Skip to content
CPA & Tax Firm IT · Dallas-Fort Worth

IT Support for Accounting Firms in Dallas-Fort Worth

Your firm holds the most complete financial picture anyone has of your clients. Social Security numbers, income, dependents, bank routing details, business books. Few businesses hold that much about one person in a single file. That concentration is why the IRS says data thefts at tax professionals' offices are on the rise, and why identity thieves have placed tax practitioners firmly in their sights.

IT support for accounting firms has to answer to that reality, not just keep printers working. Adaptive IP Services has served Texas organizations since 2014 from our base in Frisco. This page covers what the FTC Safeguards Rule actually asks of your practice, how to tell whether your firm has already been breached, and what a competent IT partner should be doing about both. Every regulatory point below comes from IRS Publication 4557.

What the FTC Safeguards Rule asks of your firm

IRS Publication 4557 is direct about coverage: the Gramm-Leach-Bliley definition of "financial institutions" includes professional tax preparers. The FTC requires covered firms to develop a written plan describing how they protect customer information, and the IRS publishes Publication 5708 to help you build one. Failing to create and enact a security plan, in the IRS's own framing, may result in an FTC investigation.

The plan has to be appropriate to your firm's size and complexity and the sensitivity of the information you handle. A sole practitioner and a forty-person firm do not owe the same artifacts. What every covered firm owes, per the IRS, is the same short list:

  • A designated qualified individual accountable for overseeing, implementing, and enforcing the program
  • Multi-factor authentication for anyone accessing customer information, using at least two of a knowledge factor, a possession factor, and an inherence factor. The IRS notes this applies to all firms regardless of size.
  • A risk assessment across every relevant area of the operation, including how well current safeguards actually work
  • A safeguards program that gets monitored and tested, not written once and filed
  • Service provider oversight, including contract terms requiring your vendors to maintain safeguards
  • Program review when the business changes or testing turns something up
  • Security awareness training with scheduled refreshers

Read that list again as a hiring test. If a prospective IT provider cannot tell you which of those items it delivers, which ones stay with your firm, and how each one gets evidenced, it is selling you helpdesk hours. Confirm your specific obligations with your counsel; we build and operate the controls underneath them.

How to tell your firm has already been breached

Firms rarely discover a breach by noticing an intruder. They discover it because clients start calling. The IRS publishes the specific signals, and it is worth knowing them cold:

  • Client e-filed returns start rejecting because a return was already filed under that Social Security number
  • Clients who have not filed receive IRS authentication letters (5071C, 4883C, 5747C)
  • Clients who have not filed receive refunds
  • Clients receive tax transcripts they never requested
  • The number of returns filed under your EFIN or PTIN exceeds the number you actually filed
  • Machines run slow, turn themselves on, lock practitioners out, or cursors move on their own

The IRS recommends checking your e-File application and, where available, PTIN return counts weekly and deactivating unused EFINs. That is a five-minute habit that catches the single clearest sign your credentials are being used to file returns you never touched. Most firms we meet have never looked.

Audit logging is the other half. If something does happen, you need a record of who did what and when. Reconstructing an incident without logs is guesswork, and guesswork is not a defensible answer to a regulator or a client.

Busy season is a security problem, not just a capacity problem

From January to April your firm roughly doubles the number of people touching client data, many of them seasonal, many of them remote, and all of them onboarded in a hurry during the period when nobody has time. Then in May the access stays behind after the people leave.

IRS Publication 4557 treats multi-factor authentication and a secure VPN as minimum standards for remote access to a firm network, and advises against using public wireless for business email or sensitive documents. It also says to limit access to taxpayer data to individuals who need to know, and to withdraw outstanding authorizations for taxpayers who are no longer clients.

The offboarding half is where firms quietly accumulate risk. Every seasonal preparer who still has working credentials in September is an account an attacker can use without tripping anything that looks unusual. Access control, endpoint protection, and monitoring are what make that manageable, and they are what our packages cover.

The cost nobody prices in: your EFIN

Firms budget for downtime and for recovery. They rarely budget for the part where they cannot file.

