Insights

Data Loss Prevention for CPA Firms: How to Keep Client Information from Leaving Your Firm

data loss prevention
A CPA firm prevents the loss of client data by controlling how sensitive information moves through email, file-sharing tools, cloud applications, removable devices, remote computers, and AI platforms. A practical data loss prevention program identifies taxpayer and financial information, limits access to people who need it, warns users before they share it, and blocks risky activity when necessary. Backups, phishing protection and antivirus still matter, but they solve different problems. CPA firms need all four working together, supported by clear policies, employee training, and ongoing monitoring.
In my work with Denver accounting firms, I know one misplaced tax return can expose Social Security numbers, birth dates, bank details, and dependent information. Once that data leaves the firm’s control, retrieving the file does not undo the exposure.
That is why prevention must start before someone clicks send, copies a folder, or uploads a document.

What Data Loss Prevention Means for a CPA Firm

Data loss prevention uses policies and technology to identify sensitive information and stop people from sending, copying, downloading, or uploading it in unsafe ways. I think of it as the first gate that information must pass before leaving the firm. If the system sees that you’re sending sensitive data, such as a birth date, Social Security number, or driver’s license number, it will not let it go past that first gate.
Depending on the firm’s rules, the system may warn the employee, require encryption, remove personal details, block the action, or alert a manager. The purpose is to intervene while the firm can still protect the information.

How Data loss Prevention Differs from Backups, Phishing Protection and Antivirus

These protections work at different stages:
  • Data Loss Prevention controls the movement of data. It looks for sensitive information and acts before that information leaves through an email, USB drive, cloud application, file-sharing service, or AI prompt. 
  • Antivirus and endpoint security protect devices. They identify and stop malicious files, suspicious software, and harmful activity on computers. 
  • Phishing protection. Blocks malicious emails that can lead to compromise. 
  • Backups help a firm recover. They restore data after deletion, corruption, equipment failure, ransomware, or another disruptive event. 
  • A broader cybersecurity plan connects the layers. It combines identity protection, access controls, endpoint security, monitoring, backups, policies, training, and incident response. 
A backup can restore a deleted tax file, but it cannot make a copied version disappear from someone’s personal drive. Antivirus may stop malware, but it may not stop an employee from emailing a payroll report to the wrong address. Phishing protection may help prevent an account compromise. Data loss prevention fills that gap, particularly where the human element is involved.

How Client Information Commonly Leaves a Firm

Many incidents begin with ordinary work, not a sophisticated cyberattack. An employee may:
  • Send an unencrypted email that contains a tax return or personal identifiers 
  • Attach the wrong client’s document to a message 
  • Forward a file to a personal email account to work from home 
  • Copy client folders onto a USB drive or external hard drive 
  • Save documents in a personal cloud account or unmanaged home computer 
  • Use an unauthorized file-transfer or synchronization program 
  • Paste client information into a personal AI account 
  • Retain access to folders after changing roles or leaving the firm 
At Onset Solutions, we see how convenience can drive these choices. During a filing deadline, an employee near the Denver Tech Center may seek the fastest way to send a document to a client in Cherry Creek. If the approved process feels confusing, that employee may create a workaround.
The answer is not to rely on perfect judgment under pressure. Firms should make the secure method simple and place technical controls around higher-risk actions.

Build a Data Loss Prevention Strategy Around Financial Data

A data loss prevention strategy defines what information the firm must protect, where that information lives, who needs access, how people may share it, and what the system should do when it detects risk. Technology enforces the rules, but firm leaders must decide what those rules should accomplish.
I recommend starting with the information that could harm a client or the firm if someone exposed it. For most CPA practices, priorities include:
  • Social Security numbers and taxpayer identification numbers 
  • Birth dates and driver’s license numbers 
  • Tax returns and supporting documents 
  • Bank account and routing numbers 
  • Payroll files, wage information, and employee records 
  • Financial statements, general ledger data, and payment information 
  • Login credentials and identity-verification answers 
  • Business ownership, transaction, and valuation information 
Microsoft 365 and other security platforms can recognize many common forms of personally identifiable information. Prebuilt templates provide a useful starting point for Social Security numbers, driver’s license numbers, health information, and other regulated data. However, a CPA firm should customize those policies around its workflows, software, client base, and risk tolerance.
I also bring the firm’s Written Information Security Plan (WISP) into this conversation. The WISP should describe how the firm protects information and responds to risk, while the technical settings should enforce that plan. A generic policy or a disconnected collection of tools will not provide consistent protection.

