Orca IT Solutions

Accounting & Finance

Financial firm IT that survives tax season

Between January and April your systems carry three times the load and hold the most sensitive data your clients own. We build for that peak, and we implement the written security program the FTC Safeguards Rule expects. Gilbert-based, remote across all 50 states.

🛡 Safeguards Rule Aware Peak-Season Ready💰 Never Outsourced Family Owned

Overview

A written security program, and a network that can take the load

Accounting firms have two IT problems: a regulator that now expects documented controls, and a four-month sprint that exposes every weakness at once.

Start with the rule. The FTC Safeguards Rule under GLBA applies to a wider set of financial institutions than most firms realize, and it reaches tax preparers, accountants who provide financial services, advisors and lenders. It expects a designated qualified individual, a documented risk assessment, a written information security program, multi-factor authentication for anyone accessing customer information, encryption of customer data in transit and at rest, access controls with periodic review, secure disposal, vendor oversight and a written incident response plan. Tax preparers carry a parallel IRS expectation to maintain a written security plan as a condition of participating in e-file.

We implement the technical half of that and we document it. MFA on Microsoft 365, on your tax software, on remote access and on the firewall. Disk encryption on every laptop. Named accounts with role-based access to client folders. Logging that is retained long enough to be useful. Offsite backups with tested restores. Secure disposal and certified wipe on retired drives. What we cannot do is write your policy for you or attest that your firm is compliant, the qualified individual is someone inside your firm, and the program is yours.

Now the load. From late January the same building suddenly runs seasonal preparers, extra monitors, dual-scanner workflows and thousands of PDF pages a day. Lacerte, Drake, UltraTax, ProSeries and CCH Axcess behave very differently under multi-user pressure, and a shared data path on a tired file server is the usual culprit when everyone says the software is slow. We measure before busy season: disk latency on the server, network throughput at the desk, scanner and OCR queues, and the size of the client file share. NVMe storage, gigabit or better to the desktop, and enough memory on the terminal server usually buy back more hours than any single upgrade a firm makes all year.

QuickBooks deserves its own paragraph because it causes so many calls. Multi-user Desktop performance depends on where the company file lives, whether the database service is configured correctly, how folder permissions are set, and how many users are hitting the same file. Hosted and Online each solve some problems and create others. We deal with this constantly, see our dedicated QuickBooks support page for the specifics.

Client portals close the loop. Emailing a return with a Social Security number attached is the single most common bad habit in the industry. We deploy or support portal workflows through SmartVault, ShareFile, Liscio, TaxCaddy or your tax software’s own portal, configure encrypted email for the exceptions, and train staff on which is which. There is more at our finance IT microsite.

Busy season does not create IT problems. It reveals the ones you already had.Orca IT, Gilbert AZ

What We Handle

The accounting firm checklist

The controls the Safeguards Rule asks about, plus the things that actually slow a firm down.

MFA on everything that holds client data

Email, tax software, remote access, portals, file storage and the firewall. Administrative accounts get hardware keys or a stronger factor.

Tax software performance tuning

Lacerte, Drake, UltraTax, ProSeries and CCH Axcess data paths measured and rebuilt on fast storage before January, not during it.

QuickBooks multi-user stability

Company file location, database service configuration, permissions and hosting decisions handled properly instead of by trial and error.

Secure client portals

Portal-first delivery of returns and source documents, with encrypted email as the exception and clear rules for staff.

Access review and clean offboarding

Seasonal staff get scoped access that expires. When they leave, accounts and portal access close the same day.

Evidence for your security program

Asset inventory, encryption status, access matrix, patch reporting, backup test records and vendor list, kept current for your qualified individual.

Peak Season

Six things we fix before January

Every one of these is cheaper to solve in the fall.

Storage

The file server that fills in March

Scanned source documents balloon. We size storage against last year’s growth and alert long before the volume is full.

Scanning

Slow scan-and-OCR pipelines

Duplex scanners, network destinations and OCR settings tuned so a preparer is not waiting on a 60-page organizer.

Remote

Remote access that cannot take the count

Terminal server sizing, session limits and licensing checked before twenty people log in from home on a Saturday.

Continuity

One internet circuit

A single outage on April 10 is a business event. We add failover so filing does not stop.

Email

Spoofed partner emails

DMARC, impersonation protection and payment-change verification rules, because tax season is prime phishing season.

Devices

Five-year-old preparer laptops

We plan a rolling refresh so hardware retires on your schedule and your budget, not in the middle of a deadline.

Accounting and finance IT questions

Does the FTC Safeguards Rule really apply to our CPA firm?

For many firms it does. The rule reaches non-bank financial institutions, and tax preparation and certain financial advisory activities are commonly treated as in scope. The safest path is to assume it applies and implement the controls, since they are the same controls your cyber insurer and your larger clients will ask about anyway. Your attorney or compliance advisor should confirm scope for your specific practice.

Can Orca IT be our qualified individual?

No. The rule expects a designated individual responsible for the security program, and that role carries accountability that belongs inside your firm. We work directly for and with that person: we implement controls, provide evidence, report on gaps and help draft the technical portions of the program. The designation itself stays with you.

Should we host QuickBooks or keep it on our own server?

It depends on user count, whether you need Desktop-only features, how many client files you carry and how your staff work remotely. Hosting solves multi-user performance and remote access but adds recurring cost and vendor dependency. A well-built local server with fast NVMe storage is often better for a single-office firm. We size it against your actual file count and user load.

How do you speed up Lacerte or Drake on a network?

Almost always by attacking disk latency and the network path to the shared data folder. That means NVMe or SSD on the server, gigabit or faster switching, correct antivirus exclusions for the data directories, and eliminating Wi-Fi from the equation for heavy users. We benchmark before and after so the improvement is measurable rather than anecdotal.

What is the right way to send a tax return to a client?

Through a portal, with the client authenticating. Portals give you delivery confirmation, access control and a record. Encrypted email is a reasonable second option for small exchanges. Sending an unprotected PDF with a Social Security number in it is the habit that most often turns into a disclosure incident.

How do you handle seasonal staff accounts?

Scoped and time-bound. Seasonal preparers get named accounts with access only to the client folders and software they need, MFA enrolled on day one, and an expiry date set at creation. In May we disable rather than delete, archive their mailbox and data, then remove after your retention window.

We had a phishing email that looked like our managing partner. What now?

First, confirm nothing was sent or paid. Then check for mailbox rules, forwarding and unfamiliar sign-in locations, reset credentials and revoke sessions. Longer term, DMARC enforcement, external sender warnings and impersonation protection cut most of this off, and a firm-wide rule that payment instruction changes require a callback removes the financial risk.

Do you support financial advisory firms and RIAs as well as CPAs?

Yes. Advisory firms have similar obligations plus custodian portal access, CRM and archiving requirements for business communications. We handle the endpoint, identity, network and backup layer, and integrate with whichever archiving or compliance vendor your firm uses.

Walk into January with a network that is ready.

Free assessment, written report, no obligation. Book it while there is still time to act on it.

Talk to Your Pod

Talk to Your Pod

Fix it in October, not on April 12.

Book a free Deep Dive before busy season. We will benchmark workstation and file performance, review your security program against the Safeguards Rule controls, and give you a written plan.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.