by Brian Thompson | Jul 8, 2026 | General, Identity Theft, Scams
On July 7, 2026, the IRS and its Security Summit partners launched a five week campaign called “Protect Your Clients; Protect Yourself.” It targets tax professionals squarely, and it makes the case for identity theft protection for tax professionals plainly: small tax and accounting firms are a preferred target for identity thieves, not an afterthought.
Last Updated: July 2026 | Reading time: ~10 minutes
If you run a small tax prep shop, bookkeeping firm, or accounting practice, this campaign is about you. Here is what it covers, why your firm faces exposure, and what to do about it before the next filing season, not during it.
Table of Contents
- Why Tax and Accounting Firms Are a Preferred Target
- What the IRS Summer Campaign Actually Covers
- The Scams Making the Rounds Right Now
- What Smart Firm Owners Are Doing Differently
- What to Look for in Identity Protection Coverage for Your Staff
- Frequently Asked Questions
Why Tax and Accounting Firms Are a Preferred Target
A ten person tax prep firm can hold more concentrated identity data than a mid sized retailer. Names, Social Security numbers, dates of birth, W-2 and 1099 records, bank routing numbers, dependents’ information, sometimes years of returns going back a decade. It is a single, dense target, and most small firms protect it with a shared office password and whatever antivirus came with the computer.
The Security Summit has run this awareness campaign for eleven years for a reason. Tax professionals keep getting hit, and the fallout does not stay contained to the firm. A single breached preparer can hand a criminal ring the raw material to file fraudulent returns in hundreds of clients’ names, each one a multi month recovery process for the victim and a reputational hit for the firm that lost the data.
Small firms also face structural exposure in ways large firms do not. Fewer dedicated IT staff. No formal incident response plan. Client documents moving over email instead of a secure portal. Seasonal staff get a login in January and are gone by May, sometimes with nobody ever revoking their access.
What the IRS Summer Campaign Actually Covers
The 2026 “Protect Your Clients; Protect Yourself” series runs five weekly releases, timed to coincide with the IRS Nationwide Tax Forums running through September (Chicago, then New Orleans August 4 to 6, New York City August 18 to 20, Orlando September 1 to 3, and San Diego September 15 to 17). Here is what each week covers, according to the IRS:
- Week one, new and emerging scams. IRS impersonation by email, text, and spoofed calls. Misleading “tax hack” advice circulating on social media. Fake prospective clients sending malware disguised as tax documents. Phishing attempts targeting a preparer’s EFIN, PTIN, or CAF number specifically.
- Week two, phishing, spear phishing, and whaling. How targeted attacks differ from generic phishing, and the “Security Six” protections the IRS recommends every firm put in place.
- Week three, the written security plan. Federal law requires paid preparers to maintain a Written Information Security Plan. The IRS is using this week to push firms that do not have one, or have not updated it, to fix that.
- Week four, tools that actually help. Multi factor authentication, Identity Protection PINs, IRS Online Accounts, and Tax Pro Accounts.
- Week five, recognizing and reporting theft. What the early signs of a breach look like and the reporting steps that limit the damage, including contacting your local IRS Stakeholder Liaison and your state tax agency through the Federation of Tax Administrators.
The “Security Six,” Explained
Week two is worth pausing on, because the “Security Six” gets referenced constantly in tax industry guidance without much explanation of what it actually requires. Under IRS Publication 4557, the six baseline protections are:
- Anti-virus and anti-malware software, kept on automatic updates so it catches newly identified threats daily.
- Firewalls, both hardware and software, to block unwanted traffic before it reaches a workstation or server.
- Multi factor authentication, on every system that touches client data, not just email.
- Backup software or services, with critical files routinely copied to an external or cloud source.
- Drive encryption, so a stolen or lost laptop does not hand over readable client files.
- A virtual private network, for any connection made outside the office, including a preparer’s home Wi-Fi during a slow afternoon.
None of this is new advice, exactly. What is new is the IRS spelling out, in public, that tax professionals remain a soft and valuable target heading into the back half of 2026.
The Scams Making the Rounds Right Now
Per the IRS’s week one release, four patterns account for most of the current activity against tax professionals:
- IRS impersonation. Scammers use email, text, direct messages, and spoofed caller ID, sometimes with computer generated voices, to push preparers or their staff toward a malicious link or a request for sensitive information.
