How To Create a Cyber Incident Response Plan for Your CPA Firm

Published September 2026

CPA firms continue to be targeted for cyberattacks, primarily due to the copious amount of confidential data they receive, use, and store. Although cybersecurity incidents are on the rise across all industry sectors, the finance and accounting industry exhibits significantly higher exposure than most other sectors. For example, the Federal Bureau of Investigation reported that 74% of all reported cyber incidents in 2023 targeted the industry.

For many CPA firms, the issue isn’t wondering if a cyberattack will happen; it’s wondering what they’ll do when it does. Creating a cyber incident response plan can give your firm a framework to respond to cyber threats and attempted data breaches, as well as hone your incident response capabilities. Here, we’ll provide information for firms to consider when building an effective incident response plan to protect both your clients and your firm.

What is a Cyber Incident Response Plan?

A cyber incident response plan is a documented framework that outlines your firm’s approach to incident management in the event of a data breach and cyberattack. The goal of an incident response plan is to minimize the impact of a cybercrime by outlining steps to contain the situation, notify impacted clients, and begin recovery.

Cyber incident response plans were first developed by the National Institute of Standards and Technology as part of its Cybersecurity Framework. The five primary components of the Cybersecurity Framework are:

  • Identify: This stage happens before a cyber incident and forms part of a CPA firm’s proactive risk management protocols. During this stage, your incident response team conducts a thorough risk assessment to uncover gaps in your cybersecurity measures.
  • Protect: This is another proactive stage in which your team outlines and enacts the measures identified to safeguard your data and protected information.
  • Detect: At this stage, your security team has a structure in place to discover breaches and attacks as soon as they happen, in order to swiftly launch an appropriate incident management response.
  • Respond: This is where your firm’s incident response plan goes into effect, coordinating and communicating all the steps you need to take to contain the situation and ensure the resilience of your business.
  • Recover: During this stage, the incident response team works to restore any capabilities that were impacted by the attack to ensure business continuity. This can also be a learning phase that helps build resilience and informs refinements to your cybersecurity risk management protocols.

Common Cyber Threats for CPA Firms

What does a cyber threat against a CPA firm actually look like? Accounting firms are subject to all types of global cyber risks, but some are more common than others due to the nature of the industry. Be on the lookout for these types of cyber incidents:

  • Ransomware: One of the top cyber threats for CPAs, especially during tax time. These scams encrypt your data until you make payments to have it released.
  • Phishing: Phishing schemes are the most common cybercrime across all industries. Typically, they use emails to send malicious links or attachments, which, when opened, install malware or steal credentials.
  • Unauthorized access: This type of data breach happens when someone accesses your clients’ confidential information, typically to sell that data to the highest bidder.
  • Insider threats: This happens when an employee with authorized access mishandles or inappropriately shares sensitive data, whether accidentally or intentionally.
  • Software vulnerabilities: Hackers often exploit vulnerabilities in older, outdated software programs, especially those used in financial management, to access private information.

Steps to Build an Incident Response Plan

You don’t have to wait until you’re facing a crisis to take action. Maintaining cybersecurity is the responsibility of every CPA. There are steps you can start taking right now to outline how you’ll deal with a cyber incident before it becomes necessary.

Step 1: Recruit Your Incident Response Team

Your cybersecurity incident response team will vary based on firm size, service offerings, and industries served. When building your team, remember that it’s important to have cross-department representation. Start with IT security and work out from there. Include representatives from leadership, human resources, and public relations if possible. Your team will likely include external vendors in addition to internal personnel.

The FTC Safeguards Rule requires covered entities to designate a “qualified individual” (QI) on the team to oversee its information security program. Although there are no official degree or title requirements, it helps if a QI has experience in risk assessment and cybersecurity (for example, a Chief Information Security Officer).

Step 2: Identify and Assess Your Data

To protect your clients’ sensitive information, you must first understand what types of data you have, where it’s stored, and who can access it. A data security audit will help you determine those data types and how to protect them, and could include the following steps:

  • Identify every data type your firm maintains. This comprises both client data and firm data. Include all personally identifiable information (SSNs, DoBs, tax details, banking information, etc.) in your inventory.
  • List where every type of data is located. Include data stored both in the cloud and on-premise. Do not forget data stored by third-party vendors who manage other services like CRM or payroll.
  • Assign levels of sensitivity to all data. Organize data from most to least sensitive and make the most sensitive information your top priority.
  • Analyze your employees’ access rights. Understand who has authorized access to sensitive data, and who doesn’t. Consider implementing the Principle of Least Privilege, which states that users should only have the minimum access privilege necessary to perform their job.
  • Document your findings. Build a register that details all of the sensitive data, where it’s located, who can access it, and how long it needs to be stored.

