Skip to main content

Browser isolation for tax and accounting firms

Shield moves page execution off-device. Review WISP fit, client data, credentials, files, and providers.

Estimated reading time: 5 min read
Security Research
Illustration of a shield separating two browser environments

Tax and accounting work often crosses a browser. Client messages, research, portals, and file transfers share that surface. Each workflow needs a clear data boundary.

Quick answer: Shield moves page execution off your device. It can be one assessed WISP control. It does not make a page trustworthy. It does not satisfy a regulation.

This guide provides general security information. It is not legal, tax, or compliance advice. Apply current law and professional rules to your firm's facts.

Start with the actual obligation

The FTC Safeguards Rule guide lists tax preparation firms. They are covered examples. Coverage depends on business activities. Covered firms need a written security program. It must match size, scope, complexity, and customer information.

The IRS issued a current WISP reminder in August 2026. It says tax and accounting professionals need written plans. It highlights risk assessment and tested safeguards. It also covers providers, contracts, and regular updates.

IRS Publication 4557 provides security guidance. Publication 5708 provides a sample WISP. Firms must tailor both to their operations and risks. Neither publication certifies a product.

Browser isolation is not a compliance checkbox. A firm may document an evaluated control. Covered firms still need a risk-based security program. Some provisions exempt firms below the 5,000-consumer threshold.

The threat is broader than one link

Microsoft documented a February 2026 campaign across many industries. It reached over 29,000 users. Those users spanned 10,000 organizations. Accountants and tax preparers were particularly represented.

The February campaign used IRS-themed messages and redirects. It delivered a malicious remote-access tool. Execution could enable credential harvesting. Browser isolation addresses only part of that path. Keep phishing-resistant authentication, email controls, endpoint security, and response procedures.

What Shield changes

Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device. Shield is the relevant mode here. It changes where the page runs.

WorkflowPotential benefitRequired check
Unfamiliar tax-themed linkPage code runs off-deviceVerify the destination before entering data
Tax or client portalA separate browser sessionThe page and provider may receive client data
Upload, download, or clipboardThe page remains off-deviceTransferred data crosses the isolation boundary
Credentials and MFANo change to page identityEntered credentials still reach the page
Desktop deploymentChrome extension entry pointTest permissions and each actual workflow
WISP documentationA tested control can be recordedLegba does not satisfy the program alone

The technical boundary guide explains these limits. The Chrome Web Store listing says files stay remote. That remains true unless users explicitly save them. Saved or copied data crosses the boundary. Sensitive work requires current retention and access verification.

Legba is a Chrome extension for computers. Google says Chrome extensions are not available on mobile devices. Do not plan an iPad workflow around the extension.

Client data changes the review

The FTC requires security reviews for certain external applications. This covers apps transmitting, accessing, or storing customer information. Covered firms must select capable service providers. Contracts must require appropriate safeguards. Firms must periodically reassess provider safeguards. An off-device browser may belong in that review.

AICPA Rule 1.700.040 covers third-party provider disclosures. It applies to members in public practice. Before disclosure, it calls for one safeguard. Use contractual confidentiality and obtain reasonable assurance. Otherwise, obtain specific client consent. IRC Section 7216 governs certain preparer disclosures and uses. Qualified counsel should assess each workflow.

NIST's browser-isolation example documents a privacy tradeoff. Centralized browsing can create privacy and access risks. Isolation does not prove short retention. Verify logs, support access, storage, deletion, and data location.

  • Identify every customer-information field entering the session.
  • Map credentials, files, clipboard data, and downloads.
  • Review the provider's access and retention terms.
  • Confirm hosting locations and subprocessors.
  • Document contracts, monitoring, and reassessment dates.
  • Get qualified advice for Section 7216 questions.

Start with low-data workflows

  • Open an unfamiliar link without signing in.
  • Review a public vendor or research page.
  • Test with a dummy account and sample files.
  • Separate one-time research from daily browser state.

Authenticated tax systems need more review. So do payroll portals, client workspaces, and document exchange. A successful login proves little. It does not prove correct file handling. It does not establish retention or support access.

Write the WISP control precisely

Sample control language: Staff may use an approved isolated browser. Limit this use to unfamiliar links. Those links must require no client data. Users verify destinations before entering credentials. They also verify before transferring files. Isolation supplements MFA and endpoint security. It also supplements email controls and provider review.

Tailor that language to the tested system. Name the control owner. Define allowed and prohibited data. Record the evidence behind each decision.

WISP recordEvidence to capture
ScopeApproved users, devices, destinations, and data
OwnerPerson responsible for approval and review
Data flowCredentials, files, clipboard, logs, and storage
Provider reviewContracts, access, retention, incidents, and subprocessors
Control testExpected behavior, actual result, and test date
Failure pathFallback, reporting, containment, and evidence
Review cycleChange triggers and next reassessment date

Run a controlled pilot

  1. Choose a public page and dummy account.
  2. Use a managed computer running desktop Chrome.
  3. Review extension permissions before installation.
  4. Verify the destination before entering credentials.
  5. Test MFA, uploads, downloads, and clipboard behavior.
  6. Compare observed results with provider documentation.
  7. Record the outcome in the WISP.

Keep the rest of the control stack. Joint CISA phishing guidance includes remote browser isolation. It treats isolation as one possible layer. It also covers MFA and email security. DNS controls and training remain separate layers.

Sources checked

Sources and product claims were last verified September 3, 2026.

Read the product boundary, law-firm guide, and current breach guidance.

Free for 30 days. No card required.

Test it without client data.

Start with a public page. Verify credentials, transfers, retention, and WISP scope before sensitive work.

See how Shield works

About the authors.

Try it on the next page you do not trust

Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device.

Free for 30 days. No card required.

Ghost. A private route for your browser. Shield. An isolated browser, off your device. Choose the mode. Close when finished.