Cybersecurity for accounting firms
Penetration Testing for Accounting and CPA Firms
Accounting firms hold tax returns, payroll files, and bank details for every client, and attackers time their campaigns to tax season. Invadel tests client portals, Microsoft 365, remote access, and the office network at a fixed price from $4,200, with a fixed scope and a free retest.






The stakes
Why accounting firms get tested differently
Attackers go after accounting firms for identity and money. A tax return holds Social Security numbers, income, and bank accounts for a whole household. A common way in is a phished staff mailbox during tax season, used to request more client files or to send altered payment instructions. Remote access to the tax software and the file server behind it then turns one stolen account into every client’s records.
The FTC lists tax preparation firms among the businesses its Safeguards Rule treats as financial institutions, and the IRS reminds preparers that the rule requires a written security plan. Section 314.4(d)(2) calls for annual penetration testing and vulnerability assessments every six months, unless the firm runs effective continuous monitoring. Cyber insurers ask about testing at renewal, and business clients send vendor questionnaires before they share payroll and banking access.
A generic external scan says the perimeter looks fine and misses where client data sits. Accounting exposure runs through the client portal, the Microsoft 365 tenant, the remote desktop or VPN staff use from home in filing season, and the tax and practice platforms behind them. Testing has to start where an attacker would, from a phished account, and report in terms a managing partner, an insurer, and the firm’s Qualified Individual can act on.
What we test
The systems attackers go after first
Client portals and file exchange
The portal where clients upload tax documents and download returns, tested for authorization flaws between clients, weak invitation and reset flows, and files reachable without a login.
Microsoft 365 and email
The tenant that carries client files and payment instructions, tested for MFA gaps, mailbox rule abuse, and conditional access policies that fail to stop a stolen session.
Tax and practice management software
Hosted or on-premises tax, accounting, and practice platforms, tested for shared logins, excessive permissions, and paths from one staff account to every client file.
Remote access
VPN gateways, remote desktop, and the remote-support tools an IT provider installed, tested for missing MFA and exposure to password spraying from the internet.
The office network
The file server, the domain controller, and the workstations that run the tax software, tested from an assumed foothold for how far one infected laptop can reach.
Partners and staff
Phishing, voice, and text campaigns built around real firm workflows, such as a client asking to change the bank account for a refund or an urgent document request from a partner.
Compliance
The frameworks that usually apply
- FTC Safeguards Rule
Annual penetration testing and vulnerability assessments every six months under 16 CFR 314.4(d)(2), absent effective continuous monitoring, for tax preparation firms and other covered financial institutions.
- SOC 2
For firms that run outsourced accounting, payroll, or bookkeeping for clients who ask for a SOC 2 report alongside the penetration test.
- Cyber insurance
Renewal applications ask about MFA, remote access, backups, and whether anyone has tested your controls in the last year. The attestation letter and retest results back up the answers.
Services
What accounting firms usually buy
- From $4,200
External Network Penetration Testing
Testing of your internet-facing perimeter, from exposed services and VPN gateways to mail and cloud edges, with a free retest, from $4,200.
- From $6,000
Internal Network Penetration Testing
Testing from an assumed foothold inside your network: Active Directory attack paths, lateral movement, and segmentation, from $6,000.
- From $3,600
Phishing Simulation & Social Engineering Testing
Phishing and social engineering campaigns that measure real-world human risk, with click and credential metrics by department, from $3,600.
- From $5,200
Web Application Penetration Testing
Manual testing of your web application across the OWASP Top 10, business logic, and all user roles, with a free retest included, from $5,200.
- From $1,500
Vulnerability Scanning Services
Managed scanning validated by an analyst, which cuts false positives down to real, ranked risk you can act on at once. From $1,500 per scan.
How it runs
Typical engagements
Illustrative scopes for this industry, written to show what a test covers and what you walk away with.
They are not client stories; our anonymized engagements are on the case studies page.
Typical engagement
CPA firm renewing its cyber insurance
A 30-person CPA firm’s renewal application asks whether the network was penetration tested in the last year and whether multi-factor authentication covers email and remote access. We run an external test of the perimeter and the remote access gateway and review the Microsoft 365 tenant’s MFA and conditional access. A phishing baseline covers every staff member. The firm returns the application with an attestation letter, three fixes ranked by urgency, and a free retest once they are done.
Typical engagement
Tax practice before filing season
A regional tax practice wants its exposure tested before January, when client documents start arriving. We run an internal test from a seasonal staff workstation toward the file server and the tax software, and test the client upload portal for access between client accounts. A shared administrator password turns out to reach every client folder. The fix is retested within the engagement, and the Qualified Individual gets the results for the annual report to the partners.
Typical engagement
Firm adding a client portal
An accounting firm replacing email attachments with a branded client portal wants it tested before clients are invited. We test the portal across client, staff, and administrator roles, the upload and e-signature flows, and the sign-in through the firm’s Microsoft 365 tenant. One client can list another client’s documents by changing an identifier in the download link. The vendor ships a fix, we retest at no cost, and the firm launches the portal with an attestation letter on file.
FAQ
What accounting firms ask
01Does the FTC Safeguards Rule apply to our firm?
If you prepare tax returns, very likely. The FTC lists tax preparation firms among the businesses the rule treats as financial institutions, and the IRS reminds preparers that it requires a written information security plan. Firms that hold customer information on fewer than 5,000 consumers are exempt from the written risk assessment, the testing requirement in 314.4(d)(2), the incident response plan, and the annual report, but not from the rest of the rule. Our FTC Safeguards Rule penetration testing page covers who is in scope.
02How often should an accounting firm run a penetration test?
Once a year at a minimum, which is what 314.4(d)(2) asks for when a firm does not run effective continuous monitoring, with vulnerability assessments at least every six months and after material changes. Test again after a move to new tax software or before a new client portal goes live. A validated vulnerability scan from $1,500 can serve as the six-monthly assessment.
03How much does penetration testing cost for an accounting firm?
External network testing starts at $4,200, internal network testing at $6,000, web application testing for a client portal at $5,200, and a phishing campaign at $3,600. Each price is fixed in writing before work starts. Penetration tests include a free retest of remediated findings. A typical first engagement combines the external test with a phishing baseline, quoted as one number. A Microsoft 365 security assessment of the tenant’s MFA, conditional access, mailbox rules, and external sharing starts at $4,200.
04Will testing get in the way of tax season?
Not if we plan it that way. We schedule testing around your filing deadlines, run it in agreed windows, and never use denial-of-service techniques. Your side of the work is a one-hour scoping call, a point of contact during testing, and a readout at the end. If an insurer or client deadline lands in the middle of filing season, tell us and we plan around both.
05Can you test our firm remotely?
Yes. External and portal testing run remotely by design, and internal testing runs through a small device we ship to your office, so nobody needs to host a tester for a week. Firms in Manhattan can also meet us at 1178 Broadway, or in their own conference room, for scoping and the readout.
Get a fixed price for your firm's scope
Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.