Your inbox holds client bank details, SSNs, and payment authority — and attackers know it. Here's the practical checklist, from free MFA settings to automated monitoring for your written security plan.
Section 01
A CPA firm's inbox may contain client bank details, payroll files, tax documents, and payment instructions. A compromised mailbox can expose the firm and affected clients to fraud or data loss.
Accounting and tax firms should determine their current FTC, IRS, state, contractual, and professional obligations from the governing sources and qualified counsel. InboxGuards reports are not a compliance determination or security audit.
Section 02
Use the provider and license controls available to your firm, and assign an owner for each item:
Section 03
Monitoring is an ongoing process. InboxGuards connects read-only with customer-admin authorization and checks supported Microsoft 365 or Google Workspace audit records at roughly 5-minute intervals for configured account-takeover indicators, subject to provider and API limits.
Alerts are timestamped and stored with remediation tracking, and you can download activity reports and a monitoring certificate from the dashboard — useful as supporting documentation for your WISP, your insurer, and client due-diligence questionnaires alike (each of those parties decides what meets their own requirements). For a 10-person firm, it's $480 a year — or $400 billed annually (2 months free).
Section 04
Clients who approve payments from email should use independent payment-verification procedures and evaluate whether authorized monitoring fits their own risks. InboxGuards does not guarantee early warning or protect a professional relationship; it provides alerts and records for configured supported events.
FAQ