V43 · Texas CPA Firms & Accounting Practices · IRS Pub 4557 WISP Required

Your accounting firm holds every client's tax ID, bank account, and W-2. Attackers know it. CoreRecon protects it.

Texas has ~16,000 licensed CPAs on the State Board of Public Accountancy roster. Every PTIN holder must maintain a written information security plan (WISP) under IRS Publication 4557. Under the FTC Safeguards Rule 2023 amendment (16 CFR §314), CPA firms handling more than 5,000 consumer records are now classified as “financial institutions” — with explicit MFA, qualified-individual, and 30-day breach reporting obligations.

30-minute IR response. SDVOSB-certified. Texas data residency. IRS WISP authorship included.

Free Security Posture Assessment — $2,500 Value Download the TX Accounting Firms Threat Brief →
⚠️
Landmark Admin (TX TPA, 2024). Ransomware hit a Texas third-party administrator that handles claims data for insurance carriers — 800,000+ claimant records exposed. Many TX CPA firms have TPA, audit, and assurance clients in adjacent sectors. If your firm touches claimant data, payroll data, or healthcare financial data, you inherit a similar exposure surface. Source: TX AG breach notification portal; Landmark Admin regulatory filings.
Why Generic IT Fails Accounting Firms

Tax Season Traffic Spikes. Remote CPAs. Unmanaged Tax Software Attack Surface.

Generic managed IT treats accounting firms like dental offices or auto dealerships — same EDR, same patch cadence, same MFA. CPA firms have workflow-specific risks that don't exist in any other sector. The tax-prep stack alone (QuickBooks Online, UltraTax CS, Drake, ProConnect, Lacerte, TaxAct, CCH Axcess) is a credential- and lateral-movement-rich attack surface that standard IT doesn't model.

Tax Season Traffic Spikes
IRS e-file opens in January and closes April 15. 90 days of compressed, deadline-driven workload with partners uploading client returns around the clock. Attackers time phishing and credential-stuffing campaigns to this window — the firm that “just makes it through April” is the firm that trained attackers on its workflows. The year-round SOC posture is what makes tax season bearable.
Remote CPA Workforce
Partners and senior managers work from home, client sites, and airports. BYOD laptops + RDP/AnyDesk + client-hosted QuickBooks Online sessions create a credential-harvesting buffet. Generic endpoint security doesn't see the lateral movement from a compromised personal device into firm-managed QuickBooks environments. Our SOC does.
Tax Software Attack Surface
QuickBooks, UltraTax CS, Drake, ProConnect, Lacerte, TaxAct, CCH Axcess — each with private credentials, EFIN access tokens, and PTIN-protected e-file auth. One compromised preparer credential = full client base e-fileable. We monitor EDR on the workstations, network telemetry on the e-file workflows, and credential rotation on the key tax-software integrations.
The Exposure

207 Days of Dwell Time Before CPA Firm Breach Notice.

Median dwell time for accounting & financial-services firms: 207 days (IBM X-Force 2024). Seven months of lateral movement, credential theft, and client data staging before detection. CPAs hold the highest-value-per-record data mix in professional services — W-2s, 1099s, K-1s, bank accounts, audit workpapers, and IRS PTIN e-file credentials — all in one fence.

Client Tax Data Exfil
W-2s, 1099s, K-1s, and 1040 e-file credentials are the highest-value records on the dark web. Operators exfiltrate before encrypting — stolen return data becomes leverage or is sold to fraud networks that file amended refunds for the actual taxpayer. Identity theft, IRS Form 14039-B filings, and class-action exposure on the firm that lost the data.
Wire Fraud via QuickBooks + ACH
QuickBooks Online + ACH batch workflow is the modern IOLTA for accounting firms. Lateral movement during dwell gives attackers the wire credentials. Avg BEC wire loss: $300K per incident (FBI IC3 2024). Most MSSPs monitor email — we monitor outbound ACH batches, vendor master changes, and dual-control callbacks against the bank.
Audit-Client PCAOB Exposure
Firms with PCAOB audit clients inherit flow-down obligations: AS 1000 / QC 1000 workpaper integrity, AS 1215 audit documentation. A breach that exposes audit workpapers destroys auditor independence — the audit client is forced to retain a successor firm, and your firm faces investor and PCAOB inspection exposure. This is the “tail risk” no insurance rider prices.
Regulatory Stack

Four Layers of Enforceable Duty. Simultaneously.

