Nearly every conversation with a CPA firm starts the same way, often with a seasonal timing bias: "we have IT, we should be fine on security." Sometimes that is true. More often it is a category mistake — one that gets amplified in the eight-week window between mid-February and April 15, when the phishing tempo against tax preparers rises. IT support and cybersecurity operations are related jobs, but they are different jobs. When an assumption gets made that the first one covers the second, the firm ends up with a gap that only shows up on the day a preparer's mailbox does something strange or the tax software server stops responding on a weekend in March.
This piece is not "your IT firm is bad." Most IT firms are excellent at what they do. This piece is about which job is which, when a CPA or tax firm needs a specific security operation on top of its IT provider, and — importantly — how to tell whether the IT firm you already have is quietly covering it.
The direct answer
Your IT provider is probably not your security team. That is usually not their fault; the two roles have different training, different tools, and different hours. Some IT firms have added a real 24/7 security operations team and can produce insurance-grade evidence — most cannot. The way to tell is to ask a small number of specific questions and listen for a specific kind of answer. The questions are below.
What a general IT provider is built to do
A good IT firm handles the layer that keeps the firm operational day-to-day:
- Helpdesk for staff — the preparer cannot print a return, the seasonal contractor's laptop will not join Wi-Fi, the front-desk phone is down.
- Hardware procurement and refresh — preparer laptops, partner workstations, the tax software server itself.
- Patching and routine maintenance — Windows updates, application updates, driver cleanup.
- Backups — the nightly job runs, the offsite copy syncs.
- Microsoft 365 or Google Workspace administration — user provisioning, mailbox forwarding, license changes.
- Wi-Fi, firewall, and network device management — the guest SSID, the preparer VPN.
- Tax software server upgrades — service packs, application updates, seasonal readiness.
- Vendor coordination — the tax software vendor, e-signature integrations, e-filing systems, the phone-system provider.
Every one of those is real work. A CPA firm without a competent IT provider runs slower, breaks more often, and takes longer to recover from small problems. This is not the layer we are trying to displace.
What a security operation is built to do
A security operation is built for a different question: not "is it working?" but "is someone attacking it right now, and if so, what are we doing about it?"
The concrete pieces:
- 24/7 detection. A real security operations center reading endpoint and identity alerts around the clock — not software that fires notifications into an email inbox nobody watches after hours.
- Response. When something fires that looks real, the compromised workstation is isolated within minutes, the identity is disabled, and the incident is contained before it spreads to the tax software server.
- Identity threat detection. Watching Microsoft 365 or Google Workspace sign-ins for adversary-in-the-middle phishing kits, mailbox rules that hide IRS and refund emails, OAuth-consent attacks, and token-replay activity — the identity-layer attacks that bypass MFA and enable refund-redirect fraud.
- Security awareness training. Continuous phishing simulations calibrated for accounting staff — IRS-impersonation, EFIN-suspension threats, payroll-lookalike lures for the office admin, refund-redirect themes for preparers and seasonal contractors — and the click-rate trend a cyber-insurance carrier and an FTC Safeguards program assessment will ask about.
- Incident response coordination. When something happens: forensics coordination, prompt IRS Stakeholder Liaison notification (the IRS asks preparers to report data theft immediately), FTC 30-day notification for breaches affecting 500 or more consumers, state breach-notification clocks, cyber-insurance claim support, and the client-facing communication.
- WISP and audit evidence. The Written Information Security Plan required by the FTC Safeguards Rule and IRS Pub 5708, audit-control logs, MFA-coverage reports, encryption attestation, training completion records, and the written incident-response plan — the evidence package a cyber-insurance underwriter, an IRS Stakeholder Liaison, or an FTC investigator actually asks for.
These are operational security tasks. They are what a security team does, not what an IT team does. A general IT firm may configure some of these; very few operate them continuously.
Why the assumption fails: everyone assumes someone else is watching
The failure mode in a CPA firm is not usually a missing tool. It is a missing owner.
A preparer or seasonal contractor gets phished at 8pm on a Tuesday in March through an email that looks like an IRS Stakeholder Liaison notice. An endpoint alert fires. The IT firm's ticket queue receives the notification. Nobody at the IT firm is on-call for it; their support hours are 8am to 6pm. Meanwhile the attacker has the preparer's session token, sets an inbox rule that hides IRS-related emails, and quietly swaps direct-deposit routing on a batch of client returns filed that week. By Friday night the tax software server is encrypted. Monday morning the firm cannot prepare, file, or bill — and April 15 does not move.
By that point either client refunds have been misrouted or the tax software is down. When the managing partner asks who was supposed to be watching, everyone points to someone else.
The alert was there. The tool worked. Nobody was watching it.
When your IT provider IS enough (honest read)
Some IT firms have genuinely built a security operation. Others have added a security bundle from a distributor and describe it that way. The words look identical on a website. The operational reality is different.
