Nothing changes
in April.
Managed IT for Utah CPA and tax firms, built around the filing calendar: tax software and portals that hold through busy season, upgrades that land in the quiet months, and the written security plan the FTC and the IRS now require, kept current for you.
We plan around your calendar, not ours.
A CPA firm has two seasons where nothing can move and a few months where everything should. We freeze the network around the deadlines, and we land every upgrade, migration, and restore test in the quiet.
Server replacements, cloud moves, new laptops, and the portal change you have been putting off, done with time to settle before fall.
We open the backup and prove it, and we rewrite the risk assessment while the last season is fresh.
The annual tax software release installed, tested with a prior-year return, and locked before the first organizer goes out.
Security fixes still land during a freeze when they must, with your approval and a rollback staged. Everything else waits.
The written plan the IRS asks about, kept current for you.
The FTC Safeguards Rule treats a tax preparer as a financial institution. It requires a written information security plan, a named person responsible for it, a risk assessment, MFA, encryption, vendor oversight, an incident plan, training, and a yearly report to the owners. Since 2024 it also requires notifying the FTC of a breach affecting five hundred or more clients within thirty days. We run the program and keep the evidence.
The plan is only worth anything if it matches the firm. We write it from what we manage, so every line is something we can show.
- Written information security plan current current
- Qualified individual named and reporting on file current
- Risk assessment due in 8 weeks scheduled
- MFA on tax software, email, and remote access enforced current
- Client data encrypted at rest and in transit verified current
- Service-provider oversight 9 vendors reviewed current
- Backup restore test, tax data passed May current
- Incident response plan, FTC notice clock rehearsed current
- Staff security training 14 of 14 current
Built on the IRS template, then made true for your firm: systems, people, vendors, and the controls that actually exist.
The rule names one person responsible. We give that person the reports, the evidence, and the yearly summary for the partners.
Where client data lives, who can reach it, and what would happen if the tax server died on April 10. Written down, reviewed yearly.
Tax software, email, the portal, remote access, and laptops that leave the office. Named accounts, so the review trail is real.
Hosting, portal, e-signature, payroll, and AI vendors reviewed and on a list, with the terms that matter recorded.
Tax data and workpapers backed up off site and opened on a schedule, so a failure in April is a restore, not a rebuild.
Who calls whom, what gets preserved, when the FTC and clients are told, rehearsed before it is needed.
The PTIN attestation, client security questionnaires, and the insurer renewal answered from files we already keep.
Day one: what we usually find.
An inventory, not a pitch. These are the conditions we walk into at most firms, in the order we find them.
- Tax software on a server nobody has restored
Ten years of returns on one box in a closet. The backup runs. Nobody has ever opened it to see if it works.
- Client documents arriving by email
W-2s, 1099s, and bank statements as attachments in a shared inbox, forwarded to personal phones during busy season.
- Remote desktop open to the internet
Preparers work from home through a port on the firewall with a password and no second factor. It is the first thing an attacker checks.
- One login for the tax software
Every preparer signs in as the same user, so nobody can say who touched a return, and the departed seasonal hire still can.
- A PTIN attestation with no plan behind it
The renewal asked whether the firm has a written information security plan. Someone checked yes.
- The update that landed on April 9
A vendor patch, a printer driver, or a router firmware change in the second week of April, because nobody owns the calendar.
AI drafts the client letter. It should never see the return to do it.
Tax research assistants, engagement letters written in a chatbot, a spreadsheet summarized by a copilot, and a preparer pasting a K-1 into a free tool to explain it. The good news: the useful parts of that work without client data. The rest is a Safeguards Rule finding and a client trust problem.
- Tax research assistants built into the tax and research platforms
- Client letters and proposals drafted in free chatbots
- Copilots inside Microsoft 365 with access to the whole file share
- Returns and statements pasted into AI tools to be summarized
The research assistants and copilots the firm pays for, what each may see, and what it may not. Short enough to remember in April.