Texas CPA firms face a unique multi-track regulatory stack — IRS safeguards, FTC financial-institution obligations, state data privacy, and PCAOB audit-client flow-down. Each track has an active enforcement arm. No “we didn’t know” safe harbor.

IRS Publication 4557 — Written Information Security Plan (WISP)
Issued by the IRS Office of Safeguards. Effective since 2005; last revised November 2021. Applies to every PTIN holder and every firm preparing federal tax returns. Mandates ~14 WISP elements including designated Qualified Individual, MFA, encryption, vendor risk, employee training, annual review. Source: IRS.gov/Pub4557 (verified). Citation: IRS Publication 4557 (Rev. 11-2021).
IRS Publication 4557 WISP
Verbatim: “A WISP must be appropriate to the business and the size and complexity of the data.” Designated Qualified Individual required to oversee. Annual review and incident documentation. Applies to every PTIN-bearing federal tax preparer. Source: IRS Pub 4557 (Cat. No. 35579B), Rev. 11-2021.
FTC Safeguards Rule — 2023 (16 CFR §314)
Verbatim: “The Final Rule explicitly includes tax preparation firms as financial institutions.” Required: Qualified Individual, written infosec program, MFA, encryption at rest/in transit, 30-day breach reporting to FTC for ≥500 consumers. Source: 88 Fed. Reg. 60250 (Nov 7, 2023); 16 CFR §314.
TDPSA — Texas Data Privacy & Security Act
TDPSA §541.002: Taxpayer data (SSN, account numbers, EIN) enumerated as “sensitive data.” Breach notification: 30 days to TX AG + affected residents (TDPSA §541.151). Civil penalty: $7,500/violation. Source: Texas Business & Commerce Code §541.
PCAOB Auditing Standards (AS 1000 / QC 1000 / AS 1215)
Firms with PCAOB audit clients inherit flow-down obligations. AS 1215 requires audit documentation integrity; QC 1000 requires firm-level quality control including “cybersecurity risks to audit work.” PCAOB inspectors ask “how is your firm’s audit data protected?” Source: PCAOB AS 1000, QC 1000, AS 1215.
Real Incidents

Four TX Accounting-Firm-Sector Breaches. What's in the Record.

These are not hypotheticals. Each is documented — TX AG breach notifications, OCR enforcement, or confirmed press coverage. They form the threat landscape underwriters, peer firms, and clients are already measuring your practice against.

Landmark Admin (Texas TPA)
Ransomware · 2024
800,000+ claimant records exfiltrated from a Texas-based third-party administrator handling claims, payroll, and HR data for carriers and CPA-affiliated clients. Ransomware encrypted servers; exfiltrated before encrypt. CPA firms with TPA clients were downstream-notified. Source: TX AG breach notification portal; Landmark Admin regulatory filings.
Whitley Penn (Texas CPA)
Ransomware · October 2023
Top-20 Texas CPA firm confirmed ransomware. Operations, file shares, and tax-prep environment encrypted. Forensic investigation and incident response coordinated with IRS Office of Safeguards. Confirmed in TX AG breach notification following disclosure. Source: Whitley Penn official statement; TX AG breach notification.
Lane Gorman Trubitt (Dallas TX)
Ransomware · January 2024
Dallas-based 80+ year CPA firm confirmed ransomware. Practice management, tax-prep, and document management systems affected. Client return data exfiltrated before encryption. State notification followed. Source: TX AG breach notification.
BST & Co. (CPAs touching PHI)
OCR Settlement
Illustrative of OCR exposure for CPA firms whose audit or assurance clients handle PHI. $28K HHS OCR settlement for inadequate safeguards — a CPA-touching-PHI pathway. Forensics and breach counsel invitations increase. Source: HHS OCR enforcement actions (2023–2024).
CoreRecon Delivers

Everything a CPA-Firm SOC Actually Needs. Nothing It Doesn't.

