MFA blocks a stolen password from becoming a login, EDR catches an attacker who gets in anyway, and encryption makes stolen data unreadable. IRS Publication 4557 treats all three as baseline controls a firm’s Written Information Security Plan (WISP) has to document, not optional extras.
Key takeaways
Opting out of MFA in your tax software is an FTC Safeguards Rule violation, not a preference.
EDR watches behavior and catches ransomware that antivirus alone misses.
Encryption protects data in transit and at rest so a stolen device isn’t a readable breach.
IRS Pub 4557 requires all three as documented WISP controls, not suggestions.
VeritSpace and VeritComplete include all three by default; VeritShield WISP documents them in 5 business days.
Table of Contents
What Is MFA and Why Does the IRS Require It?
Multi-factor authentication (MFA) requires a second proof of identity, usually a code sent to a phone or app, before anyone can log in. It matters because passwords get stolen constantly through phishing and data breaches, and MFA means a stolen password alone can’t get an attacker into your systems.
Credential theft is the single most common way tax preparers get breached. A password can leak from a phishing email, a breach at an unrelated site, or simple guessing, and none of that matters if the login also needs a code from a device the attacker doesn’t have.
Publication 4557 lists MFA as one of the baseline controls a WISP must document. It’s not framed as a recommendation. An auditor or an insurer reviewing your WISP will ask whether MFA is enabled on email, remote access, and any system touching client data, not whether you’ve considered it.
Is Turning Off MFA in Your Tax Software a Safeguards Violation?
Yes. Turning off MFA in your tax software puts your firm in violation of the FTC Safeguards Rule. IRS Publication 4557 lists MFA as a baseline WISP control, and 16 CFR 314 goes further: since June 9, 2023, MFA is a federal requirement on any system, application, or device that touches customer information.
Professional tax preparers count as financial institutions under the Safeguards Rule, and 16 CFR 314.4(c)(5) requires multi-factor authentication for anyone accessing any information system that holds customer data. Tax software vendors now build MFA into their products, and Intuit’s Tax Pro Center spells out what that means for the opt-out screen: declining MFA inside the software is a violation of the rule, not a setting the firm is free to change.
The Safeguards Rule allows exactly one alternative. Your firm’s designated Qualified Individual can approve, in writing, an access control that is reasonably equivalent to MFA or more secure. Wanting fewer login prompts during busy season doesn’t meet that bar. Without a documented equivalent control, leave MFA on and record it in your WISP as an implemented control under IRS Pub 4557.
“I have found Verito’s cloud-based infrastructure to be incredibly beneficial, as it means I don’t have to worry about maintaining any software or dealing with security requirements.” Rizwan M., Owner, Riz & Co Certified Public Accountants · G2, Oct 2025
Does MFA on the Tax App Count, or Does the Workstation Need It Too?
No, MFA on the tax app alone doesn’t cover you. The FTC Safeguards Rule (16 CFR 314) applies to any system holding customer information, so the workstation login, email, remote access, and file storage each need MFA too. Client data lives in all of those places, and the requirement follows the data.
The scope in 16 CFR 314 is “any information system,” not “the tax application,” and client data rarely stays inside the tax app. Returns get exported as PDFs to a desktop folder. Engagement letters and source documents sit in email. Staff sign in from home over remote desktop. The rule expects MFA in front of each of those sign-ins.
Five logins carry client data in a typical firm:
Tax software. The built-in MFA, kept on. This is the one login most firms already have covered.
Workstation or hosted server sign-in. The Windows desktop where the tax app, exports, and client PDFs live. App-level MFA does nothing for a stolen Windows password.
Email. Client documents plus the password-reset links for every other account. An unprotected mailbox undoes MFA everywhere else.
Remote access. VPN and remote desktop connections from home or a client site.
File sharing and client portals. Anywhere returns and source documents get uploaded or stored.
System
Does tax-app MFA cover it?
What needs its own MFA
Tax software
Yes
The app’s built-in MFA, kept on
Workstation or hosted server
No
The Windows sign-in itself
Email
No
The mailbox login (Microsoft 365 or Google Workspace)
Remote access
No
The VPN or remote desktop connection
File sharing and client portals
No
Each portal or storage account
Covering every login for every employee is exactly the kind of task that slips between tax seasons. VeritGuard enforces MFA across the devices it manages, so workstation coverage doesn’t depend on each employee remembering to opt in. VeritSpace puts MFA on the server login itself: the hosted desktop where Drake, UltraTax, or QuickBooks runs sits behind a second factor on every tier, next to 256-bit encryption. Both are designed to support IRS Pub 4557 and FTC Safeguards requirements, with the controls documented where a WISP review or an insurer’s questionnaire can see them.
