IT Support for Financial Services Firms in Maryland, Northern Virginia, West Virginia, Delaware, Pennsylvania, and the DMV Area
FTC Safeguards Rule compliance, Written Information Security Program support, Microsoft 365 management, encrypted backup, and cyber insurance readiness built around the regulatory obligations financial services firms carry
What Financial Services Firms Are Actually Dealing With
The FTC Safeguards Rule applies to you and most firms aren't fully compliant. The FTC Safeguards Rule under GLBA requires financial institutions, which includes CPAs, tax preparers, financial advisors, mortgage brokers, and most financial services firms, to implement a Written Information Security Program and a specific set of technical controls. The rule was updated in 2023 with requirements that many small firms still haven't addressed: mandatory MFA, mandatory encryption of customer data at rest and in transit, a designated qualified individual responsible for the program, and an annual report to the board or governing body. Not having a WISP isn't a gap in documentation. It's a violation.
Tax season is the highest-risk period of the year. Phishing attacks targeting accounting firms spike dramatically between January and April. Attackers know that staff is busy, email volume is high, and people are more likely to click on something that looks like a client document or a filing notification.
Client portal and file sharing security is often overlooked. Most firms have moved to client portals for document exchange. The portal itself may be secure. But how staff accesses it, where they download files to, and whether those files are encrypted at rest on the devices they land on are questions most firms haven't answered.
Remote work created access patterns nobody reviewed. Staff working from home, accessing client files from personal laptops, using personal WiFi networks, connecting to firm systems without a VPN. These patterns became normal during the pandemic and most firms never went back to review whether they created problems worth fixing.
Cyber insurance applications require controls most small firms don't have. CPAs and financial advisors are flagged as high-risk by carriers. Applications ask specifically about MFA, encryption, backup, endpoint protection, and written security policies. Firms that can't demonstrate those controls are seeing coverage reductions or outright denials at renewal.

What SNL-Tech Services Handles for Financial Services Firms
FTC Safeguards Rule Compliance & WISP Support
MFA on every system containing customer information. Encryption of customer data at rest and in transit. A designated qualified individual responsible for the security program. A Written Information Security Program that documents how you protect nonpublic personal information. An annual report to the board or governing body. These aren't recommendations. They're required by the FTC Safeguards Rule. I handle the technical implementation. Your compliance attorney or CPA association handles the policy language on top of that.
Encrypted Client Communication & File Sharing
Client portals for secure document delivery instead of emailing unencrypted files. When staff downloads files to work on them, those files are encrypted on disk. Remote access configured so accountants and advisors can work from anywhere without creating security gaps. The FTC Safeguards Rule requires encryption of customer data in transit. Unencrypted email doesn't satisfy that requirement. Secure portals and encrypted file sharing do.
Multi-Factor Authentication & Email Security
Email security with anti-phishing policies and external email banners so staff knows when an email came from outside the firm. MFA required for any staff member accessing customer information. SPF, DKIM, and DMARC configured to prevent your domain from being spoofed. These are the controls that stop the majority of successful attacks on small CPA and financial advisory firms, especially during tax season when phishing attacks spike.
Endpoint Protection & Device Encryption
EDR running on every workstation in the office. BitLocker encryption on every laptop so if a device walks out the door with customer data on it, that data is protected. Automatic patching so vulnerabilities get fixed before they can be exploited. A lost or stolen unencrypted laptop with customer tax returns or financial information on it is a breach you have to report. Encrypted devices eliminate that exposure.
Microsoft 365 Setup & Management
Email, file storage, and collaboration configured to FTC Safeguards standards. MFA enforced on every account. Conditional Access policies that block access from unmanaged or noncompliant devices. Encryption of files at rest in OneDrive and SharePoint. Audit logging enabled. External sharing controls locked down so customer files don't end up where they shouldn't. Your whole team stays connected while customer data stays protected.
Advanced Backup & Disaster Recovery Solutions
Customer data and firm files backed up daily to a managed device with an offsite cloud copy. Retention of 60 to 90 days, versioned. Restore tests documented so when something goes wrong, you know exactly how long recovery will take and what you're recovering to. If ransomware hits during tax season or a server fails in the middle of filing season, you recover from a clean backup without paying a ransom or losing customer records.
