3.3 – IRS Reporting Requirements remove this

Lesson at a Glance:

An incident response plan is the written, step-by-step procedure your practice follows from the moment a breach is discovered through containment, notification, remediation, and documentation. It is required in your WISP — and it must be understood before a breach occurs, not read for the first time during one. This lesson walks through each phase of the response in sequence, explains what must happen within the IRS’s 24-hour notification window, and provides the specific contacts and actions needed at each stage. The goal is that any person in your office — not just the coordinator — can execute the plan if needed.

Learning Objectives

After completing this lesson you will be able to:

  • Execute each phase of an incident response from discovery through post-incident review.
  • Meet the IRS 24-hour notification requirement accurately and completely.
  • Identify every internal and external party who must be contacted during a breach response.
  • Write the incident response section of your WISP using the framework provided in this lesson.

The Four Phases of Incident Response

A complete incident response moves through four sequential phases. Each phase has specific required actions. Skipping a phase — especially notification — creates regulatory and legal exposure.

  • Phase 1 — Contain (Hours 0–2)

  • The moment a breach is discovered or suspected, containment is the first priority. The goal is to stop the attacker from accessing additional data while preserving the evidence needed to understand what happened.

  • Disconnect the affected device(s) from the internet — do not power them off.
  • Revoke or change credentials for all systems that may have been accessed, from a clean, unaffected device.
  • If a physical breach (stolen device, missing file), document what is missing and secure remaining physical records.
  • Do not delete files, reinstall software, or attempt to clean the system — this destroys forensic evidence.
  • Begin your incident log: date, time, what was observed, and every action taken.
  • Phase 2 — Notify (Within 24 Hours of Discovery)

  • This is the most time-sensitive phase. The IRS requires notification within 24 hours of discovering a suspected or confirmed breach. Notification has multiple components — all must happen within that window:

Who to Notify

How

What to Say

IRS Stakeholder Liaison

Phone — find your local contact at IRS.gov/stakeholderliaisonlocalcontacts

Firm name, EFIN, nature of breach, number of potentially affected clients, actions taken so far

Tax software vendor

Phone — use the fraud/security line, not general support

Your account credentials may be compromised; request account freeze and review of recent filings

FBI Internet Crime Complaint Center

Online report at IC3.gov

Description of the incident, type of attack, estimated scope

Local law enforcement

Non-emergency line or in person for physical breaches

File a police report — the report number may be required for insurance and state notifications

Your state tax agency

Phone or online — most states have a separate breach notification requirement

Same information as IRS notification; check your state's specific requirements

Your cyber liability insurer (if applicable)

Phone — most policies require prompt notification

Nature and scope of breach; actions taken; request guidance on coverage

The 24-hour clock is firm

The IRS has stated clearly that notification should occur within 24 hours of discovery of a suspected breach — not after you have confirmed every detail, not after you have finished investigating, and not after you have notified clients. The IRS notification comes first. Client notification comes next, typically within 2–3 business days depending on your state's breach notification law.

  • Phase 3 — Assess and Remediate (Days 1–14)

  • Once containment is in place and notifications have been made, the focus shifts to understanding the full scope of the breach and restoring secure operations.

  • Determine scope: Which clients' data was potentially accessed? Use your data inventory (from your WISP) to identify every client whose records were stored on the affected system or account.
  • Engage a forensic professional if needed: For ransomware attacks or network intrusions, an IT forensics professional can determine exactly what data was accessed and when. This information is critical for accurate client notification.
  • Restore from backup: Once the affected system has been forensically examined, wipe and restore from your most recent clean backup. Test the restored system before reconnecting to the internet.
  • Remediate the vulnerability: Identify how the attacker gained access and fix the gap — whether that is enabling MFA, patching software, revoking a former employee's credentials, or replacing a compromised device.
  • Notify affected clients: Once you have identified the affected client list, send written notification. See Lesson 3.4 for what to say and how to say it.
  • Phase 4 — Document and Review (Within 30 Days)

  • After the immediate crisis is resolved, your WISP requires a post-incident review and documentation update. This is not optional — it is how you demonstrate to regulators that you responded appropriately and took corrective action.

  • Finalize your incident log with a complete timeline from discovery through resolution.
  • Document the root cause: how did the breach occur?
  • Update your WISP to address the vulnerability that was exploited.
  • Update your risk assessment to reflect the new risk landscape post-breach.
  • Conduct a staff debrief: what did your team do well? What needs to change?

Your Incident Response Quick-Reference Card

  • The following information should be printed and kept accessible in your office — not stored only on the computer that may be compromised during a breach:

Contact

Number / URL

When to Call

IRS Stakeholder Liaison (your local contact)

IRS.gov/stakeholderliaisonlocalcontacts

Within 24 hours of discovery

Tax software vendor fraud line

[Your vendor's number — fill in before a breach occurs]

Within 24 hours of discovery

FBI IC3

IC3.gov

Within 24 hours of discovery

Local law enforcement

[Your local non-emergency number]

Within 24 hours for physical breaches; same day for ransomware

Your state tax agency security contact

[Your state's contact — look up before a breach occurs]

Within 24–48 hours depending on state law

Cyber liability insurer

[Your policy number and claims line]

Within 24 hours of discovery

Fill in this card now — before a breach happens

Look up your IRS Stakeholder Liaison local contact, your software vendor's fraud line, and your state agency contact today. Print the completed card and laminate it. Store one copy at your desk and one in a location away from your primary workstation.

Scenario — Phishing Breach, 48-Hour Timeline

Monday 9:00 AM: Preparer Teresa notices her tax software is showing a login from an unrecognized IP address at 2:00 AM. Two returns were filed that she did not prepare.
9:05 AM: Teresa disconnects her computer from Wi-Fi. Begins incident log.
9:15 AM: From her phone, Teresa changes her tax software password and enables MFA. Changes email password. Changes e-Services password.
9:30 AM: Teresa calls her tax software vendor's fraud line. They freeze her account, identify 2 fraudulent returns filed, and flag her EFIN for monitoring.
10:00 AM: Teresa calls her IRS Stakeholder Liaison. Provides firm name, EFIN, nature of breach, 2 confirmed fraudulent returns, actions taken. IRS opens a case.
11:00 AM: Teresa files a report at IC3.gov and calls local law enforcement to file a police report.

Tuesday: Teresa identifies the two affected clients from the fraudulent returns. She calls each client personally, explains what happened, advises them to place an IRS Identity Protection PIN on their accounts, and follows up with written notification.
Within 2 weeks: Teresa updates her WISP to add MFA as a required control (she had not previously enabled it), updates her risk assessment, and documents the full incident timeline. She conducts a 30-minute security review with herself using the IRS Security Summit materials.