TITANIUM COMPUTING
(512) 623-9199
Free consultation
SERVICES · ACCOUNTING & TAX
Managed IT and Security for Accounting and Tax Firms in Central Texas
Tax firms need a Written Information Security Plan (WISP), multi-factor authentication and monitoring that fits their obligations. Titanium Computing runs managed IT and security under a flat monthly per-user agreement, with documentation to help your firm put its plan into practice. See the IRS and FTC sources below.
The rules your firm already answers to
The IRS says: “Tax professionals are required by law to have a WISP in place to protect customer data.” IRS data security plan guidance. IRS Publication 5708 provides a sample WISP for smaller practices; adapt it to your firm.
Publication 5708 states: “Under the GLBA and Safeguards Rule, tax and accounting professionals are considered financial institutions, regardless of size.” Publication 5708, page 2. The rule specifies:
Qualified Individual
“Designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program (for purposes of this part, “Qualified Individual”).”
Multi-factor authentication
“Implement multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls;”
Monitoring and testing
“For information systems, the monitoring and testing shall include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, you shall conduct: (i) Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment; and (ii) Vulnerability assessments, including any systemic scans or reviews of information systems reasonably designed to identify publicly known security vulnerabilities in your information systems based on the risk assessment, at least every six months; and whenever there are material changes to your operations or business arrangements; and whenever there are circumstances you know or have reason to know may have a material impact on your information security program.”
How we cover each requirement
These services support your firm’s security program. Have your Qualified Individual review coverage, testing scope and evidence against the rule; 24/7 MDR alone is not a determination that the continuous-monitoring requirement is satisfied. Compliance documentation and deeper security programs depend on the tier and agreed scope.
| Requirement or safeguard | What we run | Where you see evidence |
|---|---|---|
| WISP and program oversight | Help your firm document its plan through control mapping, policies and evidence collection. Your firm designates its Qualified Individual. | Control mapping, policies, screenshots and logs. Compliance documentation |
| MFA and access controls | MFA and conditional access on every identity. | Identity controls and detection logs. Cybersecurity |
| Monitoring and testing | 24/7 managed detection and response (MDR). Whether it meets the rule’s continuous-monitoring standard is for your Qualified Individual to decide; we agree the testing scope with you at the assessment. | Detection logs and risk assessments. Monitoring and testing |
| Data recovery safeguards | Immutable off-site backups and quarterly restore tests. | Timed restore-test reports. Backup and recovery |
| Staff security awareness | Security awareness training and monthly phishing simulations, included in Complete and Compliance+; available as an add-on to Remote-First. | Department click-rate and report-rate reporting. Training |
Tax season without downtime
Make filing deadlines part of your technology planning: agree patching windows outside deadline periods and review the latest restore-test report before tax season. Our managed IT service tests and deploys OS and third-party patches on a schedule; backup restores are tested quarterly.
When someone needs help, our help desk has a 15-minute average first response. Critical issues get an engineer 24/7; routine requests queue for business hours. Help desk details.
Software we support
We support Microsoft 365 and Google Workspace, including tenant hardening and license management. For your firm’s tax and practice software and scanners, bring the vendor and device details to the assessment so we can confirm support scope and responsibilities before quoting.
For workflow automation, explore AI for accounting and bookkeeping firms.
Accounting firm IT questions
Do tax preparers need a WISP?+
Yes. The IRS says: “Tax professionals are required by law to have a WISP in place to protect customer data.” Read the IRS guidance and use Publication 5708 as a starting point for your firm’s own plan.
Does the FTC Safeguards Rule apply to my firm?+
Most tax preparation firms fall within its scope. IRS Publication 5708, page 2 says tax and accounting professionals are considered financial institutions under the GLBA and Safeguards Rule, regardless of size. Review the rule with your own counsel for applicability, exceptions and edge cases.
What does managed IT cost for a 10-person CPA firm?+
The published tiers are Remote-First at $95, Complete at $125 and Compliance+ at $155 per user per month. For 10 users, that is $950, $1,250 or $1,550 per month before separately billed servers. Minimum 10 users; servers are billed per device. A fixed quote follows a one-hour assessment. Compliance documentation and deeper security programs depend on tier and scope.
Can you work with our existing tax software vendor?+
Our managed IT service includes vendor relationship management. Bring your tax software vendor’s support requirements to the assessment so we can confirm how responsibilities will be shared. Specific tax-platform support must be confirmed before the agreement.
Accounting firm IT across Central Texas
Service areas: Austin, Round Rock, Cedar Park, Georgetown, Pflugerville, Leander, San Marcos.
Talk to an Engineer About Your Firm
One hour, no obligation. Fixed quote at the end.