AI Governance for Financial Services Firms: A Safeguards Violation Hiding in Your Office
Staff at CPA firms, financial advisory practices, and tax preparation businesses are using AI tools. ChatGPT to draft client letters. Copilot to summarize financial statements. AI tools to research tax strategies using real client scenarios. Claude to work through complex financial situations or draft advice. Most of it happens on personal accounts with no policy, no oversight, and no documentation.
Under the FTC Safeguards Rule, this is not a gray area. Customer nonpublic personal information entered into an unapproved AI tool has left your controlled environment without authorization. That's a Safeguards violation. Your WISP is supposed to govern how NPI is handled, where it goes, and who has access to it. Personal AI accounts aren't in the WISP because nobody approved them.
The specific risk for financial services firms is acute. A staff member using ChatGPT to draft a response to a client's tax question or financial planning scenario has just uploaded actual customer financial data to OpenAI's servers. That data is no longer under your control. OpenAI's privacy policy says they may use data for model training and improvement. Your client's confidential financial information is now in a third-party system you didn't authorize and can't manage.
IBM's 2025 Cost of a Data Breach report found that shadow AI added $670,000 to average breach costs. Carriers are adding AI-specific exclusions to financial services cyber policies. An incident involving an AI tool that wasn't documented in your security program gives the carrier grounds to deny the claim.
There's also the discovery angle. If a client dispute, an FTC inquiry, or any litigation is filed, AI chat history is discoverable. If a staff member used their personal ChatGPT to work through a client's tax situation or draft financial advice, those records can be subpoenaed. Personal accounts have no retention policy and no corporate IT controls. The firm has no ability to manage or produce those records. Worse, you may not even know those records exist.
SNL-Tech Services has built a structured AI Governance Kit with a specific addendum for financial services firms and FTC Safeguards compliance. It includes shadow AI discovery to find what tools are already in use, risk classification, an Acceptable Use Policy that maps to your Safeguards obligations, a workflow review that identifies where AI is touching NPI, and a cyber insurance AI risk checklist. The documentation the kit produces becomes part of your WISP and supports your compliance posture.
The entry point is a standalone AI Governance Assessment at $1,700. For firms ready to implement the full framework, SNL-Tech Services delivers the complete kit as part of that engagement.
If your firm is using AI tools without a governance framework, the question isn't whether there's a risk. It's whether you know about it before something goes wrong, and whether your cyber insurance will cover it when it does.
Frequently Asked Questions for Financial Services Firms
Does the FTC Safeguards Rule actually apply to my CPA firm or is that just for banks?
It applies to your firm. The FTC Safeguards Rule under GLBA covers any financial institution significantly engaged in financial activities, and the FTC's interpretation includes CPAs, tax preparers, and financial advisors who handle nonpublic personal information. If you prepare tax returns or provide financial planning advice and handle customer data, the rule applies.
We're a two-person practice. Does the rule still apply?
Yes. The FTC Safeguards Rule does not have a small business exemption. Firms with fewer than five thousand customers have a slightly modified set of requirements, but the core requirements including a WISP, MFA, encryption, a designated qualified individual, and a risk assessment apply regardless of firm size.
What's a WISP and do we actually need one?
A Written Information Security Program is a documented policy that describes how your firm protects customer nonpublic personal information. Not having one isn't a gap in documentation. Under the FTC Safeguards Rule, it's a violation. I handle the technical foundation the WISP documents: MFA, encryption, access controls, audit logging, patch management, and endpoint protection. Your compliance attorney or CPA association can help with the policy language on top of that.
What's the biggest risk during tax season?
Phishing. Attacks on accounting firms spike significantly between January and April because attackers know staff is busy and email volume is high. The most impactful thing you can do before tax season is enforce MFA on every email account and configure anti-phishing protection on your email platform. Those two things stop the majority of successful attacks on small CPA firms.
We use tax software that our clients don't access. Does that still need to be secured?
Yes. Any system that stores or processes customer nonpublic personal information needs to meet the Safeguards requirements, including tax software. That means MFA for access, encryption of stored data, access controls that limit who can see which client files, and audit logging.
We send client documents by email. Is that a problem?
Potentially. Unencrypted email is not a secure way to transmit client tax returns or financial documents. The FTC Safeguards Rule requires encryption of customer information in transit. Most firms have moved to client portals for document delivery, which is the right approach. If you're still emailing documents directly, that's worth addressing.
Can you help us prepare for our cyber insurance renewal?
Yes. I offer a standalone Cyber Insurance Readiness Assessment at $1,750 that reviews your full environment against what carriers require, assembles an evidence package, and walks through your renewal questionnaire with you. Financial services firms have some of the toughest renewal conversations in the small business market right now.
