CPA firms and tax practices
Firms that prepare returns, hold Social Security numbers and bank details, and need systems that hold up when the workload peaks.
Your busiest weeks are the worst time for a locked account, a failed server or a phishing email dressed up as a client document. Chrysalis Tech Group gives accounting and certified public accountant (CPA) firms 24/7 IT support, secure ways to exchange client files and help with the security program the Federal Trade Commission (FTC) Safeguards Rule asks for.
IT support for accounting firms keeps your tax and accounting software, client files and email working and protected, with extra attention before and during tax season. Chrysalis provides 24/7 help desk support, monitoring, backups, secure client file exchange and email security. We also help you put in place the controls the FTC Safeguards Rule expects, including a WISP and MFA. The plan and the decisions stay with your firm; we do the technical work and keep it running.
Firms that hold sensitive financial data and cannot lose a day in filing season.
Firms that prepare returns, hold Social Security numbers and bank details, and need systems that hold up when the workload peaks.
Practices that sign in to client banking and accounting systems every day and need those credentials protected.
Partners and office managers who currently fix the printer, reset passwords and renew software licenses themselves.
Accounting firms hold the data criminals want, and tax season leaves little time to spot a scam.
A slow server or a locked-out preparer costs hours you cannot get back in the final weeks. Seasonal staff also need accounts, devices and access set up quickly, then removed when the season ends.
Criminals send fake client documents, fake payment requests and emails pretending to come from the Internal Revenue Service (IRS), timed for when staff are busiest. One stolen password can open a mailbox full of tax returns.
The FTC counts tax preparation firms as financial institutions under its Safeguards Rule. The rule expects a written security plan, a named person in charge of it, risk assessments, and controls such as MFA and encryption. Your firm stays responsible for it even when IT is outsourced.
Day-to-day support, plus the security work the Safeguards Rule calls for.
Support for partners, staff and seasonal preparers at any hour, with monitoring of the servers, cloud apps and computers your firm depends on. Before the season starts, we check updates, backups, licenses and remote access, so problems surface early instead of in the final week.
A secure way for clients to send and receive documents, so returns and statements stop traveling as email attachments. We help you choose and configure the file-sharing workflow and show staff how to use it.
Filtering for phishing and spoofed messages, MFA on email and remote access, and security awareness training before the season, so staff know what a fake client email looks like before the rush.
Help with the technical side of your WISP: a risk assessment, access controls, encryption, logging and an incident response plan. Your firm owns the plan; Chrysalis does the technical work and keeps records of it.
Backups of your tax and accounting data, restore tests, and a plan for keeping the office working through storms and outages. Client servers can be housed at Fibertown, a data center rated for up to a Category 5 hurricane.
A complimentary risk assessment gives you a high-level view of your email security, backups and access before the season starts. It is also a useful starting point for the risk assessment the Safeguards Rule expects.
Request a risk assessmentMurphy’s Corporate Housing Associates, on moving from an in-house server to a cloud-based solution with Chrysalis.
Read more client stories“The company successfully migrated from an in-house server to a cloud-based solution, thanks to Chrysalis MSP. It was a seamless transition, and the team proved to be reliable and responsive to the firm's inquiries. They used their experience to recommend solutions to meet the client's requirements.”
Understand your environment, agree on the priorities, then make progress together.
Talk through your business, current systems and what needs to change.
Assess risks and build a practical plan around your priorities.
Put the agreed technology and security improvements in place.
Stay supported as your people, systems and business evolve.
Common questions from accounting and CPA firms.
If you prepare tax returns, the FTC treats your firm as a financial institution under the rule, and the IRS reminds tax professionals that a written security plan is required. Other financial services can also bring a firm under the rule, so confirm your position with your own advisers. Chrysalis helps with the technical side.
We help you build it. Chrysalis can document the technical controls for your WISP, help with the risk assessment inputs and put the agreed controls in place, but the plan has to describe how your firm actually works, and your firm owns it. No provider can make you compliant on its own.
The help desk is available 24/7, so a preparer working late can still get help. Before the season we review updates, backups, licenses and remote access, and we agree with you how urgent issues are handled and when someone comes onsite.
Yes. Remote access protected by MFA, managed and encrypted laptops, and secure access to your tax software let staff work from home without copying client files to personal computers.
We support the servers, cloud accounts, computers and network your tax and accounting software runs on, and we work with the software vendor when an issue sits on their side. Tell us what you use and we will explain how we would support it.
Managed IT is a flat monthly fee. Plans start at $125 per user per month with Chrysalis Essential, and the final figure depends on the agreed scope, mainly the number of people and devices, your servers and the security work you need. Your proposal lists what the plan covers.
Talk to Chrysalis about your firm, your software and your Safeguards Rule plan. We start with a conversation and a complimentary risk assessment.