The Safeguards Rule treats an AI tool that sees client data as a service provider. We review the terms, turn off training on your data where the setting exists, and keep the record.
A copilot inherits the file permissions of whoever asks. We fix the permissions first, so it cannot surface a return the preparer was never meant to see.
Research memos and client letters start from a draft. A CPA reviews, edits, and signs, and the workpaper says so.
- Returns, K-1s, or statements in free chatbots
- Social Security numbers or bank details in any prompt
- Client lists in personal AI accounts
- AI tools with no vendor review
The AI rule is a page inside the written information security plan, reviewed with the rest of it every year, so it never becomes its own project.
We already know your stack.
Tax and accounting software, the client portal, and the everyday office systems around them.
- Lacerte, ProSeries, UltraTax CS, Drake, and CCH Axcess
- QuickBooks Desktop and Online, Xero
- Hosted desktops such as Rightworks, supported properly
- Cloud moves when the firm is ready, never in season
- Client portals such as SafeSend, ShareFile, SmartVault, and TaxDome
- E-signature and organizers
- Practice management such as Karbon and Canopy
- Scanners and PDF workflow that behave in April
- Microsoft 365 with MFA and encrypted email
- Laptops for remote preparers, encrypted and managed
- On-prem servers while you need them, backed up off site
- Phones with a busy-season call flow
We support the software the firm runs and work with its vendors. Migrations and upgrades happen in the quiet months, on a calendar you approve.
What changes for the people in the firm.
The partner, the preparers, and the office manager each feel it differently. This is what each of them gets.
The plan the IRS asks about exists.
- A written security plan you can hand over, kept current for you.
- Nothing changes on the network between January and April without your say.
- One bill, one number, and a person who answers on April 14.
Fast in busy season, from anywhere.
- Tax software and the portal that hold at full load.
- Secure remote work that feels like the office, with MFA that takes seconds.
- Named logins, so the review trail is real.
Client documents in one place.
- A client portal instead of a shared inbox.
- New preparers ready before their first day, gone the day they leave.
- Vendor reviews and training tracked, not remembered.
Most firms land on Hardened.
Same plans as every SeriousIT client. The Safeguards Rule program is what a tax firm needs, so Hardened is where most firms belong.
One team for the whole firm.
Phones with a busy-season call flow, fiber to the office, and the cabling and access control for a move or a second office, from the same people who run your IT.
Firm phones
Hosted phones with a receptionist flow, voicemail to email, and mobile apps so preparers working from home answer on the firm number.
Business phonesBusiness fiber
UTOPIA Fiber for the office, supported by the team that runs your network, so hosted desktops and portals stop waiting in April.
Business fiberMoves and second offices
Structured cabling, door access, and a network built to the same standard as the first office, managed after install.
InfrastructureStraight answers.
Do we really need a written information security plan?
Yes. The FTC Safeguards Rule applies to tax preparers, and the IRS asks about the plan at PTIN renewal. We write it from what we actually manage and keep it current.
Will you change anything during busy season?
No. From mid-January through the April deadline, and again through the October extension deadline, the network is frozen except for security fixes you approve.
Can you support hosted desktops like Rightworks?
Yes. We support the firm side, the devices, identity, and the network, and coordinate with the hosting vendor on their side.
Our preparers work from home. Is that a problem?
Not when it is done right. Managed, encrypted laptops, MFA, and a secure path to the firm instead of a remote desktop port on the firewall.
What about seasonal preparers?
Named accounts created before their first day and removed on their last, from a roster, so nobody keeps access past the season.
Can you help with a client’s security questionnaire?
Yes. Larger clients increasingly ask their CPA for one. We answer it from evidence we already keep.
Start with a Safeguards gap check.
Send us your current bills and your written security plan, if you have one. We come back with what is exposed, what the plan would need to say, and what consolidating would cost.