- “New client” phishing. A fraudster poses as a prospective client and sends an attachment disguised as a tax document. Opening it hands over firm and client data at once.
- EFIN, PTIN, and CAF number theft. These are the credentials that let a preparer file on a client’s behalf. Once stolen, they let a criminal file fraudulent returns that look, on paper, like they came from a legitimate practice.
- Viral tax misinformation. Social media “hacks” convince taxpayers to claim credits they do not qualify for or file with false information, which then lands on the preparer’s desk as a compliance headache, and sometimes as an accusation that the preparer enabled fraud.
What Smart Firm Owners Are Doing Differently
The firms that stay off next year’s breach notification list treat this as an operating requirement, not a once a year training video.
Write the security plan and actually follow it. A Written Information Security Plan is a federal requirement for paid preparers, not a nice to have. If your firm does not have a current one, the IRS publishes a template. If you have one from three years ago, assume it is out of date.
Turn on multi factor authentication everywhere client data lives. Tax software, email, cloud storage, the works. This single step stops the majority of credential based break ins.
Verify before you trust a “new client.” A legitimate prospective client will tolerate a phone call to confirm identity before you open their attachment. A fraudster will not.
Lock down access the day someone leaves. Seasonal and part time staff need offboarding discipline as much as full time employees. Revoke logins the day the engagement ends, not whenever someone gets around to it.
Protect the people who handle the data, not just the data itself. Your staff’s own identities are a target too. A preparer or bookkeeper whose personal Social Security number ends up on the dark web is one incident away from a very bad month, and a distracted employee is a bigger risk to your clients’ data. Offering identity theft protection as a benefit is not just goodwill. It is a control that keeps your team focused and your firm out of a second, unrelated breach story.
What to Look for in Identity Protection Coverage for Your Staff
If you are evaluating identity protection as a benefit for your firm, whether it is three employees or thirty, the features that matter are the same ones that matter for any small business:
- Dark web monitoring, so you find out if an employee’s credentials or Social Security number are circulating before a criminal uses them.
- SSN and credit file monitoring, which flags new accounts or inquiries early, the first sign something is wrong.
- Fully managed recovery, meaning a dedicated advocate handles the calls, disputes, and paperwork if a criminal compromises an employee’s identity, rather than handing them a checklist during your firm’s busiest season.
- Family plan coverage, since a compromised household member’s finances can distract an employee just as much as their own.
- U.S. based support with real response times, measured by how fast someone picks up, not by a features list.
Frequently Asked Questions
Does my small tax practice really need a Written Information Security Plan?
Yes. It is a federal requirement for any paid tax return preparer, regardless of firm size. The IRS publishes a template (Publication 5708) that firms can adapt rather than build from scratch.
What is an EFIN, and why do criminals want it?
An Electronic Filing Identification Number is what the IRS issues to authorize a preparer to e-file returns. A stolen EFIN lets a criminal file fraudulent returns that appear to come from a legitimate firm, which is why this year’s campaign calls out phishing attempts targeting EFINs, PTINs, and CAF numbers specifically.
What should I do if I think my firm has been breached?
Contact your local IRS Stakeholder Liaison immediately so the IRS can move to block fraudulent returns filed under your clients’ names. Also report the incident to your state tax agency through the Federation of Tax Administrators’ data breach reporting page, and follow the FTC’s data breach response guidance for businesses.
Is offering identity theft protection to my employees actually useful, or just a nice-to-have benefit?
Both. For a firm handling client SSNs and financial data all day, a compromised employee identity creates both a distraction and a risk vector at the same time. Coverage that includes dark web monitoring and managed recovery limits how much of your busiest season gets eaten up by one employee’s personal identity theft crisis.
What exactly are the IRS’s “Security Six” protections?
Six baseline controls defined in IRS Publication 4557: anti-virus and anti-malware software, firewalls, multi factor authentication, regular data backups, drive encryption, and a VPN for remote connections. The IRS treats these as the minimum, not a finish line.
How should I handle security for seasonal or part-time tax prep staff?
