IT support for accountants in Los Angeles has become a compliance requirement, not a convenience. CPA firms and tax practices handling client financial data must now satisfy three overlapping federal frameworks — IRS Publication 4557, the FTC Safeguards Rule, and AICPA cybersecurity standards — each of which carries direct IT infrastructure mandates. A firm that lacks multi-factor authentication, encrypted storage, a Written Information Security Plan, and documented incident response procedures is already out of compliance, regardless of how strong its client relationships are.
This guide covers what Los Angeles accounting practices need to know — and do — in 2026.
Why Accounting Firms Are High-Value Targets for Cybercriminals
The data held by a CPA firm or tax practice is among the most sensitive and actionable information a cybercriminal can obtain. Social Security numbers, bank account details, income records, business financials, and tax identification numbers are all present in a typical client file. A single compromised dataset can fuel identity theft, fraudulent tax filings, and financial fraud for years.
The financial stakes of a breach are significant across every industry, but the accounting and financial sector sits near the top of the exposure curve. According to IBM’s 2025 Cost of a Data Breach Report, the global average cost of a data breach is $4.44 million. The financial services sector specifically averages $5.56 million per breach — second only to healthcare at $7.42 million. For a 10–25 person CPA firm, an incident at even a fraction of that cost could be existential.
This is the environment Los Angeles CPA firms are operating in, and it is the baseline against which every IT decision should be evaluated.
The Compliance Frameworks Every CPA Firm Must Understand
No single regulation defines cybersecurity compliance for accounting firms. Instead, CPA practices must navigate several overlapping federal and professional frameworks, each addressing different aspects of protecting taxpayer and financial data. Together, these standards establish the baseline security controls, documentation requirements, and operational practices firms are expected to maintain.
IRS Publication 4557: Safeguarding Taxpayer Data
IRS Publication 4557 is the foundational federal guidance for tax professionals on protecting taxpayer information. The IRS requires all tax professionals who access federal tax information to implement and maintain security measures consistent with its requirements.
The key obligations under Pub 4557 include:
- Developing and maintaining a Written Information Security Plan (WISP) tailored to the firm’s size and complexity
- Implementing multi-factor authentication (MFA) for all systems that access taxpayer data
- Encrypting taxpayer data both at rest and in transit
- Restricting and logging access to tax preparation software and client records
- Conducting annual risk assessments and updating the WISP accordingly
- Training staff on data security practices and phishing awareness
- Establishing an incident response plan with IRS notification procedures
The IRS has made clear that a data breach involving taxpayer information must be reported to the agency, and that firms without documented security measures will face heightened scrutiny in any subsequent investigation.
FTC Safeguards Rule for Tax Preparers
The Federal Trade Commission’s Safeguards Rule, updated in 2023, explicitly classifies tax preparation businesses as financial institutions. This means the full scope of Safeguards Rule requirements now applies to CPA firms, enrolled agents, and tax preparers of all sizes. The FTC Safeguards Rule requires:
- A written information security program overseen by a designated coordinator
- Encryption of customer financial information on all systems and during transmission
- Multi-factor authentication for any employee accessing customer financial data
- Access controls limiting data access to authorized personnel only
- Regular monitoring and testing of the security program
- Vendor management procedures ensuring third-party service providers maintain appropriate safeguards
- An incident response plan and breach notification procedures
The FTC has enforcement authority and has demonstrated willingness to pursue action against firms that fail to comply. For Los Angeles accounting practices, the Safeguards Rule adds a federal regulatory layer on top of California’s already stringent data privacy requirements under the CCPA.
AICPA Cybersecurity Standards
The American Institute of CPAs has developed a cybersecurity risk management reporting framework that addresses both internal security practices and the communication of security posture to clients and stakeholders. While AICPA standards are not federally mandated in the same way as the IRS and FTC frameworks, they represent the professional standard of care against which accounting firms will be evaluated in any legal or regulatory proceeding following a breach.
AICPA’s guidance emphasizes entity-level controls, logical access controls, change management, and risk monitoring — all of which have direct IT infrastructure implications. Firms that cannot demonstrate alignment with AICPA standards face professional liability exposure that goes beyond regulatory penalties.
