Blog Post

IT Support for Accounting Firms and CPAs

Tax preparers are "financial institutions" under the FTC Safeguards Rule, so your firm must run a written information security program, use MFA and encryption, and report any breach of 500 or more clients' unencrypted data to the FTC within 30 days. IT support for accounting firms turns those rules into daily practice. Network Right provides it from San Francisco and New York.

What accounting firms need from IT

An accounting firm needs IT that protects client tax data and keeps preparers working through deadline weeks. That means a written information security plan (WISP), MFA on every system, encrypted devices and file transfer, reliable remote access for seasonal staff, and support for tax software like UltraTax CS, Lacerte and CCH Axcess.

Get it right and three things get easier. Your security program is documented when the rules ask. Your cyber insurance renewal goes faster because the answers are already written down. Clients get a secure portal instead of an emailed PDF of their W-2s. And March and April run without downtime.

Accounting sits inside Network Right's professional services IT practice, next to law firms and consultancies with the same confidentiality demands.

FTC Safeguards Rule and IRS WISP requirements for tax preparers

The FTC Safeguards Rule (16 CFR Part 314) names "tax preparation firms" as financial institutions, and its updated requirements took effect June 9, 2023. It requires a Qualified Individual, a written risk assessment, MFA, encryption, staff training, vendor oversight and an incident response plan. IRS Publications 4557 and 5708 explain how tax professionals meet it.

Here is what each obligation requires and what your IT provider does about it:

Requirement Source What it requires What IT does
Qualified Individual 16 CFR 314.4(a) One person runs the security program; can be an outside provider, but the firm stays responsible Define who fills the role and who at the firm oversees it
Written risk assessment 16 CFR 314.4(b) A written list of risks to client data and how you handle each Annual assessment and asset inventory
Access controls and encryption 16 CFR 314.4(c)(1), (c)(3) Only authorized staff see client data; encrypt it in transit and at rest Role-based access; FileVault or BitLocker; encrypted email and portals
Multi-factor authentication 16 CFR 314.4(c)(5) MFA "for any individual accessing any information system" MFA on email, tax software, portals, remote access and admin accounts
Secure disposal 16 CFR 314.4(c)(6) Dispose of client data within two years of last use, unless you must keep it Retention schedule; secure wipe of old devices
Monitoring and testing 16 CFR 314.4(d)(2) Continuous monitoring, or an annual penetration test plus scans every six months Endpoint monitoring, patch reports, scheduled scans
Training and vendor oversight 16 CFR 314.4(e), (f) Train staff; vet and monitor vendors Phishing simulations; vendor reviews
Incident response plan 16 CFR 314.4(h) A written plan: who does what, who you tell, how you fix it Plan written and tested yearly
Annual report 16 CFR 314.4(i) Written report at least yearly to the partners or a senior officer Year-end security report
FTC breach notice 16 CFR 314.4(j), effective May 13, 2024 Tell the FTC within 30 days if unencrypted data on 500+ consumers is taken Logs that show what was accessed; encryption that keeps lost devices out of scope
Written information security plan IRS Publication 5708 IRS sample WISP for tax and accounting practices WISP built from your real systems, reviewed yearly
PTIN renewal attestation Form W-12, line 11 Preparers check a box acknowledging the WISP duty Current WISP on file before renewal

The full rule text is on eCFR at 16 CFR Part 314. Two details matter for smaller firms.

The small-firm exemption is narrow. If your firm holds data on fewer than 5,000 consumers, 16 CFR 314.6 drops four items: the written risk assessment, the testing schedule, the written incident response plan and the annual report. MFA, encryption, training and the security program itself still apply.

Encryption changes the breach math. The FTC notice covers unencrypted data only. A stolen laptop holding 800 client returns is generally not a notification event if the drive is encrypted and the key was not taken. State breach laws still apply, so check with counsel.

IRS Publication 4557, Safeguarding Taxpayer Data, says plainly that professional tax return preparers fall within the Safeguards Rule's "financial institutions" definition and must "develop a written information security plan." It also tells firms to report data theft to their IRS Stakeholder Liaison.

