IT Support for Accountants: A 2026 Compliance Guide

IT support for accountants

IT support for accountants in Los Angeles has become a compliance requirement, not a convenience. CPA firms and tax practices handling client financial data must now satisfy three overlapping federal frameworks — IRS Publication 4557, the FTC Safeguards Rule, and AICPA cybersecurity standards — each of which carries direct IT infrastructure mandates. A firm that lacks multi-factor authentication, encrypted storage, a Written Information Security Plan, and documented incident response procedures is already out of compliance, regardless of how strong its client relationships are.

This guide covers what Los Angeles accounting practices need to know — and do — in 2026.

IT Support for Accounting Firms

Why Accounting Firms Are High-Value Targets for Cybercriminals

The data held by a CPA firm or tax practice is among the most sensitive and actionable information a cybercriminal can obtain. Social Security numbers, bank account details, income records, business financials, and tax identification numbers are all present in a typical client file. A single compromised dataset can fuel identity theft, fraudulent tax filings, and financial fraud for years.

The financial stakes of a breach are significant across every industry, but the accounting and financial sector sits near the top of the exposure curve. According to IBM’s 2025 Cost of a Data Breach Report, the global average cost of a data breach is $4.44 million. The financial services sector specifically averages $5.56 million per breach — second only to healthcare at $7.42 million. For a 10–25 person CPA firm, an incident at even a fraction of that cost could be existential.

This is the environment Los Angeles CPA firms are operating in, and it is the baseline against which every IT decision should be evaluated.


The Compliance Frameworks Every CPA Firm Must Understand

No single regulation defines cybersecurity compliance for accounting firms. Instead, CPA practices must navigate several overlapping federal and professional frameworks, each addressing different aspects of protecting taxpayer and financial data. Together, these standards establish the baseline security controls, documentation requirements, and operational practices firms are expected to maintain.

IRS Publication 4557: Safeguarding Taxpayer Data

IRS Publication 4557 is the foundational federal guidance for tax professionals on protecting taxpayer information. The IRS requires all tax professionals who access federal tax information to implement and maintain security measures consistent with its requirements.

The key obligations under Pub 4557 include:

  • Developing and maintaining a Written Information Security Plan (WISP) tailored to the firm’s size and complexity
  • Implementing multi-factor authentication (MFA) for all systems that access taxpayer data
  • Encrypting taxpayer data both at rest and in transit
  • Restricting and logging access to tax preparation software and client records
  • Conducting annual risk assessments and updating the WISP accordingly
  • Training staff on data security practices and phishing awareness
  • Establishing an incident response plan with IRS notification procedures

The IRS has made clear that a data breach involving taxpayer information must be reported to the agency, and that firms without documented security measures will face heightened scrutiny in any subsequent investigation.

FTC Safeguards Rule for Tax Preparers

The Federal Trade Commission’s Safeguards Rule, updated in 2023, explicitly classifies tax preparation businesses as financial institutions. This means the full scope of Safeguards Rule requirements now applies to CPA firms, enrolled agents, and tax preparers of all sizes. The FTC Safeguards Rule requires:

  • A written information security program overseen by a designated coordinator
  • Encryption of customer financial information on all systems and during transmission
  • Multi-factor authentication for any employee accessing customer financial data
  • Access controls limiting data access to authorized personnel only
  • Regular monitoring and testing of the security program
  • Vendor management procedures ensuring third-party service providers maintain appropriate safeguards
  • An incident response plan and breach notification procedures

The FTC has enforcement authority and has demonstrated willingness to pursue action against firms that fail to comply. For Los Angeles accounting practices, the Safeguards Rule adds a federal regulatory layer on top of California’s already stringent data privacy requirements under the CCPA.

AICPA Cybersecurity Standards

The American Institute of CPAs has developed a cybersecurity risk management reporting framework that addresses both internal security practices and the communication of security posture to clients and stakeholders. While AICPA standards are not federally mandated in the same way as the IRS and FTC frameworks, they represent the professional standard of care against which accounting firms will be evaluated in any legal or regulatory proceeding following a breach.

