Busy Season Is Not The Time To Find Out
IT for CPA and financial services firms — a change freeze during filing season, wire fraud controls that catch a spoofed instruction, and a documented Safeguards Rule plan.
45 min · Free · No commitment
Four months of the year, downtime is not an inconvenience
Most businesses spread their workload across twelve months, which gives an IT outage some slack to be absorbed — reschedule a meeting, push a deliverable a day. A tax or audit practice compresses most of its annual work into a few months, so an outage in the middle of filing season is not proportionally worse than one in July, it is categorically worse, because there is no slack anywhere in the calendar to absorb it. A server issue on March 14th does not feel like a server issue — it feels like a deadline the firm might actually miss, with a client who will remember exactly whose fault that felt like.
Firms that move client money are targeted for business email compromise specifically, and the attack is social engineering wearing a technical costume: a spoofed email thread, a revised wire instruction that looks routine, and money that does not come back once it clears. It rarely announces itself as an attack. It looks exactly like a client's normal request, which is precisely why it works, and why filtering alone is not the whole answer — the process around a wire change has to catch what the inbox does not, because by the time the email looks suspicious to a human reader the transfer is often already done.
The FTC Safeguards Rule obliges many tax preparers and financial services firms to maintain a written information security plan, and most firms discover that obligation from an insurer's questionnaire or a client's security review rather than in advance, at which point it is a scramble instead of routine paperwork. Facet MSP documents and implements that plan, deploys Proofpoint email filtering tuned for wire fraud patterns, and treats the weeks around filing deadlines as a change freeze — nothing gets touched that does not have to be, and the plan itself gets revisited annually rather than left to go stale the moment it is finished.
What a finance firm actually needs
Busy-Season Change Freeze
No non-critical updates, migrations, or configuration changes during the weeks your firm can least afford a surprise. What gets touched during a freeze is decided in advance, in writing, not improvised under deadline pressure with a filing due in two days.
Wire Fraud and Email Compromise Controls
Proofpoint filtering tuned to catch spoofed domains and lookalike senders, paired with a verification step for any changed payment instruction — so a fraudulent wire request gets caught by a process, not by whether someone happened to notice the sender address looked slightly off.
Written Information Security Plan
A documented plan covering your actual systems and practices, built to satisfy what the FTC Safeguards Rule and most client security questionnaires ask for, kept current rather than written once during onboarding and never revisited.
Secure Client Document Exchange
Clients send tax documents and financial statements through a secure portal instead of an email attachment, which closes off one of the more common ways sensitive financial data ends up somewhere it should not, sitting in an inbox indefinitely.
Multi-Factor Authentication Everywhere
Every login to client financial data, through Microsoft 365 and Entra, requires a second factor — a single stolen password stops being enough to reach client information.
Tax and Practice Software Support
We support the infrastructure your tax and practice management software runs on, and coordinate with the software vendor directly when an issue is specific to the platform rather than the network underneath it.
Backup and Retention for Working Papers
Working papers and client files are backed up and retained on a schedule that matches your professional retention obligations, so a records request does not turn into a search through someone’s personal archive years after the engagement closed.
Client trust stops being a gamble
- Nothing changes under your systems during filing season
- Spoofed payment instructions get caught before they are acted on
- Your security plan exists in writing when a client asks for it
- Clients send documents through a portal, not an email attachment
- Every login to client data requires a second factor
- Working papers are retained and recoverable on demand
We plan around your calendar, not ours
We freeze changes when you cannot absorb them.
Maintenance windows and upgrades get scheduled around your busy season, not ours — the weeks you can least afford surprise are exactly the weeks we touch the least.
Wire fraud is a process problem, so we fix the process.
Filtering catches most of it, but the real control is a verification step for any changed payment instruction — a habit we help build into how your firm actually handles money movement.
We answer the security questionnaire with you.
When a client or insurer sends a security review, we help complete it using documentation that already exists, instead of scrambling to produce answers to questions nobody has thought about since the last one arrived, usually a year earlier.
Accounting and finance IT questions
Can you support us through busy season without making changes?
Yes — a defined change freeze during filing season is standard for our accounting clients. Anything genuinely urgent still gets handled, but routine updates and non-critical projects wait until the calendar allows it.
What is the FTC Safeguards Rule and does it apply to us?
It requires many tax preparers and financial services firms to maintain a written information security program. Whether it applies to your specific firm is a question for your compliance advisor or counsel; what we do is document and implement the technical controls a plan like that typically requires, once you know it applies, and keep the plan current after that first pass.
How do you stop a spoofed wire request?
Email filtering tuned to catch lookalike domains catches a large share of it before it ever reaches an inbox. The other half is a verification habit — any changed payment instruction gets confirmed through a second channel, by phone, before money moves.
Do you support our tax software?
We support the infrastructure your tax and practice management software runs on and coordinate with the software vendor on platform-specific issues, so a slow login or a sync error gets resolved instead of bounced between two support queues while a return sits unfinished.
Our client sent us a security questionnaire. Can you help?
Yes — this comes up often, and having a documented security plan already in place is what makes answering it fast instead of stressful. We help complete it using documentation we maintain as part of the engagement, rather than reconstructing answers from memory under a deadline.
Ready to take this off your plate? Six questions.
Spend 90 seconds answering. We'll spend a few hours putting together a written assessment of where your IT stands — and a 45-minute call with one of our engineers.