA/FBI joint advisory on ALPHV/BlackCat (AA23-353A, Dec 2023) • BST & Co. HIPAA BA regulatory action reporting (2023–2024) • HHS OCR: HIPAA Business Associate enforcement guidance • Orrick Herrington & Sutcliffe class action settlement reporting (2025) • IBM Cost of Data Breach Report 2025 (241-day dwell, $10.22M US avg, 600 orgs) • FBI IC3 2024 Annual Report ($2.77B BEC, professional services data) • FBI IC3 2025 Annual Report ($20.877B total cybercrime losses) • FTC enforcement actions against financial institutions and accountants (2024) • Thomson Reuters Professional Services platform breach incidents (2024) • AICPA PCPS Member Survey: Cybersecurity (2024) • AccountingToday: CPA firm cybersecurity coverage (2023–2025) • Journal of Accountancy: cybersecurity for tax practitioners (2024) • CPA Journal: data breach liability for accounting firms (2024) • GoAnywhere MFT CVE-2023-0669 security advisory (Jan 2023) • Cleo vulnerability reporting (CVE-2024-55956, Dec 2024) • NIST SP 800-171 Rev 3 (controlled unclassified information — relevant to defense-adjacent CPA clients) • GLBA Interagency Guidelines (12 CFR Appendix B) • FDIC: Professional Services Provider Risk Guidance • TX Secretary of State: CPA license data (37,000+ licensed CPAs in TX) • TSCPA: Texas Society of CPAs membership and practice data • CoreRecon threat intelligence: professional services vertical targeting patterns (2023–2025) • CISA #StopRansomware advisory series (professional services sector)