
Reliable IT support helps Las Vegas CPA Firms stay secure and productive during the busy tax season.
Before tax season, Las Vegas CPA firms should ask prospective or existing IT providers about response times, after-hours support, CPA-industry experience, cybersecurity, Microsoft 365 security, client document protection, backups, recovery, remote access and how the provider protects its own administrative access. The goal is to understand exactly what will happen when employees need help during the busiest part of the year.
Tax season has a way of exposing technology problems that were merely annoying in October. A slow computer becomes a real problem when someone is trying to finish returns late in the day, and unreliable remote access becomes considerably more frustrating when a CPA is working from home on Saturday. Even a routine support delay feels different when several employees can't work and a deadline is getting closer.
That's why Las Vegas CPA firms should ask very specific questions before choosing an IT provider—or before assuming their current provider is ready for another tax season. Response times, after-hours support, cybersecurity, Microsoft 365, backups, recovery, remote access, client document security, employee onboarding and tax software support should all be part of that conversation.
The important part is getting beyond “Yes, we handle that.” Ask what happens when something goes wrong, how quickly someone responds, who takes responsibility and what the actual process looks like. A good IT provider should be able to explain what your firm can expect when everything is running normally and, more importantly, what happens when it isn't.
What Should CPA Firms Ask an IT Provider Before Tax Season?
CPA firms should ask questions that reveal how an IT provider actually responds to real problems, not simply what services appear on its website. Ask about response times, escalation procedures, after-hours support, cybersecurity, backups, Microsoft 365, client data protection and experience supporting accounting firms during tax season.
You don't need to turn your IT-provider meeting into an interrogation, but you do need to get beyond the sales presentation. Broad questions tend to produce broad answers, and those answers don't tell you much about what working with the provider will actually be like.
For example, asking “Do you provide cybersecurity?” will almost certainly get you a yes. Asking “What happens if one of our Microsoft 365 accounts is compromised at 9:00 on a Monday morning during tax season?” gives the provider something real to explain. Scenario questions are useful because they show you how the provider thinks, who takes ownership and whether there's an actual process behind the promise.
Here are the questions we'd put on the list.
How Quickly Will You Respond When We Have an IT Problem During Tax Season?
Ask for specific, documented response targets rather than promises of “fast” support. A CPA firm should know the provider's average response time, critical-issue response target, help desk hours, escalation process and what happens when an outage affects multiple employees during tax season.
Response time becomes very real when employees are waiting. Ask the provider how support requests are prioritized and what happens when an issue affects one person versus five people versus the entire firm. You should also know whether response targets are documented and whether tax-season support differs from support during the rest of the year.
Questions worth asking include:
- What is your average response time?
- What response time do you commit to for a critical issue?
- What qualifies as a critical issue?
- How do employees contact the help desk?
- What happens when several employees are affected?
- What happens during a firm-wide outage?
- Are your response commitments documented?
Words such as “fast,” “priority” and “responsive” sound reassuring, but they don't tell you much on their own. Ask for the provider's actual average response time, critical-issue response target, help desk hours and after-hours process so you understand what those promises mean in practice.
Average response time: [X minutes]
Critical issue response target: [X minutes]
Help desk hours: [X to X]
After-hours process: [INSERT ACTUAL PROCESS]
Those numbers become particularly important when you're comparing providers. One company's idea of “priority support” may be very different from another's, and tax season is not the ideal time to discover that difference.
What Support Is Available After Hours and on Weekends?
CPA firms that work evenings and weekends during tax season should confirm whether their IT provider offers support during those hours, what qualifies as an emergency, how issues are escalated, who responds and whether additional charges apply.
Tax season doesn't always respect business hours. If your accountants regularly work evenings or weekends, your IT coverage needs to make sense for the hours your people actually work rather than the hours printed on the provider's website.
Find out whether after-hours and weekend support is available, what qualifies as an emergency, whether there's an additional charge and who actually responds. A useful scenario to give the provider is: “It's 7:30 p.m. during tax season and five employees suddenly can't access a critical system. What happens?”
Listen to what happens after the initial call. Who receives the request? How is it escalated? Does someone begin troubleshooting immediately? Is there a separate emergency process, and can employees use it directly? “Call us and we'll take care of it” may sound good, but your firm should understand what “take care of it” actually means before an after-hours problem occurs.
How Many CPA and Accounting Firms Do You Support?
