Your firm may already have a WISP, MFA, endpoint protection, backups, and an MSP.
But what happens when the next attack exploits a vulnerability nobody knew existed?
That question is becoming more important for CPA firm managing partners as artificial intelligence changes what attackers can do.
OpenAI’s newest Astra model recently crossed the company’s “Critical” cybersecurity capability threshold. According to reporting on OpenAI’s evaluations, the model demonstrated the ability to independently discover previously unknown vulnerabilities and chain multiple weaknesses together during testing. (SecurityWeek)
For a CPA firm, this is not simply a technology story.
It is a client-data, operational-risk, and leadership issue.
Why should CPA managing partners pay attention?
CPA firms hold exactly the kind of information cybercriminals want.
Tax returns. Social Security numbers. Banking information. Payroll records. Financial statements. Business records. Employee information.
The IRS continues to remind tax professionals that protecting this information is not optional. In June, the IRS again stated that tax professionals are required by law to maintain a Written Information Security Plan, or WISP, tailored to the size, complexity, and sensitivity of the information the firm handles. (Internal Revenue Service)
The FTC Safeguards Rule can also apply to tax preparation firms and requires covered organizations to maintain a written information-security program with administrative, technical, and physical safeguards designed to protect customer information. (Federal Trade Commission)
That creates an important question for firm leadership:
Has your security program evolved as quickly as the threat has?
What is changing about the threat?
Traditionally, cybersecurity has depended heavily on recognizing something malicious.
A suspicious file.
Known malware.
An abnormal process.
A known vulnerability.
A recognizable attack pattern.
AI is challenging that model.
An autonomous system can increasingly help discover vulnerabilities, generate or modify exploits, test different attack paths, and adapt when something gets blocked.
A future attack may be:
unknown
polymorphic
credential-driven
living off the land
built around a zero-day vulnerability
changing faster than traditional response cycles
There is no patch for a vulnerability nobody knows exists.
And there may be no detection rule for an attack technique nobody has seen before.
Doesn’t our EDR protect us from that?
EDR remains important.
But Detect and Respond should not be the only thing standing between an unknown attack and the firm’s client data.
The problem is timing.
An attack does not need to remain invisible forever.
It only needs to remain unrecognized long enough to succeed.
Once that happens, the issue is no longer just cybersecurity.
It becomes business interruption.
During tax season, that could mean staff unable to access applications, unavailable client files, disrupted portals, missed productivity, forensic investigation, recovery costs, client communications, and potential regulatory obligations.
The leadership question should therefore become:
What happens if detection fails or arrives late?
What does prevention change?
This is where Isolation and Containment become important.
Detection asks:
“Is this malicious?”
Isolation and Containment asks:
“Should this application or process be allowed to do this at all?”
That distinction matters when the attack is unknown.
AppGuard is a proven endpoint protection solution with a 10-year track record focused on prevention through Isolation and Containment.
The objective is to reduce the usable endpoint attack surface so an unknown exploit has fewer opportunities to execute, persist, access protected resources, move laterally, or begin encryption.
A zero-day may create an opening.
It should not automatically give the attacker freedom once inside.
What does this have to do with compliance?
Compliance should not be treated as a checklist exercise.
A WISP documents how the firm intends to protect sensitive information.
The more important leadership question is whether those safeguards remain effective against the threat environment the firm faces today.
The IRS specifically says a WISP should address areas including information systems and the detection and management of system failures. (Internal Revenue Service)
That means managing partners should periodically ask whether existing controls still provide reasonable protection as attack capabilities change.
Compliance tells you safeguards must exist. Cyber resilience asks whether those safeguards will actually keep the firm operating when something gets through.
What Should Businesses Do Next?
CPA firm leaders should review their cybersecurity plans before the next filing season becomes the next crisis.
Assume detection can fail or arrive late. Review your WISP. Ask whether your current endpoint strategy includes prevention in addition to detection. Reduce unnecessary endpoint execution freedom. Review privileged and remote access. Segment critical systems. Protect credentials and browser sessions. Test backups and incident-response procedures.
And ask your MSP or security provider this question:
“If an attack exploits a vulnerability nobody knows exists, what prevents it from turning access into damage?”
That is the question firms need to answer before tax season, not during it.
Business owners who want to better understand how prevention-first security can stop attacks before damage occurs should talk with CHIPS about how AppGuard can help prevent incidents like this through Isolation and Containment.
September 8, 2026