AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / The data you hold

The data you hold

Client Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding

Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The closing binders in the scanned folder

A paralegal at a 40-person law firm has scanned every real-estate closing binder for eight years. It is good practice: the paper goes to storage and the PDF stays searchable. Each binder holds the client's bank statements, the lender's payoff letter, a copy of the driver's licence, the wire instructions and, for the older ones, a Social Security number on the settlement statement.

The scans live in a folder on the document management system called "Closings, all years." Permissions were set when the firm had twelve people. Every user has read access, because in 2018 that was easier than asking who needed it. The firm now has 40 people, including four summer associates, two contract attorneys and an IT vendor with an admin account.

On a Tuesday in July, one of the summer associates, working from a coffee shop, opens a phishing email that looks like a court e-filing notice. Her password goes to someone in another time zone. For nine days that someone reads the document management system as her. The firm's audit logs, which default to 30 days and which nobody reviews, show 2,140 documents opened from an IP address in a country the firm has no clients in.

The managing partner learns the scale on day ten. He now has to work out which of 900 closings are affected, whose bank statements were among them, and which state and federal clocks started nine days ago without anyone hearing them.

What the heck does this mean

Client financial data is any record that ties an identifiable person to their money: statements, tax returns, loan files, brokerage records, wire instructions, payroll details. Law firms, CPAs and advisors hold more of it per employee than most banks.

Nonpublic personal information, NPI, is the regulators' term for that data when a financial institution holds it. Under the FTC's Safeguards Rule, a tax preparer or a firm giving financial advice is a financial institution, whether or not it has ever thought of itself that way.

A WISP, written information security program, is the document that says what you hold, who protects it and how. The FTC expects one. The IRS requires one of every tax professional.

Least privilege is the principle that a person can open only what their job requires. "Everyone can read Closings, all years" is its opposite.

Business email compromise, BEC, is the attacker using a stolen or spoofed mailbox to redirect money. In a law firm the target is the wire instructions in the closing folder, and the settlement funds that follow them.

The numbers that matter

The FTC Safeguards Rule requires notice to the FTC within 30 days of a breach affecting 500 or more consumers (FTC, effective May 2024). Nine hundred closings clears that threshold on the first afternoon.

Smaller SEC-registered advisers had to comply with the amended Regulation S-P by 3 June 2026, including 30-day notification to affected customers (SEC, 2024 amendments). The wealth advisor down the hall is on the same clock as the law firm, from a different regulator.

Business email compromise cost USD 3.05 billion across 24,768 complaints (FBI IC3 2025 Annual Report). Every one of those complaints started with someone reading email that was not theirs, which is exactly what the summer associate's stolen password allowed.

What to do this week

  1. Open the permissions on your three biggest client folders and count how many people can read them. Cut the list to the people working those matters. Do closings, tax returns and client statements first. (CIS 6 Access Control Management)
  2. Turn on MFA for the document management system, email and the remote-access tool, including for contract staff and the IT vendor. A stolen password without a second factor is a key; with one, it is a key to a locked door. (CIS 6 Access Control Management)
  3. Extend your audit log retention to at least a year and assign one person to review the "documents opened" report every Monday for the unusual: volume, hour, location. The nine days in the story would have been one. (CIS 8 Audit Log Management)
  4. Find the financial data outside the system: the paralegal's scan folder on her desktop, the shared inbox of wire instructions, the spreadsheet of client account numbers in the finance department. Move it in or delete it. (CIS 3 Data Protection)
  5. Write, or rewrite, the WISP with real names: who owns it, which systems hold client data, which vendors have access, and the phone number of the lawyer you will call on day one of a breach. Date it and put a calendar reminder to review it in twelve months. (CIS 3 Data Protection)
  6. Add a callback rule for wire instructions: any change is confirmed by phone to a number on file, never to a number in the email. Put it in the engagement letter so clients expect it. (CIS 3 Data Protection)

Where AccuSights fits

Our assessment finds the client financial data your firm holds, shows who can reach it, checks whether the logs would answer "what did they open" and maps the result to the Safeguards Rule, Reg S-P or your bar's guidance. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer turns the permissions problem into a short, costed list.

Our team implements these controls at a reasonable rate, from data loss prevention and access reviews to scanning and protection of assets, and Protect watches 24/7 so a stolen password from a coffee shop is an alert at 2 a.m., not a discovery on day ten.

Questions people ask

Is a CPA firm a financial institution under the Safeguards Rule? If the firm prepares tax returns or provides financial advice for individuals, yes. The FTC's definition turns on the activity, not the licence, and tax preparation is named in it. That makes the firm responsible for a written information security program, a designated person who owns it, and a 30-day notice to the FTC after a breach affecting 500 or more people. The IRS reinforces this by requiring every tax professional to keep a written plan regardless of size.

What is a WISP? A written information security program: a document that says what client data you hold, who is responsible for protecting it, which safeguards you use and what you do when something goes wrong. The FTC requires one under the Safeguards Rule and the IRS requires one of every tax preparer. A template is a starting point, not a finished WISP; the version that counts names your systems, your people and the date you last tested the backup.

Do law firms have to report breaches? In most US states, yes, under the state breach-notification law that applies to the affected clients, and the professional-conduct rules add a duty to tell clients whose matters were affected. Firms that hold tax or financial data for individuals may also fall under the FTC Safeguards Rule's 30-day notice. In the UAE, the federal PDPL and the DIFC and ADGM regimes each set their own notification clock. The practical answer is to know which clocks apply before the day you need them.

Your clients handed you their bank statements because they trusted you more than the bank. The folder permissions should say the same thing.

Controls this post maps to

CIS 3 Data ProtectionCIS 6 Access Control ManagementCIS 8 Audit Log Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.