Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

IT During Tax Season: What Accounting Firms Should Sort Out Before January

Managed IT
Last updated: July 15, 2026

Tax season IT prep means checking five things before January: remote access capacity, tax software licensing and backups, multi-factor authentication on every system touching client data, a written information security plan, and a tested backup restore. Miss one and it usually surfaces in February, at the worst possible time.

I’ve walked into two different accounting firms in the last three Januarys where the fix was something the owner had been meaning to get to since October. A VPN concurrent-user cap set for a twelve-person office that just hired six seasonal preparers. A backup job that had been silently failing since September because nobody got the alert email. Small things. Both of them. They don’t feel small on February 20th with three hundred returns in the pipeline.

VJNetworks supports accounting and CPA firms across Rockland, Westchester, and Bergen as part of our broader managed IT services for companies of 5 to 60 employees, so this list is partly built from what we walk into every fall. What follows works whether you fix it yourself, hand it to your current IT person, or use it to check whether they’re already covering it.

Why Tax Season Breaks Infrastructure That Was Fine in August

Nothing about a CPA firm’s network changes physically between September and January. What changes is load. Load exposes whatever was already marginal. A server that handled eight concurrent users comfortably starts choking at fourteen. A firewall rule written for one office location strains once three staff members start working weekends from home. None of this is new hardware failing. Old hardware, meeting real demand for the first time all year.

Seasonal staffing makes it worse. Firms bring on preparers and reviewers for twelve to sixteen weeks, and every one of them needs an account, a license seat, and access scoped to exactly what they should touch. Rushed onboarding in the second week of January means shared logins, over-permissioned accounts, and licenses nobody remembers to remove in April. That part matters more than owners think. Far more. The FTC’s Safeguards Rule treats access controls as a core requirement, not a nice-to-have. An ex-seasonal-preparer’s still-active login is exactly the kind of gap an examiner finds first. Or a plaintiff’s attorney.

Accounting firm staff working through stacks of paper tax files at their desks during filing season

The Compliance Backdrop Most Firms Ignore Until It’s a Problem

Every paid tax return preparer is legally required to maintain a Written Information Security Plan. Regardless of firm size. That comes straight from IRS guidance: “Having a written data security plan isn’t just a good idea, it’s federal law.” The requirement traces back to the Gramm-Leach-Bliley Act and the FTC’s Safeguards Rule, and it applies whether you’re a two-partner practice or a firm with forty staff.

A WISP isn’t a binder that sits in a drawer for the one time in a decade someone asks to see it. It’s supposed to name who owns information security at the firm, document the actual risks, describe the safeguards in place, cover how vendors and cloud services are vetted, and get tested and updated on some regular schedule. Most of the firms I’ve reviewed have something written. Technically. Fewer have anything that describes what they’re running today.

The IRS Security Summit also flags something specific to this industry: fraudsters posing as new clients, sending malicious attachments disguised as W-2s or 1099s, specifically targeting the busiest weeks of filing season. Their guidance for tax professionals calls out phishing attempts aimed at stealing EFIN, PTIN, and CAF numbers, not just client data. A firm’s own credentials are a target too. Not only the returns sitting in the file server.

What Actually Fails Every January

Same list. Almost every year, across almost every firm size. Order roughly matches how often we see each one.

What breaksWhy tax season triggers itWhat fixes it before January
Remote access / VPNConcurrent-user licensing capped for normal headcount, not weekend crunch staffingConfirm license count against peak expected concurrent users, not average
Tax software performanceServer-hosted CCH ProSystem fx or ProSeries instances hit by concurrent-session load nobody testedLoad-test with realistic concurrent users, not just a login check
Backup verificationA silently failing backup job goes unnoticed for months when nobody’s watching alertsRestore a real file from backup. Don’t just check a green checkmark.
Seasonal staff accessRushed onboarding in January, forgotten offboarding in AprilScoped accounts from day one, calendar reminder to disable in April
MFA coverage gapsEnabled on email, skipped on the tax software, the client portal, or remote desktopAudit every system that touches taxpayer data, not just the obvious ones

The tax software row deserves a second look. Firms running CCH ProSystem fx or ProSeries on an aging on-premise server rarely test what happens at eight or ten simultaneous logins. Not until eight or ten people are sitting there logged in on January 27th, waiting. By then testing isn’t an option. Only troubleshooting is.

