Accounting & Tax Firm IT

The IRS expects a written security plan. Most firms have a downloaded template.

Every firm with a PTIN carries a Written Information Security Plan requirement, and it recurs every year. We do the accounting-firm IT work that generalist shops treat like any other office, and we produce the document the requirement actually asks for.

The systems we work in

  • Lacerte
  • UltraTax
  • Drake
  • QuickBooks

The firm-specific problems

A firm is not an office with spreadsheets. It is a federal data-security obligation with a busy season.

Generalist IT treats a CPA firm like any twelve-person office. But a firm is classified as a financial institution under Gramm-Leach-Bliley, which puts the FTC Safeguards Rule on the managing partner's desk alongside IRS Pub 4557. Both want written evidence, and both arrive on an annual cycle that lands right when nobody has time.

  • F-01

    The WISP that exists as a file, not a plan

    Someone downloaded a template three seasons ago and put the firm name at the top. That version does not survive being read closely, and reading it closely is exactly what happens after an incident or during an examination.

  • F-02

    Client data on staff devices nobody inventoried

    Working copies of returns on a home laptop, a thumb drive from an intake appointment, a scan folder that never gets cleared. The data inventory is the step firms skip and the step every other safeguard depends on.

  • F-03

    Seasonal preparers who still have access in July

    A cohort arrives in January and leaves in April. Their portal logins, tax software accounts, and email forwarding rules outlive them. Offboarding at a firm is a safeguards control, not an HR checkbox.

  • F-04

    Returns and source documents traveling by email

    A W-2 as an unencrypted attachment to a personal inbox is the default breach in this industry. A client portal only helps if it is configured, MFA-protected, and staff use it instead of falling back to email in the last week of March.

  • F-05

    The client who asks how you protect their data

    More firms are getting this question, sometimes from a business client with its own compliance program. The answer needs to be a document you can hand over, not a description of good intentions.

  • F-06

    Nobody knows what happens if it goes wrong on April 10

    Ransomware during busy season is a different event than ransomware in September. Whether the firm can file depends on a restore nobody has tested and a response plan nobody has written.

The accounting on-ramp

Start with an assessment. Finish with the plan on paper.

Most firms carry a few seasons of deferred IT decisions. The on-ramp is a ladder: a low-cost baseline assessment first, a deeper gap assessment and remediation roadmap next, and at the top the foundation bundle for firms that want the whole backlog cleared and the WISP written properly.

  1. 01

    Baseline assessment

    A low-cost snapshot of your current IT and how client data is actually handled.

  2. 02

    Gap assessment

    A deeper, scoped review of everything the baseline surfaced.

  3. 03

    Remediation roadmap

    A prioritized plan you can run yourself, or hand to us.

  4. 04

    Foundation bundle

    The done-for-you top rung: we clear the backlog and write the plan.

Not sure where you stand? Start with a baseline assessment.

Accounting Foundation

Onboarding project, fixed scope

Top rung · done-for-you

$899-$1,149

17 credits · one-time

Range reflects standard vs specialist delivery; your quote fixes the number

Scope an accounting foundation

Free scoping call. Fixed quote, target within 3 business days.

What is included

  • Written Information Security Plan built for your firm against IRS Pub 4557 and the FTC Safeguards Rule: data inventory, named security coordinator, written safeguards, incident response plan, annual review schedule
  • Firewall tightened and locked down
  • Client data handling audit: how tax and financial data moves through the firm, from intake channels through working copies on staff devices to archival storage, retention and destruction
  • Business email security
  • Written findings and a prioritized list of fixes you keep

A full Security Risk Analysis and the deeper remediation work are scoped separately, as project work or through the compliance rungs, when you want them.

What comes after the foundation

The monthly plan: firm-shaped, not generic.

Once the foundation lands, the firm moves to a monthly plan sized to staff count. What the plan actually does for a practice:

  • Tax software day-to-day

    Workstation rebuilds, seasonal-preparer setup, network share repair, year-over-year rollover problems, and the update that has to land between filings rather than during one.

  • The WISP kept current, not rewritten annually

    The requirement includes an annual review, and a plan that has not changed in three years reads as one nobody follows. We keep the inventory, the safeguards and the dates moving so the review is a real one.

  • Seasonal onboarding and offboarding as a process

    A documented sequence for the January arrivals and the April departures: portal, tax software, email and forwarding, devices, shared credentials. Signed off in writing, because that is the version that helps you during an examination.

  • Portal and MFA coverage checked, not assumed

    The Safeguards Rule expects multi-factor authentication on anything touching client information. We verify coverage across the portal, the tax software and email rather than taking the vendor default on faith.

