A managed IT provider runs your firm's computers, network, email and backups for a monthly fee. For a CPA firm it should also cover the security controls the IRS and the FTC expect you to have, and help you keep the written plan the law requires.
If you are looking for an IT provider in Kyle, Buda, San Marcos, Austin or Bastrop, use the list below to compare what each one actually covers.
Why CPA firms need more than basic IT support
Your firm holds Social Security numbers, bank account details and income records for every client. The FTC Safeguards Rule treats tax preparation firms as financial institutions, and the IRS says tax and accounting professionals must have a written data security plan. Your IT setup is the technical half of that plan.
The IRS names six basic protections it calls the Security Six:
- Anti-virus software
- A firewall
- Two-factor authentication
- Backup software or services
- Drive encryption
- A virtual private network
A good provider handles all six as part of the service, and goes further.
What a provider should do for your firm
Secure and monitor every computer and server. That includes endpoint protection, patching and someone watching the alerts. Laptops that travel to client sites and staff who work from home are the usual weak spots.
Set up multifactor authentication. Email, tax software, cloud storage and remote access should all require a second factor. The Safeguards Rule requires it for any individual accessing an information system, unless your Qualified Individual approves an equivalent control in writing.
Encrypt client data. The rule calls for encryption of customer information at rest and in transit over external networks. Your provider should confirm this for laptops, servers, backups and file transfers.
Run backups and test the restore. Backups only count if you can restore from them. Ask how often they run, where the copies live and when a restore was last tested.
Filter email. Phishing is the usual way in. Email filtering, plus staff training that is refreshed regularly, cuts the risk.
Scan for weaknesses. The FTC guidance calls for annual penetration testing and vulnerability assessments, with system-wide scans every six months. Firms with fewer than 5,000 consumers are exempt from that specific requirement, but scanning is still good practice.
Manage your vendors. Your tax software, client portal and cloud services all touch client data. The rule expects you to pick vendors carefully and require safeguards by contract.
Help you write the plan. The IRS offers Publication 5708, a 28-page template for a written information security plan. Your provider can fill in the technical sections and keep them current.
Prepare an incident response plan. When something goes wrong, you should already know who calls whom. That includes the notification deadlines we cover in our post on what a Texas CPA firm must do after a data breach.
Answer the phone in busy season. When a workstation dies on March 28, the fix cannot wait until Monday. Ask about response times and whether the provider sends someone on site.
Questions to ask before you sign
- Who will be our Qualified Individual, and are they on staff or from your team?
- Which of the IRS Security Six do you cover, and what is extra?
- Do you help us write and update our written information security plan?
- How often do you test restores, and can we see the results?
- What is your response time in January through April?
- Do you charge a flat monthly fee, and what falls outside it?
- What happens to our data and access if we leave?
- Will you meet with the partners at least once a year to report on security?
The last question matters because the Safeguards Rule requires the Qualified Individual to report in writing to leadership at least once a year.
Why local matters
A firm in Central Texas benefits from a provider that can reach the office. Hardware fails, and a network problem in the middle of filing season is easier to fix with someone nearby. Ask whether the provider has technicians who can be in your office the same day.
The bigger lesson
Compare providers on what they cover and how fast they answer in January through April, not on the monthly price alone. The right one treats the IRS and FTC requirements as part of the service and shows you proof, such as restore test results and a yearly security report to the partners.
safemode IT is a managed IT and cybersecurity provider based in Kyle, Texas. We support CPA firms and other small businesses along the I-35 corridor, from Bastrop and Austin to Buda and San Marcos. To compare what your current setup covers against the list above, call 512-761-7652 or visit safemodeit.com.
Sources
- IRS, Tax Security 2.0: The Taxes-Security-Together Checklist
- IRS, Publication 5708 and WISP guidance
- FTC, FTC Safeguards Rule: What Your Business Needs to Know
- eCFR, 16 CFR 314.4 Elements
- eCFR, 16 CFR 314.6 Exceptions
Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.
Book a 10-Minute Discovery Call →Frequently asked questions
What does managed IT include for a CPA firm?
Device security and monitoring, multifactor authentication, encryption, tested backups, email filtering, vulnerability scanning, vendor review and help with your written security plan.
What is the IRS Security Six?
Anti-virus software, a firewall, two-factor authentication, backup software or services, drive encryption and a virtual private network.
Why does a CPA firm need a local provider?
Hardware fails during filing season, and a nearby technician can be on site the same day. Ask any provider about response times and on-site support before you sign.
What should I ask a managed IT provider before signing?
Ask who your Qualified Individual will be, how often restores are tested, what response time to expect in January through April, what falls outside the flat fee, and what happens to your data if you leave.
Can safemode IT be our CPA firm's managed IT provider?
Yes. We are based in Kyle and support CPA firms from Bastrop and Austin to Buda and San Marcos. Learn more about our managed IT services or reach out for a free assessment.
Last updated: September 30, 2026