Treat their offboarding with the same discipline as a full time employee’s. Revoke login credentials, tax software access, and shared drive permissions the day the engagement ends, not weeks later when someone remembers to do it. A seasonal preparer’s forgotten login is one of the more common ways firm data stays exposed long after filing season closes.
The Window to Fix This Is Now, Not January
Tax season is when firms discover their security gaps. Summer is when firms actually have time to close them. The IRS is using its five week campaign to make that case publicly. Use the slow season to write or update your security plan, turn on multi factor authentication, and decide whether your team has the identity protection coverage they need before next filing season puts everyone back under pressure.
If you are evaluating identity theft protection as a benefit for your practice’s employees, defend-id works with small businesses to provide identity theft protection and recovery services for employees and their families. A dedicated, U.S. based recovery advocate is what matters most when something actually goes wrong.
Articles related to protecting tax and accounting firms
by Brian Thompson | Jan 21, 2026 | Breach, General, Identity Theft
Remote work security best practices are essential for protecting company data when employees work outside a traditional office environment. Whether working from home full-time, logging in after hours, or traveling for business, remote employees face increased cybersecurity risks that don’t exist inside a monitored corporate network. That’s why strong security habits—combined with clear company policies—are now critical to reducing cyber risk and preventing costly incidents.
When employees operate outside a monitored corporate network, credentials, devices, and internet connections are more exposed to attack. That’s why strong remote work security practices are no longer optional—they’re a core part of protecting both employees and the organization.
This guide breaks down the most important remote work security best practices every employee should follow to reduce cyber risk and avoid costly incidents.
Table of Contents
- Why Remote Work Increases Cyber Risk
- Password Security: Your First Line of Defense
- Why Multi-Factor Authentication Matters
- Using Personal Devices and Email for Work
- Securing Your Home and Public Internet Connections
- Keeping Devices Updated and Protected
- Why Remote Security Is a Shared Responsibility
Why Remote Work Increases Cyber Risk
Inside the office, employees benefit from layered protections—firewalls, monitoring tools, and controlled access environments. Outside that environment, those safeguards are often missing or weaker.
Remote workers face increased exposure to:
- Credential theft through phishing and social engineering
- Unsecured or poorly configured home networks
- Public Wi-Fi attacks while traveling
- Outdated devices missing critical security patches
Because attackers know remote workers are easier targets, they actively look for weak passwords, unprotected devices, and unsecured connections.
Password Security: Your First Line of Defense
Passwords remain one of the most common ways attackers gain access to systems—and one of the easiest weaknesses to exploit.
Strong password security means:
- Using unique passwords for every work account
- Avoiding reused or recycled passwords
- Storing credentials in a secure password manager
- Never sharing passwords through email, chat, or text
A single compromised password can expose email, internal tools, and sensitive employee or customer data. That’s why passwords should always be treated as sensitive credentials—not convenience shortcuts.
Why Multi-Factor Authentication Matters
Even strong passwords can be stolen. That’s why multi-factor authentication (MFA) is critical for remote workers.
MFA adds a second verification step—such as a mobile prompt or authentication app—before access is granted. If a password is compromised, MFA can stop an attacker from moving forward.
Best practice:
- Enable MFA on all work accounts, especially those accessing sensitive or personal data
- Use authentication apps instead of SMS codes whenever possible
- Treat MFA prompts you didn’t request as potential warning signs
Layering passwords with MFA significantly reduces the risk of account takeover and data breaches.
Using Personal Devices and Email for Work
When working remotely, it can feel easier to use personal laptops, phones, or email accounts. Unfortunately, this often increases risk.
Business-managed devices and email systems typically include:
- Endpoint security and monitoring
- Automated updates and patching
- Controls to prevent data loss
Personal devices may lack these protections, making it easier for attackers to access work data. Employees should always follow company policies regarding device and email use and confirm what is—and isn’t—approved.
If policies aren’t clear, employees should ask before using personal systems for work tasks.
Securing Your Home and Public Internet Connections
Internet security matters just as much as device security.
Remote workers should be mindful of:
- Public Wi-Fi at airports, hotels, or cafés
- Residential home networks using default router settings
- Unencrypted connections that expose traffic
Best practices include:
- Using a company-approved VPN on public networks
- Securing home routers with strong passwords and updated firmware
- Avoiding sensitive work tasks on open Wi-Fi whenever possible
A secure connection helps prevent attackers from intercepting credentials or monitoring activity.