What managed IT for accounting firms includes

Managed IT for accounting firms covers the helpdesk, every device, secure client file exchange, email encryption, backups, MFA and fast onboarding for seasonal staff, for one per-user monthly price. Network Right assigns a dedicated IT consultant who learns your tax software, your deadlines and your WISP.

  • Helpdesk. Same-day answers on tax software errors, printer queues and locked accounts. Network Right has handled 100K+ tickets with 99% SLA adherence and a 4.95/5 NPS. As Clearbit COO Robin Spencer put it: "Network Right anticipates every issue and responds quickly, effectively, and professionally to every request or problem."
  • Device management. Every laptop enrolled in Intune, Jamf or Iru (formerly Kandji), patched on schedule and remotely wipeable. Our managed device encryption covers the Safeguards Rule encryption-at-rest requirement.
  • Secure client portals. SmartVault, ShareFile, Canopy or TaxDome portals configured with MFA, so returns never go out as email attachments.
  • Email encryption and filtering. One-click encrypted send, impersonation protection, and DMARC to stop fake "IRS" and "client" emails, backed by phishing awareness training for the Safeguards Rule training requirement.
  • Backup. Daily backup of Microsoft 365, file shares and tax software data, with restore tests every quarter.
  • MFA everywhere. Email, tax software, portals, remote access and banking.
  • Seasonal staff. Laptops and accounts ready before January, access removed the day the season ends through secure offboarding for seasonal staff.

A firm without a security specialist still needs clear ownership of its security program. Define the Qualified Individual's responsibilities, reporting duties and oversight before assigning the role. Include the IT support needed for risk assessments, documentation and ongoing maintenance in the service scope.

Tax and accounting software we support

Network Right supports the tax, accounting and practice management platforms firms run every day, from desktop tax software to cloud practice management and secure document portals. We manage installs, updates, user access, integrations and hosting, and we work the vendor's support queue when the application itself fails.

  • Tax preparation: CCH Axcess, CCH ProSystem fx, UltraTax CS, Lacerte, ProSeries, Drake Tax
  • Accounting and bookkeeping: QuickBooks Online and Desktop, Xero, Sage Intacct, Bill.com
  • Practice management: Karbon, Canopy, TaxDome, Financial Cents
  • Document management and portals: SmartVault, ShareFile, SurePrep, Thomson Reuters GoFileRoom
  • Productivity: Microsoft 365, Google Workspace, Adobe Acrobat, DocuSign

Desktop tax programs such as Lacerte and ProSeries push updates all season, and every workstation has to match. We install them after hours and check each machine before morning. Our customer stories from growing companies show how the dedicated-consultant model works day to day.

Tax-season IT readiness calendar

Tax-season readiness means IT work is scheduled around the filing calendar: hardware and seasonal accounts in place by early January, a freeze on risky changes from March through April 15, and a second push before the October 15 extension deadline. Network Right plans this calendar with your firm each year.

When Filing milestone (calendar-year filers) IT work
October to December PTINs expire December 31; renewal season WISP review, PTIN attestation, laptop refresh, tax software installs for next season
Early January W-2 and 1099 deadline January 31 Seasonal staff laptops and accounts live; MFA enrolled; portal invites sent
February to March 15 Partnership and S corporation returns due March 15 Capacity check on remote access and portal storage; change freeze begins
March 16 to April 15 Individual and C corporation returns due April 15 After-hours coverage, no non-urgent changes, daily backup checks
Late April to May Post-season Offboard seasonal staff, security review, schedule vulnerability scans
September 15 to October 15 Extended business and individual returns Second change freeze and after-hours coverage

Deadlines shift when they fall on a weekend or holiday. Seasonal staff working from home get the same managed laptop and MFA as full-time staff. Remote workers follow the same device rules explained in our guide to mobile device management for company laptops and phones.

Accounting firm IT pricing by firm size

Accounting firm IT is priced per user. Network Right publishes its rates: $120 per user per month on the Start-up tier and $170 per user per month on Scale-up, with Enterprise quoted to scope. A 15-person firm on Scale-up pays about $2,550 a month.

Include seasonal staff in your capacity and cost planning, and agree how changes in headcount affect billing. The full tier comparison is on the Network Right pricing page.