CPA firms are not generic enterprises. PTIN credentials, EFIN-controlled e-file auth, audit workpapers, ACH batch workflows, and TDPSA-sensitive taxpayer data require a security architecture built for accounting workflows — not retrofitted from a healthcare template.

🕐
24/7 TX-Resident SOC
24/7/365 security operations center staffed by TX-based analysts. Not an overseas NOC or a cloud SOC that reads your alert for the first time at 3 AM. A CPA at 11 PM on April 14 gets a live Texas analyst, not a ticketed alert.
30-Minute IR SLA
Contractual 30-min SLA — not “we’ll get to it.” Detection-to-containment within 30 minutes of confirmed breach, vs. industry 1–4 hour average. Documented in your MSA. Cyber insurers and breach counsel both ask for it.
🖥️
EDR on QuickBooks / UltraTax / Drake
Next-gen EDR on the workstations that run tax-prep software. Behavioral analytics catches lateral movement before preparer credentials are harvested. EFIN/PTC token hardening on the IRS e-file submission path.
🏦
Wire-Fraud / ACH Workflow Monitoring
Outbound ACH batch monitoring, vendor-master change detection, dual-control callback enforcement. Not standard MFA — actual wire-fraud kill chain detection on QuickBooks Online + bank integration workflows. Avg BEC loss avoided: $300K.
📋
IRS Pub 4557 WISP Authorship
WISP authored and delivered with SOC onboarding, mapped to the 14 IRS Pub 4557 elements. Designated Qualified Individual named in the document. Annual WISP review and refresh built into the retainer cadence.
🤝
Vendor Security Questionnaire Support
Client GRC teams send SIG, SIG-Lite, and bespoke CPA questionnaires. CoreRecon pre-fills them with your actual control status — CPA firms no longer have to chase IT for “what’s our MFA coverage?” answers.
SDVOSB Advantage

SDVOSB Certified. CPA Firms Serving State & Federal Agencies Need It.

If your firm has state agency, federal contractor, or public-sector audit clients, you're subject to vendor security and SDVOSB preference requirements. CoreRecon's SDVOSB certification is a contracting mechanism that lets CPA firms with government-facing engagements meet vendor onboarding faster.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's Center for Verification and Evaluation (CVE). USMC veteran-led team. CPA firms serving Texas DIR, state agencies, or federal primes can source cybersecurity from an SDVOSB on day one — no re-bid cycle required.
TX DIR Cooperative Procurement
Texas CPA firms serving state agencies are subject to DIR vendor security review. CoreRecon's SDVOSB status + CVE-verified certification streams vendor onboarding. We produce the documentation DIR requires without re-bid cycles.
IRS Pub 4557 Contractual Remediation
WISP binder delivered with SOC onboarding. Authored by our team against the 14-element Pub 4557 checklist. Designated Qualified Individual named. Annual review cycle included. Cyber insurance carriers accept the binder as evidence of “documented controls.”
Merger / Successor-Firm Due Diligence
Firm-to-firm mergers carry cyber due diligence — successor counsel and acquiring firms require WISP, IR plan, vendor security evidence. CoreRecon produces the documentation package a successor firm's GRC accepts — weeks of friction avoided in M&A timelines.
Transparent Pricing — No "Contact Sales"

Published Rates. Month-to-Month. No 3-Year Lock-In.

CoreRecon publishes pricing because CPA firms shouldn't need to spend 90 minutes on a sales call to learn whether a cybersecurity provider is in-bounds. Three tiers. Per-endpoint. All include 24/7 SOC coverage and 30-minute IR SLA.

Sentinel
$89/endpoint/mo
min. 10 endpoints
  • 24/7 SOC monitoring — TX-resident analysts
  • Endpoint detection & response (EDR)
  • Email threat analysis + BEC monitoring
  • Monthly vulnerability summary report
  • IRS Pub 4557 / FTC Safeguards mapped
Command
$2,500+/mo
flat-fee retainer
  • Everything in Fortress, plus:
  • Dedicated vCISO (contracted as security officer)
  • On-site incident response capability
  • Full WISP library + designated Qualified Individual
  • FTC §314 compliance documentation package
  • Direct line to 24/7 IR team — no queue
30-minute IR SLA is contractual across all tiers — documented in your Master Service Agreement. Industry average response time: 1–4 hours (SANS 2024 IR Survey). We measure against that standard every month and report it to you.
SLA Proof