Keeping Devices Updated and Protected
Outdated software is one of the most common attack vectors. Operating system and application updates often include security patches designed to close known vulnerabilities.
Remote workers should:
- Enable automatic operating system updates
- Install updates promptly when released
- Ensure endpoint security or antivirus software is installed and active
- Keep security tools updated to detect the latest threats
These steps help block malware, ransomware, and credential-stealing attacks before they cause damage.
Why Remote Security Is a Shared Responsibility
Remote work security isn’t just an IT problem—it’s a shared responsibility between the organization and every employee.
Employees play a critical role by:
- Following password and MFA best practices
- Using approved devices and tools
- Securing their internet connections
- Keeping systems updated and protected
Organizations that support employees with clear policies, ongoing training, and identity protection services reduce both risk and disruption. Solutions like defend-id help support employees before, during, and after identity-related incidents—reducing recovery time and lost productivity.
Final Thoughts
Remote work is here to stay—but so are the risks that come with it. By following strong password practices, enabling multi-factor authentication, securing devices and networks, and understanding company policies, employees can significantly reduce cyber risk.
The goal isn’t perfection—it’s layered protection. Small habits, applied consistently, make a meaningful difference in keeping both employees and organizations secure.remote work security best practices.
Articles related to remote work security best practices
by Brian Thompson | Oct 29, 2025 | General, Identity Theft
When identity theft strikes, the panic can be paralyzing. Credit cards are frozen, accounts locked, and hours vanish chasing answers. A fully-managed recovery service changes that story—replacing stress with expert guidance and measurable peace of mind.
While many vendors claim “full service,” few define what that really means. Here’s how defend-id sets the gold standard for true fully-managed recovery.
What “Fully-Managed Recovery” Really Means
Fully-managed recovery means a dedicated, certified Recovery Advocate does the work for the victim—filing disputes, contacting creditors, and restoring identities to pre-theft status.
Unlike DIY credit-monitoring add-ons, this model provides:
-
24/7/365 access to recovery support and your secure Identity Care Center
-
Coverage for every fraud type—financial, medical, criminal, even acts of terrorism
-
Certified professionals (FCRA, FACT Act, CITRMS, licensed PI credentialed)
-
Limited Power of Attorney authority, allowing advocates to act directly on the victim’s behalf
-
12 months of post-resolution follow-up to confirm every record is cleared
That’s peace of mind—and productivity—restored.
| Feature |
What It Delivers |
| Customized Recovery Plan |
Personalized steps for each fraud type—medical, financial, criminal, or synthetic ID. |
| Identity Care Account |
Secure portal to track case progress, upload documents, and message your advocate 24/7. |
| Credit Monitoring & Alerts |
Ongoing alerts during and 12 months after recovery to prevent repeat fraud. |
| Credit Freeze & Dispute Assistance |
Hands-on help placing/removing freezes and correcting bureau errors. |
| Lost-Document Replacement |
Rapid replacement of IDs, cards, and records to minimize downtime. |
| Three-Generation Family Coverage |
Extends to spouses, dependents, and parents — with 12 months of service after death . |
Why It Matters to Employers
For HR and finance leaders, identity theft isn’t just personal—it’s operational.
Each incident can consume 30–100 employee work-hours in lost productivity and stress .
Providing fully-managed recovery as a paid or voluntary benefit:
-
Shields employees (and families) from financial chaos and anxiety
-
Demonstrates a duty-of-care culture that strengthens retention and employer brand
-
Costs ≤ $5 PEPM, far less than even a single unresolved incident
-
Reduces liability exposure under expanding state privacy laws
The defend-id Difference
defend-id delivers enterprise-grade recovery to groups as small as two employees.
Every member receives the same certified-advocate experience Fortune 500 companies rely on—now scaled for mid-market organizations.
You’re not buying another monitoring app; you’re giving your team a place to turn when it matters most.
Conclusion
Monitoring tells you something went wrong.
Fully-managed recovery ensures it’s made right.
By offering a plan that covers every family member and manages every step, employers deliver genuine peace of mind—and reclaim valuable time and trust after an incident.
