Blog / The data you hold
The data you hold
Client Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding
Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.
The closing binders in the scanned folder
A paralegal at a 40-person law firm has scanned every real-estate closing binder for eight years. It is good practice: the paper goes to storage and the PDF stays searchable. Each binder holds the client's bank statements, the lender's payoff letter, a copy of the driver's licence, the wire instructions and, for the older ones, a Social Security number on the settlement statement.
The scans live in a folder on the document management system called "Closings, all years." Permissions were set when the firm had twelve people. Every user has read access, because in 2018 that was easier than asking who needed it. The firm now has 40 people, including four summer associates, two contract attorneys and an IT vendor with an admin account.
On a Tuesday in July, one of the summer associates, working from a coffee shop, opens a phishing email that looks like a court e-filing notice. Her password goes to someone in another time zone. For nine days that someone reads the document management system as her. The firm's audit logs, which default to 30 days and which nobody reviews, show 2,140 documents opened from an IP address in a country the firm has no clients in.
The managing partner learns the scale on day ten. He now has to work out which of 900 closings are affected, whose bank statements were among them, and which state and federal clocks started nine days ago without anyone hearing them.
What the heck does this mean
Client financial data is any record that ties an identifiable person to their money: statements, tax returns, loan files, brokerage records, wire instructions, payroll details. Law firms, CPAs and advisors hold more of it per employee than most banks.
Nonpublic personal information, NPI, is the regulators' term for that data when a financial institution holds it. Under the FTC's Safeguards Rule, a tax preparer or a firm giving financial advice is a financial institution, whether or not it has ever thought of itself that way.
A WISP, written information security program, is the document that says what you hold, who protects it and how. The FTC expects one. The IRS requires one of every tax professional.
Least privilege is the principle that a person can open only what their job requires. "Everyone can read Closings, all years" is its opposite.
Business email compromise, BEC, is the attacker using a stolen or spoofed mailbox to redirect money. In a law firm the target is the wire instructions in the closing folder, and the settlement funds that follow them.
The numbers that matter
The FTC Safeguards Rule requires notice to the FTC within 30 days of a breach affecting 500 or more consumers (FTC, effective May 2024). Nine hundred closings clears that threshold on the first afternoon.
Smaller SEC-registered advisers had to comply with the amended Regulation S-P by 3 June 2026, including 30-day notification to affected customers (SEC, 2024 amendments). The wealth advisor down the hall is on the same clock as the law firm, from a different regulator.
Business email compromise cost USD 3.05 billion across 24,768 complaints (FBI IC3 2025 Annual Report). Every one of those complaints started with someone reading email that was not theirs, which is exactly what the summer associate's stolen password allowed.
What to do this week
- Open the permissions on your three biggest client folders and count how many people can read them. Cut the list to the people working those matters. Do closings, tax returns and client statements first. (CIS 6 Access Control Management)
- Turn on MFA for the document management system, email and the remote-access tool, including for contract staff and the IT vendor. A stolen password without a second factor is a key; with one, it is a key to a locked door. (CIS 6 Access Control Management)
- Extend your audit log retention to at least a year and assign one person to review the "documents opened" report every Monday for the unusual: volume, hour, location. The nine days in the story would have been one. (CIS 8 Audit Log Management)
- Find the financial data outside the system: the paralegal's scan folder on her desktop, the shared inbox of wire instructions, the spreadsheet of client account numbers in the finance department. Move it in or delete it. (CIS 3 Data Protection)
- Write, or rewrite, the WISP with real names: who owns it, which systems hold client data, which vendors have access, and the phone number of the lawyer you will call on day one of a breach. Date it and put a calendar reminder to review it in twelve months. (CIS 3 Data Protection)
- Add a callback rule for wire instructions: any change is confirmed by phone to a number on file, never to a number in the email. Put it in the engagement letter so clients expect it. (CIS 3 Data Protection)
Where AccuSights fits
Our assessment finds the client financial data your firm holds, shows who can reach it, checks whether the logs would answer "what did they open" and maps the result to the Safeguards Rule, Reg S-P or your bar's guidance. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer turns the permissions problem into a short, costed list.
We map the assessment to the PDPL and, for DIFC and ADGM firms, the free-zone data rules, and our read-only compliance agent shows where client data sits and which controls have drifted, so you prioritize the right things and keep an eye on them. Like a falcon, it picks out the one thing worth acting on. We have no access and do not remediate; you or your IT partner fix, and we show you where.
Questions people ask
Is a CPA firm a financial institution under the Safeguards Rule? If the firm prepares tax returns or provides financial advice for individuals, yes. The FTC's definition turns on the activity, not the licence, and tax preparation is named in it. That makes the firm responsible for a written information security program, a designated person who owns it, and a 30-day notice to the FTC after a breach affecting 500 or more people. The IRS reinforces this by requiring every tax professional to keep a written plan regardless of size.
What is a WISP? A written information security program: a document that says what client data you hold, who is responsible for protecting it, which safeguards you use and what you do when something goes wrong. The FTC requires one under the Safeguards Rule and the IRS requires one of every tax preparer. A template is a starting point, not a finished WISP; the version that counts names your systems, your people and the date you last tested the backup.
Do law firms have to report breaches? In most US states, yes, under the state breach-notification law that applies to the affected clients, and the professional-conduct rules add a duty to tell clients whose matters were affected. Firms that hold tax or financial data for individuals may also fall under the FTC Safeguards Rule's 30-day notice. In the UAE, the federal PDPL and the DIFC and ADGM regimes each set their own notification clock. The practical answer is to know which clocks apply before the day you need them.
Your clients handed you their bank statements because they trusted you more than the bank. The folder permissions should say the same thing.
Questions people ask
Is a CPA firm a financial institution under the Safeguards Rule?
If the firm prepares tax returns or provides financial advice for individuals, yes. The FTC's definition turns on the activity, not the licence, and tax preparation is named in it. That makes the firm responsible for a written information security program, a designated person who owns it, and a 30-day notice to the FTC after a breach affecting 500 or more people. The IRS reinforces this by requiring every tax professional to keep a written plan regardless of size.
What is a WISP?
A written information security program: a document that says what client data you hold, who is responsible for protecting it, which safeguards you use and what you do when something goes wrong. The FTC requires one under the Safeguards Rule and the IRS requires one of every tax preparer. A template is a starting point, not a finished WISP; the version that counts names your systems, your people and the date you last tested the backup.
Do law firms have to report breaches?
In most US states, yes, under the state breach-notification law that applies to the affected clients, and the professional-conduct rules add a duty to tell clients whose matters were affected. Firms that hold tax or financial data for individuals may also fall under the FTC Safeguards Rule's 30-day notice. In the UAE, the federal PDPL and the DIFC and ADGM regimes each set their own notification clock. The practical answer is to know which clocks apply before the day you need them.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
PII You Did Not Know You Were Holding: Employee Files, Web Forms and the CRM Export
PII hides in employee files, web forms and CRM exports. What counts as personally identifiable information, which laws reach a small business, what to delete.
Practical controlsAudit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door
Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.
UAE complianceDIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company
DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.
