CPA Firm Data Breach: Your 72-Hour Response Plan
If you suspect your firm has experienced a data breach, time is your enemy. This guide provides immediate action steps and compliance navigation.
Need Immediate Assistance?
If you're experiencing an active breach, contact our incident response team immediately. We can help you contain the threat and navigate compliance requirements.
Call Now: (702) 727-1125First 24 Hours: Critical Actions
The decisions you make in the first 24 hours will determine whether this becomes a manageable incident or a firm-ending catastrophe.
Stop the Bleeding
- Isolate compromised systems from your network
- Change ALL passwords, especially for email, banking, and client portals
- Secure your backups—attackers often delete backups to increase ransom leverage
- Do NOT pay a ransom without legal and forensic counsel
Assemble Your Response Team
- IT Provider/MSP: Technical containment and recovery
- Breach Counsel: Legal guidance on notification requirements
- Forensics Expert: Independent investigation to determine scope
- Professional Liability Carrier: Report incident immediately (even if unsure of coverage)
Begin Forensic Investigation
- What data was accessed? (Tax returns, W-2s, bank statements, etc.)
- When did the breach occur? (This determines notification deadlines)
- How did attackers gain entry? (Phishing, compromised credentials, software vulnerability?)
- Were backups exfiltrated or encrypted?
State-by-State Notification Requirements
CPA firms often serve clients across multiple states. Each state has different notification thresholds and deadlines. Here are the requirements for Pacific Northwest states:
| State | Notification Deadline | Threshold | AG Notification |
|---|---|---|---|
| Oregon | 45 days maximum | 250+ residents OR any SSN/financial data | Required if 250+ affected |
| California | Without unreasonable delay | Any CA resident | Required if 500+ affected |
| Washington | 30 days | 500+ residents | Required if 500+ affected |
Pro Tip: If you serve clients in multiple states, you must comply with the most restrictive notification requirement. When in doubt, notify within 30 days to all affected individuals regardless of state.
Breach Response Timeline
- Notify your professional liability insurance carrier
- Engage breach counsel to assess legal obligations
- Begin forensic investigation to determine scope
- Notify affected individuals per state law requirements
- File notification with state Attorney General (if threshold met)
- Notify credit bureaus if 1,000+ individuals affected
- Prepare client communication plan
- Complete FTC Safeguards Rule incident response documentation
- Conduct post-incident review and remediation
- Update incident response plan based on lessons learned
FTC Safeguards Rule Obligations
The FTC Safeguards Rule requires CPA firms (as "financial institutions") to have a written incident response plan. If you experienced a breach, you must:
- Document the incident in your Information Security Program
- Notify your board/partners within required timeframes
- Conduct post-incident review to prevent recurrence
Oregon-Specific Requirements
Oregon law (ORS 646A.604) imposes additional obligations on top of federal requirements:
- 45-day maximum notification deadline (stricter than most states)
- Lower threshold for Attorney General notification (250 vs. 500+ in other states)
- Requirement to prove "reasonable safeguards" were in place
Prevention Is Cheaper Than Response
The average cost of a data breach for a CPA firm is $280,000 when you factor in forensics, legal fees, notification costs, regulatory fines, and lost clients. The cost of prevention? A fraction of that.
Our vCISO service helps Oregon CPA firms build the security program that prevents breaches—and provides the documentation you need if one occurs anyway.
Learn About Our Oregon vCISO Services