With defend-id, recovery isn’t a DIY journey; it’s a guided return to normal.
Articles related to fully-managed identity theft recovery
by Brian Thompson | Apr 23, 2025 | Employee Benefits, General, Identity Theft
Small and medium-sized businesses (SMBs) face the same cybersecurity threats as large corporations, without having the same budgets or dedicated security teams. Cybercriminals know this, so they’re increasingly targeting smaller companies with phishing attacks, ransomware, data breaches, and network intrusions. In fact, recent studies show that over 40% of cyberattacks today specifically target small businesses. This is why a VPN for small businesses is critical.
To protect your company from these threats, a Virtual Private Network (VPN) isn’t just beneficial—it’s essential. Remote WorkForce VPN is designed precisely for SMBs, offering business-level security without enterprise-level costs or complexities.
Why VPNs Are Crucial in a Remote and Hybrid World
With more employees working remotely, secure internet access has become vital. Employees regularly access company files, applications, and emails from home offices, airports, coffee shops, or hotels. Unfortunately, these public networks often lack security and are easy targets for cybercriminals.
A VPN solves this problem by creating an encrypted tunnel between an employee’s device and your company resources. As a result, it prevents unauthorized access, protecting credentials, customer information, and intellectual property from theft.
As cyberattacks continue to evolve, a VPN provides your first and most effective defense when employees connect from outside your secure office network.
Why Cybercriminals Target SMBs
You might assume your business is too small to attract cybercriminals. However, attackers think otherwise. Smaller companies often lack proper security measures, have outdated systems, or inconsistent policies. Additionally, many SMBs don’t have a full-time cybersecurity staff or IT team.
Even one compromised device can lead to data theft, costly fines, or significant disruption. Therefore, proactive cybersecurity, starting with a reliable VPN, is essential—not optional.
What Makes Remote WorkForce VPN Different
Many VPN solutions exist, but few cater specifically to SMB needs. Remote WorkForce VPN stands out in several key ways:
-
Easy to Deploy: Our cloud-based VPN can be set up within minutes, whether you have five employees or fifty. There’s no complicated hardware or difficult network configuration needed. Thanks to a simple interface and guided setup, you don’t need to be tech-savvy to secure your business.
-
Fast Performance: Many VPNs slow down internet connections—but not Remote WorkForce VPN. Using advanced traffic optimization and high-speed global servers, our VPN provides seamless, encrypted connections. Consequently, employees can work without delays or interruptions.
-
Strong Encryption: Our VPN uses military-grade encryption (AES-256) and trusted protocols (WireGuard and OpenVPN). This ensures all data remains secure during transmission, whether accessing cloud services or sending confidential documents.
-
Multi-Device Protection: Employees switch between laptops, tablets, and smartphones. Remote WorkForce VPN covers all major platforms—Windows, macOS, iOS, Android—protecting your team no matter their location or device.
-
Affordable Pricing: Most enterprise VPNs are expensive. In contrast, Remote WorkForce VPN offers flexible pricing specifically for small businesses. Thus, you pay only for the features you need, scaling affordably as your company grows.
Compliance and Building Client Trust
If your business manages customer data, financial details, or health records, using a VPN helps you comply with regulations such as HIPAA, GDPR, or PCI-DSS. Secure remote access is often required in compliance audits.
Moreover, clients and partners trust businesses that prioritize data security. Adopting a VPN shows your commitment to protecting sensitive information, helping build lasting credibility and trust.
VPNs and ZTNA: Better Together
Although Zero Trust Network Access (ZTNA) solutions are beneficial, VPNs remain effective, especially as part of a layered cybersecurity strategy.
VPNs are excellent at encrypting traffic and providing secure connections for employees, contractors, or consultants who require extensive resource access. For many SMBs, starting with a VPN and gradually moving toward ZTNA makes practical and financial sense.
Bottom Line: Why You Still Need a VPN for small businesses
In 2025, firewalls and antivirus software alone won’t fully protect your business. SMBs must proactively secure their data, employees, and reputations. Implementing a VPN is among the most effective, immediate, and affordable security upgrades you can make.
Remote WorkForce VPN specifically addresses the unique challenges faced by small businesses. It’s secure, fast, easy to use, and scales as your company grows.