Step 3: Define and Prioritize Types of Incidents

Not every cyber incident requires the same response. Your cyber incident response team can establish a clear classification system to categorize incidents by their level of severity and potential impact. Your classification system may include:

  • Low risk: These incidents could include suspicious emails that are caught by spam filters or failed login attempts from unknown sources.
  • Medium risk: A moderately successful phishing attempt (link was clicked or attachment downloaded, but no data access) may fall into this category. It could also include malware being detected and then quarantined, or unauthorized access to non-critical systems.
  • High risk: These are typically confirmed data breaches that involve non-sensitive information, successful malware infections, or system outages that impact operations.
  • Critical risk: The highest level of incident may involve data breaches that impact SSNs or finance/tax information, or ransomware attacks that encrypt client data. Any incident during peak tax season is likely to be considered critical for CPA firms.

Step 4: Establish Incident Response Procedures

A dedicated incident reporting system helps ensure that potential threats are identified and escalated quickly. Implementing clear procedures makes it easier for any team member to report suspicious activity. Here’s what an incident reporting system could include:

  • A single point of contact within your incident response team.
  • A simple reporting mechanism, whether that’s a dedicated email, ticketing system, or hotline.
  • 24/7 availability for critical-level incidents.
  • Endpoint detection and response software for workstation and server monitoring, along with email security gateways and network intrusion detection systems.
  • Communications outlining the incident response process to all employees and adequate training on its use.
  • Documentation of all aspects. Follow up every incident report with written documentation and attach any relevant information.

Step 5: Develop Containment and Remediation Strategies

Once an incident has been confirmed, swift containment is critical. This can prevent further damage and loss to your firm.

Containment

Containment steps once a cyberattack has been identified could include:

  • Isolate: Disconnect all affected systems from the network to prevent malware spread.
  • Restrict: Immediately disable compromised user accounts and credentials to limit access.
  • Segment: Use existing network divisions to limit lateral movement.
  • Preserve: Maintain all evidence for future investigations or potential legal proceedings.

Remediation and Eradication

Once the breach or threat has been contained, move into remediation and eradication. This may involve the following actions:

  • Identify: Determine the root cause of the breach and how the attacker gained access.
  • Remove: Delete any malicious elements like malware, close backdoors, and patch your vulnerabilities.
  • Reset: Change all passwords and credentials for affected systems and accounts.
  • Update: Install patches that address exploited vulnerabilities.
  • Verify: Confirm that the malicious code and unauthorized access paths have been removed before moving on to restoration.

Recovery

Resilience is key when it comes to managing cyber incidents. To begin the journey toward recovery, consider:

  • Restore: Utilize clean, verified backups to restore all data.
  • Monitor: Closely watch restored systems to spot early signs of re-infection.
  • Upgrade: Implement additional security controls to stave off recurrence.
  • Resume: Slowly return your systems to normal operation after thorough monitoring.

Step 6: Outline Communication Protocols

Effective communication during a cyber incident is essential for managing the response, meeting legal obligations, and maintaining trust. Establish clear chains of communication for both internal and external stakeholders. Understand the laws and regulations in your state regarding data breach notifications so you can stay compliant. This includes the timelines for reporting and contacting clients about the breach, as well as which entities may need to be notified, such as state attorneys general, the FTC, the IRS, or your professional liability insurance carrier.

Post-incident activity should include communications about the resolution to affected parties. Depending on the audience and legal or contractual requirements, you may provide information on how you plan to prevent future incidents, available resources (credit monitoring or identity theft protection), and key security measures you have updated.

Step 7: Conduct a Post-Incident Recovery Debrief

Recovery doesn’t end when systems are restored. A comprehensive post-incident debrief helps your firm learn from each event and strengthen its security against future incidents. Gather the entire team to discuss the lessons learned from the incident, including:

  • How it occurred and whether it was preventable.
  • Whether it was detected in a timely manner.
  • How effectively the response team executed the plan.
  • What additional tools or training could have helped.
  • Whether communication protocols were sufficient.

Make any needed adjustments to your incident response plan at this time.

Step 8: Document the Cyber Incident Response Process

Documentation is the foundation of an effective incident response plan. Without clear, accessible documentation, even the best strategies can fail during a high-pressure incident. Consider implementing these documentation best practices:

  • Store critical documents in multiple secure locations. Keep copies on secure servers, in the cloud, and in hard copy format.
  • Regularly update. Review and revise quarterly, or after any significant changes.
  • Make sure documents are version-controlled. Track changes and maintain previous versions.
  • Ensure everything is role-specific. Provide team members with relevant sections for their responsibilities.
  • Use plain language that all staff members can understand.
  • Use screenshots and visual aids where they can clarify complex steps.
  • Ensure your legal and compliance teams review all documentation for accuracy.

Step 9: Test, Review, and Adapt Your Plan Regularly

Creating an incident response plan is beneficial but regularly testing that plan is even more important. Testing ensures your team can execute the plan effectively when facing a real-time threat. Conduct cyber incident simulations or tabletop exercises to run through the entire incident response plan. Consider testing at regular, scheduled intervals, as well as when your firm goes through major changes, or after an incident has already occurred.

Furthermore, review and update your plan whenever:

  • New threats targeting CPA firms emerge.
  • Your firm implements new technology or unfamiliar cloud services.
  • Relevant laws or regulations change.
  • Staff turnover impacts the composition or capability of your response team.
  • Testing reveals major gaps or weaknesses.
  • Your firm merges with or acquires another firm.
  • Client services expand to include new types of sensitive data.

