{"id":54880,"date":"2022-11-30T10:03:46","date_gmt":"2022-11-30T18:03:46","guid":{"rendered":"https:\/\/lapost.us\/?p=54880"},"modified":"2022-11-30T10:03:46","modified_gmt":"2022-11-30T18:03:46","slug":"security-summit-offers-tools-tips-to-tax-pros-during-national-tax-security-awareness-week-highlights-importance-of-security-plans","status":"publish","type":"post","link":"https:\/\/lapost.us\/?p=54880","title":{"rendered":"Security Summit offers tools, tips to tax pros during National Tax Security Awareness Week; highlights importance of security plans"},"content":{"rendered":"<p>IR-2022-209, Nov. 30, 2022<\/p>\n<p>&nbsp;<\/p>\n<p>WASHINGTON \u2013 With tax season quickly approaching, the Internal Revenue Service and the <a href=\"https:\/\/www.irs.gov\/newsroom\/security-summit\">Security Summit<\/a> partners today urged tax professionals to remain focused on security issues and to review resources available to them, including sample security plans and checklists.<\/p>\n<p>&nbsp;<\/p>\n<p>During National Tax Security Awareness Week, now in its seventh year, the Security Summit partnership of the IRS, state tax agencies and the tax software and tax professional communities work to highlight data security and provide scam prevention tips. Part of the Summit\u2019s effort continues to be focusing tax professionals, including smaller practices, on ways to protect themselves and safeguard client information. Day three of this special week focuses on several important aspects for the tax community to keep in mind.<\/p>\n<p>&nbsp;<\/p>\n<p>\u201cTaxpayer information can be a gold mine for identity thieves. As the Security Summit partners strengthened our internal defenses in recent years, we\u2019ve seen identity thieves shift their focus onto the tax professional community and their client information,\u201d said IRS Acting Commissioner Doug O\u2019Donnell. \u201cSpecific taxpayer information can help a scammer prepare a more authentic looking tax return, so tax professionals maintaining strong security is a critical line of defense for themselves, their clients and the nation\u2019s tax system.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Written Information Security Plan (WISP)<\/strong><\/p>\n<p>The IRS and Security Summit partners remind tax professionals that federal law requires them to have a written information security plan. Earlier this year, members of the Summit\u2019s tax professional team developed a special document that allows practitioners to quickly develop their own written security plans.<\/p>\n<p>&nbsp;<\/p>\n<p>This sample document, a <a href=\"https:\/\/www.irs.gov\/pub\/newsroom\/creating-a-wisp.pdf\">Written Information Security Plan (WISP)<\/a>, can be scaled for a company\u2019s size, scope of activities, complexity and customer data sensitivity. There\u2019s not a one-size-fits-all WISP. For example, a sole practitioner can use a more abbreviated and simplified plan than a 10-partner accounting firm, which is reflected in the sample WISP from the Security Summit group.<\/p>\n<p>&nbsp;<\/p>\n<p>There are many aspects to running a successful business in the tax preparation industry, including reviewing tax law changes, learning software updates and managing and training staff. But an often overlooked but critical component is creating a WISP.<\/p>\n<p>&#8220;There&#8217;s no way around it for anyone running a tax business. Having a written security plan is a sound business practice \u2013 and it&#8217;s required by law,&#8221; said Jared Ballew of Drake Software, co-lead for the Summit tax professional team and chair of the Electronic Tax Administration Advisory Committee (ETAAC). &#8220;The sample provides a starting point for developing your plan, addresses risk considerations for inclusion in an effective plan and provides a blueprint of applicable actions in the event of a security incident, data losses and theft.&#8221;<\/p>\n<p>Security issues for a tax professional can be daunting. The Summit team worked to make this document as easy to use as possible, including special sections to help tax professionals get to the information they need.<\/p>\n<p>Here are a few WISP considerations for tax pros:<\/p>\n<ul>\n<li>Save the WISP in a format others can easily access and read, such as a PDF or Word document.<\/li>\n<li>Make the WISP available to all employees for training purposes.<\/li>\n<li>Store a copy offsite or in the cloud in the event of an incident or natural disaster.<\/li>\n<\/ul>\n<p><strong>Taxes-Security-Together Checklist<\/strong><\/p>\n<p>Unfortunately, tax practitioners remain high-value targets of cybercriminals seeking to steal sensitive tax information. With this in mind, the Security Summit created the <a href=\"https:\/\/www.irs.gov\/tax-professionals\/tax-security-20-the-taxes-security-together-checklist\">\u201cTaxes-Security-Together\u201d Checklist<\/a> to help tax professionals identify basic cybersecurity measures to implement.<\/p>\n<p>&nbsp;<\/p>\n<p>These six easy steps can make a big difference in protecting information, both for tax pros and taxpayers:<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Use anti-virus software and set it for automatic updates to keep systems secure. This includes all digital products, computers and mobile phones.<\/li>\n<li>Use firewalls. Firewalls help shield computers from outside attacks but cannot protect systems in cases where users accidentally download malware, for example, from phishing email scams.