Ask an IT provider for specific CPA and accounting experience, including how many firms and accounting professionals it supports, how long it has worked with the industry, which applications its team encounters and examples of problems it has solved for similar firms.
Industry experience isn't everything, but it does matter. CPA firms have busy seasons, sensitive client information and applications that a general IT provider may not encounter every day. You don't want your employees repeatedly explaining why a tax application matters or why waiting until tomorrow isn't particularly helpful three days before a deadline.
Ask about the provider's actual experience:
- How many CPA and accounting firms do you currently support?
- Approximately how many accounting professionals do you support?
- How long have you worked with CPA firms?
- Which tax and accounting applications do you encounter?
- Can you give us an example of a problem you've solved for a similar firm?
Only include software your team genuinely has experience supporting. Specific experience is useful; a long list of software names added for SEO isn't.
How Will You Protect Our Firm From Cyberattacks During Tax Season?
A CPA firm's IT provider should be able to explain how multiple cybersecurity controls work together to protect sensitive financial and taxpayer information. The discussion should include MFA, endpoint and email security, phishing protection, Microsoft 365 security, monitoring, patching, employee awareness, incident response, backups and recovery.
CPA firms hold sensitive financial and taxpayer information, so cybersecurity should be part of the IT-provider conversation long before tax season starts. That doesn't mean the provider should scare you through the sales process. It means the provider should be able to explain, in plain English, how the different layers protecting your firm work together.
The conversation should cover areas such as:
- Multi-factor authentication
- Endpoint security
- Email security
- Phishing protection
- Microsoft 365 security
- Employee permissions
- Security monitoring
- Patch management
- Employee security awareness
- Incident response
- Backup and recovery
One useful question is: “If one of our employees clicks a malicious link during tax season, what protections are in place before and after that click?” The answer should involve more than one security product because protecting a CPA firm isn't usually a matter of installing one piece of software and calling it finished.
Your provider should be able to explain how identity protection, email security, endpoint protection, monitoring, backups and incident response work together. If the explanation requires 14 acronyms and a cybersecurity dictionary, ask for the plain-English version. Firm leadership needs to understand the security strategy too.
How Does Your IT Service Support Our Written Information Security Plan?
Ask how the IT provider's security controls and processes support your firm's Written Information Security Plan (WISP). That can include access controls, MFA, device and email security, encryption, backups, monitoring, incident response, onboarding and offboarding, and service-provider security.
This is an important question for tax and accounting firms because cybersecurity isn't simply an IT purchasing decision. The IRS says tax and accounting professionals are required by federal law to create and maintain a Written Information Security Plan (WISP) for protecting client information, and the plan should be appropriate for the practice and the information it handles.
When you're evaluating an IT provider, ask how the technology and processes it manages fit into that plan. The discussion may include:
- Employee access controls
- Multi-factor authentication
- Device security
- Email security
- Encryption
- Backups
- Monitoring
- Incident response
- Employee onboarding and offboarding
- Vendor and service-provider security
An IT provider isn't a replacement for your firm's legal, regulatory or professional advisers. However, if the provider is responsible for a significant part of your technology environment, it should be able to explain how the controls it manages support the security program your firm maintains.
That is a much more useful conversation than asking which cybersecurity package the provider sells.
How Do You Secure Microsoft 365 for CPA Firms?
CPA firms should ask how an IT provider protects Microsoft 365 accounts, administrator access, email and employee identities—and what happens when suspicious activity is detected. MFA, account permissions, suspicious sign-in monitoring, former employee accounts, access reviews and Microsoft 365 backup should all be part of the discussion where applicable.
For many CPA firms, Microsoft 365 sits in the middle of everyday work. Employees may use it for email, files, collaboration and communication, which means Microsoft 365 security deserves more attention than simply creating accounts and resetting passwords.
Ask how the provider handles:
- Multi-factor authentication
- Administrator accounts
- Suspicious sign-ins
- Employee permissions
- Email security
- Former employee accounts
- Access reviews
- Microsoft 365 backup, if included in the service
Instead of asking which Microsoft security products the provider uses, ask what happens when something suspicious occurs. For example: “Microsoft flags a suspicious login to one of our employee accounts. What happens next?”
The provider should be able to explain who receives the alert, who investigates it, how the employee is contacted and what happens if the sign-in appears malicious. “We use Microsoft security” doesn't tell you whether anyone is actually watching, responding or taking responsibility when something happens.
How Do You Protect Client Documents and Sensitive Tax Information?
