We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / The data you hold

The data you hold

Client Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding

Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The closing binders in the scanned folder

A paralegal at a 40-person law firm has scanned every real-estate closing binder for eight years. It is good practice: the paper goes to storage and the PDF stays searchable. Each binder holds the client's bank statements, the lender's payoff letter, a copy of the driver's licence, the wire instructions and, for the older ones, a Social Security number on the settlement statement.

The scans live in a folder on the document management system called "Closings, all years." Permissions were set when the firm had twelve people. Every user has read access, because in 2018 that was easier than asking who needed it. The firm now has 40 people, including four summer associates, two contract attorneys and an IT vendor with an admin account.

On a Tuesday in July, one of the summer associates, working from a coffee shop, opens a phishing email that looks like a court e-filing notice. Her password goes to someone in another time zone. For nine days that someone reads the document management system as her. The firm's audit logs, which default to 30 days and which nobody reviews, show 2,140 documents opened from an IP address in a country the firm has no clients in.

The managing partner learns the scale on day ten. He now has to work out which of 900 closings are affected, whose bank statements were among them, and which state and federal clocks started nine days ago without anyone hearing them.

What the heck does this mean

Client financial data is any record that ties an identifiable person to their money: statements, tax returns, loan files, brokerage records, wire instructions, payroll details. Law firms, CPAs and advisors hold more of it per employee than most banks.

Nonpublic personal information, NPI, is the regulators' term for that data when a financial institution holds it. Under the FTC's Safeguards Rule, a tax preparer or a firm giving financial advice is a financial institution, whether or not it has ever thought of itself that way.

A WISP, written information security program, is the document that says what you hold, who protects it and how. The FTC expects one. The IRS requires one of every tax professional.

Least privilege is the principle that a person can open only what their job requires. "Everyone can read Closings, all years" is its opposite.

Business email compromise, BEC, is the attacker using a stolen or spoofed mailbox to redirect money. In a law firm the target is the wire instructions in the closing folder, and the settlement funds that follow them.

The numbers that matter

The FTC Safeguards Rule requires notice to the FTC within 30 days of a breach affecting 500 or more consumers (FTC, effective May 2024). Nine hundred closings clears that threshold on the first afternoon.

Smaller SEC-registered advisers had to comply with the amended Regulation S-P by 3 June 2026, including 30-day notification to affected customers (SEC, 2024 amendments). The wealth advisor down the hall is on the same clock as the law firm, from a different regulator.

Business email compromise cost USD 3.05 billion across 24,768 complaints (FBI IC3 2025 Annual Report). Every one of those complaints started with someone reading email that was not theirs, which is exactly what the summer associate's stolen password allowed.

What to do this week

  1. Open the permissions on your three biggest client folders and count how many people can read them. Cut the list to the people working those matters. Do closings, tax returns and client statements first. (CIS 6 Access Control Management)
  2. Turn on MFA for the document management system, email and the remote-access tool, including for contract staff and the IT vendor. A stolen password without a second factor is a key; with one, it is a key to a locked door. (CIS 6 Access Control Management)
  3. Extend your audit log retention to at least a year and assign one person to review the "documents opened" report every Monday for the unusual: volume, hour, location. The nine days in the story would have been one. (CIS 8 Audit Log Management)
  4. Find the financial data outside the system: the paralegal's scan folder on her desktop, the shared inbox of wire instructions, the spreadsheet of client account numbers in the finance department. Move it in or delete it. (CIS 3 Data Protection)
  5. Write, or rewrite, the WISP with real names: who owns it, which systems hold client data, which vendors have access, and the phone number of the lawyer you will call on day one of a breach. Date it and put a calendar reminder to review it in twelve months. (CIS 3 Data Protection)
  6. Add a callback rule for wire instructions: any change is confirmed by phone to a number on file, never to a number in the email. Put it in the engagement letter so clients expect it. (CIS 3 Data Protection)

Where AccuSights fits

Our assessment finds the client financial data your firm holds, shows who can reach it, checks whether the logs would answer "what did they open" and maps the result to the Safeguards Rule, Reg S-P or your bar's guidance. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer turns the permissions problem into a short, costed list.

We map the assessment to the PDPL and, for DIFC and ADGM firms, the free-zone data rules, and our read-only compliance agent shows where client data sits and which controls have drifted, so you prioritize the right things and keep an eye on them. Like a falcon, it picks out the one thing worth acting on. We have no access and do not remediate; you or your IT partner fix, and we show you where.

Questions people ask

Is a CPA firm a financial institution under the Safeguards Rule? If the firm prepares tax returns or provides financial advice for individuals, yes. The FTC's definition turns on the activity, not the licence, and tax preparation is named in it. That makes the firm responsible for a written information security program, a designated person who owns it, and a 30-day notice to the FTC after a breach affecting 500 or more people. The IRS reinforces this by requiring every tax professional to keep a written plan regardless of size.

What is a WISP? A written information security program: a document that says what client data you hold, who is responsible for protecting it, which safeguards you use and what you do when something goes wrong. The FTC requires one under the Safeguards Rule and the IRS requires one of every tax preparer. A template is a starting point, not a finished WISP; the version that counts names your systems, your people and the date you last tested the backup.

Do law firms have to report breaches? In most US states, yes, under the state breach-notification law that applies to the affected clients, and the professional-conduct rules add a duty to tell clients whose matters were affected. Firms that hold tax or financial data for individuals may also fall under the FTC Safeguards Rule's 30-day notice. In the UAE, the federal PDPL and the DIFC and ADGM regimes each set their own notification clock. The practical answer is to know which clocks apply before the day you need them.

Your clients handed you their bank statements because they trusted you more than the bank. The folder permissions should say the same thing.

Questions people ask

Is a CPA firm a financial institution under the Safeguards Rule?

If the firm prepares tax returns or provides financial advice for individuals, yes. The FTC's definition turns on the activity, not the licence, and tax preparation is named in it. That makes the firm responsible for a written information security program, a designated person who owns it, and a 30-day notice to the FTC after a breach affecting 500 or more people. The IRS reinforces this by requiring every tax professional to keep a written plan regardless of size.

What is a WISP?

A written information security program: a document that says what client data you hold, who is responsible for protecting it, which safeguards you use and what you do when something goes wrong. The FTC requires one under the Safeguards Rule and the IRS requires one of every tax preparer. A template is a starting point, not a finished WISP; the version that counts names your systems, your people and the date you last tested the backup.

Do law firms have to report breaches?

In most US states, yes, under the state breach-notification law that applies to the affected clients, and the professional-conduct rules add a duty to tell clients whose matters were affected. Firms that hold tax or financial data for individuals may also fall under the FTC Safeguards Rule's 30-day notice. In the UAE, the federal PDPL and the DIFC and ADGM regimes each set their own notification clock. The practical answer is to know which clocks apply before the day you need them.

Controls this post maps to

CIS 3 Data ProtectionCIS 6 Access Control ManagementCIS 8 Audit Log Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.