Don’t wait until a cyberattack hits. Let us help you protect your business today.
Related Articles to VPN for small businesses:
by Brian Thompson | Jan 29, 2025 | Breach, General, Identity Theft
The 2024 Data Breach Trends Report from the Identity Theft Resource Center (ITRC) reveals a troubling reality—despite ongoing cybersecurity efforts, data breaches remain at near-record levels, with over 1.7 billion victim notices issued, a staggering 312% increase from the previous year. According to James E. Lee, President of the ITRC, “Stolen and compromised data is so ubiquitous that the number of people and businesses who have not been impacted by a data breach is now dwarfed by the number of victims who have—by a factor of five”. This surge, driven largely by six massive mega-breaches, underscores the urgent need for stronger data security measures, better breach disclosure policies, and widespread adoption of advanced authentication solutions like passkeys.
This report highlights the key trends shaping cybersecurity in 2024, including the industries most affected, the growing impact of AI in cyberattacks, and strategies to enhance data protection for businesses and individuals alike.
Key Findings: The State of Data Breaches in 2024
1. Data Breaches in 2024 Remain at Record Highs
- Total breaches reported: 3,158 (only 44 short of 2023’s record).
- Victim notices issued: Over 1.7 billion notices, representing a 312% year-over-year increase.
- Six major mega-breaches accounted for 85% of all victim notices.
- Despite new privacy laws, data breaches continue to rise.
The rise in victim notices suggests that while breach disclosures may have increased, security improvements remain inadequate.
2. Financial Sector Overtakes Healthcare as the Most Targeted Industry
For the first time since 2018, financial services surpassed healthcare as the most breached industry.
Top Five Breached Industries in 2024
- Financial Services – 737 breaches
- Healthcare – 536 breaches
- Professional Services – 345 breaches
- Manufacturing – 317 breaches
- Education – 162 breaches
While commercial banks and insurance companies saw an increase in attacks, healthcare remained a major target, with breaches exposing sensitive medical and insurance records.
3. Cyberattack Trends and Emerging Threats
Cyberattacks remained the leading cause of data breaches, with stolen credentials, phishing, and AI-driven scams being the most common attack methods.
Most Common Cyberattack Methods in 2024
- Phishing & Smishing Attacks – 455 incidents
- Ransomware – 188 reported cases
- Malware Attacks – 48 breaches
- Credential Stuffing – 29 breaches
Alarmingly, 65% of breach notices failed to disclose the attack method, raising concerns about transparency in cyberattack reporting.
Enhance Protection in 2025
1. Strengthen Authentication and Password Security
One of the most effective ways to prevent data breaches is to eliminate weak passwords and implement stronger authentication methods.
- Adopt Multi-Factor Authentication (MFA) and Passkeys
- Eliminate password reuse across accounts
- Enable biometric authentication for added security
According to the ITRC, many of the biggest breaches of 2024 could have been prevented if organizations had properly implemented MFA and passkeys.
2. Improve Cloud Security Measures
21 major breaches were linked to misconfigured cloud security settings, emphasizing the need for better cloud security controls.
Key Cloud Security Best Practices:
- Implement a Zero Trust security model
- Regularly audit cloud permissions
- Enable automated patching for vulnerabilities
3. AI’s Role in Cybersecurity: A Double-Edged Sword
While AI is helping attackers create more sophisticated cyber threats, it is also being used to enhance cybersecurity defenses.
How AI is Helping Cybersecurity:
- AI-driven monitoring tools detect anomalies faster
- Automated security patches prevent vulnerabilities
- Predictive risk analysis enhances cyber resilience
Organizations should invest in AI-powered cybersecurity solutions to stay ahead of cybercriminals.
Are Data Breach Disclosure Laws Failing?
Despite state and federal breach notification laws, breaches continue to rise, and disclosure remains inadequate.
Key Issues with Current Disclosure Laws:
- 70% of cyberattack-related breach notices lacked details on attack methods
- Publicly traded companies accounted for 76% of all victim notices, despite being only 7% of affected organizations
- Many breaches remain underreported or undisclosed due to regulatory loopholes
However, state privacy laws are beginning to take the lead. Twenty U.S. states have passed comprehensive privacy laws, with eight more taking effect in 2025.