  • Solo and small practices (1 to 10 people): Start-up tier covers the helpdesk, fundamental IT security, device management, onboarding and offboarding.
  • Growing firms (10 to 50 people): Scale-up adds advanced IT security and advanced networking, which fits firms with an office network, a portal and a WISP to maintain.
  • Multi-office firms (50+ people): Enterprise adds a dedicated IT projects team, cybersecurity and vCISO, and quarterly security audit reports.

For how other providers price and what drives the number, see our managed IT pricing benchmarks.

Firms that need 24/7 threat monitoring on top can add managed SOC services, which also produces the continuous-monitoring evidence 16 CFR 314.4(d)(2) accepts in place of annual penetration testing.

New York firms get onsite help from our IT support team in New York City, and Bay Area firms from our San Francisco office.

Law firms face a parallel set of ethics rules, covered in managed IT for law firms.

Frequently asked questions

Does the FTC Safeguards Rule apply to CPA firms?

Yes, if the firm prepares tax returns. The rule lists "tax preparation firms" as financial institutions under 16 CFR 314.1, and IRS Publication 4557 confirms professional tax return preparers are covered. Firms that only provide audit or advisory services should confirm their status with counsel, since coverage depends on the financial activities performed.

What is the FTC breach notification threshold for tax preparers?

You must notify the FTC when unencrypted customer information of at least 500 consumers is acquired without authorization. The notice is due as soon as possible and no later than 30 days after discovery, using the FTC's online form. The requirement took effect May 13, 2024.

Do small accounting firms need a WISP?

Yes. IRS Publication 5708 states that tax and accounting professionals are financial institutions "regardless of size," and implementing a WISP is a Safeguards Rule requirement. Firms with fewer than 5,000 consumers are exempt only from four specific provisions, such as the written risk assessment and annual report.

What does IRS Publication 5708 include?

Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice, gives a sample WISP with sections for objective, purpose, scope, responsible officials, internal and external risk mitigation, and implementation. It also includes sample attachments such as a hardware inventory and an authorized access list.

What does the PTIN renewal ask about data security?

Form W-12, line 11, asks preparers to check a box acknowledging that paid tax return preparers are required by law to create and maintain a written information security plan. It is an acknowledgment, not an audit, but you should have a current WISP before you check it.

Is MFA required for accounting firms?

Yes. 16 CFR 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system, unless your Qualified Individual approves in writing an equivalent or stronger control. In practice, that means MFA on email, tax software, client portals, remote access and banking.

Can an outsourced IT provider be our Qualified Individual?

Yes. 16 CFR 314.4(a) allows the Qualified Individual to be employed by a service provider. Your firm keeps responsibility for compliance, must designate a senior member of the firm to oversee the provider, and must require the provider to maintain its own security program.

How long can we keep old client tax data?

The Safeguards Rule requires secure disposal of customer information no later than two years after it was last used for that client, unless you need it for business purposes or another law requires retention. Set a written retention schedule that reflects your record-keeping obligations and follow it.

Does Network Right support UltraTax CS, Lacerte and CCH Axcess?

Yes. Network Right supports CCH Axcess, CCH ProSystem fx, UltraTax CS, Lacerte, ProSeries, Drake Tax, QuickBooks, Xero, Karbon, Canopy, TaxDome, SmartVault and ShareFile. We handle installs, season updates, user access and hosting, and work the vendor's support queue when the application itself fails.

What does managed IT cost for a 15-person CPA firm?

About $2,550 a month on Network Right's Scale-up tier, which is $170 per user per month. The Start-up tier is $120 per user, and Enterprise is quoted to scope. Seasonal staffing, billing adjustments and WISP work should be included in the scope of your proposal.

Get IT support for your accounting firm from Network Right

Prepare IT around the tax calendar. Seasonal access, software updates, backups and security records need attention before deadline weeks, with clear ownership when something goes wrong.

Network Right gives your firm a dedicated IT consultant, published per-user pricing and offices in San Francisco and New York. Our customers stay 5+ years on average. If your firm already has a current WISP, MFA everywhere and encrypted devices, we will say so and suggest you keep your setup.

Tell us your headcount (including seasonal staff), your tax and portal software, and whether you have a WISP today. We can discuss the IT work behind your security plan and priorities for the next filing season. Discuss your WISP and IT support needs.

‍