“Verito has allowed my firm to maintain security and support remote work, featuring aspects such as a backup server and a central sign-in location for employees.”
April W., Owner, AAA Business Services LLC · G2, Oct 2025
What Is EDR and How Is It Different From Antivirus?
Endpoint Detection and Response (EDR) watches behavior instead of matching known malicious files. It flags a program doing something suspicious, like suddenly encrypting hundreds of files, even if that specific program has never been seen before. Antivirus can’t do that.
Ransomware increasingly uses techniques that don’t trip traditional antivirus, because antivirus is built to recognize known threats, not new behavior. EDR catches the pattern of an attack in progress, which is often the only way to stop it before it spreads across a network.
Ransomware against tax preparers isn’t a hypothetical. It’s one of the most common breach types reported to the IRS Identity Theft office each year, and EDR is the control most likely to interrupt an attack mid-execution rather than after the damage is already done.
What Does Encryption Protect and When Does It Matter Most?
Encryption scrambles data so a stolen file, laptop, or backup is unreadable without the key. It matters in two states: encryption in transit, for data moving between systems, and encryption at rest, for data sitting on a server or backup drive.
A stolen laptop or a hacked backup only becomes a breach if the data on it is readable. Encrypted data that falls into the wrong hands is functionally useless to whoever took it, which is why encryption is one of the few controls that limits damage after something has already gone wrong.
Client Social Security numbers, bank details, and tax records are exactly what encryption is built to protect. That’s also why it shows up in nearly every compliance framework a firm might face, not just the IRS’s.
How Do MFA, EDR, and Encryption Work Together in a WISP?
None of the three controls works alone. MFA stops someone from getting in with a stolen password, EDR catches an attacker who gets in anyway, and encryption limits the damage if data is accessed or stolen despite both. A WISP that lists all three without implementing them fails an IRS audit or an insurer’s questionnaire.
Each control covers a different stage of an attack:
MFA stops unauthorized login even when a password is compromised.
EDR detects and interrupts malicious behavior already inside the network.
Encryption limits exposure if data is accessed or removed regardless of the first two controls.
Control
Stage it protects
What it stops
IRS/insurer relevance
MFA
Login
Stolen or guessed passwords
Baseline WISP control under Pub 4557
EDR
In-network activity
Ransomware and novel attack behavior
Increasingly required on cyber insurance applications
Encryption
Data at rest and in transit
Readable data after theft
Protects SSNs, bank details, and tax records specifically
An insurer’s questionnaire increasingly asks about the same three controls the IRS requires in a WISP. Firms that treat them as three separate checkboxes instead of a stacked system tend to fail both reviews at once.
“I value the robust firewall that Verito provides, helping me maintain compliance with WISP and ensuring the protection of client data.”
Carrol G., Owner, Gatlin Tax, Ltd · G2, Nov 2025
Do VeritSpace and VeritComplete Include MFA, EDR, and Encryption by Default?
Yes. Firms hosted on VeritSpace or bundled under VeritComplete get MFA, EDR, and encryption built into the environment from day one, not a separate project the firm has to manage. VeritShield WISP produces audit-ready documentation of those controls in 5 business days.
That means a firm doesn’t configure these controls piecemeal across a patchwork of vendors. They’re part of the hosting environment itself, alongside 256-bit encryption, SOC 2 certification, and IRS Pub 4557 compliance built into every VeritSpace tier.
If something does go wrong, support isn’t a ticket queue. Every request reaches a real person in under 60 seconds, with 92% resolved on the first touch.
Sponsored by Verito
Verito hosts Drake, Lacerte, UltraTax, and QuickBooks on private dedicated servers — with 24/7 support from techs who actually know tax software. Used by 1,000+ accounting firms.
See plans from $69/user →
“The customer support team at Verito is very quick to respond and consistently courteous, providing excellent support that enhances my overall experience.”
David C., Owner, David Cleaver-Bartholomew, EA · G2, Oct 2025
How Do I Know If My Firm’s Current Setup Would Pass an IRS or Insurer Review?
The fastest check is matching your current MFA, EDR, and encryption setup against what Pub 4557 and a typical insurer questionnaire ask for by name, not by whether you have generic security software installed. A firm running all three, documented in a current WISP, passes both. A firm missing documentation, even with the controls in place, often doesn’t.
Not sure whether your firm’s current setup would hold up? Get a compliance check-in with Verito and find out what an IRS review or an insurer’s questionnaire would actually flag.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.
QuickBooks Desktop and a tax suite like Drake, UltraTax, Lacerte, ProSeries, or CCH can share one dedicated private server. How isolation and sizing keep it fast.