
The IRS Security Six are the six baseline security controls the IRS expects every tax and accounting firm to have in place. They are not complicated, and you do not need an IT department to put them in. What trips small firms up is not difficulty, it is that these controls get set up once, drift out of date, and nobody checks them again until a renewal form or a client asks. This is a plain-English run through all six, what each one is, and what “done” looks like at a small practice.
The Security Six come from the IRS Security Summit, and they apply to anyone who prepares returns for pay, whatever the firm’s size. They are the technical floor beneath the written security plan the IRS asks every preparer to keep, and they are also the controls a cyber-insurance questionnaire now tends to check. So getting them right matters for more than one reason, and none of the six is expensive to put in place.
If you can’t do all six at once
Start with multi-factor authentication and drive encryption. Between them, they stop the two most common ways small firms lose client data: a password that ends up in the wrong hands, and a laptop that walks off. The other four matter, and you should close them too, but those two buy you the most protection for the least effort. As you go, write down what you have in place and when you last checked it. That record is the start of the written information security plan the IRS expects, which we cover in our guides to the WISP requirements and the IRS Publication 4557 checklist.
Where hosting covers part of the list
If your accounting software runs in a hosted environment, several of the Security Six are handled on the server side: multi-factor authentication, encryption, managed backups, and anti-virus and firewall protection where your data actually lives. A hosted setup also gives you secure remote access, which reduces how much you lean on a patchy VPN. It does not cover everything. The laptop or desktop you connect from still needs its own anti-virus, its own encryption, and a VPN when you are on an untrusted network, because those protect the device in your hands, not the server. Think of hosting as covering the data side of the list, with the endpoint side still yours.
This article is general information, not legal or compliance advice. Confirm your obligations against the current IRS guidance and a qualified advisor.
If you want the server side of these controls handled in one place, that is part of what hosting does. You can get a personalized quote or book a short call whenever it is useful.
Book a 15-minute call → to talk through which of the Security Six hosting can cover for your firm.


Leave a Reply