Final Thoughts: The Future of Data Security
The 2024 Data Breach Trends Report highlights ongoing cybersecurity failures but also presents opportunities for stronger data protection.
Key Takeaways for 2024:
- Businesses must implement MFA and passkeys to prevent credential-based attacks.
- Cloud security misconfigurations remain a major vulnerability.
- AI is transforming cybersecurity—for both attackers and defenders.
- Data breach disclosure laws need improvement for greater transparency.
By adopting proactive cybersecurity measures, businesses and individuals can reduce their risk of data breaches and better protect sensitive information.
FAQs on 2024 Data Breach Trends
1. What were the biggest data breaches in 2024?
The largest data breaches included:
- Ticketmaster Entertainment – 560 million victims
- Advance Auto Parts – 380 million victims
- Change Healthcare – 190 million victims
- AT&T – 110 million victims
2. What industries were most affected by cyberattacks in 2024?
The financial services sector had the highest number of breaches, followed by healthcare, professional services, and manufacturing.
3. How can businesses prevent data breaches?
- Use Multi-Factor Authentication (MFA) and passkeys
- Train employees on phishing scams and social engineering
- Monitor and secure cloud environments
4. How is AI impacting cybersecurity?
AI is being used by both attackers and defenders. Cybercriminals leverage AI for phishing and automated attacks, while security teams use AI for threat detection and automated responses.
5. Are state data privacy laws more effective than federal laws?
Yes. Twenty U.S. states have passed strong privacy laws, and more are expected in 2025, filling the gap left by federal inaction.
Articles related to 2024 Data Breach Trends:
by Ryan Smith | Aug 8, 2024 | Employee Benefits, General, Identity Theft
Where do you start with Personal Cyber or Identity Theft Protection? I’ve been getting this question more and more. Agencies I’ve been talking to are noticing the trend:
- Our data is out there due to breach after breach, and it’s only a matter of time before it gets used against us.
- Threat actors are targeting us (especially the elderly and minors) with sneaky social engineering attacks and using AI to get better and faster.
- The fear of ID Theft, Fraud, and the hassle of recovery are on more and more people’s minds.
- With cyber liability becoming more crucial for businesses, offering coverage for individuals makes good sense.
What do people need? And is it a viable option in today’s market? Let’s dig into it in today’s article!
What Do People Need to Protect?
For individuals, cyber threats and fraud risks can be similar to the cyber risks businesses face. It’s easier to start with the “What if I have an incident?” perspective and look at the CIA Triad of Cybersecurity for three easy categories to consider:
- Confidentiality: What data do I need to keep protected, and where is it?
- Integrity: What do I trust, and what if that trusted resource becomes compromised?
- Availability: What technology do I rely on, and what does it mean if it’s not there?
When thinking about home and family, consider these questions:
- Is sensitive data about me out there? What is out there? Is anyone using it?
- Could someone hack my computer or another account? What would they do if they did?
- If I trust a scammer by mistake, can I get any lost money back?
- If someone pretends to be me and accesses my accounts, how do I get my money back and restore my identity? How long will it take, and what do I do in the meantime?
It all comes down to monitoring for suspicious activity and recovering by restoring my identity and getting my money back. The second component is preventing this from happening, which involves awareness, security tools, and being cautious.
The good news is that the same types of coverage that provide monitoring and recovery often offer resources to help individuals reduce their chances of falling victim. Even when we do a good job of protecting ourselves, identity theft can still happen. This is why having protection and recovery services is crucial for everyone.
What Is Often Covered?
When looking into Personal Cyber or Identity Theft Protection, ensure your coverage includes three core capabilities:
- Detect, Monitor, and Alert: Every second counts, so knowing about suspicious activity quickly helps minimize damage. You need a service that can watch for misuse of your information and alert you promptly.
- Recover: Fixing your identity can take time and often pulls people away from work. You may need to change bank accounts, social security numbers, or other items related to your identity and accounts to protect yourself. Repairing your credit or getting money back can be stressful and difficult without experience. A team doing this on your behalf helps you get your life back to normal faster.
- Insure Against Loss: Recovering your identity can be costly. Expenses can mount up, and it can take weeks to get frozen bank accounts active again. Reimbursement insurance can help cover expenses related to restoring your identity.