AICPA’s guidance emphasizes entity-level controls, logical access controls, change management, and risk monitoring — all of which have direct IT infrastructure implications. Firms that cannot demonstrate alignment with AICPA standards face professional liability exposure that goes beyond regulatory penalties.


Tax Season vs. Off-Season: The IT Load Reality for CPA Firms

One of the most underappreciated IT planning challenges for accounting firms is the dramatic swing in system demand between tax season (January through April) and the remainder of the year. IT infrastructure sized for off-season baseline load will buckle under tax season demands. Understanding this cycle is essential to designing the right IT support model for a CPA firm.

Tax Season vs. Off-Season IT Requirements

IT Requirement Tax Season (Jan–Apr) Off-Season (May–Dec)
Concurrent software users Peak — all staff active simultaneously Reduced — partial staff, lower concurrency
Tax software in active use Lacerte, ProSeries, UltraTax, CCH Axcess, QuickBooks Hosted Minimal or maintenance mode
Data transfer volume Very high — large return files, e-filing submissions Low to moderate
Remote access demand High — staff may work extended hours from multiple locations Standard
Help desk ticket volume 3–5x baseline Baseline
Backup frequency needs Daily minimum, real-time preferred Daily standard
Phishing/attack risk Elevated — IRS-themed campaigns spike Jan–Apr Moderate baseline
Compliance deadline pressure Critical — filing deadlines non-negotiable Lower urgency
IT support response time needed Immediate (under 1 hour) Standard (4-hour)

This table illustrates why a one-size-fits-all managed IT support for accountants contract often fails. The right provider will include provisions for elevated response times during tax season, proactive performance monitoring during peak periods, and scalable infrastructure that adjusts to demand without requiring firms to permanently over-provision.


Tax Software Compatibility: What a Managed IT Support for Accountants Provider Must Know

Los Angeles CPA firms rely on a handful of enterprise tax platforms with specific, non-negotiable IT requirements. A provider of IT support for accountants who is unfamiliar with these platforms will create friction at exactly the moments when reliability matters most.

Common Tax Software and Key IT Considerations

Software Deployment Key IT Requirements Common Issues
Lacerte (Intuit) Local or hosted SQL Server backend, specific port requirements, antivirus exclusions Slow performance without SSD/RAM optimization
ProSeries (Intuit) Local install Windows compatibility, network share configuration Update conflicts, multi-user access errors
UltraTax CS (Thomson Reuters) Local or Virtual Office CS Citrix or RDP for hosted, specific firewall rules Licensing errors, VPN latency on hosted version
CCH Axcess (Wolters Kluwer) Cloud-native Reliable high-bandwidth internet, browser compatibility Performance tied to internet stability
QuickBooks Hosted Cloud/hosted Thin client or browser access, MFA enforcement Session timeouts, printer mapping issues

Every one of these platforms requires specific antivirus exclusions, firewall rules, and network configurations to perform reliably. An IT provider that applies generic configurations to a tax software environment will generate support tickets and downtime at the worst possible times. This is why outsourced IT support for accountants should come from a provider with documented hands-on experience in these environments — not general IT expertise applied broadly.

An accountant in need of IT support

How to Build an 8-Step IT Compliance Checklist for a 10–25 Person CPA Firm

The following checklist is designed specifically for small to mid-sized accounting practices that need to meet IRS Pub 4557, FTC Safeguards Rule, and AICPA standards without the internal IT resources of a large enterprise. Each step is actionable and maps directly to a specific compliance requirement.

Step 1: Develop or update your Written Information Security Plan (WISP). Every CPA firm subject to IRS Pub 4557 and the FTC Safeguards Rule is required to maintain a WISP. For a 10–25 person firm, the WISP should identify a designated security coordinator, document all systems that handle client data, and outline procedures for access control, breach response, and staff training. Review and update it annually, and after any significant system change or incident.

Step 2: Implement multi-factor authentication across all systems. MFA is explicitly required by both the IRS and FTC frameworks. Enable MFA on all systems that access taxpayer data — including tax software logins, email, remote access tools, cloud storage, and the firm’s Microsoft 365 or Google Workspace environment. Authenticator app-based MFA is preferred over SMS codes, which are vulnerable to SIM-swapping attacks.