Your IT firm may already have you covered if all of these are true:
- They operate — not merely resell — a managed endpoint detection and response service on every workstation AND the tax software server (including a documented seasonal-contractor coverage lifecycle), with a real 24/7 security operations team behind it.
- They can produce, on request, the audit-control logs, MFA-coverage report, and identity-monitoring evidence a cyber-insurance underwriter wants for a renewal application.
- They have a documented incident-response process specific to your firm, including who they call at your firm at 2am, how they coordinate with your cyber-insurance carrier, and how they support the IRS Stakeholder Liaison and FTC notification timelines.
- They have a written vendor engagement covering FTC Safeguards Rule § 314.4(f) service-provider oversight — meaning they can produce evidence of their own information-security program and will maintain the safeguards the rule requires you to require of them.
- They carry appropriate cybersecurity insurance and errors-and-omissions coverage themselves.
If all five are true and you can verify them, you may not need a separate security firm. If any are unclear, the security layer is not owned — the firm is uncovered even if the IT relationship is excellent.
Questions to ask your IT provider (bring these to your next review)
The point of these questions is not to trap anyone. It is to find out what is being operated on the firm's behalf and what is not, so any gaps can be assigned to someone before the gap becomes an incident.
-
"Is there a security operations center monitoring our endpoints 24 hours a day, or is it software that runs unattended after your business hours?" A yes-there-is-a-team answer should name the team and the escalation path.
-
"If a workstation starts behaving like an active ransomware intrusion at 2am on a Saturday, who acts, how fast, and what do you do first?" The answer should describe automatic isolation within minutes, not "we'd see it Monday and call you."
-
"Can you produce the audit-control logs, MFA-coverage report, and identity-monitoring evidence our cyber-insurance renewal will ask for?" The answer should be "yes, here are samples from last quarter," not "we'd have to check."
-
"Do you have a written vendor engagement covering FTC Safeguards Rule § 314.4(f) service-provider oversight, and can you produce evidence of your own information-security program?" The Safeguards Rule requires the firm to select service providers capable of maintaining appropriate safeguards and to require them by contract to do so. That is a specific ask with a specific paper trail — "we've been with you for years, we're fine" is not the same as a written engagement and evidence.
-
"Do you monitor our Microsoft 365 or Google Workspace tenant for identity attacks — session-token theft, adversary-in-the-middle sign-ins, malicious inbox rules — not just email spam filtering?" The answer should distinguish identity threat detection from anti-spam. Most IT firms provide the second and not the first. This is the layer that catches refund-redirect and wire-fraud attempts before the money moves.
-
"When you deploy patches, do you have a documented SLA for critical CVEs, and do you specifically track the CISA Known Exploited Vulnerabilities list?" The answer should be a written policy, not "auto-update is on."
If the answers on any of these are hesitant or unclear, the security layer for that specific piece is unowned. That does not mean firing anyone. It means naming who owns it going forward.
Co-managed is the healthy model
The mental model most CPA firms default to — one firm, all of it — is not the model that works best for security. It is a leftover from an era when small offices had a single IT contact and everything technical went through that person.
The model that works now is co-managed. Your IT firm keeps the firm operational — the layer they are excellent at. A security firm operates the detection, response, identity monitoring, awareness training, and evidence layer — the layer they are excellent at. The two coordinate: when a security incident touches an IT-owned system, the two firms work together. When an IT change might affect the security posture, the two firms coordinate the change.
No one gets fired. The firm pays for two functions instead of one because those functions are actually two things. Total cost is often closer than partners expect to what a single do-everything provider would charge for comparable depth, because each specialist runs its own layer more efficiently than a generalist can run both.
What we do
Obsidian Ridge is a managed security firm, not an IT MSP. We coordinate with the IT firm the accounting firm already has — we do not replace them. Our program is managed detection and response, identity threat detection, and security awareness training, operated end-to-end for the firm with the WISP maintenance, FTC Safeguards Rule evidence, and cyber-insurance readiness support attached. Deeper on the accounting context: the CPA and accounting cybersecurity page.
If a cyber-insurance renewal is the pressure point that surfaced this whole question, the Cyber Insurance Readiness Sprint is the fixed-scope engagement — from $1,500, delivered in 7 business days — that turns the questionnaire into a paperwork step instead of a scramble.
If you want the broader tool-and-service-model taxonomy before the co-managed conversation with your IT firm, the MDR vs EDR vs MSSP vs SOC-as-a-service decision tree is the buyer-side companion piece.
Next step
If this article named a gap you already suspected, the practical next step is either the free carrier questionnaire — score the firm yourself first — or the Cyber Insurance Readiness Sprint if the renewal, an FTC Safeguards program review, or a Stakeholder Liaison conversation is already on the calendar.
Last updated
July 28, 2026. We refresh this content as the threat landscape and tools evolve.