Accounting & Tax Firm IT
The IRS expects a written security plan. Most firms have a downloaded template.
Every firm with a PTIN carries a Written Information Security Plan requirement, and it recurs every year. We do the accounting-firm IT work that generalist shops treat like any other office, and we produce the document the requirement actually asks for.
The systems we work in
- Lacerte
- UltraTax
- Drake
- QuickBooks
The firm-specific problems
A firm is not an office with spreadsheets. It is a federal data-security obligation with a busy season.
Generalist IT treats a CPA firm like any twelve-person office. But a firm is classified as a financial institution under Gramm-Leach-Bliley, which puts the FTC Safeguards Rule on the managing partner's desk alongside IRS Pub 4557. Both want written evidence, and both arrive on an annual cycle that lands right when nobody has time.
- F-01
The WISP that exists as a file, not a plan
Someone downloaded a template three seasons ago and put the firm name at the top. That version does not survive being read closely, and reading it closely is exactly what happens after an incident or during an examination.
- F-02
Client data on staff devices nobody inventoried
Working copies of returns on a home laptop, a thumb drive from an intake appointment, a scan folder that never gets cleared. The data inventory is the step firms skip and the step every other safeguard depends on.
- F-03
Seasonal preparers who still have access in July
A cohort arrives in January and leaves in April. Their portal logins, tax software accounts, and email forwarding rules outlive them. Offboarding at a firm is a safeguards control, not an HR checkbox.
- F-04
Returns and source documents traveling by email
A W-2 as an unencrypted attachment to a personal inbox is the default breach in this industry. A client portal only helps if it is configured, MFA-protected, and staff use it instead of falling back to email in the last week of March.
- F-05
The client who asks how you protect their data
More firms are getting this question, sometimes from a business client with its own compliance program. The answer needs to be a document you can hand over, not a description of good intentions.
- F-06
Nobody knows what happens if it goes wrong on April 10
Ransomware during busy season is a different event than ransomware in September. Whether the firm can file depends on a restore nobody has tested and a response plan nobody has written.
The accounting on-ramp
Start with an assessment. Finish with the plan on paper.
Most firms carry a few seasons of deferred IT decisions. The on-ramp is a ladder: a low-cost baseline assessment first, a deeper gap assessment and remediation roadmap next, and at the top the foundation bundle for firms that want the whole backlog cleared and the WISP written properly.
- 01
Baseline assessment
A low-cost snapshot of your current IT and how client data is actually handled.
- 02
Gap assessment
A deeper, scoped review of everything the baseline surfaced.
- 03
Remediation roadmap
A prioritized plan you can run yourself, or hand to us.
- 04
Foundation bundle
The done-for-you top rung: we clear the backlog and write the plan.
Not sure where you stand? Start with a baseline assessment.
Accounting Foundation
Onboarding project, fixed scope
$899-$1,149
17 credits · one-time
Range reflects standard vs specialist delivery; your quote fixes the number
Scope an accounting foundationFree scoping call. Fixed quote, target within 3 business days.
What is included
- Written Information Security Plan built for your firm against IRS Pub 4557 and the FTC Safeguards Rule: data inventory, named security coordinator, written safeguards, incident response plan, annual review schedule
- Firewall tightened and locked down
- Client data handling audit: how tax and financial data moves through the firm, from intake channels through working copies on staff devices to archival storage, retention and destruction
- Business email security
- Written findings and a prioritized list of fixes you keep
A full Security Risk Analysis and the deeper remediation work are scoped separately, as project work or through the compliance rungs, when you want them.
What comes after the foundation
The monthly plan: firm-shaped, not generic.
Once the foundation lands, the firm moves to a monthly plan sized to staff count. What the plan actually does for a practice:
Tax software day-to-day
Workstation rebuilds, seasonal-preparer setup, network share repair, year-over-year rollover problems, and the update that has to land between filings rather than during one.
The WISP kept current, not rewritten annually
The requirement includes an annual review, and a plan that has not changed in three years reads as one nobody follows. We keep the inventory, the safeguards and the dates moving so the review is a real one.
Seasonal onboarding and offboarding as a process
A documented sequence for the January arrivals and the April departures: portal, tax software, email and forwarding, devices, shared credentials. Signed off in writing, because that is the version that helps you during an examination.
Portal and MFA coverage checked, not assumed
The Safeguards Rule expects multi-factor authentication on anything touching client information. We verify coverage across the portal, the tax software and email rather than taking the vendor default on faith.
Busy-season readiness before busy season
Capacity, backups and restore drills reviewed ahead of January rather than discovered in March. The point is that the worst week of the year is not the week you find out.
Backup verification and quarterly restore drills
A backup nobody has restored is a hope. We pull a representative restore each quarter, document it, and keep the signed record. It is also what the incident response plan depends on being true.
24/7 AI support, human dispatch in business hours
The AI assistant answers around the clock, which matters more in this industry than most: a Sunday-night problem in the first week of April gets worked at 11 PM. Human dispatch runs Monday through Friday, 8 AM to 6 PM.
Why us, not a generalist
We can name the rule, the publication, and what it wants from you.
Most IT providers will tell a CPA firm they take security seriously. Fewer can say which rule applies, why an accounting firm counts as a financial institution, or what an examiner is actually looking for. That gap is where template WISPs come from.
So the work here is shaped around the two things a firm is measured on: whether client data is handled the way the plan says it is, and whether the plan exists in a form someone else can read. Everything else is ordinary IT, and we do that too.
The rule, cited
FTC Safeguards Rule (16 CFR Part 314) via Gramm-Leach-Bliley, and IRS Publication 4557 via your PTIN. The size exemption went away with the 2023 update, so a three-person office carries the same baseline as a regional firm. Framework detail on the compliance page.A plan about your firm, not about security in general
If two firms could swap WISPs without noticing, neither has one. Ours names your tax software, where the workpapers sit, who has admin, and what happens when a seasonal preparer leaves in April.A document, never a certification
We produce the written plan and the evidence behind it. We are not a certifying body, and no engagement here makes your firm certified under any framework. Anyone telling you otherwise is selling something else.Month to month, through busy season and after it
The three-year agreement is the norm in this market. Plans here are month to month and cancel with 30 days notice, which also means we do not get to coast between Aprils.
Accounting FAQ
The questions firms ask first
The requirement, the deliverable, and what happens during busy season. Specifics a managing partner can act on.
One scoping call. We will tell you what your firm actually needs.
Free, 30 minutes. Staff and seasonal count, your tax software, and whether the plan you have would survive being read.
Prefer the phone? (435) 227-5583
Built for 5-50 person firms