Control Where Employees Can Move Information

CPA firms can control personal email, USB drives, cloud storage, and unauthorized sharing through a combination of written policy, permissions, endpoint controls, and monitoring. For example, group policy rules can block employees from copying files to USB drives. A firm may prohibit removable storage for most users while approving a specific encrypted device for a legitimate business need. Application controls can also prevent employees from installing unauthorized synchronization or file-sharing software.
Large file transfers can happen quickly. Our team once helped an organization investigate a departing employee who connected an external drive, used file-sync software, moved company files, and deleted the originals. Monitoring logs showed when he connected the drive and how much data moved. Stronger controls can now stop unauthorized software before it runs and alert company leaders.

Give People Only the Access They Need

Access should follow a person’s current job responsibilities. A staff accountant should not receive access to an entire HR folder merely because broad permissions make setup faster. Likewise, an employee who moves from payroll to another service area should not keep payroll access by default.
Firms need a consistent process for three common changes:
  1. Role changes: Review group memberships, shared folders, applications, mailboxes, and administrative rights. Remove access that the new role does not require. 
  2. Remote work: Decide which devices may access firm data and whether users can download files. Microsoft 365 can limit an unmanaged computer to browser-based access. 
  3. Departures: Coordinate HR and IT before the employee’s last day. Disable accounts, revoke sessions, remove remote access, recover devices, transfer needed files, and preserve appropriate logs. 
Fast offboarding matters whether someone works in Lakewood, near Sloan’s Lake, or elsewhere along the Front Range. Location should not delay protection.

Practical Data Loss Prevention Without Slowing the Firm

Security fails when every routine task creates a roadblock. Strong controls should match the risk and guide employees toward a safe action whenever possible.
Microsoft 365 data loss prevention capabilities can inspect email and files for sensitive information. A policy can warn an employee who includes a Social Security number in an email, prompt that person to use encryption, automatically encrypt the message, or block it entirely. The firm can choose how the system reacts and who receives an alert.
Google Workspace offers protection features in certain service tiers. Third-party platforms can add another layer to Microsoft 365 or Google Workspace. Our team can configure Check Point policies to identify sensitive content, customize the response, and maintain logs.
The right action depends on context. A warning may work when someone forgets encryption on an approved message. A hard block may make more sense when someone sends taxpayer data to a personal address. Firms can study normal activity, then tighten rules around clear risks.

Protect Data When Employees Work Remotely

Remote work should not require employees to store client files on personal computers. Many firms give remote users secure access to an office workstation. Data stays in the controlled environment, and IT can end the connection when necessary. This setup can also improve performance for tax and accounting applications that depend on an office server.
For cloud files, browser-only access can let users view and edit online without downloading to an unmanaged device. Multi-factor authentication and session controls add protection.

Include AI in the Firm's Controls

AI has created a new path for information to leave a firm. An employee may paste a client email, tax scenario, payroll file, or meeting transcript into a personal AI account without realizing where that content may go.
I recommend that firms approve specific AI platforms, require business accounts where appropriate, and define which information users may enter. Security tools can block an unapproved platform, redact personal details before submission, stop a prompt, or log activity for review.
The policy should also cover voice-note applications, meeting recorders, transcription services, and video tools. Clear rules help employees use approved tools without guessing.

Monitor Risk Without Disrupting Client Service

The firm should focus monitoring on meaningful actions rather than every employee click. Start with events that create the greatest exposure:
  • Messages that contain sensitive identifiers 
  • Large or unusual file transfers 
  • USB and external-drive connections 
  • Downloads from restricted folders 
  • New file-sharing or synchronization software 
  • Access from unmanaged devices 
  • Uploads to personal cloud or AI accounts 
  • Activity involving an employee who will change roles or leave 
Decide who needs each alert. IT may handle a routine warning, while a managing partner or HR leader may need immediate notice of a large transfer by a departing employee.
We balance security with the way the firm serves clients. We learn how staff exchange documents, work after hours, and support deadlines. Then we protect the highest-risk information without blocking legitimate tasks.

Keep Client Data Inside Your Firm's Control

CPA firms cannot prevent every mistake, but they can prevent one mistake from becoming a serious data exposure. The strongest approach combines clear rules, limited access, secure sharing, managed devices, remote-work controls, AI oversight, monitoring, backups, and endpoint security
The Onset Solutions team helps Denver-area accounting firms understand where sensitive data lives and how it can leave. We then recommend practical safeguards that fit the firm’s employees, applications, and client-service needs.

If you want to know where your firm has gaps, contact Onset Solutions for a free IT assessment. We will evaluate your environment, identify avoidable risks, and help you build a practical plan to keep client information where it belongs. 

Hilary Taylor 

Hilary is the CEO of Onset Solutions. She helps small and mid-sized businesses strengthen their IT strategy, improve cybersecurity, and streamline daily operations. With a practical, people-first approach, Hilary focuses on making complex technology simple, secure, and easy to use for growing organizations. 

Latest Posts

Categories