# Endpoint Security for Tax and Accounting Firms: Device Logs Decide Whether You Report to the FTC

> How the FTC Safeguards Rule and IRS Publication 4557 apply to a tax or accounting practice's computers, which duties fall away for firms holding data on fewer than 5,000 consumers and which do not, and which EDR products fit a sole preparer, a seasonal firm and a firm that must show continuous monitoring.

Endpoint Index research (Industry guide). Published 2026-09-25, updated 2026-09-30, data as of 2026-10-02. Source: https://endpointindex.com/research/endpoint-security-accounting-tax-firms/

## Executive summary

**A tax or accounting firm needs endpoint detection and response (EDR) on every workstation, because under the FTC Safeguards Rule an intrusion is presumed to be an unauthorised acquisition of client data unless the firm has reliable evidence that it was not, and device activity records are that evidence.** The presumption sits in the definition of a "notification event" ([16 CFR 314.2(m)](https://www.law.cornell.edu/cfr/text/16/314.2)). If the event involves 500 or more consumers, the firm must tell the FTC within 30 days ([314.4(j)](https://www.law.cornell.edu/cfr/text/16/314.4)). A firm that cannot show what the intruder did not reach ends up reporting as if the intruder reached everything.

Tax preparers are squarely inside the rule: the definitions name an accountant or tax preparation service completing income tax returns as a financial institution (314.2(h)(2)(viii)). In the endpoint database behind this guide, last checked against vendor pages on 2026-10-02, 8 products carry EDR and 3 bundle a round-the-clock team to watch it.

Firm size changes the rest of the answer. A practice holding information on fewer than 5,000 consumers is excused from four provisions, including continuous monitoring. It is not excused from monitoring user activity, multi-factor authentication or FTC notification.

## Which Safeguards Rule duties apply to a small firm?

[16 CFR 314.6](https://www.law.cornell.edu/cfr/text/16/314.6) says that 314.4(b)(1), (d)(2), (h) and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers. Read against the endpoint-related provisions, that gives:

| Provision | What it requires | Under 5,000 consumers |
|---|---|---|
| 314.4(b)(1) | A written risk assessment | Does not apply |
| 314.4(c)(5) | Multi-factor authentication for anyone accessing any information system | Applies |
| 314.4(c)(8) | Controls to monitor and log the activity of authorised users and detect unauthorised access or tampering | Applies |
| 314.4(d)(2) | Continuous monitoring, or annual penetration testing plus vulnerability assessments every six months | Does not apply |
| 314.4(h) | A written incident response plan | Does not apply |
| 314.4(j) | Notify the FTC within 30 days of a notification event involving 500 or more consumers | Applies |

The row most small firms miss is (c)(8). Logging what authorised users do on the systems holding client data is a duty at every size, and an EDR agent on each workstation is the cheapest way to produce that log.

The IRS adds its own expectation. [Publication 4557](https://www.irs.gov/pub/irs-pdf/p4557.pdf) (Rev. 6-2024) tells preparers to install anti-malware on all devices and keep it set to update automatically, and states that under the Safeguards Rule tax return preparers must create and enact a written security plan. Publication 5708 is the IRS template for that plan.

## Two ways to meet continuous monitoring

A firm above 5,000 consumers must choose under 314.4(d)(2): continuous monitoring, or an annual penetration test plus vulnerability assessments every six months. Continuous monitoring on the endpoints means an EDR product that someone watches all the time. For a firm without security staff, that someone is a vendor's 24/7 team:



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">Per unit per month</th><th scope="col">10 seats / yr</th><th scope="col">25 seats / yr</th><th scope="col">100 seats / yr</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/threatdown.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/threatdown-elite/">ThreatDown Elite</a></span></span></td><td data-label="Per unit per month"><span class="cell"><span class="num">$8.25</span> <span class="unit">/endpoint/mo</span></span></td><td data-label="10 seats / yr"><span class="cell"><span class="num">$990.00</span></span></td><td data-label="25 seats / yr"><span class="cell"><span class="muted">Via sales (online up to 20)</span></span></td><td data-label="100 seats / yr"><span class="cell"><span class="muted">Via sales (online up to 20)</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="Per unit per month"><span class="cell"><span class="muted">Min 50 seats</span></span></td><td data-label="10 seats / yr"><span class="cell"><span class="muted">Min 50 seats</span></span></td><td data-label="25 seats / yr"><span class="cell"><span class="muted">Min 50 seats</span></span></td><td data-label="100 seats / yr"><span class="cell"><span class="num">$9,588.00</span></span></td></tr></tbody></table></div><figcaption>Annual totals from each vendor's store or calculator at list price. "Quote only" means the vendor publishes no online price at that seat count; "Min N seats" means the vendor's smallest purchase is larger. Not shown because the vendor does not publish a price: <a href="/products/cynet/">Cynet</a>.</figcaption></figure>



The alternative is EDR you or your IT provider review, backed by the testing cycle. These six products are the ones worth comparing for an accounting practice: each includes EDR, and between them they cover both routes. Patch management is included as a column because a vulnerability assessment is only useful if someone then patches what it finds.



