Ransomware is targeting professional services firms.
Cyber insurance applications are demanding evidence.
Clients are asking how you protect confidential information.
Regulators want documented safeguards, not verbal assurances.
And for covered organizations, a security incident involving at least 500 consumers’ unencrypted information may trigger an FTC reporting obligation within 30 days of discovery.
If your firm still relies on informal IT support, outdated policies, or “I got a guy” cybersecurity, now is the time to take a closer look.
The FTC Safeguards Rule and broader GLBA compliance requirements directly affect many accounting firms, tax preparers, financial advisors, and related businesses. Law firms and medical practices may not automatically fall under the Rule, but they face comparable expectations through client contracts, professional obligations, HIPAA compliance, cyber insurance, and state privacy laws.
The practical message is simple:
Your organization needs a documented, operational, and continuously maintained cybersecurity program.
First, Determine Whether the FTC Safeguards Rule Applies to You
The FTC Safeguards Rule implements part of the Gramm-Leach-Bliley Act, or GLBA. It applies to certain non-bank financial institutions under FTC jurisdiction.
The definition is broader than many business owners expect. The question is not simply whether you call yourself a law firm, accounting firm, or medical practice.
The better question is:
Does your organization provide services that are financial in nature and handle nonpublic personal information as part of those services?
The FTC specifically identifies tax preparation firms, financial advisors, mortgage brokers, lenders, account servicers, and other businesses as examples of potentially covered financial institutions. You can review the FTC’s official Safeguards Rule compliance guide and the current Rule text for additional detail.
Accounting firms and tax preparers
Accounting practices are often the most likely to fall directly within the Rule.
If your firm prepares tax returns or provides financial advisory services, you may handle:
- Social Security numbers
- Bank account information
- Income and payroll records
- Investment details
- Business financial statements
- Tax identification numbers
- Consumer credit or lending information
That data creates both regulatory and operational responsibility. Accounting firm IT must protect information throughout its lifecycle, from collection and transmission to storage, retention, and secure disposal.
Law firms
A traditional law firm is not automatically a financial institution simply because it stores client financial information. However, the analysis may change if your firm provides consumer financing, operates a lending-related business, or performs other activities that are financial in nature.
Even where the FTC Safeguards Rule does not directly apply, law firms face significant cybersecurity obligations and expectations. Clients may require MFA, encryption, logging, vendor oversight, and incident response procedures before signing an engagement. Professional responsibility rules also make confidentiality and reasonable data protection essential components of modern law firm cybersecurity.
Medical practices
Most medical practices primarily focus on HIPAA compliance, state health privacy laws, and the protection of electronic protected health information.
A medical practice does not generally become subject to the FTC Safeguards Rule merely because it processes patient payments or maintains billing records. However, a practice that is significantly engaged in consumer financing or other financial activities may require a more specific legal analysis.
Regardless of the regulatory label, medical practice IT must protect patient data, support clinical operations, and maintain availability during an outage.
What the FTC Safeguards Rule Requires
The FTC requires covered organizations to develop, implement, and maintain a written information security program appropriate to the size, complexity, activities, and data sensitivity of the business.
That means a small firm does not necessarily need the same structure as a national financial institution.
It does need a real program.
Documented. Risk-based. Enforced. Reviewed.
The FTC’s guidance identifies nine core elements.
1. Designate a Qualified Individual
Someone must be responsible for implementing and supervising your information security program.
That person may be an employee, an affiliate, or a qualified managed services provider. However, outsourcing the work does not eliminate management responsibility. Your firm still needs a senior leader who understands the program, reviews risks, and oversees the provider relationship.
2. Complete a Written Risk Assessment
You cannot protect information you have not identified.
A written IT assessment should document:
- What sensitive information you collect
- Where it is stored
- Who can access it
- How it moves between systems
- Which vendors and applications process it
- What threats could expose, alter, destroy, or misuse it
An assessment is not a one-time exercise. Revisit it when you add a new cloud platform, open an office, adopt remote work, change vendors, or experience a significant security event.

3. Enforce Access Controls and MFA
Access should be based on business need, not convenience.
Your employees should only have access to the systems and data required for their roles. Permissions should be reviewed after promotions, transfers, terminations, and contractor changes.
Multi-factor authentication should protect:
- Microsoft 365 and email
- Remote access
- Administrative accounts
- Cloud applications
- Financial and tax platforms
- Electronic health record systems
- Backup consoles
A password alone is not a sufficient defense against phishing and credential theft.
4. Encrypt Sensitive Information
The Rule calls for encryption of customer information on your systems and while it is in transit, unless an effective alternative control is approved by the Qualified Individual.
For your business, that may include encryption for:
- Laptops and mobile devices
- Cloud storage
- Backups
- Secure file transfers
- Email attachments
- Databases and servers
Encryption does not replace other controls. It reduces the damage when a device, account, or storage location is exposed.
5. Deploy Endpoint Security and Email Security
Traditional antivirus is not enough.
Your firm needs modern endpoint security that can detect suspicious behavior, investigate activity, and isolate a compromised workstation. This is particularly important for remote employees, unmanaged devices, and systems that access confidential client or patient information.
You also need layered email security to address phishing, malicious attachments, spoofing, business email compromise, and MFA fatigue attacks.