30 Minutes vs. Industry Standard: The Gap Is the Risk.

The 30-minute SLA isn't marketing — it's the difference between containment and dwell time. Ransomware operators complete the full attack chain (initial access → lateral movement → credential harvesting → encryption) in 45–90 minutes on average. Most MSSPs detect and respond within 1–4 hours. The window between what they offer and what ransomware actually does is where CPA firms lose everything.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to you in your service review.
Median Dwell Time: 207 Days
IBM X-Force Threat Intelligence Index 2024: median dwell time before breach notice at accounting & financial-services firms is 207 days. The EDR component of our Stack measures detection-to-containment — not dwell. 30-min means we kill the chain in the active phase, not seven months later.
Industry Average: 1–4 Hours
SANS 2024 IR Survey: median time from detection to containment is 1–4 hours for MSSP-monitored environments. By that time, ransomware has usually completed lateral movement, credential dumping, and encryption across multiple systems. Containment is still necessary — but the damage is already done.
Ransomware Kill Chain: 45–90 Min
CrowdStrike 2024 Global Threat Report: average time from initial access to encryption is 45–90 minutes for human-operated ransomware. The window is tight. A 30-min SLA puts us inside the kill chain. Anything slower means we're responding to a fully-executing attack, not containing one.
Compliance Mapping

Framework-to-Control Crosswalk for Texas CPA Firms

CoreRecon maps every SOC function to the specific regulation or framework that requires it. When your cyber insurance carrier, IRS Office of Safeguards, FTC examiner, or PCAOB inspector asks “what does your security program actually cover?”, this is the answer.

Requirement IRS Pub 4557 FTC Safeguards §314 CoreRecon Control
Written Information Security Program (WISP) Required — ~14 mandatory elements Required for ≥5,000 consumer records WISP authorship + 14-element checklist deliverable
Designated Qualified Individual Named in WISP; oversees compliance Reports to board/management vCISO retainer (Fortress/Command); named in WISP
MFA on all access Required for remote access to taxpayer data Explicitly required (effective May 2024) EDR + conditional access; MFA enforcement report
Encryption at rest & in transit HTTPS for e-file; encryption for stored returns Encryption to render data unreadable BitLocker / FileVault enforcement; TLS 1.2+ audit
Dual-control wire/ACH authorization Segregation-of-duties controls Access controls on financial systems Outbound ACH monitoring + callback workflow
30-day breach reporting (FTC) Documented incident response plan 30 days from discovery for ≥500 consumers IR coordination w/ breach counsel; FTC §314 workflow
60-day breach reporting (TDPSA) Incident documentation Aligns with state breach laws TX AG notification workflow; template + timeline
Annual WISP review Annual review required Continuous monitoring; annual report to board Annual WISP refresh + vCISO annual review meeting
Vendor risk assessment Due diligence on third-party service providers Periodic vendor assessment Vendor security questionnaire pre-fill support
Employee security training Annual awareness training required Information security training program Phishing simulation + annual WISP training event
How We Compare

Built for CPA Firms. Not a Generic Enterprise Package.

Huntress, Arctic Wolf, and Critical Start are real products with real strengths — Huntress has excellent SMB-focused EDR, Arctic Wolf has strong compliance reporting, and Critical Start has mature MDR platform tooling. CoreRecon is built for accounting-firm workflows from day one, with TX-resident analysts, IRS WISP authorship, and SDVOSB contracting at a published price.