Tax Season vs. Off-Season: The IT Load Reality for CPA Firms
One of the most underappreciated IT planning challenges for accounting firms is the dramatic swing in system demand between tax season (January through April) and the remainder of the year. IT infrastructure sized for off-season baseline load will buckle under tax season demands. Understanding this cycle is essential to designing the right IT support model for a CPA firm.
Tax Season vs. Off-Season IT Requirements
| IT Requirement | Tax Season (Jan–Apr) | Off-Season (May–Dec) |
|---|---|---|
| Concurrent software users | Peak — all staff active simultaneously | Reduced — partial staff, lower concurrency |
| Tax software in active use | Lacerte, ProSeries, UltraTax, CCH Axcess, QuickBooks Hosted | Minimal or maintenance mode |
| Data transfer volume | Very high — large return files, e-filing submissions | Low to moderate |
| Remote access demand | High — staff may work extended hours from multiple locations | Standard |
| Help desk ticket volume | 3–5x baseline | Baseline |
| Backup frequency needs | Daily minimum, real-time preferred | Daily standard |
| Phishing/attack risk | Elevated — IRS-themed campaigns spike Jan–Apr | Moderate baseline |
| Compliance deadline pressure | Critical — filing deadlines non-negotiable | Lower urgency |
| IT support response time needed | Immediate (under 1 hour) | Standard (4-hour) |
This table illustrates why a one-size-fits-all managed IT support for accountants contract often fails. The right provider will include provisions for elevated response times during tax season, proactive performance monitoring during peak periods, and scalable infrastructure that adjusts to demand without requiring firms to permanently over-provision.
Tax Software Compatibility: What a Managed IT Support for Accountants Provider Must Know
Los Angeles CPA firms rely on a handful of enterprise tax platforms with specific, non-negotiable IT requirements. A provider of IT support for accountants who is unfamiliar with these platforms will create friction at exactly the moments when reliability matters most.
Common Tax Software and Key IT Considerations
| Software | Deployment | Key IT Requirements | Common Issues |
|---|---|---|---|
| Lacerte (Intuit) | Local or hosted | SQL Server backend, specific port requirements, antivirus exclusions | Slow performance without SSD/RAM optimization |
| ProSeries (Intuit) | Local install | Windows compatibility, network share configuration | Update conflicts, multi-user access errors |
| UltraTax CS (Thomson Reuters) | Local or Virtual Office CS | Citrix or RDP for hosted, specific firewall rules | Licensing errors, VPN latency on hosted version |
| CCH Axcess (Wolters Kluwer) | Cloud-native | Reliable high-bandwidth internet, browser compatibility | Performance tied to internet stability |
| QuickBooks Hosted | Cloud/hosted | Thin client or browser access, MFA enforcement | Session timeouts, printer mapping issues |
Every one of these platforms requires specific antivirus exclusions, firewall rules, and network configurations to perform reliably. An IT provider that applies generic configurations to a tax software environment will generate support tickets and downtime at the worst possible times. This is why outsourced IT support for accountants should come from a provider with documented hands-on experience in these environments — not general IT expertise applied broadly.
How to Build an 8-Step IT Compliance Checklist for a 10–25 Person CPA Firm
The following checklist is designed specifically for small to mid-sized accounting practices that need to meet IRS Pub 4557, FTC Safeguards Rule, and AICPA standards without the internal IT resources of a large enterprise. Each step is actionable and maps directly to a specific compliance requirement.
Step 1: Develop or update your Written Information Security Plan (WISP). Every CPA firm subject to IRS Pub 4557 and the FTC Safeguards Rule is required to maintain a WISP. For a 10–25 person firm, the WISP should identify a designated security coordinator, document all systems that handle client data, and outline procedures for access control, breach response, and staff training. Review and update it annually, and after any significant system change or incident.
Step 2: Implement multi-factor authentication across all systems. MFA is explicitly required by both the IRS and FTC frameworks. Enable MFA on all systems that access taxpayer data — including tax software logins, email, remote access tools, cloud storage, and the firm’s Microsoft 365 or Google Workspace environment. Authenticator app-based MFA is preferred over SMS codes, which are vulnerable to SIM-swapping attacks.
Step 3: Audit and control access permissions. Apply the principle of least privilege: every staff member should have access only to the client files and systems their role requires. Conduct a full access audit at the start of each tax season and immediately following any staff departure. Shared logins must be eliminated. Individual accounts with role-based permissions are a baseline compliance requirement.