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">EDR</th><th scope="col">24/7 managed response</th><th scope="col">Patch management</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/microsoft.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/microsoft-defender-for-business/">Microsoft Defender for Business</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="Patch management"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/threatdown.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/threatdown-elite/">ThreatDown Elite</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Patch management"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/threatdown.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/threatdown-advanced/">ThreatDown Advanced</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="Patch management"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sentinelone.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sentinelone-singularity-control/">SentinelOne Singularity Control</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="Patch management"><span class="cell"><span class="state state-add_on">Add-on</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Patch management"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/cynet.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/cynet/">Cynet</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Patch management"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td></tr></tbody></table></div><figcaption>From each vendor's product and pricing pages. "Add-on" means available at extra cost. Follow a product link for sources and verification dates.</figcaption></figure>



## What should each firm buy?

**Sole preparer with fewer than 5,000 consumers.** Microsoft Defender for Business ($36.00 per user per year) on every machine, with MFA on email and tax software. It meets the IRS anti-malware line and gives you the (c)(8) activity log. Continuous monitoring is not required at your size, but a weekly look at the alert list is cheap, and it is what would let you rebut the notification presumption.

**Firm of 5 to 15 staff that has crossed 5,000 consumers.** Count carefully: the test is consumers whose information you maintain, so returns kept from earlier seasons can push you over. Once over, pick a route. ThreatDown Elite ($99.00 per endpoint per year) includes the 24/7 team and patching. ThreatDown Advanced ($79.00 per endpoint per year) has the same agent without the team, which works if your IT provider watches it and you buy the testing cycle.

**Firm that grows every January.** Seasonal preparers bring extra laptops for the filing season. Check minimum purchases: Huntress requires 50 endpoints if bought direct or from a reseller (an MSP can sell it with no Huntress minimum) and ThreatDown 5; SentinelOne shows its Control price for 5 to 100 workstations and leaves the terms to its partners. ThreatDown's online store only sells 5 to 20 devices, so a firm that swells past 20 in January buys through ThreatDown sales or a partner. Microsoft licenses per user, which suits staff who come back each season. Every temporary machine needs the agent before it opens client data.

**Firm with an outsourced IT provider.** Ask the provider to name the product, confirm who watches it outside business hours, and write both into your written security plan. The Qualified Individual the rule requires (314.4(a)) should have their own console login.

## Mistakes tax firms make

- **Reading the 5,000-consumer exception as a full exemption.** It removes four provisions. Activity logging, MFA and FTC notification remain.
- **Counting only this season's clients.** Retained prior-year files count as information you maintain.
- **Relying on the tax software vendor's security.** Cloud tax software protects its servers, not the preparer's laptop where the password is typed.
- **Buying antivirus with no activity record.** It meets the IRS checklist line and leaves the firm unable to show reliable evidence that data was not acquired.

## Frequently asked questions

### Is a CPA firm a financial institution under the Safeguards Rule?

A firm in the business of completing income tax returns is, under 16 CFR 314.2(h)(2)(viii). Other accounting services may also fall within the rule; confirm with counsel or your professional body.

### Does a small tax practice need continuous monitoring?

Not if it maintains customer information on fewer than 5,000 consumers, because 314.6 removes 314.4(d)(2) for those firms. It still has to monitor and log authorised users' activity under 314.4(c)(8).

### What is a notification event, and when is it presumed?

The acquisition of unencrypted customer information without the consumer's authorisation. Unauthorised access is presumed to be acquisition unless you have reliable evidence it was not, or could not reasonably have been (314.2(m)).

### How fast must a firm tell the FTC?

As soon as possible and no later than 30 days after discovery, for a notification event involving at least 500 consumers (314.4(j)). State breach laws and IRS data-loss reporting may add duties.

## Methodology and caveats

We re-read 16 CFR 314.2, 314.4 and 314.6 at Cornell's LII, and Publication 4557 on irs.gov, on 30 September 2026. The capability table's six products were chosen by hand for the reason stated beside it; the cost table is filtered to products with 24/7 managed response included. Prices and capability states are inserted from our product records at build time.

This guide describes the rule for buying purposes and is not legal advice. Your counsel or professional body is the authority on how it applies to your firm.

## Sources

1. Legal Information Institute. [16 CFR 314.4, Elements of an information security program](https://www.law.cornell.edu/cfr/text/16/314.4). Checked 30 September 2026.
2. Legal Information Institute. [16 CFR 314.2, Definitions](https://www.law.cornell.edu/cfr/text/16/314.2). Checked 30 September 2026.
3. Legal Information Institute. [16 CFR 314.6, Exceptions](https://www.law.cornell.edu/cfr/text/16/314.6). Checked 30 September 2026.
4. Internal Revenue Service. [Publication 4557, Safeguarding Taxpayer Data](https://www.irs.gov/pub/irs-pdf/p4557.pdf) (Rev. 6-2024). Checked 30 September 2026.
5. Endpoint Index product records for the six products compared (latest vendor check 2026-10-02).