IRS guidance on recovering from a data loss says to determine how the intrusion or theft occurred and make any required fixes before resuming tax preparation activities and being issued a new EFIN. Read that in the context of April. Reporting obligations run in parallel: your IRS Stakeholder Liaison, local law enforcement, and every state where you prepare returns.

This is the argument for tested backups rather than assumed ones. The IRS advises backing up to a secure external source that is not connected to your network full time, encrypting those backups, and backing up more often during filing season. Ransomware operators go after backups first. Ask your current provider when it last performed an actual test restore, not when it last checked that the backup job reported success.

What we actually provide

We sell defined packages with published pricing, so you can compare us against any proposal on your desk before you talk to us.

  • SOC package: managed detection and response. Continuous monitoring and a security operations function that investigates alerts rather than forwarding them to your inbox. See our SOC package.
  • NOC package: managed network operations. Continuous monitoring of the devices and links your firm runs on, early-warning alerting, and capacity trends on a single pane. See Managed NOC.
  • IT consulting: strategy, projects, and fractional leadership through our consulting practice.

Pricing is published at /packages. No "call for a quote" games.

Who you are actually hiring

Adaptive IP Services was founded in 2014 by David Boggs, who has worked in technology since 1997 and spent 20+ years in enterprise IT, including senior network security architecture in the financial sector. That background is the relevant part here: the controls the Safeguards Rule asks for are the controls regulated financial institutions have run for years. Applied at CPA-firm scale, that discipline is the product.

One thing we will not promise is that your firm can never be breached. Nobody can honestly promise that. What we promise is disciplined controls, continuous monitoring, tested recovery, and straight answers.

Frequently asked questions

Does the FTC Safeguards Rule apply to my accounting firm?

Most likely yes. IRS Publication 4557 states plainly that the Gramm-Leach-Bliley definition of "financial institutions" includes professional tax preparers, which puts firms that prepare returns under the Safeguards Rule. The rule is written to be flexible, so what it demands of a four-person practice is not what it demands of a regional firm. Confirm how it applies to your specific practice with your counsel.

What is a WISP, and does my tax practice need one?

A WISP is a written information security plan describing how your firm protects client data. IRS Publication 4557 says tax return preparers must create and enact security plans to protect client data, and that failing to do so may result in an FTC investigation. The IRS publishes Publication 5708 specifically to help firms build one. We help firms implement and document the underlying controls so the plan matches what the firm actually does.

How much does IT support for an accounting firm cost?

Our pricing is published at adaptiveips.com/packages, so you can price your firm before you ever call us. Managed security and managed network operations are separate packages, and most firms handling client tax data need both. We will tell you if a smaller tier fits.

How would I know if my firm has already been breached?

The IRS lists specific warning signs, and most of them show up on the client side before anything looks wrong internally. Client e-filed returns start rejecting because a return was already filed under that Social Security number. Clients who have not filed receive IRS authentication letters, refunds, or transcripts they never requested. The return count under your EFIN or PTIN exceeds what you actually filed. The IRS recommends checking those counts weekly, where your account provides them.

Can you support seasonal preparers working remotely during filing season?

Yes, and the access side is the part firms usually get wrong. IRS Publication 4557 treats multi-factor authentication and a secure VPN as minimum standards for remote access to a firm network. The harder discipline is offboarding: revoking access and withdrawing authorizations when seasonal staff leave and when clients leave. Our packages cover the access control, endpoint protection, and monitoring that this depends on.

What happens to our EFIN if we suffer a data theft?

This is the cost most firms do not price in. IRS guidance on recovering from a data loss says to determine how the intrusion occurred and make any required fixes before resuming tax preparation activities and being issued a new EFIN. Your ability to file can pause while that happens. Reporting runs to your IRS Stakeholder Liaison, local law enforcement, and every state where you file.

See where your firm stands

Start with our free 18-point security snapshot at /evaluation. It walks the controls that matter for a firm holding client tax data, and you keep the findings either way.

Prefer to talk first? Call (888) 382-7685 or reach us at /contact. Review our published pricing anytime at /packages.

Adaptive IP Services, Frisco, Texas. Serving accounting and CPA firms across Dallas-Fort Worth since 2014. Regulatory points on this page reference IRS Publication 4557, Safeguarding Taxpayer Data. This page is not legal advice; confirm your firm's obligations with your counsel.