Skip to content
Corelink
Menu

Endpoint protection for accounting and tax firms

The Safeguards Rule made written security obligations real for practices that had never had them. Endpoint protection is one requirement among several, and it is the one we can supply.

Industries summary

Where this usually goes wrong

  1. 1 The Safeguards Rule obligations were explained once, at a seminar, and nobody left with a clear list of what to actually do.
  2. 2 Protection is installed on most machines but there is no console and therefore no way to show that it is installed on all of them.
  3. 3 Staff work on client returns from home computers that the practice does not license or control.
  4. 4 The written information security plan names controls the practice does not currently have.
  5. 5 A professional liability insurer or a larger client has asked specific questions about endpoint security and the answers are guesses.

What Corelink does

  • License business endpoint protection with a central console, so coverage across every machine is a report rather than an assumption.
  • Count the devices that handle client data, including home machines and any server, before quoting anything.
  • Deliver licences and console access to the practice, in the practice's name, so the Qualified Individual can see the estate.
  • Align renewal dates so that coverage cannot lapse quietly in the middle of filing season.
  • Say plainly which parts of the rule our software does not address, so nobody mistakes a licence for compliance.

What the obligation is

The Federal Trade Commission’s Safeguards Rule sits under the Gramm-Leach-Bliley Act and sets out what a covered business must do to protect customer information. The Commission has stated that professional tax preparers are among the non-banking businesses the rule treats as financial institutions, which brought a large number of small practices inside a regime most of them had never had to think about.

The rule is written in terms of a programme rather than a product. A covered business is expected to maintain a written information security programme, to put a named individual in charge of it, to base it on a risk assessment, to implement safeguards addressing the risks that assessment identifies, to oversee the service providers it relies on, and to keep the whole thing under review. The FTC’s own guidance for small businesses is short and readable, and it is a better first source than any vendor’s summary, including this one.

Note what the rule does not say. It does not name a product, a brand or a category. It does not say “install antivirus”. It describes outcomes and leaves the practice to decide, on the evidence of its own risk assessment, which safeguards meet them. That is why no software purchase can make a practice compliant, and why a reseller claiming otherwise should be treated with suspicion.

We are not a law firm and nothing here is legal advice. A practice should confirm its own obligations with its attorney or its professional body. What follows is only the part we can speak to: the software.

Where endpoint protection fits

Most written information security programmes end up describing, among other things, how the practice protects the computers that client data sits on. In practice that means three things a small practice is routinely unable to demonstrate.

The first is coverage. Not “we have antivirus” but “every device that touches client information is protected, and here is the list”. A console that enumerates machines produces that list. A collection of retail subscriptions does not.

The second is currency. Protection that stopped updating in October is not protection, and on scattered consumer subscriptions nobody finds out until something goes wrong. A managed console shows which machines have stopped reporting.

The third is scope. Practices of this size run on a mix of office desktops, laptops that go home, and personal machines used during filing season. The personal machines are where the gap usually is, and they are the hardest category to account for after the fact.

What we provide

We license business endpoint protection products to the practice, sized to the real device count, and deliver keys and console access by email. The account is registered to the practice, so the individual responsible for your security programme can sign in and see the estate without going through us.

Before quoting we ask what machines exist, what runs on them, and who uses them from where — including home computers used for client work. That conversation takes a few minutes and it is the difference between a licence count that reflects your practice and one that reflects a guess.

We align renewal dates where they are scattered. For a tax practice this is worth more than it sounds: a licence that lapses in the second week of March is a problem discovered at the worst possible moment.

What we do not do

We do not write information security plans, perform risk assessments, or represent that any product makes a practice compliant with anything. We do not administer your console or connect to your machines. We do not receive your clients’ data.

If a supplier offers you compliance as a feature of a software purchase, ask them to put the claim in writing alongside the rule text it relies on. The answer is usually instructive.

How pricing works

Business endpoint products are licensed per device, per year, with the per-device cost falling as device count and term length rise. We quote itemised: product, seats, term, unit price, total. No prices are published on this site, because distributor pricing and publisher promotions both change and a stale number helps nobody.

Common questions

Does the FTC Safeguards Rule apply to our practice?

It applies to businesses the Gramm-Leach-Bliley Act treats as financial institutions, and the Federal Trade Commission has stated that professional tax preparers fall within that definition. Whether it reaches a particular accounting or bookkeeping practice depends on the services that practice provides. We are not a law firm, and this is a question to put to your own attorney or professional body rather than to a software reseller.

Does buying antivirus software make us compliant?

No, and anyone who tells you otherwise is selling something. The rule requires a written information security programme, a named person responsible for it, a risk assessment, oversight of service providers and several other elements. Endpoint protection supports some of the technical safeguards. It is one component, not the programme.

What about staff who work on returns from home?

A home computer used for client work is part of the practice's environment in every way that matters, and it needs to be licensed and visible in the same console as the office machines. Business licences are ordinarily counted per installed device, so a home machine consumes a seat. We ask about this before quoting because it is the most commonly forgotten category.

Can you produce evidence for our written information security plan?

We can supply the licence documentation showing what is licensed, for how many devices, and until when. The console produces the deployment status. What we cannot do is write your plan or attest to your compliance, and we will not pretend to.

Do you have access to our client data?

No. We sell and renew software licences. We do not administer your console, we do not connect to your machines, and we do not receive, store or process your clients' information.

Request a quote for your practice

Tell us how many computers you have and what you run today. We reply with options and pricing during business hours — there is no automated checkout and no obligation.

Optional. Useful if a renewal date is close.

An approximate count is fine.

Whatever is installed today, or "not sure".

Renewal date, compliance requirement, or anything else that matters.

We use your details to answer this request. See our privacy policy.