IT Support for Accounting and Tax Firms in Broward County
Accounting and tax firms hold more sensitive personal data per client than almost any other small business — social security numbers, bank details, income, dependants. Federal rules treat you accordingly, and a lot of firms have not caught up.
The gap most firms have
- The FTC Safeguards Rule under Gramm-Leach-Bliley applies to tax preparers. That means a written information security plan is expected, not optional, and most small firms either do not have one or have a template nobody has read.
- Seasonal staff get accounts in January and nobody removes them in May. By the following season there is a drawer of live credentials belonging to people who no longer work there.
- Client documents arrive by ordinary email, sit in mailboxes indefinitely, and get forwarded to personal addresses so someone can work on them at home.
- The one machine running the tax software is treated as too critical to touch, so it is also the least maintained device in the office.
What actually goes wrong
Tax season is the target season
Attackers know when your firm is busiest, most distracted, and most likely to open an attachment from an unfamiliar client. Phishing volume against preparers is not evenly spread across the year.
A written security plan is expected of you
Federal expectations for tax professionals include maintaining a written information security plan. It has to reflect what you actually do — a downloaded template describing controls you do not have is worse than useless if anyone ever looks.
Client data leaves through email, not through hackers
The most common real-world exposure is not a sophisticated intrusion. It is a return with a full set of personal details sitting in an unsecured mailbox, or forwarded to a personal Gmail account, for years.
How we handle it
- Multi-factor authentication everywhere, with no exceptions for partners
- A seasonal staff process that provisions in January and revokes in May, automatically
- Email security that catches the phishing aimed specifically at preparers
- Encrypted client document exchange instead of ordinary email attachments
- EDR and patching on the tax software machine, scheduled around your season
- Documentation of the technical controls, so your written security plan describes reality
Common questions
Does the FTC Safeguards Rule apply to my accounting firm?
If you prepare tax returns or provide financial services to consumers, you are generally treated as a financial institution under Gramm-Leach-Bliley, and the Safeguards Rule applies. That brings an expectation of a written information security plan, a named person responsible for it, risk assessment, access controls and encryption. We handle the technical controls and document them; the plan itself should be reviewed by someone qualified to advise you on your specific obligations. This is not legal advice.
Can you help us produce a written information security plan?
We produce the technical half — an accurate written record of the controls actually in place, which is the part most templates get wrong because they describe an ideal rather than your office. Pair that with professional advice on the policy and administrative side and you have something defensible.
Can you work around tax season?
We plan for it. Nothing disruptive gets scheduled between late January and mid-April. Onboarding a new firm is easiest in the summer, and if you come to us in March we will stabilise things and save the larger work for after the deadline.
What does it cost?
Endpoint protection is $32 per device per month. A ten-person firm typically runs twelve to eighteen devices once you count laptops and the machines that only wake up for the season. Project work and clean-up come out of prepaid support hours from $115 per hour.
Start with the free assessment
We run an external security assessment on your domain and show you what we find before you spend anything.