IT support for accounting and bookkeeping firms
Filing season leaves no room for downtime, and your files hold exactly the data criminals want most. I keep accounting firms across New York City and Long Island running and defensible.
Call or text
(929) 779-3188Same-day response on business days. Existing clients get an emergency number for evenings and weekends.
Where accounting firms are exposed
- No written information security plan — which the FTC Safeguards Rule requires of tax preparers, and which the IRS expects you to produce.
- Client tax documents arriving as plain email attachments, then living in an inbox for years.
- Seasonal staff given broad access to client data in February and never removed in May.
- Remote access to the office set up quickly during a busy period and never secured properly afterwards.
- Tax software and a workstation failing in the last week of filing season, with no spare machine and no tested restore.
What is put in place
- A written information security plan built around your actual systems, in the form the FTC Safeguards Rule and IRS Publication 4557 contemplate — including the designated qualified individual, risk assessment and incident response plan those rules call for.
- Multi-factor authentication on email, tax software and any remote access, which the Safeguards Rule requires for systems holding customer information.
- A secure client portal for document exchange, replacing emailed W-2s, returns and bank statements.
- Encryption on every laptop and workstation, with remote wipe for lost devices.
- Support for the software you run — Drake, Lacerte, UltraTax, ProSeries, QuickBooks Desktop and Online — including hosted and terminal server setups.
- Backups tested before filing season starts, and a spare-machine plan so one dead workstation in April does not cost you a week.
- Access that is granted and revoked on schedule as seasonal staff come and go.
Questions
Do we really need a written information security plan?
If you prepare tax returns, yes. The FTC Safeguards Rule applies to tax preparers as financial institutions, and the IRS has made having a written plan a condition of participating in e-file programmes. IRS Publication 4557 sets out what it should contain. Requirements change, so confirm current specifics with the IRS or your professional body — but plan on needing one.
Can you get this ready before filing season?
Yes, and the time to do it is well before January. Security work, backup testing and any hardware replacement should happen in the autumn. Firms that call in February usually need triage rather than improvement, which costs more and helps less.
Is hosted tax software worth it?
Often, for firms with staff working from more than one place. It removes the single-workstation failure risk and the need to maintain a terminal server. It is not automatically cheaper and it does not remove your security obligations — you are still responsible for access control and for vetting the host.
What happens if client data is exposed?
You face notification duties under New York law and, for tax data, IRS and FTC reporting expectations. Having an incident response plan written in advance is the difference between a controlled process and an improvised one. Writing that plan is part of the security plan work.
Request a free IT assessment
About an hour, on-site or remote. You get a written summary of what I found and what I would fix first — whether or not you hire me.