What happens if the FTC investigates our firm?
The FTC's enforcement actions against small firms typically result from a reported incident or a consumer complaint. The firms that handle investigations without significant penalty are the ones that can produce their WISP, their risk assessment, their access control documentation, and evidence that controls were actually in place. The firms that can't produce that documentation face civil monetary penalties. Having your documentation current and your controls implemented is the difference between a manageable investigation and a significant fine.
What's a designated qualified individual and do we need one?
Yes. Under the FTC Safeguards Rule, you need someone designated as responsible for the information security program. For most small firms, this is the managing partner or firm owner, but the designation and their role needs to be documented. They don't need to be technically proficient, but they need to be accountable for the program.
Do we need to report to the board or governing body?
Yes. The FTC Safeguards Rule requires an annual report to the board or governing body documenting the state of the security program. For a small firm, this is a report from whoever manages IT to the partners or owners. Most firms don't know this requirement exists, but it's required under the rule.
We allow staff to work from home and access client files from personal laptops. Is that secure?
Not necessarily. Staff accessing client files from personal laptops on personal WiFi creates exposure the rule requires you to address. I configure remote access with MFA and device compliance requirements so the person's device has to meet security standards before they can reach firm systems. This gives your team flexibility to work remotely without creating security gaps.
When a staff member leaves, how do we make sure their access is actually revoked?
I put a documented offboarding process in place so it happens consistently and immediately. When someone leaves or changes roles, their access to tax software, client portals, email, file storage, and remote access goes with them the same day. This prevents former staff from retaining access to active client files.
What happens if we get breached or compromised?
Call me directly. I work with managed clients through incidents: containment, evidence preservation, notification of affected parties, and FTC notification if the breach affects 500 or more consumers. Having a written incident response plan in place beforehand is the difference between a manageable incident and a crisis that derails your business during busy season.
What about AI tools that staff are using?
Your staff is using AI tools. ChatGPT, Claude, Copilot, Gemini. Most of it is happening on personal accounts with no oversight or policy. When a staff member pastes a client's tax return into ChatGPT to draft a response, that customer data has left your firm with no confidentiality agreement. Under the FTC Safeguards Rule, that's a violation. I help firms find out what tools are in use, put an Acceptable Use Policy in place, and build the documentation that supports your compliance posture and protects your cyber insurance coverage.
What does managed IT actually cost for our firm?
Managed IT pricing is based on the number of users and devices your firm has. Most small CPA and financial advisory practices fall within the Essential or Professional plan. A 3-person firm with 5 to 6 devices typically runs $1,597 to $2,097 per month. That's your insurance against phishing losses, ransomware, breached client data, and regulatory penalties. If you want to understand your costs before committing, I offer a flat-rate IT Baseline Assessment for $2,500 that documents your environment and what you're currently spending on IT.
Do you monitor our systems?
Managed clients have real-time protection and alerts on their systems. I monitor your servers, workstations, backup status, security alerts, and network activity. If something looks wrong, I get an alert and I respond. That proactive monitoring is the difference between preventing an incident and responding to one after it happens.
We're not sure if we're actually compliant with the Safeguards Rule. What do we do?
I offer an IT Baseline Assessment and Documentation for $2,500 that documents your current environment, identifies where customer data lives, reviews your access controls, and assesses your current security posture. This becomes the foundation for your risk assessment and your WISP. It gives you a clear picture of where you stand and what needs attention.
Is the FTC actually enforcing the Safeguards Rule against small firms?
Yes. The FTC closed 21 enforcement actions in 2025 collecting over $8.3 million in penalties. Small firms are not excluded from enforcement. The gaps the FTC cites most often in small practice investigations are no completed risk analysis, no MFA, no WISP, and no documented controls. Having your documentation current and your controls implemented is not optional.
We're thinking about switching tax software. Can you help with the transition?
Yes. Data migration, server requirements, network changes, and getting the new system connected properly while maintaining security are all things I can support. Software transitions are one of the highest-risk periods for data loss in a financial services firm. Having IT support through the transition means problems get caught before they become permanent.
How do I know if my cyber insurance will actually cover a breach?
That depends on whether your controls match what you told the carrier when you applied. If your application said you have MFA on every account and you don't, or it said you have a WISP and you don't, the carrier may deny a claim. I help firms document what controls are actually in place so when you renew, you're answering accurately and your coverage reflects your actual environment.

