Guide
The FTC Safeguards Rule: A Compliance Checklist for Accounting Firms
A plain-language FTC Safeguards Rule checklist for accounting and tax firms: what the rule requires, who it applies to, and how a normal firm actually complies.
July 23, 2026
Independent rankings and reviews for accounting firms
By Dale Hoffman · Published June 5, 2026
Accounting firms are not optional targets. A firm's servers hold Social Security numbers, bank details, and enough financial history to impersonate every client on the books. The FTC Safeguards Rule requires firms to run a written security program, and IRS Publication 4557 spells out what the IRS expects a tax practice to have in place. Neither document names products. Both assume you have picked good ones.
This ranking covers the tools we would build a small or mid-sized firm's security stack from. These products are not interchangeable. Each one covers a different layer: watching for intrusions, blocking malicious software on each computer, training the people who click the links, and locking down the passwords everything else depends on. The order reflects how much impact each layer has for a typical firm, not which product beats the others at its own job.
Best for firms that want someone watching for intrusions
Best advanced antivirus for firm-owned computers
Best for training staff to spot phishing
Best password manager for staff who resist new software
Best password manager for firms that want tight admin control
1. Best for firms that want someone watching for intrusions
Managed detection and response, meaning a service where real analysts watch your computers for signs of intrusion, built for small businesses instead of enterprises.
Huntress sells managed detection and response, which means software on each computer feeds signals to a security operations team, and human analysts investigate anything suspicious. That last part is the point. Most small firms can install security software, but nobody at the firm is qualified to judge whether a strange process at midnight is a false alarm or an active intrusion. Huntress puts trained people on that question so the firm does not have to guess.
The service is deliberately aimed at small businesses. Pricing, reporting, and remediation instructions all assume the reader is an owner or office manager, not a security engineer. When Huntress finds something, the report explains what was found, why it matters, and what to do next, in plain language. For a firm answering to the FTC Safeguards Rule, that paper trail also doubles as evidence that someone is actually monitoring the environment, which the rule expects.
The honest caveats: Huntress is a detection layer, not a complete shield, so it belongs on top of a solid advanced antivirus product rather than instead of one. It is also sold mostly through managed IT providers, so a firm buying directly has a slightly clumsier path. And a solo practitioner with minimal infrastructure may reasonably decide this layer can wait. For everyone else, it is the single highest-impact addition to a firm's stack, which is why it sits first.
2. Best advanced antivirus for firm-owned computers
Business-grade endpoint protection with consistently strong independent test results and central management of every machine in the firm.
Every firm needs advanced antivirus on every computer, full stop. It is the layer that blocks malicious software the moment someone opens the wrong attachment. Bitdefender GravityZone is our pick because it pairs protection that scores consistently well in independent lab testing with a central console, so the owner or IT contact can confirm every machine is protected and updated from one screen instead of walking desk to desk.
The features that matter most to an accounting firm are the ransomware defenses. GravityZone watches for the telltale pattern of files being encrypted in bulk and steps in, which is exactly the disaster scenario that ends tax practices. It also runs quietly. Staff working in tax software during a deadline week will not feel it dragging the machine down.
The main friction is administrative. The console is powerful and correspondingly busy, and a firm without an IT person will spend some time learning it or will want their IT provider to run it. Bitdefender's small-business support also draws mixed feedback. Neither issue changes the fundamentals: this is the strongest baseline protection layer for the money, and every other tool in this ranking assumes it or something like it is already in place.
3. Best for training staff to spot phishing
The market leader in security awareness training and simulated phishing, addressing the way most firms actually get breached.
Most breaches at accounting firms do not start with sophisticated code. They start with an email. A fake IRS notice, a spoofed e-signature request, a client email hijacked mid-thread during filing season. KnowBe4 attacks that problem directly by training staff with short lessons and then testing them with simulated phishing emails that look like the real thing. The people who click get more training. Over time, the whole firm gets measurably harder to fool.
For compliance purposes, KnowBe4 quietly earns its keep. The FTC Safeguards Rule and IRS Publication 4557 both call for security awareness training, and KnowBe4's reporting produces dated records of who completed what. When an insurer or regulator asks how the firm trains its people, there is an answer with documentation behind it.
The weaknesses are human ones. A training platform cannot run itself, and firms that launch it enthusiastically in June often let it stall by January. Some of the video content feels like corporate training from another era. And partners should explain the phishing simulations before they start, because staff who feel tricked by their own firm push back. Used steadily and communicated well, this is the highest-return spend in the stack relative to its cost.
4. Best password manager for staff who resist new software
The password manager your staff will actually use, with a business tier that adds the sharing and oversight a firm needs.
