Over the past several months, we’ve met with CPA firms across Oklahoma.
Different firm sizes.
Different tax software.
Different client bases.
Same assumption.
“We’ve never had a breach.”
That statement feels responsible, but in 2026, it’s no longer sufficient.
What “We’ve Never Had a Breach” Often Means
When we review a CPA firm’s security posture and documentation, we typically find:
- Backups are running — but haven’t been formally tested and documented.
- Multi-factor authentication is partially implemented.
- Vendor access hasn’t been formally reviewed.
- Administrative credentials are aging.
- Risk assessments were completed once — but not consistently updated.
- No independent testing has validated exposure.
Client work continues.
Tax returns are filed.
Payroll runs.
Nothing has triggered an incident.
So it feels stable.
But stability in accounting isn’t about uptime alone.
It’s about defensibility.
SB 626 Changes the Risk Equation
As of January 1, 2026, Oklahoma’s SB 626 strengthens requirements around safeguarding personal information and breach notification timelines.
CPA firms are custodians of some of the most sensitive personal data in the state:
- Social Security numbers
- Income records
- Banking information
- Employer data
- Dependent information
If that data is exposed, notification obligations are immediate and public.
Regulators don’t ask: “Did your IT provider mean well?”
They ask:
What safeguards were in place?
When were they reviewed?
Where is the documentation?
Comfort is not a defense.
Documentation is.
Stability vs. Liability
CPA firms operate on trust.
Clients assume their financial life is secure.
When IT environments remain unchanged simply because “nothing has happened,” that isn’t stability. It’s unvalidated exposure.
Ransomware during tax season is not theoretical.
Phishing campaigns targeting accounting staff are not rare.
Cyber insurance carriers are tightening underwriting standards specifically around financial data custodians.
Deferred modernization becomes emergency response.
Emergency response becomes expensive.
In a CPA firm, credibility is everything.
Five Questions Every CPA Firm Should Be Able to Answer
These are not IT questions.
They are fiduciary questions.
- When was our last documented risk assessment?
- Can we clearly demonstrate how we safeguard client financial data under both federal expectations and Oklahoma SB 626?
- When were user access permissions formally reviewed?
- Has an independent penetration test validated our security posture?
- If a breach occurs tomorrow, do we have a documented and leadership-approved response plan?
If those answers rely on assumption instead of documentation, the exposure is not hypothetical.
It is regulatory.
What Responsible Modernization Looks Like
Responsible modernization for CPA firms means:
- Regular documented risk assessments.
- Consistent enforcement of multi-factor authentication.
- Vendor oversight documentation.
- Validated backup restoration testing.
- Continuous monitoring.
- Secure communication systems, including VoIP platforms with redundancy during peak tax season.
This is not about fear, it is about protecting client trust, regulatory standing, and firm reputation.
Because in accounting, mistakes don’t just cost money, they cost credibility.
Comfort feels safe.
But under SB 626, comfort without documentation becomes liability.
If your firm’s IT “works,” that’s not a reason for alarm, but it is a reason to verify. And verification is what separates stability from exposure.