Tax season IT prep means checking five things before January: remote access capacity, tax software licensing and backups, multi-factor authentication on every system touching client data, a written information security plan, and a tested backup restore. Miss one and it usually surfaces in February, at the worst possible time.
I’ve walked into two different accounting firms in the last three Januarys where the fix was something the owner had been meaning to get to since October. A VPN concurrent-user cap set for a twelve-person office that just hired six seasonal preparers. A backup job that had been silently failing since September because nobody got the alert email. Small things. Both of them. They don’t feel small on February 20th with three hundred returns in the pipeline.
VJNetworks supports accounting and CPA firms across Rockland, Westchester, and Bergen as part of our broader managed IT services for companies of 5 to 60 employees, so this list is partly built from what we walk into every fall. What follows works whether you fix it yourself, hand it to your current IT person, or use it to check whether they’re already covering it.
Why Tax Season Breaks Infrastructure That Was Fine in August
Nothing about a CPA firm’s network changes physically between September and January. What changes is load. Load exposes whatever was already marginal. A server that handled eight concurrent users comfortably starts choking at fourteen. A firewall rule written for one office location strains once three staff members start working weekends from home. None of this is new hardware failing. Old hardware, meeting real demand for the first time all year.
Seasonal staffing makes it worse. Firms bring on preparers and reviewers for twelve to sixteen weeks, and every one of them needs an account, a license seat, and access scoped to exactly what they should touch. Rushed onboarding in the second week of January means shared logins, over-permissioned accounts, and licenses nobody remembers to remove in April. That part matters more than owners think. Far more. The FTC’s Safeguards Rule treats access controls as a core requirement, not a nice-to-have. An ex-seasonal-preparer’s still-active login is exactly the kind of gap an examiner finds first. Or a plaintiff’s attorney.

The Compliance Backdrop Most Firms Ignore Until It’s a Problem
Every paid tax return preparer is legally required to maintain a Written Information Security Plan. Regardless of firm size. That comes straight from IRS guidance: “Having a written data security plan isn’t just a good idea, it’s federal law.” The requirement traces back to the Gramm-Leach-Bliley Act and the FTC’s Safeguards Rule, and it applies whether you’re a two-partner practice or a firm with forty staff.
A WISP isn’t a binder that sits in a drawer for the one time in a decade someone asks to see it. It’s supposed to name who owns information security at the firm, document the actual risks, describe the safeguards in place, cover how vendors and cloud services are vetted, and get tested and updated on some regular schedule. Most of the firms I’ve reviewed have something written. Technically. Fewer have anything that describes what they’re running today.
The IRS Security Summit also flags something specific to this industry: fraudsters posing as new clients, sending malicious attachments disguised as W-2s or 1099s, specifically targeting the busiest weeks of filing season. Their guidance for tax professionals calls out phishing attempts aimed at stealing EFIN, PTIN, and CAF numbers, not just client data. A firm’s own credentials are a target too. Not only the returns sitting in the file server.
What Actually Fails Every January
Same list. Almost every year, across almost every firm size. Order roughly matches how often we see each one.
| What breaks | Why tax season triggers it | What fixes it before January |
|---|---|---|
| Remote access / VPN | Concurrent-user licensing capped for normal headcount, not weekend crunch staffing | Confirm license count against peak expected concurrent users, not average |
| Tax software performance | Server-hosted CCH ProSystem fx or ProSeries instances hit by concurrent-session load nobody tested | Load-test with realistic concurrent users, not just a login check |
| Backup verification | A silently failing backup job goes unnoticed for months when nobody’s watching alerts | Restore a real file from backup. Don’t just check a green checkmark. |
| Seasonal staff access | Rushed onboarding in January, forgotten offboarding in April | Scoped accounts from day one, calendar reminder to disable in April |
| MFA coverage gaps | Enabled on email, skipped on the tax software, the client portal, or remote desktop | Audit every system that touches taxpayer data, not just the obvious ones |
The tax software row deserves a second look. Firms running CCH ProSystem fx or ProSeries on an aging on-premise server rarely test what happens at eight or ten simultaneous logins. Not until eight or ten people are sitting there logged in on January 27th, waiting. By then testing isn’t an option. Only troubleshooting is.

The Nine-Item Checklist to Run Before January
This is close to what we walk through with firms during a fall readiness review. Print it. Assign an owner to each line. None of it requires a big budget. Most of it just needs someone to actually do it.
- Confirm VPN and remote access licensing against peak seasonal headcount, not your normal staff count.
- Load-test your tax software server with a realistic number of simultaneous users. Before the season. Not during it.
- Restore an actual file from backup and confirm it opens correctly. Green checkmarks lie.
- Enable multi-factor authentication everywhere taxpayer data lives. Email, tax software, client portal, remote desktop, cloud storage. All of it, not most of it.
- Write or update your Written Information Security Plan. If nobody at the firm can produce one on request, you don’t have one. Doesn’t matter what’s in a drawer.
- Set up seasonal staff accounts with scoped access from the first login, and put an April offboarding date on the calendar now.
- Patch everything. Operating systems, tax software, browsers, firewall firmware. All of it. A missed patch in September is still missed in January, just with worse timing.
- Confirm your printer and scanner fleet can handle e-file volume. No queue backing up during the last week of the deadline.
- Train staff on the new-client phishing pattern the IRS Security Summit has flagged. Fake W-2 attachments, fake 1099 links, timed to your busiest weeks.
Nine items. None of them exotic. The firms that skip this list aren’t lazy, usually. They’re the same firms every year. Running the same fire drill in February that a Tuesday afternoon in November could have prevented.
What Partners Ask Us Before Filing Season
Do we really need a formal WISP if we’re only three partners?
How much does it cost to get IT support in place before tax season?
Can our current IT person just handle this checklist?
What’s the single biggest mistake firms make heading into January?
Is a data breach at a small accounting firm genuinely likely?
None of this needs to happen in a single weekend. It definitely shouldn’t happen for the first time during the third week of January. We’ve supported firms like yours with a cybersecurity program built around exactly this kind of seasonal load.
A free IT assessment from VJNetworks walks your firm’s setup against this exact checklist. No pitch attached. You keep the findings either way.
Over 20 years in the Tri-State area · 97% client retention · a real person responds within 15 minutes