Password reuse is the quietest risk in an accounting firm. One shared spreadsheet of portal logins, one password reused between a personal account and the IRS e-Services login, and the firm's whole client list is one leaked database away from exposure. A password manager fixes this, but only if people use it, and 1Password wins this spot because it is the product staff stop complaining about fastest. It is genuinely pleasant to use, and in our experience that matters more than any feature list.
The business tier covers what a firm needs. Shared vaults hold team logins for client portals, state agencies, and banks, so a departure or new hire is a permissions change rather than a scramble. Watchtower gives the owner a firm-wide view of weak and reused passwords, which is a ready-made agenda item for the security portion of a staff meeting. The design is zero knowledge, meaning everything is encrypted before it leaves your device and 1Password itself has no ability to read it.
The trade-off against Keeper, ranked next, is depth of control. 1Password's admin roles, reporting, and fine-grained sharing restrictions are serviceable but thinner. A firm with a compliance-minded administrator who wants detailed activity records may prefer Keeper. For the typical small firm whose real enemy is staff never adopting the tool at all, 1Password is the safer bet.
5. Best password manager for firms that want tight admin control
Enterprise-grade password management with the granular permissions and audit records compliance-focused firms want, behind a more utilitarian interface.
Keeper approaches the same problem as 1Password from the administrator's chair instead of the end user's. Its strength is control. Roles and policies let the firm decide precisely who can view, use, share, or export each credential, and its reporting records who touched what and when. For a firm writing the security program the FTC Safeguards Rule requires, those records slot directly into the documentation, and during a security review they answer questions before they are asked.
The underlying security is excellent. Keeper is zero knowledge, meaning your data is encrypted on your own device and the company holds no key to read it, and it has maintained a strong reputation and independent certifications over many years. On pure security engineering, nothing separates it from 1Password.
It ranks a step below for two practical reasons. The interface is functional rather than inviting, and in small firms that translates into slower adoption and more owner nagging. And Keeper's habit of packaging useful features as separate add-ons means the firm has to think harder about what it is actually buying. Firms with an administrator who will genuinely use the controls should flip our order. Firms without one should not.
| Huntress | Bitdefender GravityZone | KnowBe4 | 1Password | Keeper | |
|---|---|---|---|---|---|
| Security layer | Intrusion detection with human analysts | Advanced antivirus on each computer | Staff training and simulated phishing | Password management | Password management |
| Who runs it day to day | The vendor's analysts, often via your IT provider | Your IT contact, from a central console | An owner or office manager | Every staff member, light admin work | Every staff member, admin-heavy by design |
| Compliance paperwork it produces | Monitoring and incident reports | Protection status across all machines | Training completion records | Firm-wide password health reports | Detailed access and audit logs |
| Best fit | Firms with several staff and real client data exposure | Every firm, as the baseline layer | Firms whose staff handle client email all day | Firms that struggle to get staff onto new tools | Firms with a compliance-minded administrator |
In plain terms, it requires firms that handle client financial data to run a written information security program. That means naming someone responsible for security, taking stock of what data you hold and what could go wrong, putting protections in place such as access controls, encryption, and multi-factor login, training staff, monitoring for problems, vetting vendors, and having a plan for when something goes wrong. It does not name products. The tools in this ranking are how a small firm covers those obligations in practice.
You need each layer, not necessarily each product. Every firm should have advanced antivirus, a password manager, and some form of staff training. Managed detection and response, the layer where analysts watch for intrusions, is the one we would add as soon as the firm has more than a couple of staff and meaningful client data. Pick one password manager, not two.
Built-in protection has gotten genuinely good for personal use, but a firm needs central management, ransomware-specific defenses, and reporting that shows every machine is covered. That is what business endpoint protection like Bitdefender GravityZone adds. For a practice holding client Social Security numbers, we consider it the floor, not an upgrade.
We ordered the list by impact for a typical small or mid-sized firm: how much each layer reduces the most likely ways a firm actually gets breached, weighted by how realistic it is for a small practice to buy and run the product. Scores reflect each product's quality at its own job, based on public information, independent testing where it exists, and industry feedback. See our How We Review page for the methodology.
Guide
A plain-language FTC Safeguards Rule checklist for accounting and tax firms: what the rule requires, who it applies to, and how a normal firm actually complies.
July 23, 2026
Comparison
1Password and Keeper are the two password managers we recommend most to accounting firms. We compare them head to head across six criteria that matter in practice.
June 17, 2026
Ranking
We ranked the best document management software for accounting firms in 2026. See scores, pros and cons, and which platform fits your practice.
May 13, 2026