  • Busy-season readiness before busy season

    Capacity, backups and restore drills reviewed ahead of January rather than discovered in March. The point is that the worst week of the year is not the week you find out.

  • Backup verification and quarterly restore drills

    A backup nobody has restored is a hope. We pull a representative restore each quarter, document it, and keep the signed record. It is also what the incident response plan depends on being true.

  • 24/7 AI support, human dispatch in business hours

    The AI assistant answers around the clock, which matters more in this industry than most: a Sunday-night problem in the first week of April gets worked at 11 PM. Human dispatch runs Monday through Friday, 8 AM to 6 PM.

Why us, not a generalist

We can name the rule, the publication, and what it wants from you.

Most IT providers will tell a CPA firm they take security seriously. Fewer can say which rule applies, why an accounting firm counts as a financial institution, or what an examiner is actually looking for. That gap is where template WISPs come from.

So the work here is shaped around the two things a firm is measured on: whether client data is handled the way the plan says it is, and whether the plan exists in a form someone else can read. Everything else is ordinary IT, and we do that too.

  • The rule, cited

    FTC Safeguards Rule (16 CFR Part 314) via Gramm-Leach-Bliley, and IRS Publication 4557 via your PTIN. The size exemption went away with the 2023 update, so a three-person office carries the same baseline as a regional firm. Framework detail on the compliance page.
  • A plan about your firm, not about security in general

    If two firms could swap WISPs without noticing, neither has one. Ours names your tax software, where the workpapers sit, who has admin, and what happens when a seasonal preparer leaves in April.
  • A document, never a certification

    We produce the written plan and the evidence behind it. We are not a certifying body, and no engagement here makes your firm certified under any framework. Anyone telling you otherwise is selling something else.
  • Month to month, through busy season and after it

    The three-year agreement is the norm in this market. Plans here are month to month and cancel with 30 days notice, which also means we do not get to coast between Aprils.

Accounting FAQ

The questions firms ask first

The requirement, the deliverable, and what happens during busy season. Specifics a managing partner can act on.

Yes. The informal small-preparer distinction went away with the 2023 update to the FTC Safeguards Rule, so a three-person office carries the same baseline written program as a regional firm. Two rules land on the same desk: the Safeguards Rule (16 CFR Part 314) reaches you because tax and advisory work classify a firm as a financial institution under Gramm-Leach-Bliley, and IRS Publication 4557 applies to anyone with a PTIN. The longer version is in our write-up on what a real WISP contains.
It is enough to have a file, which is not the same as having a plan. A WISP is a description of your firm: which tax software you run, where the workpapers sit, who has admin, how a seasonal preparer is offboarded in April. A generic document is the version that fails when someone reads it closely, and reading it closely is exactly what happens after an incident or during an examination. If two firms could swap plans without noticing, neither has one.
In: a Written Information Security Plan built against Pub 4557 and the FTC Safeguards Rule, firewall hardening, a client data handling audit covering intake through retention and destruction, business email security, and the written findings you keep. Not in: a full Security Risk Analysis and the deeper remediation work, which we scope separately, and ongoing month-to-month management, which is the monthly plan after the foundation lands.
No, and be careful with anyone who says it does. We produce the written plan and the technical evidence behind it, which is what the rules ask a firm to have. Compliance is a state you maintain, not a badge, and there is no certifying body for a WISP. We are not auditors and this is not legal advice; we do the technology side of a requirement your firm carries.
That is the assumption, not the exception. Assessment and planning work is best done between May and November, and we schedule anything that touches a workstation or the network outside filing windows. During busy season the posture changes to keeping you running: the AI assistant answers around the clock, and human dispatch runs Monday through Friday, 8 AM to 6 PM.
That scenario is the reason the incident response plan and the restore drills are in the foundation rather than sold as extras. The plan names who is called and in what order, and the quarterly restore drill is what tells you the backup is real before you need it. The Safeguards Rule also added a notification duty in the 2024 amendments: report to the FTC within 30 days of discovering a breach affecting 500 or more people.
Yes. Lacerte, UltraTax, Drake, ProSeries, ProConnect and the QuickBooks side all stay with their vendors for application support, and we handle everything on your side of the line: the workstations, the network, the shares, the backups, and the access controls the vendor assumes you have configured. We coordinate with their support rather than getting between you and it.
Yes, and it is a growing ask, particularly from business clients that have their own compliance program. The deliverable is the same work: an assessment, the fixes it surfaces, and a written record you can answer from. If you want to start before committing to anything, the free IT audit produces a written report you keep. Phone is (435) 227-5583.

One scoping call. We will tell you what your firm actually needs.

Free, 30 minutes. Staff and seasonal count, your tax software, and whether the plan you have would survive being read.

Prefer the phone? (435) 227-5583

Built for 5-50 person firms