
Most accounting firms think hard about their technology exactly once a year, in March, when a workstation dies mid-return or a file won't open the day before a deadline. By May it's background noise again. The reason the off-season conversation almost never happens isn't budget. It's that nobody has told the firm what to ask.
That's a provider failure, not a client failure. If your IT company only appears when something breaks, you'll only think about IT when something's broken. The off-season plan — hardware replacement, backup testing, security review, Microsoft 365 cleanup, and fixing whatever caused friction last busy season — should land on your desk without you asking for it.
Late summer and early fall are the window. Here's the order we'd work in.
Backups first, and “we have backups” is not the answer
The question isn't whether a backup job runs. It's whether anyone has restored from it. A job that reports success every night and fails at recovery is worse than no backup at all, because it buys you confidence you haven't earned.
Ask for a test restore. A real file, a real mailbox, ideally a whole machine, with someone watching the clock. Recovery time matters as much as recovery itself for an accounting firm: losing a day in August is irritating, losing a day in March is a client problem and possibly a filing problem.
Then audit who can get into Microsoft 365
Four things, in this order:
- Multi-factor authentication on every account, including the partners'. The owner exemption is the single most common hole we find.
- Admin accounts — how many exist, who holds them, and whether anyone is reading daily email from one.
- Mail forwarding rules. Auto-forwarding is one of the clearest signs of a compromised mailbox and one almost nobody checks.
- The account list itself. Last season's preparer, the bookkeeper you used for one project, the person who left in May. Every account still standing is a door.
Then price out the hardware that won't survive January
Workstations and servers rarely fail at a convenient moment. A five-year-old machine that feels slow in September is a machine that dies in March, and in March you will pay whatever it costs to make the problem go away that day. Building the replacement list now lets you spread the spend across two quarters and schedule the downtime yourself.
Your tax software is secure. The firm around it may not be.
The most common misconception we hear is that because client data lives in tax software, a hosted portal, or Microsoft 365, it's handled. The platform is generally the strongest part of the setup. Almost every real exposure at a small firm happens in the space around it: an account without MFA, a departed employee whose access was never removed, a return downloaded to a local desktop and never deleted, a reused password, a client file emailed as an attachment because the portal felt like too many steps.
The software may be secure. The people, devices and permissions surrounding it are still yours to manage.
Where the vendor's responsibility ends and yours begins
Draw the line explicitly, because it comes up the moment something goes wrong. The vendor is responsible for securing their platform and their infrastructure. You are responsible for who gets an account, whether MFA is enabled, who can see which clients, what happens the day someone leaves, what gets downloaded to a local machine, and how credentials are stored.
You can outsource the application. You cannot outsource responsibility for your clients' data because the application is hosted by someone else. If a preparer's credentials are used to pull returns after they've left, no vendor is going to be the one explaining it to your clients.
What's actually different about a Rhode Island firm
The security requirements themselves don't change at the state line. Client tax data needs the same protection in Cranston that it needs in Chicago. What changes is the shape of the problem.
Most accounting firms in Rhode Island are small. One person is frequently the office manager, the HR department and the IT contact at the same time. Relationships are informal in a way that's genuinely pleasant to work with — the seasonal preparer is somebody's cousin, the part-time bookkeeper has been around for a decade. Informal works fine right up to the moment you need to state exactly who has access to client data and can't.
Seasonal staffing compounds it. A firm that goes from six people to ten in January and back to six in April is turning over accounts and devices twice a year, every year. Do that for a few years without a written process and you accumulate accounts nobody remembers creating and laptops nobody remembers issuing.
So the boring stuff — documentation, a written onboarding checklist, a written offboarding checklist — carries more weight in a small firm, not less. A 200-person firm has an HR department forcing the process. A six-person firm in Warwick has to decide to do it.
The other local difference is practical: during busy season, being able to get someone physically into your office the same morning is worth real money. Most of this work is remote, but the day a server or a switch dies on March 10th, distance stops being an abstraction.
What to do in the next 30 days
- Have a test restore performed while you watch, and write down how long it took.
- Pull a full list of Microsoft 365 accounts and disable anything you don't recognize.
- Turn on MFA everywhere, partners included.
- Check every mailbox for forwarding rules.
- List every workstation and server with its age, and pick the ones getting replaced before January.
- Write down, on one page, what happens when someone leaves.
None of that is expensive. It's just work that never feels urgent until it's February and it's far too late to start.
If you'd rather not run that list yourself, this is the kind of thing we handle for accounting firms across Rhode Island year-round. Get in touch and we'll walk your setup before the season starts.