Step 4: Encrypt client data at rest and in transit. Encryption is required under both the IRS and FTC frameworks. Ensure that laptops and workstations holding client data use full-disk encryption (BitLocker for Windows, FileVault for Mac). All data transmitted to clients or between offices must use TLS-encrypted channels. Unencrypted email attachments containing tax documents are a compliance violation.
Step 5: Configure and test your backup and recovery system. Data loss during tax season is a liability. Implement automated daily backups with off-site or cloud redundancy, and test restoration procedures at least quarterly. For a 10–25 person firm, the recovery time objective (RTO) should be defined and documented in the WISP. Know exactly how long it will take to restore operations after a ransomware attack or hardware failure — before it happens. See how Be Structured approaches data backup and protection for compliance-sensitive environments.
Step 6: Deploy endpoint protection and email security. Every workstation and laptop used by firm staff must have enterprise-grade endpoint detection and response (EDR), not basic antivirus. Email security should include spam filtering, phishing detection, and sandboxing of attachments. Configure antivirus exclusions for tax software installations (Lacerte, ProSeries, UltraTax) to prevent performance conflicts, but ensure those exclusions are carefully scoped. Our IT security services for Los Angeles businesses cover all of these controls.
Step 7: Conduct annual staff security training with phishing simulations. The IRS explicitly requires security awareness training as part of Pub 4557 compliance. For a 10–25 person firm, annual training should cover phishing recognition, password hygiene, safe handling of client data, and the firm’s incident reporting procedures.
Step 8: Establish a vendor management and third-party access review process. Both the FTC Safeguards Rule and AICPA standards require firms to assess the security practices of vendors and service providers that handle client data. Review IT vendors, cloud storage providers, document management platforms, and any third-party portal used for client file exchange. Require written security commitments from vendors with access to sensitive data, and review those commitments annually.
What to Look for in a Managed IT Support for Accountants Provider
Not every managed IT provider is equipped to support a compliance-driven accounting environment. The right partner for a CPA firm brings a specific combination of regulatory familiarity, tax software expertise, and responsive support during peak periods.
The managed IT support for accountants that matters most for accounting firms goes beyond standard help desk support. Look for a provider that can demonstrate:
- Familiarity with IRS Pub 4557, FTC Safeguards Rule, and AICPA cybersecurity standards
- Hands-on experience supporting Lacerte, ProSeries, UltraTax, CCH Axcess, or QuickBooks Hosted environments
- The ability to assist with WISP development and documentation
- Guaranteed response times during tax season that reflect the urgency of compliance deadlines
- Proactive monitoring rather than reactive break-fix support
- A clear process for handling staff onboarding and offboarding, including immediate access revocation
For Los Angeles firms specifically, a dedicated IT support for accounting firms provider with physical proximity offers an additional advantage: on-site support is available when remote resolution is not sufficient. Server issues, hardware failures, and network outages during tax season require a provider who can respond in person, not just remotely.
FAQ: IT Support for Accountants and CPA Firms
What IT compliance requirements apply to CPA firms?
What is a Written Information Security Plan, and does my firm need one?
What does the FTC Safeguards Rule require for tax preparers?
How does tax season affect IT infrastructure requirements for CPA firms?
What tax software platforms should my IT provider support?
What should I do if my firm experiences a data breach?
Does my CPA firm need cybersecurity insurance?
How is managed IT support for accountants different from standard IT support?
Solve Compliance Issues with Managed IT Support for Accountants
The compliance obligations facing Los Angeles CPA firms in 2026 are not abstract regulatory requirements. They are specific, technical mandates that require specific, technical infrastructure: multi-factor authentication, encrypted storage, access-controlled systems, documented incident response, and ongoing monitoring to detect and respond when something goes wrong.
Be Structured provides all-inclusive managed IT services in Los Angeles built specifically for the compliance requirements and operational rhythms of CPA firms and accounting practices. From WISP development and MFA deployment to tax software configuration, security monitoring, and tax season support coverage, we handle the full IT compliance stack so your firm can focus on serving clients and meeting deadlines.
Contact Be Structured today to schedule a compliance assessment for your Los Angeles accounting practice.