Step 3: Audit and control access permissions. Apply the principle of least privilege: every staff member should have access only to the client files and systems their role requires. Conduct a full access audit at the start of each tax season and immediately following any staff departure. Shared logins must be eliminated. Individual accounts with role-based permissions are a baseline compliance requirement.

Step 4: Encrypt client data at rest and in transit. Encryption is required under both the IRS and FTC frameworks. Ensure that laptops and workstations holding client data use full-disk encryption (BitLocker for Windows, FileVault for Mac). All data transmitted to clients or between offices must use TLS-encrypted channels. Unencrypted email attachments containing tax documents are a compliance violation.

Step 5: Configure and test your backup and recovery system. Data loss during tax season is a liability. Implement automated daily backups with off-site or cloud redundancy, and test restoration procedures at least quarterly. For a 10–25 person firm, the recovery time objective (RTO) should be defined and documented in the WISP. Know exactly how long it will take to restore operations after a ransomware attack or hardware failure — before it happens. See how Be Structured approaches data backup and protection for compliance-sensitive environments.

Step 6: Deploy endpoint protection and email security. Every workstation and laptop used by firm staff must have enterprise-grade endpoint detection and response (EDR), not basic antivirus. Email security should include spam filtering, phishing detection, and sandboxing of attachments. Configure antivirus exclusions for tax software installations (Lacerte, ProSeries, UltraTax) to prevent performance conflicts, but ensure those exclusions are carefully scoped. Our IT security services for Los Angeles businesses cover all of these controls.

Step 7: Conduct annual staff security training with phishing simulations. The IRS explicitly requires security awareness training as part of Pub 4557 compliance. For a 10–25 person firm, annual training should cover phishing recognition, password hygiene, safe handling of client data, and the firm’s incident reporting procedures.

Step 8: Establish a vendor management and third-party access review process. Both the FTC Safeguards Rule and AICPA standards require firms to assess the security practices of vendors and service providers that handle client data. Review IT vendors, cloud storage providers, document management platforms, and any third-party portal used for client file exchange. Require written security commitments from vendors with access to sensitive data, and review those commitments annually.


What to Look for in a Managed IT Support for Accountants Provider

Not every managed IT provider is equipped to support a compliance-driven accounting environment. The right partner for a CPA firm brings a specific combination of regulatory familiarity, tax software expertise, and responsive support during peak periods.

The managed IT support for accountants that matters most for accounting firms goes beyond standard help desk support. Look for a provider that can demonstrate:

  • Familiarity with IRS Pub 4557, FTC Safeguards Rule, and AICPA cybersecurity standards
  • Hands-on experience supporting Lacerte, ProSeries, UltraTax, CCH Axcess, or QuickBooks Hosted environments
  • The ability to assist with WISP development and documentation
  • Guaranteed response times during tax season that reflect the urgency of compliance deadlines
  • Proactive monitoring rather than reactive break-fix support
  • A clear process for handling staff onboarding and offboarding, including immediate access revocation

For Los Angeles firms specifically, a dedicated IT support for accounting firms provider with physical proximity offers an additional advantage: on-site support is available when remote resolution is not sufficient. Server issues, hardware failures, and network outages during tax season require a provider who can respond in person, not just remotely.


FAQ: IT Support for Accountants and CPA Firms

What IT compliance requirements apply to CPA firms?

CPA firms and tax preparers in the United States are subject to three primary compliance frameworks with direct IT implications: IRS Publication 4557, which requires a Written Information Security Plan, multi-factor authentication, and data encryption for all firms handling taxpayer data; the FTC Safeguards Rule, which classifies tax preparation businesses as financial institutions and mandates a comprehensive information security program; and AICPA cybersecurity standards, which define the professional standard of care for client data protection. California-based firms must also comply with the CCPA, which adds state-level data privacy obligations on top of federal requirements.

What is a Written Information Security Plan, and does my firm need one?

