The file server that fills in March
Scanned source documents balloon. We size storage against last year’s growth and alert long before the volume is full.
Accounting & Finance
Between January and April your systems carry three times the load and hold the most sensitive data your clients own. We build for that peak, and we implement the written security program the FTC Safeguards Rule expects. Gilbert-based, remote across all 50 states.
Overview
Accounting firms have two IT problems: a regulator that now expects documented controls, and a four-month sprint that exposes every weakness at once.
Start with the rule. The FTC Safeguards Rule under GLBA applies to a wider set of financial institutions than most firms realize, and it reaches tax preparers, accountants who provide financial services, advisors and lenders. It expects a designated qualified individual, a documented risk assessment, a written information security program, multi-factor authentication for anyone accessing customer information, encryption of customer data in transit and at rest, access controls with periodic review, secure disposal, vendor oversight and a written incident response plan. Tax preparers carry a parallel IRS expectation to maintain a written security plan as a condition of participating in e-file.
We implement the technical half of that and we document it. MFA on Microsoft 365, on your tax software, on remote access and on the firewall. Disk encryption on every laptop. Named accounts with role-based access to client folders. Logging that is retained long enough to be useful. Offsite backups with tested restores. Secure disposal and certified wipe on retired drives. What we cannot do is write your policy for you or attest that your firm is compliant, the qualified individual is someone inside your firm, and the program is yours.
Now the load. From late January the same building suddenly runs seasonal preparers, extra monitors, dual-scanner workflows and thousands of PDF pages a day. Lacerte, Drake, UltraTax, ProSeries and CCH Axcess behave very differently under multi-user pressure, and a shared data path on a tired file server is the usual culprit when everyone says the software is slow. We measure before busy season: disk latency on the server, network throughput at the desk, scanner and OCR queues, and the size of the client file share. NVMe storage, gigabit or better to the desktop, and enough memory on the terminal server usually buy back more hours than any single upgrade a firm makes all year.
QuickBooks deserves its own paragraph because it causes so many calls. Multi-user Desktop performance depends on where the company file lives, whether the database service is configured correctly, how folder permissions are set, and how many users are hitting the same file. Hosted and Online each solve some problems and create others. We deal with this constantly, see our dedicated QuickBooks support page for the specifics.
Client portals close the loop. Emailing a return with a Social Security number attached is the single most common bad habit in the industry. We deploy or support portal workflows through SmartVault, ShareFile, Liscio, TaxCaddy or your tax software’s own portal, configure encrypted email for the exceptions, and train staff on which is which. There is more at our finance IT microsite.
Busy season does not create IT problems. It reveals the ones you already had.Orca IT, Gilbert AZ
What We Handle
The controls the Safeguards Rule asks about, plus the things that actually slow a firm down.
Email, tax software, remote access, portals, file storage and the firewall. Administrative accounts get hardware keys or a stronger factor.
Lacerte, Drake, UltraTax, ProSeries and CCH Axcess data paths measured and rebuilt on fast storage before January, not during it.
Company file location, database service configuration, permissions and hosting decisions handled properly instead of by trial and error.
Portal-first delivery of returns and source documents, with encrypted email as the exception and clear rules for staff.
Seasonal staff get scoped access that expires. When they leave, accounts and portal access close the same day.
Asset inventory, encryption status, access matrix, patch reporting, backup test records and vendor list, kept current for your qualified individual.
Peak Season
Every one of these is cheaper to solve in the fall.
Scanned source documents balloon. We size storage against last year’s growth and alert long before the volume is full.
Duplex scanners, network destinations and OCR settings tuned so a preparer is not waiting on a 60-page organizer.
Terminal server sizing, session limits and licensing checked before twenty people log in from home on a Saturday.
A single outage on April 10 is a business event. We add failover so filing does not stop.
DMARC, impersonation protection and payment-change verification rules, because tax season is prime phishing season.
We plan a rolling refresh so hardware retires on your schedule and your budget, not in the middle of a deadline.
For many firms it does. The rule reaches non-bank financial institutions, and tax preparation and certain financial advisory activities are commonly treated as in scope. The safest path is to assume it applies and implement the controls, since they are the same controls your cyber insurer and your larger clients will ask about anyway. Your attorney or compliance advisor should confirm scope for your specific practice.
No. The rule expects a designated individual responsible for the security program, and that role carries accountability that belongs inside your firm. We work directly for and with that person: we implement controls, provide evidence, report on gaps and help draft the technical portions of the program. The designation itself stays with you.
It depends on user count, whether you need Desktop-only features, how many client files you carry and how your staff work remotely. Hosting solves multi-user performance and remote access but adds recurring cost and vendor dependency. A well-built local server with fast NVMe storage is often better for a single-office firm. We size it against your actual file count and user load.
Almost always by attacking disk latency and the network path to the shared data folder. That means NVMe or SSD on the server, gigabit or faster switching, correct antivirus exclusions for the data directories, and eliminating Wi-Fi from the equation for heavy users. We benchmark before and after so the improvement is measurable rather than anecdotal.
Through a portal, with the client authenticating. Portals give you delivery confirmation, access control and a record. Encrypted email is a reasonable second option for small exchanges. Sending an unprotected PDF with a Social Security number in it is the habit that most often turns into a disclosure incident.
Scoped and time-bound. Seasonal preparers get named accounts with access only to the client folders and software they need, MFA enrolled on day one, and an expiry date set at creation. In May we disable rather than delete, archive their mailbox and data, then remove after your retention window.
First, confirm nothing was sent or paid. Then check for mailbox rules, forwarding and unfamiliar sign-in locations, reset credentials and revoke sessions. Longer term, DMARC enforcement, external sender warnings and impersonation protection cut most of this off, and a firm-wide rule that payment instruction changes require a callback removes the financial risk.
Yes. Advisory firms have similar obligations plus custodian portal access, CRM and archiving requirements for business communications. We handle the endpoint, identity, network and backup layer, and integrate with whichever archiving or compliance vendor your firm uses.
Free assessment, written report, no obligation. Book it while there is still time to act on it.
Talk to Your Pod
Book a free Deep Dive before busy season. We will benchmark workstation and file performance, review your security program against the Safeguards Rule controls, and give you a written plan.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.