Browser isolation for tax and accounting firms
Shield moves page execution off-device. Review WISP fit, client data, credentials, files, and providers.

Tax and accounting work often crosses a browser. Client messages, research, portals, and file transfers share that surface. Each workflow needs a clear data boundary.
Quick answer: Shield moves page execution off your device. It can be one assessed WISP control. It does not make a page trustworthy. It does not satisfy a regulation.
This guide provides general security information. It is not legal, tax, or compliance advice. Apply current law and professional rules to your firm's facts.
Start with the actual obligation
The FTC Safeguards Rule guide lists tax preparation firms. They are covered examples. Coverage depends on business activities. Covered firms need a written security program. It must match size, scope, complexity, and customer information.
The IRS issued a current WISP reminder in August 2026. It says tax and accounting professionals need written plans. It highlights risk assessment and tested safeguards. It also covers providers, contracts, and regular updates.
IRS Publication 4557 provides security guidance. Publication 5708 provides a sample WISP. Firms must tailor both to their operations and risks. Neither publication certifies a product.
Browser isolation is not a compliance checkbox. A firm may document an evaluated control. Covered firms still need a risk-based security program. Some provisions exempt firms below the 5,000-consumer threshold.
The threat is broader than one link
Microsoft documented a February 2026 campaign across many industries. It reached over 29,000 users. Those users spanned 10,000 organizations. Accountants and tax preparers were particularly represented.
The February campaign used IRS-themed messages and redirects. It delivered a malicious remote-access tool. Execution could enable credential harvesting. Browser isolation addresses only part of that path. Keep phishing-resistant authentication, email controls, endpoint security, and response procedures.
What Shield changes
Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device. Shield is the relevant mode here. It changes where the page runs.
| Workflow | Potential benefit | Required check |
|---|---|---|
| Unfamiliar tax-themed link | Page code runs off-device | Verify the destination before entering data |
| Tax or client portal | A separate browser session | The page and provider may receive client data |
| Upload, download, or clipboard | The page remains off-device | Transferred data crosses the isolation boundary |
| Credentials and MFA | No change to page identity | Entered credentials still reach the page |
| Desktop deployment | Chrome extension entry point | Test permissions and each actual workflow |
| WISP documentation | A tested control can be recorded | Legba does not satisfy the program alone |
The technical boundary guide explains these limits. The Chrome Web Store listing says files stay remote. That remains true unless users explicitly save them. Saved or copied data crosses the boundary. Sensitive work requires current retention and access verification.
Legba is a Chrome extension for computers. Google says Chrome extensions are not available on mobile devices. Do not plan an iPad workflow around the extension.
Client data changes the review
The FTC requires security reviews for certain external applications. This covers apps transmitting, accessing, or storing customer information. Covered firms must select capable service providers. Contracts must require appropriate safeguards. Firms must periodically reassess provider safeguards. An off-device browser may belong in that review.
AICPA Rule 1.700.040 covers third-party provider disclosures. It applies to members in public practice. Before disclosure, it calls for one safeguard. Use contractual confidentiality and obtain reasonable assurance. Otherwise, obtain specific client consent. IRC Section 7216 governs certain preparer disclosures and uses. Qualified counsel should assess each workflow.
NIST's browser-isolation example documents a privacy tradeoff. Centralized browsing can create privacy and access risks. Isolation does not prove short retention. Verify logs, support access, storage, deletion, and data location.
- Identify every customer-information field entering the session.
- Map credentials, files, clipboard data, and downloads.
- Review the provider's access and retention terms.
- Confirm hosting locations and subprocessors.
- Document contracts, monitoring, and reassessment dates.
- Get qualified advice for Section 7216 questions.
Start with low-data workflows
- Open an unfamiliar link without signing in.
- Review a public vendor or research page.
- Test with a dummy account and sample files.
- Separate one-time research from daily browser state.
Authenticated tax systems need more review. So do payroll portals, client workspaces, and document exchange. A successful login proves little. It does not prove correct file handling. It does not establish retention or support access.
Write the WISP control precisely
Sample control language: Staff may use an approved isolated browser. Limit this use to unfamiliar links. Those links must require no client data. Users verify destinations before entering credentials. They also verify before transferring files. Isolation supplements MFA and endpoint security. It also supplements email controls and provider review.
Tailor that language to the tested system. Name the control owner. Define allowed and prohibited data. Record the evidence behind each decision.
| WISP record | Evidence to capture |
|---|---|
| Scope | Approved users, devices, destinations, and data |
| Owner | Person responsible for approval and review |
| Data flow | Credentials, files, clipboard, logs, and storage |
| Provider review | Contracts, access, retention, incidents, and subprocessors |
| Control test | Expected behavior, actual result, and test date |
| Failure path | Fallback, reporting, containment, and evidence |
| Review cycle | Change triggers and next reassessment date |
Run a controlled pilot
- Choose a public page and dummy account.
- Use a managed computer running desktop Chrome.
- Review extension permissions before installation.
- Verify the destination before entering credentials.
- Test MFA, uploads, downloads, and clipboard behavior.
- Compare observed results with provider documentation.
- Record the outcome in the WISP.
Keep the rest of the control stack. Joint CISA phishing guidance includes remote browser isolation. It treats isolation as one possible layer. It also covers MFA and email security. DNS controls and training remain separate layers.
Sources checked
- FTC Safeguards Rule business guide
- IRS 2026 WISP reminder
- IRS Publication 4557
- IRS Publication 5708
- Microsoft tax-season campaign analysis
- AICPA Code of Professional Conduct
- IRS Section 7216 information center
- NIST browser-isolation example
- Joint CISA phishing guidance
- Current Legba product boundary
Sources and product claims were last verified September 3, 2026.
Continue the control review
Read the product boundary, law-firm guide, and current breach guidance.
Browser isolation for law firms
Browser isolation changes where law-firm pages run. It does not decide privilege. Review credentials, files, provider access, and ethics questions.
The 60% small-business cyberattack claim needs context
The claim that 60% of small businesses close after a cyberattack lacks a reliable universal basis. Build continuity around tested recovery and layered controls.
What is browser isolation? The complete 2026 guide
Browser isolation separates web execution from a local device. This guide covers architectures, risk reduction, tradeoffs, and verification.
Free for 30 days. No card required.
Test it without client data.
Start with a public page. Verify credentials, transfers, retention, and WISP scope before sensitive work.