Industry
Returns, payroll, and a mailbox that approves payments.
Accounting firms hold tax returns, payroll files, and the authority to move money. The work rhymes with law firms: a small partnership, Microsoft 365 or Google Workspace, a cyber insurance form, and no in-house SOC. We will take this work. We are not leading with it, because the first customers should look alike while we learn how to onboard.
Why the work shows up
- IRS Publication 4557 is a public guide on safeguarding taxpayer data. It is a useful checklist for a firm. It is not a certification we issue, and reading it does not make a practice compliant by itself.
- Tax season concentrates the sensitive data and the fatigue. A fake IRS notice or a fake client upload lands when people are moving fast.
- W-2 requests and business-email compromise against a controller or a partner are ordinary crimes against firms of this size. They do not require a novel exploit.
- Renewal questionnaires look a lot like the ones law firms see: MFA, endpoints, mail, backups, and prior incidents.
What we would actually do
- Monitor the computers that hold the tax software and the mail identities that can approve a payment.
- Watch for new inbox rules and for sign-ins that do not match the firm’s pattern.
- Time awareness exercises outside the worst two weeks of the calendar, unless you ask otherwise.
- Write the monthly letter so a partner can hand it to an insurer or a client who asked what the firm does for security.
What we will not take on
- We will not prepare returns, touch payroll processing, or give tax advice.
- We will not claim IRS compliance, SOC 2, or any other attestation.
- We will not email your clients about an incident. That notice is the firm’s, with the firm’s counsel.
- We are not the managed service provider who keeps the tax application updated, unless that is separately written down.
The bundles and the hours are the same ones on the pricing page. A profession does not get a secret package.