A Daily Network publication
Explore the network
Wealth Advisor Daily
The advisor's edition — practice, portfolio, and the book.
Sunday, September 13, 2026The Morning Brief →Sign in
The Practice

The IRS security checklist doubles as a marketing asset

Six controls the IRS wants owned and documented are the evidence file a client’s attorney, accountant or bank eventually asks to see.

The Internal Revenue Service and its Security Summit partners closed the eleventh annual “Protect Your Clients; Protect Yourself” campaign in July 2026, a five-week summer series written for tax preparers and organized around the documents that advisory practices also hold: the returns, W-2s and account forms sitting on advisory and estate-planning laptops and shared drives. The Security Summit, the partnership of the IRS, state tax agencies and the tax industry that has worked on tax-related identity theft since 2016, published a number this year that explains why the series persists: through June 2025, the IRS reported nearly 300 data breaches among tax preparers, affecting 250,000 clients.

Divide 250,000 by nearly 300 and the average incident reaches more than 800 people, which is how one firm’s lapse becomes an event for its entire book. That is why the campaign belongs on an advisory practice’s fourth-quarter calendar rather than in the folder marked for the firm’s CPA.

The attack starts with a fake prospect

Three threat categories carried the series: in “new client” spear phishing, criminals impersonate prospective clients and send malicious attachments disguised as tax documents; credential theft operations target professional identification numbers; and viral “tax hacks” on social media persuade taxpayers to file returns with false information or claim credits they do not qualify for. The first maps onto an advisory practice’s growth engine, and the mapping is uncomfortable. Marketing for inbound inquiries trains everyone who watches the firm inbox, including the client-service associate who answers the website form, to open what strangers send, because a stranger with a document attached is exactly what a new relationship looks like in its first hour. Tax preparers meet that pattern during filing season; advisors who solicit continuously meet it all year.

The third category is the quiet one because it requires no malware, only a taxpayer talked into filing a return built on false claims. The damage likely surfaces later, in amended returns and revised projections, after a relationship has been built on numbers that were never right.

An owner, a configuration and a document

The operational core of the campaign is shorter and more useful: six controls the IRS and its Security Summit partners say professionals handling taxpayer data need in place, each of which has a counterpart in a wealth management firm’s stack.

ControlWhat the campaign calls for
Antivirus softwareEnterprise-grade anti-malware with automatic updates
FirewallNetwork security that blocks unauthorized access
Multi-factor authenticationRequired on all systems containing client data
Backup software or servicesRegular, tested backups stored securely off-site
Drive encryptionFull-disk encryption on every device used for work
Virtual private networkMandatory for all remote access to firm networks

Those six are the foundation of IRS Publication 4557, “Safeguarding Taxpayer Data,” and the sentence that follows the list is the one worth taping inside a compliance calendar: each control needs an owner, a working configuration and documented evidence. The software is the cheap and easy half. Anti-malware with automatic updates, a firewall, multi-factor authentication on every system holding client data, tested backups stored off-site, full-disk encryption on every work device and a VPN for all remote access can be bought in a week, and every competitor can buy the same products on the same terms. Documentation is where practices diverge, because a backup nobody has restored is a hope rather than a control, and an authentication rollout with no inventory of covered systems cannot be produced for anyone who asks to see it.

That documentation is the part with a business-development use. The campaign was written to prevent breaches rather than to win clients, but what it asks a firm to assemble—a tested backup schedule, a device inventory and evidence that can be handed to a third party—is close to what a client’s attorney, accountant or bank asks for when new money or a new relationship moves. A firm that can say where a client’s documents live and who can open them is likely to clear that diligence faster and to look like the most careful shop in a referral conversation, which is a marketing position built out of a compliance requirement. It is easier to assemble on a quiet week than during a breach investigation or in the middle of year-end document traffic.

The same discipline is what advisory technology decisions now call for. As this publication has argued, firms that buy tools before they build compliance sign-off pay twice, and the IRS list supplies the sign-off template for anything new that touches client data, whether it is an AI meeting recorder, a client portal or a planning tool that syncs to the cloud. Each one should arrive with an owner, a working configuration and evidence, or it should wait. That standard has the advantage of being written down by the government rather than assembled by a vendor’s sales engineer.

The campaign also points to the legal floor, noting that federal law requires tax and accounting professionals to create and maintain a written information security plan; whether advisory firms carry the same mandate is not something the coverage addresses, and the practices most exposed are the ones already sitting on the same documents their clients’ accountants hold.

IRS guidance keeps arriving on the practice calendar regardless. Advisors spent August working through proposed rules for employer contributions to Trump Accounts, another case of agency detail that has to be converted into a client process before it is useful. These controls have no upside to sell: no client hires a firm because the laptops are encrypted, and the 250,000 people in last year’s count did not choose their preparer on security either. What a practice can take from the campaign’s eleventh edition is the part that requires no purchase—a name beside each of the six controls, in place before the year-end documents start moving between clients, firms and preparers.

a backup nobody has restored is a hope rather than a control
Sources & further reading
WealthManagement.com
More from Wealth Advisor Daily
The Advisor's Note

Mariner's $175 million bot budget is a supervision purchase

At $250,000 a bot, the AI gap in wealth management is now a data-custody and review-standard problem.
The Exit

Sanchez's real multiple sits in the terms nobody published

Modern Wealth bought a $710 million book and a founder's remaining career in one signature, which makes the price that matters the one the announcement left out.
Elsewhere in the networkAll titles →
Every weekday · 6:30 a.m. ET

The Morning Brief

The private wealth industry in four minutes, every weekday at 6:30 a.m. ET. Free.