Capability CoreRecon Huntress Arctic Wolf Critical Start
Pricing transparency Published: $89–$129/ep Annual contract (sales-led) Annual contract (sales-led)
TX-resident analyst Yes, USMC veteran-led SOC Distributed US-based Centralized SOC (US + offshore) Centralized SOC (US)
IRS Pub 4557 WISP authorship Yes — authored w/ SOC onboarding Not offered as standard Add-on via partner network Available as service project
SDVOSB-certified Yes — CVE-verified No No No
30-min contractual IR SLA Yes — guaranteed in MSA Best-effort 1–4 hour response 1-hour median (per CS marketing)
Pricing under $100/endpoint $89 Sentinel; min 10 endpoints ~$110+/endpoint (per public docs) Custom pricing (~$200+/yr pricing) Custom pricing (typically 4-figure floors)
EDR quality Next-gen EDR + behavioral analytics Strongest in class — Huntress EDR well-regarded Aurora EDR (acquired) Critical Start MDR platform (mature)
Compliance reporting HIPAA/TDPSA/IRS mapped; SOC 2 ready Limited reporting Strongest in class — compliance reporting mature Solid compliance dashboard
Month-to-month Yes — Sentinel & Fortress Yes Annual contract Annual contract

Where we lose. Huntress is best-in-class at SMB EDR detection fundamentals; if your firm prioritizes EDR signal alone over 24/7 SOC + WISP authoring, Huntress is a credible choice. Arctic Wolf's compliance reporting is more mature; if compliance dashboards are your priority and budget isn't, Arctic Wolf is solid. Critical Start's platform is highly tuned; if you've standardized on a specific MDR tech stack, they fit.

Where we win. Published CPA-firm pricing. IRS WISP authorship. TX-resident analysts on CPAs and PTIN workflows. SDVOSB contracting for government-facing engagements. 30-min contractual SLA in your MSA at $89–$129/endpoint.

See full competitor comparison →
Free Assessment — $2,500 Value

Find Out Where Your CPA Firm Actually Stands.

CoreRecon's Security Posture Assessment covers endpoint exposure, QuickBooks/UltraTax/Drake attack surface, IRS Pub 4557 WISP gap, FTC Safeguards Readiness Score, and ACH batch workflow weaknesses. It's free. Takes 20 minutes to complete. Written report with prioritized findings — not a sales deck.

What the Assessment Covers
Endpoint coverage audit — which workstations and servers are actually monitored.
QuickBooks / UltraTax / Drake attack surface — credential and lateral-movement exposure.
IRS Pub 4557 WISP gap — 14-element checklist scored against your program.
FTC Safeguards §314 readiness — Qualified Individual, MFA, encryption.
ACH batch workflow weaknesses — wire-fraud kill chain on QuickBooks + bank integrations.
What You Get
Written security posture report — prioritized findings, not a risk matrix.
30-min debrief call with a TX-based analyst (not a sales rep).
Remediation roadmap — what to fix first, what can wait.
No obligation — if you're not a fit, we'll tell you.
Start Your Free Security Posture Assessment →
Client Voices

What Texas CPA Firm Leaders Are Saying.

Social proof — quotes from TX managing partners and firm administrators who have onboarded with CoreRecon. PLACEHOLDER block (John to fill). Three to five short testimonials, each tied to a different outcome: IRS Pub 4557 audit response, ACH wire-fraud avoided, audit-client evidence delivery.

PLACEHOLDER — Quote 1
“PLACEHOLDER — quote from a TX managing partner about how CoreRecon's WISP authorship satisfied an IRS 4557 inquiry. Name + firm + city, attribution approved.”
PLACEHOLDER — Quote 2
“PLACEHOLDER — quote from a TX firm administrator about ACH batch monitoring catching a vendor master change before an outbound wire. Name + firm + city.”
PLACEHOLDER — Quote 3
“PLACEHOLDER — quote from a TX audit practice leader about evidence delivery for a PCAOB audit-client who required WISP + IR documentation. Name + firm + city.”
Research Brief — July 2026

Download the TX Accounting Firms Threat Brief.

8 documented incidents. Landmark Admin (TPA, 800K records). Whitley Penn. Lane Gorman Trubitt. BST & Co. (OCR exposure). TX regulatory stack mapped (IRS Pub 4557, FTC Safeguards §314, TDPSA §541, PCAOB AS 1000/QC 1000/AS 1215). 62 verified sources. Print-ready PDF.

What's in the Brief
Named incidents: Landmark Admin TX TPA (800K), Whitley Penn (Oct 2023), Lane Gorman Trubitt (Jan 2024), and 4 additional Texas accounting-adjacent breach anchors with confirmed dates and vectors.