IT technician checking server rack and backup appliance cables in a small accounting firm server closet

The Nine-Item Checklist to Run Before January

This is close to what we walk through with firms during a fall readiness review. Print it. Assign an owner to each line. None of it requires a big budget. Most of it just needs someone to actually do it.

  1. Confirm VPN and remote access licensing against peak seasonal headcount, not your normal staff count.
  2. Load-test your tax software server with a realistic number of simultaneous users. Before the season. Not during it.
  3. Restore an actual file from backup and confirm it opens correctly. Green checkmarks lie.
  4. Enable multi-factor authentication everywhere taxpayer data lives. Email, tax software, client portal, remote desktop, cloud storage. All of it, not most of it.
  5. Write or update your Written Information Security Plan. If nobody at the firm can produce one on request, you don’t have one. Doesn’t matter what’s in a drawer.
  6. Set up seasonal staff accounts with scoped access from the first login, and put an April offboarding date on the calendar now.
  7. Patch everything. Operating systems, tax software, browsers, firewall firmware. All of it. A missed patch in September is still missed in January, just with worse timing.
  8. Confirm your printer and scanner fleet can handle e-file volume. No queue backing up during the last week of the deadline.
  9. Train staff on the new-client phishing pattern the IRS Security Summit has flagged. Fake W-2 attachments, fake 1099 links, timed to your busiest weeks.

Nine items. None of them exotic. The firms that skip this list aren’t lazy, usually. They’re the same firms every year. Running the same fire drill in February that a Tuesday afternoon in November could have prevented.

What Partners Ask Us Before Filing Season

Do we really need a formal WISP if we’re only three partners?
Firm size doesn’t change the requirement. None. The IRS is explicit that every paid preparer needs a written plan, and a three-partner firm handling the same taxpayer data as a forty-person firm carries the same legal exposure if that data gets exposed.
How much does it cost to get IT support in place before tax season?
Around $995 a month as a flat baseline. That’s the starting point. The real number depends on headcount, software, and how much cleanup is needed going in. What it usually saves is the emergency-rate invoice from whoever gets called in February when something breaks.
Can our current IT person just handle this checklist?
Possibly. Depends on the bandwidth and the tax-software-specific experience. A lot of solo IT hires are strong generalists who’ve never load-tested a ProSystem fx server under real concurrent use, because most of their clients don’t run anything like it. Worth asking directly whether they have.
What’s the single biggest mistake firms make heading into January?
Treating last year’s setup as this year’s baseline. It isn’t. Headcount changes, software gets updated, staff work from more locations than they did twelve months ago, and none of that gets re-tested until it fails under load.
Is a data breach at a small accounting firm genuinely likely?
More likely than owners assume. Small firms get targeted for exactly that reason. Less security. Smaller budget. Easier target. The IRS Security Summit’s own guidance calls out tax preparers by name as a recurring target, independent of firm size, which is part of why the WISP requirement doesn’t have a small-firm exception.

None of this needs to happen in a single weekend. It definitely shouldn’t happen for the first time during the third week of January. We’ve supported firms like yours with a cybersecurity program built around exactly this kind of seasonal load.

Want a second set of eyes before January?

A free IT assessment from VJNetworks walks your firm’s setup against this exact checklist. No pitch attached. You keep the findings either way.

Get Your Free IT Assessment →

Or call (845) 440-5000

Over 20 years in the Tri-State area · 97% client retention · a real person responds within 15 minutes