A Written Information Security Plan (WISP) is a documented policy that describes your firm's approach to protecting sensitive client data — including the security controls you have implemented, your process for conducting risk assessments, your access control procedures, your incident response plan, and your staff training program. Both the IRS and the FTC Safeguards Rule require tax preparers and accounting firms to maintain a WISP. It must be reviewed and updated at least annually.

What does the FTC Safeguards Rule require for tax preparers?

The FTC Safeguards Rule classifies tax preparation businesses as financial institutions and requires them to implement a written information security program that includes designation of a security coordinator, encryption of customer financial data at rest and in transit, multi-factor authentication for all employees accessing customer data, access controls limiting data to authorized personnel, regular security monitoring and testing, vendor management procedures, and a documented incident response plan. The FTC has enforcement authority and can take action against non-compliant firms.

How does tax season affect IT infrastructure requirements for CPA firms?

Tax season (January through April) creates a significant spike in IT demand relative to off-season baselines. Concurrent user loads on tax software platforms peak, data transfer volumes increase substantially with large return files and e-filing submissions, remote access demand rises as staff work extended hours, and phishing attacks targeting tax professionals increase measurably. Help desk ticket volume during tax season typically runs three to five times the off-season baseline for accounting firms. IT infrastructure and support contracts should be specifically designed to account for this seasonality, including elevated response time guarantees during the January–April window.

What tax software platforms should my IT provider support?

The most common enterprise tax platforms in use at Los Angeles CPA firms include Lacerte and ProSeries (both Intuit), UltraTax CS (Thomson Reuters), CCH Axcess (Wolters Kluwer), and QuickBooks Hosted. Each has specific IT requirements around server configuration, antivirus exclusions, network port access, and remote access setup. An IT provider without hands-on experience with these platforms will create configuration problems that surface as performance issues and outages during the periods when reliability matters most.

What should I do if my firm experiences a data breach?

If your firm experiences a breach involving taxpayer data, immediately contain the breach by isolating affected systems, then notify the IRS using the Taxpayer Guide to Identity Theft reporting procedures — a mandatory requirement under Pub 4557. Notify affected clients as required under applicable state breach notification laws (California requires notification within 72 hours for CCPA-covered breaches). Engage legal counsel early in the process. Document every step of your response for regulatory and insurance purposes.

Does my CPA firm need cybersecurity insurance?

Cybersecurity insurance is not mandated by any of the primary compliance frameworks, but it is strongly advisable for any firm handling sensitive client financial data. Policies typically cover breach notification costs, forensic investigation, legal fees, client notification, and some portion of business interruption losses.

How is managed IT support for accountants different from standard IT support?

Managed IT support for accountants is built around the specific compliance rhythms, software environments, and security obligations of accounting practices — rather than applying a generic IT framework. It includes provisions for elevated response times during tax season, familiarity with platforms like Lacerte, ProSeries, and UltraTax, WISP development assistance, and proactive security monitoring calibrated to the threat landscape facing tax professionals. Standard IT support typically addresses none of these vertical-specific requirements by default.

Solve Compliance Issues with Managed IT Support for Accountants

The compliance obligations facing Los Angeles CPA firms in 2026 are not abstract regulatory requirements. They are specific, technical mandates that require specific, technical infrastructure: multi-factor authentication, encrypted storage, access-controlled systems, documented incident response, and ongoing monitoring to detect and respond when something goes wrong.

Be Structured provides all-inclusive managed IT services in Los Angeles built specifically for the compliance requirements and operational rhythms of CPA firms and accounting practices. From WISP development and MFA deployment to tax software configuration, security monitoring, and tax season support coverage, we handle the full IT compliance stack so your firm can focus on serving clients and meeting deadlines.

Contact Be Structured today to schedule a compliance assessment for your Los Angeles accounting practice.

About Chad Lauterbach

Founder & CTO at Be Structured Technology Group, Inc., a Los Angeles-based provider of Managed IT Services for small businesses. I desire to help small businesses better utilize technology by assisting in high-level planning to make sure that new systems will benefit them both operationally and financially. I am careful to implement and support systems using industry best practices.