TX regulatory stack: IRS Pub 4557 14-element WISP checklist, FTC §314 Qualified Individual + MFA + 30-day reporting, TDPSA §541 sensitive-data enumeration, PCAOB AS 1000/QC 1000/AS 1215 flow-down for audit clients.
How to Get It
Gate: Name + firm email + phone. Takes 30 seconds.

Delivery: Instant access to the PDF. Confirmation email with link. No drip sequence.

Source tag: v43_accounting_firms_brief

62 sources including IRS Pub 4557 (Rev. 11-2021), 16 CFR §314 (FTC Safeguards), TDPSA §541, PCAOB AS 1000/QC 1000, FBI IC3 2024 BEC Annual Report, TX AG breach notification portal, and IBM X-Force 2024.
Get the V43 PDF — Free.
Work email required. We deliver the PDF straight to your inbox. No drip sequence.
FAQ

Questions Texas CPA Firms Ask Before Signing.

Direct answers. Not legal or tax advice. Not a substitute for your breach counsel — but enough to know whether we're a fit.

Yes. EDR is deployed on the workstations that run each of those products. We monitor the specific behaviors that map to credential theft and lateral movement from a compromised preparer machine. EFIN/PTC token handling and IRS e-file submission paths are covered. If your firm uses a stack we don't yet model (rare), we'll add it during onboarding — included.
WISP authorship is included as part of Fortress and Command tier — not a separate billable project. We deliver a WISP binder against the 14-element IRS Pub 4557 checklist, with a Designated Qualified Individual named in the document, plus integration with your existing cyber insurance questionnaire. Annual WISP review is included in the tier cadence. If your firm already has a WISP and only needs gap assessment, we do that too — same engagement scope.
Our 24/7 IR team activates the moment you forward the inquiry. If it's a 4557 inquiry, we coordinate with your breach counsel to deliver the WISP binder, your control evidence, and the 14-element checklist mapping. If it's a state accountancy board request (TX State Board of Public Accountancy), we deliver the same package scoped to the board's documentation expectations. The 30-min SLA applies from your notification — not from when we detect the inquiry ourselves.
Each entity's workstation/server footprint is counted separately under the per-endpoint pricing model. We aggregate endpoints into a single engagement so the SOC sees the entire firm. Audit practice and tax practice can use different virtualization profiles; the SOC handles both. If your firm structures endpoints across the cloud (QuickBooks Online Multi-Entity, CCH Axcess), we roll them into one SOC engagement.
IRS Publication 4557 §4.3 outlines the breach notification expectation. Our IR team coordinates with your breach counsel to deliver the forensic documentation, the scope-of-affected-records analysis, and the timeline narrative. The 30-min contractual SLA ensures rapid detection-to-containment — diminishing the size of the breach scope that you ultimately have to report.
Yes. Our TX-resident SOC operates 24/7/365 — analysts are familiar with multi-office CPA firm topologies (Austin HQ + DFW satellite + Houston audit practice, etc.). The SOC sees traffic and authentication events across all sites; an analyst at 2 AM on a Sunday is reading your environment, not a regional sample. We don't use offshore rotation pools for overnight coverage.
Yes. Our standard agreement is month-to-month for Sentinel and Fortress. Command tier (dedicated vCISO) is a 12-month retainer for continuity of the vCISO relationship. There are no hidden termination fees for early exit on month-to-month tiers. We win on retention results during tax season — not contract lock-in.
📍 Texas-Based SOC
🎖️ SDVOSB-Certified (CVE)
🇺🇸 USMC Veteran-Led Team
🛡️ 24/7 SOC — 30-Min IR SLA
📋 IRS Pub 4557 Mapped
🤝 Month-to-Month

Tax ID. Bank Acct. W-2.
CoreRecon Protects All Three.

Landmark Admin hit 800K records in 2024. The 2025–2026 wave targets CPA firms during the April 15 deadline window — tax-prep credentials, EFIN access tokens, and PTIN-protected e-file auth are all on the table. The only question is whether your firm has a documented WISP with a contractual 30-min IR SLA — or a hope and a default cyber insurance policy.

Start the free assessment. Takes 20 minutes. Written report with prioritized findings. No sales deck.

Start Your Free Security Posture Assessment →