The “Hey Margaret!” scenario is familiar:
“Hey Margaret, this is Kevin from IT. I need you to approve this sign-in so I can fix your account.”
It sounds routine. It may be an attacker using urgency and authority to bypass your controls.
Technology helps. Training matters. You need both.
Why Paper Compliance Is Not Enough
Policies gather dust.
Shared folders fill up.
Checklists get marked “complete.”
Then an auditor, insurer, or client asks for evidence.
A written policy without technical enforcement is not a mature security program. If your policy requires MFA but several accounts remain unprotected, the gap is easy to identify. If your incident response plan lists people who no longer work at the firm, it will not help during a ransomware event.
This is where temporary fixes fail.
One employee may know the server. Another may manage Microsoft 365. A third person may “handle backups.” No one may have the complete picture.
That is the “I got a guy” problem.
A capable IT provider should give you documented ownership, consistent standards, monitoring, reporting, and a clear escalation process: not just someone who responds when a printer stops working.
Incident Response, Business Continuity, and Disaster Recovery
Security and availability are connected.
Your incident response plan should explain how you will detect, contain, investigate, communicate, and recover from a security event. It should identify:
- Who declares an incident
- Who isolates affected accounts and devices
- Who contacts legal counsel, insurance, and law enforcement
- Who communicates with employees, clients, patients, or regulators
- How evidence and logs are preserved
- How clean backups are validated
- How systems are restored
- How lessons learned update your controls
For covered financial institutions, a notification event involving the unauthorized acquisition of at least 500 consumers’ unencrypted information must be reported to the FTC as soon as possible and no later than 30 days after discovery. The FTC provides an online reporting form and related guidance.
You should also maintain a broader business continuity and disaster recovery strategy.
A backup is important. It is not a complete continuity plan.
Your plan must answer practical questions:
- How will employees communicate if email is unavailable?
- How will a medical office operate if its EHR is down?
- How will a law firm meet a filing deadline during an outage?
- How will an accounting firm securely exchange documents with clients?
- Which systems must be restored first?
- How quickly must each system return to service?
HIPAA-covered organizations should also review HHS guidance on ransomware and contingency planning.

Internal IT vs. a Managed Services Provider
You may be considering whether to build a larger internal team or partner with a managed services provider.
Internal IT: Potential advantages
- Direct familiarity with your systems and workflows
- Immediate physical presence
- Internal control over priorities
- Strong understanding of your organization’s culture
Internal IT: Potential disadvantages
- Hiring and training costs
- Limited coverage during vacations or turnover
- Dependence on one or two individuals
- Difficulty maintaining expertise across cloud security, compliance, endpoint security, and disaster recovery
- Higher costs for enterprise-grade tools and 24/7 monitoring
Managed services: Potential advantages
- Predictable monthly costs
- Access to a broader technical team
- Economies of scale on cybersecurity tools
- Proactive maintenance and helpdesk support
- Documented compliance processes
- Vendor management and strategic planning
- Consistent support when an employee is unavailable
Managed services: Potential disadvantages
- You must select a provider carefully
- Transitioning from informal support requires planning
- Your leadership team still needs to remain engaged
- Not every MSP has the same security maturity or industry experience
Managed IT is not about giving up control. It is about gaining accountability, redundancy, and specialized expertise without hiring every security, cloud, compliance, and infrastructure role internally.
Your FTC Safeguards and Cybersecurity Action Plan
Start with these five steps:
- Confirm your obligations. Work with qualified legal counsel to determine whether GLBA, the FTC Safeguards Rule, HIPAA, or other requirements apply.
- Schedule an IT audit or IT assessment. Identify sensitive data, outdated systems, excessive permissions, unsupported devices, and security gaps.
- Document your security program. Assign a Qualified Individual and establish a written information security program.
- Verify foundational controls. Review MFA, encryption, endpoint security, email security, patching, backups, logging, vendor oversight, and employee training.
- Test your response plan. Conduct a tabletop exercise, vulnerability assessment, backup restoration test, or independent security review.
A checklist is a starting point.
It is not the finished program.
Final Word
The FTC Safeguards Rule is part of a larger shift in how professional services firms are expected to manage technology and risk.
For accounting firms and tax preparers, GLBA compliance may be a direct obligation. For medical practices, HIPAA compliance remains central. For law firms, confidentiality, client contracts, cyber insurance, and professional responsibilities create equally serious expectations.
The strategy is consistent across all three industries:
- Identify your risks
- Protect sensitive information
- Limit access
- Monitor continuously
- Train your people
- Manage your vendors
- Test your recovery procedures
- Document what you can prove
You did not build your practice to spend evenings reviewing firewall alerts, investigating suspicious logins, or wondering whether your backups will restore.
At A PC of Mind, we help law firms, accounting firms, medical practices, and other regulated organizations build secure, modern technology environments through managed IT, cybersecurity, cloud management, backup, disaster recovery, and strategic IT consulting.
Do not wait for an audit request, insurance renewal, ransomware incident, or client questionnaire to expose the gaps.
Schedule an IT assessment with A PC of Mind and turn compliance from a recurring burden into a reliable business advantage.
This article is for general informational purposes only and is not legal advice. Consult qualified counsel to determine whether the FTC Safeguards Rule, GLBA, HIPAA, or other regulatory requirements apply to your organization.