<\/li>\n<li>Use multi-factor authentication to protect all online accounts, especially tax products, cloud software providers, email providers and social media.<\/li>\n<li>Back up sensitive files, especially client data, to secure external sources, such as external hard drive or cloud storage.<\/li>\n<li>Encrypt data. Tax professionals should consider drive encryption products for full-drive encryption. This will encrypt all data.<\/li>\n<li>Use a Virtual Private Network (VPN) product. As more practitioners work remotely during the pandemic, a VPN is critical for secure connections.<\/li>\n<\/ul>\n<p><strong>\u00a0<\/strong><\/p>\n<p>For more information on how to protect client information, tax professionals should look to <a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\">Publication 4557, Safeguarding Taxpayer Data<\/a>.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Phishing scams, malware and ransomware present risks<\/strong><\/p>\n<p>For both tax professionals and taxpayers, phishing emails generally have an urgent message and try to direct users to an official-looking link or attachment. But the link instead may take users to a fake site made to appear like a trusted source where it requests a username and password. The attachment may also contain malware, which secretly downloads software that tracks keystrokes and allows thieves to eventually steal all the tax professional\u2019s passwords.<\/p>\n<p>&nbsp;<\/p>\n<p>Some thieves also pose as potential clients and may interact repeatedly with a tax professional and then send an email with an attachment that claims to include their tax information. The attachment may contain malware that allows the thief to track keystrokes and eventually steal all passwords or take over control of the computer systems.<\/p>\n<p>&nbsp;<\/p>\n<p>The IRS warns tax pros not to take any of the steps demanded in these types of email, and to delete the email.<\/p>\n<p>Recipients of these IRS-related scams can report them to <a href=\"mailto:phishing@irs.gov\">phishing@irs.gov<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>Sometimes, phishing scams are <a href=\"https:\/\/www.ftc.gov\/business-guidance\/small-businesses\/cybersecurity\/ransomware\">ransomware schemes<\/a> in which the thief gains control of the tax professional\u2019s computer systems and holds the data hostage until a ransom is paid. The Federal Bureau of Investigation (FBI) has warned against paying a ransom because thieves often leave the data encrypted.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Security plan requirement and recommended data theft plan <\/strong><\/p>\n<p>In addition to the required information security plan, tax pros also should consider an emergency response plan should they experience a breach and data theft. This time-saving step should include contact information for the <a href=\"https:\/\/www.irs.gov\/businesses\/small-businesses-self-employed\/stakeholder-liaison-local-contacts\">IRS Stakeholder Liaisons<\/a>, who are the first point of contact for tax professional data theft reporting to the IRS and to the states.<\/p>\n<p>&nbsp;<\/p>\n<p>IRS <a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p5293.pdf\">Publication 5293, Data Security Resource Guide for Tax Professionals<\/a>, provides a compilation of data theft information available on IRS.gov, including the reporting processes.<\/p>\n<p>&nbsp;<\/p>\n<p>In addition to reviewing IRS\u00a0<a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\">Publication 4557, Safeguarding Taxpayer Data<\/a>, tax professionals can also get help with security recommendations by reviewing <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2016\/NIST.IR.7621r1.pdf\">Small Business Information Security: The Fundamentals<\/a>\u00a0by the National Institute of Standards and Technology. The IRS <a href=\"http:\/\/www.irs.gov\/identitytheft\">Identity Theft Central<\/a> pages for tax pros, individuals and businesses have important details as well.<\/p>\n<p>&nbsp;<\/p>\n<p>Employers can share <a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4524.pdf\">Publication 4524, Security Awareness for Taxpayers<\/a>, with their employees and customers and tax professionals can share with clients.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>For more details on National Tax Security Awareness Week, visit <a href=\"https:\/\/www.irs.gov\/newsroom\/security-summit\">IRS.gov\/securitysummit<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IR-2022-209, Nov. 30, 2022 &nbsp; WASHINGTON&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-54880","post","type-post","status-publish","format-standard","hentry","category-business"],"_links":{"self":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/54880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=54880"}],"version-history":[{"count":1,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/54880\/revisions"}],"predecessor-version":[{"id":54881,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/54880\/revisions\/54881"}],"wp:attachment":[{"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=54880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=54880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=54880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}