Cybersecurity, Identity Theft & AI Risks for Tax Professionals
Why this matters right now:
Tax professionals are among the most targeted professionals for cybercrime in the United States. The FTC Safeguards Rule (revised 2023) now explicitly requires all tax preparation firms to maintain a Written Information Security Plan (WISP) — with civil penalties up to $50,120 per violation per day. AI-powered voice cloning and deepfake attacks targeting tax offices increased by over 300% in 2024. This course gives you the knowledge and tools to protect your practice and your clients.
$50,120
FTC civil penalty per violation per day for WISP non-compliance
207
Average days between a breach and its discovery at a tax office
300%
Increase in AI-powered attacks on small professional services firms 2020–2024
19 mo
Average IRS resolution time for tax identity theft cases
What you will master
Core competencies covered in this course
- Implement all six IRS Security Six components and document them in a compliant WISP — the mandatory baseline every tax professional must meet
- Use AI tools in your practice safely — understanding exactly when uploading client data constitutes a federal data protection violation under IRC §7216
- Protect your EFIN and PTIN from hijacking, monitor for unauthorized use, and respond immediately if your credentials are compromised
- Recognize AI-powered phishing, voice cloning, deepfake video calls, and AI-generated IRS correspondence — and apply verification protocols that defeat them
- Respond to a data breach, ransomware attack, or identity theft incident with a precise step-by-step protocol — including mandatory IRS, FTC, and state reporting
Course Structure at a Glance
1 – Foundations: Cybersecurity & Identity Theft

Why it matters · legal obligations · IRS Security Six · data you must protect
4 lessons
Why cybersecurity matters for tax professionals — FTC Safeguards Rule, IRC §7216, OPR consequencesIRS Required
Identity theft: how it targets tax professionals — the five-stage attack chain; EFIN hijacking mechanics
The IRS Security Six — detailed requirements for all six components; self-audit frameworkIRS Required
Data every tax office must protect — four data categories, where data lives, §7216 disclosure rules
2 – Phishing, Social Engineering & AI-Powered Scams

Recognizing and defeating modern attacks — including AI deepfakes and voice cloning
Phishing & spear-phishing against tax professionals — red flags, IRS email policy, verification protocol
AI-powered scams, deepfakes & voice cloning — four attack types; verification protocols that defeat AIAI Risk
IRS Dirty Dozen scams for 2026 — current list, practitioner obligations, §10.34 implicationsIRS Required
Real-world tax office breach examples — four anonymized cases with root cause and prevention analysisCase Studies
3 – Protecting Client Data in the Modern Tax Office

Breach response, IRS reporting, client notification
assword security, MFA & credential management — NIST standards; three MFA types ranked by security
Securing client portals & cloud storage — consumer vs. business-grade; required portal security settings; DPA requirements
Backup, ransomware protection & recovery basics — 3-2-1 rule; why paying ransom may violate OFAC sanctions
IRS WISP requirements & the FTC Safeguards Rule — six required WISP elements; when to update; Publication 4557IRS Required
AI tools in the tax office — safe vs. unsafe use — §7216 analysis framework; enterprise vs. consumer AI; DPA requirements
4 – Incident Response & Reporting

What to do after a breach, ransomware, or identity theft — precise step-by-step protocols
What to do after a data breach: the first 72 hours — IRS e-help Desk reporting; FTC notification; state laws
Reporting identity theft to the IRS — Form 14039; IP PIN program; Taxpayer Advocate Service; §10.21 obligationsIRS Forms
Responding to ransomware & recovering your practice — FBI IC3 reporting; office recovery plan; OFAC sanctions riskCase Study
Client communication after a breach — state notification requirements; §7216 limits; sample notification letter framework
5 – ProtectingPractitioner Best Practices & Compliance Checklist

EFIN/PTIN protection · vendor due diligence · 12-point annual checklist · final review
EFIN, PTIN & IRS account protection — EFIN hijacking response; e-services MFA; monitoring unauthorized useIRS Required
Vendor & software security due diligence — three-part evaluation framework; SOC 2 certification; contract requirements
Annual cybersecurity checklist — 12-point checklist covering all Security Six, WISP, credentials, incident preparedness
Final review & key takeaways — Circular 230 cybersecurity obligations summary; five highest-priority actions; resources
CE Credit & Certification Details
Upon passing the 15-question final exam with a score of 70% or higher, you will receive a personalized certificate of completion confirming 2 hours of IRS-approved Continuing Education. Retain your certificate for at least 3 years as required by your enrollment agreement. This course satisfies the cybersecurity CE requirement recommended by the IRS Security Summit for all tax professionals.
What makes this course different
Core competencies covered in this course
- Implement all six IRS Security Six components and document them in a compliant WISP — the mandatory baseline every tax professional must meet
- Use AI tools in your practice safely — understanding exactly when uploading client data constitutes a federal data protection violation under IRC §7216
- Protect your EFIN and PTIN from hijacking, monitor for unauthorized use, and respond immediately if your credentials are compromised
- Recognize AI-powered phishing, voice cloning, deepfake video calls, and AI-generated IRS correspondence — and apply verification protocols that defeat them
- Respond to a data breach, ransomware attack, or identity theft incident with a precise step-by-step protocol — including mandatory IRS, FTC, and state reporting
Enrolled Agents
Satisfies IRS CE requirements; covers EFIN/PTIN protection and e-services security
CPAs
Covers FTC Safeguards Rule WISP obligation now mandatory for all tax preparation firms
Solo Practitioners
Tailored for small offices with limited IT resources — practical, low-cost implementations
Firm Staff
Staff training on phishing, AI scams, and data handling — your compliance obligation under §10.36
Your complete reference guide for this course — all lessons, tables, and key concepts in one printable document. Keep it handy while studying or during your final exam.
Available to enrolled students only · Tax Year 2026