The level of service behind these capabilities may vary from policy to policy. Many offerings have different levels of coverage offered at various prices to give consumers options. In addition to coverage, consider a few other areas to compare to find the right offering for you:
- Options for consumers (Levels of coverage, Family or Individual options, Group options for Employer Paid or Voluntary, and resources or services available to consumers)
- Price
- Minimum Group Size (when offered to individuals as a group benefit)
- Minimum Book Size
- Commission
- Reseller Costs
- Ease of Enrollment
- Reseller Tools and Resources
- Exclusivity (can you only have one option?)
How Do You Roll It Out?
Depending on the offering you choose, many agencies can find quick wins. I work with defend-id to help agencies become resellers, and here are three strategies I always recommend:
Personal Lines
Start with an announcement and content that will draw in quick wins with your current book of business and give you a good reason to advertise to current prospects. A webinar can bring awareness to the current risks of ID theft and fraud, how attacks happen today, and ways to help people protect themselves with tips, resources, and your new offering. Follow up with articles, newsletters, or tips shared through social media or other channels. For those who don’t engage initially, create a drip marketing or call campaign to share tips and build awareness so they’re primed to consider it upon renewal. Since this type of coverage can be sold to a business as a group benefit, create a referral system to get individuals discounted or paid-for coverage through their workplace.
Groups
If you already sell benefits and don’t offer Personal Cyber or Identity Theft Protection, you may find this easy to add. Many businesses don’t offer it yet, but it can add value for employers since identity theft impacts them too. Employees miss work, are stressed, and it affects others around them. There’s a good incentive for businesses to invest in this for their employees. Ask, “Should we include ID Theft Protection and Recovery?” Employer-paid rates can be as cheap as a cup of coffee per employee per month, so many people are open to it and want it for themselves. If they say no, offer the Voluntary option: “No problem! We have a voluntary option where the employee can get it at a discounted price.”
Cyber Liability
Consider leveling up your cyber liability offer by adding coverage for individuals at the business. If businesses are protecting themselves from cyber risks, one of their biggest challenges is culture. To change the culture, get employees bought in. Investing in them through personal cyber or Identity Theft Protection coverage gets their attention. By adding this, the business can say: “We are building a smarter culture around cybersecurity and want to start by investing in protecting you at home. Our company will provide coverage to help you detect and monitor for suspicious activity and services that will help you recover your identity if needed. This also gives you access to resources to learn how to protect yourself at home. In return, we ask you to take what you learn and apply it here. Help us protect the company and your coworkers from cyber threats by taking part in our training and supporting necessary changes to be safer.”
This approach not only helps change the business’s culture but also adds value to your cyber liability offering without much cost.
Is It Worth It?
I can’t speak to other offerings outside of defend-id, but here are some figures around the value of this kind of offering:
- defend-id’s average group size is 65 employees, with an average rate of $5/employee/month or $325/month.
- Our commission varies between 20% on our Retail (Individual) and Voluntary offerings and 25% on Employer Paid.
- Pricing depends on coverage choices, but every option we have is below $22/month (the average cost is $5/person/month).
- For our offering, there’s no cost to resell or minimum requirements, so there’s no real downside.
The biggest hurdle for many agencies isn’t seeing the financial potential but finding the time to get it going. We work to make it easy for you to implement this as a new offering. Our enrollment process is simple to learn and takes only a moment to set up a group, so the learning curve is minimal.
With strategies like those I laid out above, you should have some ideas about how to get initial sales. We’re always happy to work with agencies to provide templates, content, or other tools to help make launching easy. Just like cyber liability riders vs. a standalone option, having options helps you be more versatile in meeting customers’ needs and nurturing their accounts.
How Do People Get Going?
For defend-id, if you’d like to consider reselling, you can check out our site and sign up as a partner to start reselling right away. Check it out here: defend-id. If you want to explore it further first, I help with onboarding new agencies and would be happy to answer any questions you have. Just message me through my LinkedIn page, below.
Whatever you decide to offer, this is a product many people need today, and I encourage you to look deeper into finding a product that fits you and your agency. Best of luck!
-Ryan
RLSConsulting – strategic partner with defend-id