Common Mistakes CPA Firms Make in Cyber Incident Handling

Even with good intentions, an accounting firm can stumble when developing or executing its cyber incident response plan. Avoiding these common pitfalls can help improve your firm’s security:

  • Making the plan too complicated: Overly complex processes can confuse staff, especially in high-stress situations. Keep it simple and actionable.
  • Overlooking third-party vendor risks: Your tax software vendors, cloud providers, and IT service providers can be entry points for cyberattackers. Include their incident protocols and contact information in your plan.
  • Failing to test the plan: An untested plan may not work when you actually need it. Regular testing reveals gaps before they become failures.
  • Not training staff: The best technical controls can fail if employees click phishing links or mishandle incidents. Ongoing security awareness training is encouraged.
  • Lacking leadership buy-in: Without partner-level support, incident response planning may lack the necessary resources and authority.
  • Assuming it won’t happen to you. Cybercriminals are targeting CPA firms specifically for their access to financial data and tax information. Small firms are often seen as easier targets, and a cyberattack can cause significant financial and operational disruption.
  • Not having cyber liability insurance: Professional liability insurance may not cover all costs associated with a data breach. Depending on the policy, cyber liability insurance can help with expenses such as investigations, notification costs, legal fees, and regulatory fines.

Key Takeaways to Help Protect Your CPA Firm from Cybersecurity Incidents

Cybersecurity threats aren’t going away. If anything, they’re becoming more sophisticated and more frequent. For CPA firms handling sensitive client data, it’s advantageous to be prepared.

Remember these essential takeaways:

  • Preparation is protection: Incident response plans don’t just provide clarity once a breach occurs; preparing the plan helps to proactively identify and address cybersecurity weaknesses.
  • Documentation saves time: When minutes matter, clear protocols prevent costly delays and mistakes.
  • Testing validates effectiveness: Regular drills ensure your team can execute the plan under pressure.
  • Communication is critical: Knowing what to say, when to say it, and to whom can preserve client relationships and help meet legal obligations.
  • Recovery requires planning: Getting back to business quickly depends on strategies developed before an incident occurs.

Looking for more information about cybersecurity, risks, and liability? Download our free ebook, Understanding Cyber Liability: What Every CPA Should Know, today!

Cyber Incident Response Plan FAQs

Still have questions about incident response planning? The following FAQs may help:

How often should a CPA firm update its cyber incident response plan?

The frequency depends on a firm’s size and risk profile, but at a minimum, annual reviews are recommended. In addition, certain events can trigger an immediate review and update, including after a security incident, when you adopt new technology or cloud services, when key personnel change roles or leave, when relevant laws or regulations are updated, or when new or heightened threats emerge.

Do small CPA firms really need a cyber incident response plan?

Yes. A cyber incident response plan is just as critical for small CPA firms as for large firms. Small CPA firms are often targeted specifically because cybercriminals assume they have fewer resources than larger firms. Size doesn’t matter to hackers, but access to confidential data does. Your incident response plan does not have to be elaborate, but it should address detection, containment, notification, and recovery. It’s important to remember that failure to respond appropriately can result in regulatory penalties, reputational harm, and increased professional liability exposure.

How does professional liability insurance relate to incident response planning?

Professional liability insurance typically covers claims arising from professional services, such as tax preparation errors or inaccurate advice. However, it may not fully cover the costs associated with cyber incidents, including investigations, breach notifications, credit monitoring, regulatory fines, or business interruption. Cyber liability insurance is specifically designed to address many of these risks. In addition, many cyber policies offer incident response resources, such as access to forensic experts, legal counsel specializing in data breaches, and public relations professionals.

Original Publish Date: 2026-09-12. Last Modified Date: 2026-09-26.

Share:

Print:

Print Friendly and PDF

How Helpful Was This Article?

 

Related Content

Related Products

The information contained in this article is for general purposes only. This article is not providing any individual business, financial, regulatory, or legal advice. Readers should speak with their legal counsel prior to taking any action. While care has been taken in the production of this article, Aon does not warrant, represent, or guarantee the accuracy, adequacy, completeness, or fitness for any purpose of the article or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Readers shall be responsible for the use to which they put this article. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.
 
Continental Casualty Co., one of the CNA insurance companies, is the underwriter of the AICPA Professional Liability Insurance Program. Aon Insurance Services, the National Program Administrator for the AICPA Professional Liability Program, is available at 800-221-3023 or visit cpai.com.
 
Any references to non-CNA Web sites are provided solely for convenience, and CNA disclaims any responsibility with respect to such websites.

Examples are for illustrative purposes only and not intended to establish any standards of care, serve as legal advice, or acknowledge any given factual situation is covered under any CNA insurance policy. The relevant insurance policy provides actual terms, coverages, amounts, conditions, and exclusions for an insured. All products and services may not be available in all states and may be subject to change without notice.

“CNA” is a registered trademark of CNA Financial Corporation. Certain CNA Financial Corporation subsidiaries use the “CNA” trademark in connection with insurance underwriting and claims activities. Copyright © 2026 CNA. All rights reserved