An IT provider supporting a CPA firm should understand how sensitive client information is received, accessed, stored, shared and backed up. Ask about secure client portals, encrypted communications, secure file sharing, MFA, permissions, storage, device security and employee access procedures.
Your clients trust your firm with tax returns, Social Security numbers, bank information, payroll records and financial statements. Your IT provider should understand how that information moves through your environment and help your firm establish sensible ways for employees to receive, access, store and share it.
That conversation may include:
- Secure client portals
- Encrypted communications
- Secure file sharing
- Multi-factor authentication
- Employee permissions
- File storage
- Device security
- Backup
- Employee onboarding and offboarding
A useful scenario is: “A client emails one of our employees a document containing sensitive taxpayer information. What should our employee do?” This moves the conversation away from security products and toward the decisions employees make every day.
Your firm needs a process people can actually follow when they're busy. If the approved secure method is so complicated that employees regularly find another way to get the job done, the process deserves another look before peak season.
How Does the IT Provider Protect Its Own Access to Your Firm?
Because an IT provider may have administrative access to critical systems, CPA firms should ask how the provider secures its own technicians, credentials and management tools. MFA, privileged access controls, monitoring, technician onboarding and offboarding, administrative credential protection and incident response should be part of that conversation.
This is one of the questions CPA firms may not think to ask. Your IT provider can have administrative access to Microsoft 365, employee devices, security tools, backup systems and other important parts of your technology environment, so the security of the provider itself matters.
Ask how the provider protects that access, including:
- MFA for technicians and administrators
- Privileged access controls
- Security monitoring
- Employee access controls
- Technician onboarding and offboarding
- Protection of administrative credentials
- Incident-response procedures
- Cyber insurance
- Third-party tools used to manage client environments
A useful question is: “If your company is compromised, what prevents an attacker from using your access to reach our firm?” You don't need the provider to disclose its entire internal security playbook, but you should know that the company you're trusting with administrative access has taken steps to protect that access.
For organizations subject to the FTC Safeguards Rule, oversight of service providers is also part of the security conversation. Whether and how the Rule applies to a particular CPA firm depends on the activities the firm performs, so it shouldn't be treated as a blanket statement that every CPA firm has identical requirements.
What Is Our Backup and Recovery Plan During Tax Season?
Before tax season, a CPA firm should know exactly what is backed up, how often backups run, where they are stored, how they are protected, who monitors failures, how frequently restores are tested and how long recovery could realistically take after an outage or ransomware incident.
“We back everything up” sounds comforting until you start asking what “everything” actually includes. Before tax season, your firm should know which systems are backed up, how often those backups run, where they're stored, who gets notified when a backup fails and when the provider last tested a successful restore.
Ask about:
- Which systems and data are backed up
- How frequently backups run
- Where backups are stored
- How backups are protected
- Whether backups are isolated from the systems they're protecting
- What happens to backups during a ransomware incident
- Who monitors backup failures
- How often restores are tested
- What happens if a server fails
- How long recovery could realistically take
Two questions make this conversation particularly useful: “How much data could we lose?” and “How long could it take before our employees can work again?” Those questions help firm leadership understand recovery point and recovery time objectives in practical terms rather than simply being told that backups exist.
Resources
For CPA and accounting firms that want to dig deeper into the security requirements and guidance discussed in this article, these IRS resources provide the original guidance rather than another technology company's interpretation of it.
- IRS — Written Information Security Plans Are Essential for Tax Pros
Current 2026 IRS guidance covering Written Information Security Plans, what a WISP should address and the importance of tailoring the plan to the practice.
External link: https://www.irs.gov/newsroom/written-information-security-plans-are-essential-for-tax-pros - IRS Publication 4557 — Safeguarding Taxpayer Data
IRS guidance covering tax professionals' obligations to protect taxpayer information and steps for creating and maintaining a security plan.
External link: https://www.irs.gov/pub/irs-pdf/p4557.pdf - IRS Publication 5708 — Creating a Written Information Security Plan for Your Tax & Accounting Practice
A Security Summit resource specifically developed to help tax and accounting practices create a WISP based on the needs of their business.
External link: https://www.irs.gov/pub/irs-pdf/p5708.pdf - IRS — Data Theft Information for Tax Professionals
IRS guidance covering what tax professionals should do when client information may have been compromised, including reporting client data theft to the local IRS Stakeholder Liaison.
External link: https://www.irs.gov/individuals/data-theft-information-for-tax-professionals



