HD Tech - SecurITy Delivered
Back to Blog
Managed IT

Managed IT for CPA Firms in Irvine: What to Expect

By Tom Hermstad · HD Tech

Managed IT for CPA Firms in Irvine: What to Expect

What should a CPA firm in Irvine expect from a managed IT provider?

Managed IT for CPA firms in Irvine should deliver continuous monitoring, secure remote access, helpdesk support, and verified data backup — plus cybersecurity controls that satisfy the FTC Safeguards Rule and IRS Publication 4557. For practices handling sensitive taxpayer data, managed IT is not optional infrastructure. It's the foundation that keeps your firm running, compliant, and protected when it matters most.


By Tom Hermstad, Founder & CEO, HD Tech IT veteran | Managed IT for Orange County CPA and accounting firms


If you run a manufacturing business in Orange County, odds are you also work closely with a CPA firm — or you know the owner personally. Maybe you've considered adding professional services to your portfolio. Maybe you're the one steering both ships.

Either way, the risks your accountant carries aren't separate from yours. Their breach becomes your breach the moment your financials are in their system.

Running a CPA firm in Irvine means carrying client trust that most businesses never face. Tax returns. Bank records. Social Security numbers. Business financials. All of it sitting in your systems, managed by a staff already stretched thin from January through April.

Working with Orange County businesses, I've seen this exact failure mode in accounting firms, law offices, and manufacturing ops alike. I sat across from a small accounting firm in Orange County — good people, serious about their clients — who had just discovered their "backup" was a single external drive that hadn't been tested since the day it was plugged in. No redundancy. No restore plan. Just a very bad week in the middle of tax season.

We got them back on their feet, but it should never have gotten that far. Keep paddling — but paddle with a tested restore plan, not a drive you plugged in once and forgot.

That story isn't unique. It plays out every year — and it's exactly why managed IT for CPA firms in Irvine is the most important conversation an accounting firm owner can have right now.

Your IT provider either protects that data — or they don't. There's no middle ground.

Here's what an Irvine CPA practice should expect, and demand, from managed IT.


What does managed IT actually include for a CPA firm?

This is the question I love answering — because most firms don't know what they're actually missing until it's too late.

Break-fix IT — where you call someone when something breaks — stopped being acceptable for accounting firms. If you're still on that model, you're at serious risk of a failed server or a phishing click shutting your practice down during tax season.

A lot of what's sold as "managed IT" is really just reactive support with a monthly fee attached. Real managed IT is proactive by design. The Lifeguard Loop™ is built around exactly that principle: listening first, then locking things down, then watching continuously, then making sure you always know where you stand.

For a firm like yours, where the stakes are this high, that distinction is everything.

Managed IT services for a CPA firm should include, at minimum:

  • Continuous remote monitoring — someone watching your systems consistently, not just during business hours
  • Patch management — keeping Windows, your tax software, and all connected systems updated before attackers exploit the gaps
  • Secure remote access — encrypted, multi-factor authentication (MFA — meaning a second verification step beyond your password) protected access for staff working from home or a satellite office
  • Data backup and disaster recovery — tested, verified backups you can actually restore from, not just backups that exist on paper
  • Helpdesk support — fast, plain-English help when your team hits a problem, with defined response times you can hold us to

If your current provider doesn't deliver all of the above, you don't have managed IT. You have managed chaos.


Why CPA firms in Irvine are a high-value target

The threat landscape has shifted — and I'm fired up about this topic because firms that see it clearly right now have a real chance to get ahead of it.

Your firm holds a significant concentration of exploitable data — meaning a large volume of sensitive financial and personal records packed into a small, lean environment — relative to your staff size. That's not a theoretical risk. It's the reason attackers look at accounting practices the same way a thief eyes an unlocked safe.

AI-assisted phishing has fundamentally changed the game. Attackers are using AI tools to generate phishing emails that are nearly impossible to distinguish from a real colleague or vendor — no typos, no awkward phrasing, perfectly matched to the tone of someone you trust.

For a CPA firm, that looks like a fake client portal request or a spoofed partner email requesting a wire. Legacy email security trained on yesterday's attack patterns won't catch it.

It's not if, it's when — and the firms that recognize this now are the ones that will still have their clients' trust a year from now. When a prospect asks how you protect their data and you hand them a written security program, that's the conversation your competitor can't have. The firms that move first on this create a clear gap that slower competitors simply can't close overnight.

The 2024 Verizon Data Breach Investigations Report found financial services are heavily targeted by cybercriminals. Common attack methods include stolen login credentials and email account takeover — where an attacker hijacks a real employee's email to redirect wire transfers or payroll.

According to the FBI IC3 2025 Internet Crime Report, business email compromise and email account compromise schemes resulted in approximately $3.046 billion in adjusted losses in 2025.

The threat isn't abstract in Southern California — it's local. In 2022, the Los Angeles Unified School District suffered a ransomware attack by the Vice Society criminal group that exposed sensitive personal data belonging to students, staff, and contractors. CISA and the FBI jointly issued an advisory on the attack.

LAUSD is a large organization with a dedicated IT team — and they still got hit. The lesson for a lean CPA practice in Irvine is straightforward: scale doesn't protect you, and the attackers operating in this region are active and capable.

The "we're too small to be targeted" belief? That's exactly what attackers count on. Small and mid-size firms hold valuable data and many lack formal security programs. You're not invisible. You're just easier.

Your compliance obligations are substantial regardless of firm size. A small practice in Irvine that qualifies as a covered financial institution under the FTC Safeguards Rule faces the same requirements as a large regional firm, with no blanket small-business exemption for covered entities.

Accounting firms, law offices, and manufacturing operations all share the same underlying vulnerability: high data concentration, lean IT teams, and compliance mandates that don't scale down with headcount. CPA firms aren't unique in their risk. They're just uniquely trusted by their clients — and that trust is the asset worth protecting.


Tax season is when everything breaks — and attackers know it

Failing to plan is planning to fail. And nowhere is that more painfully true than in the weeks leading up to April 15.

Tax season is the worst possible time for an IT failure. Your staff is working overtime. Deadlines are fixed. Clients are anxious. And your systems are under more load than any other time of year.

A managed IT partner who understands accounting firms plans for this in advance — not after the crisis starts. Here's what that looks like:

  • Surge capacity planning — infrastructure ready for peak load before January, not scrambling in March
  • Scheduled maintenance windows — no surprise reboots or updates during crunch periods
  • Escalation protocols — a clear chain of contact when something goes wrong late on a filing deadline

This is the difference between a vendor and a partner. A vendor shows up when you call. A partner is already watching.

There's real satisfaction in building a system so buttoned-up that when the pressure hits in March, your team barely notices — because everything just works. When a firm rolls through April 15 without incident, that's the win we're chasing every single time. Unplanned downtime during tax season doesn't just cost hours — it costs clients. That preparation is what separates firms that retain their best clients from firms that spend April apologizing to them.


Your tax software is only as secure as the environment around it

Here's something I genuinely love digging into — because fixing this gap is 100% solvable, and most firms don't realize how exposed they are until we walk them through it.

QuickBooks, Thomson Reuters, Lacerte, CCH — these platforms hold your clients' most sensitive financial data. Securing it is not the software vendor's job. It's yours. And it's your IT provider's job to harden the environment around that software.

The FTC Safeguards Rule and IRS Publication 4557 aren't just compliance boxes. They're a roadmap to what actually protects your clients — and most firm owners don't find out they apply until something goes wrong.

That changes right here.

The FTC Safeguards Rule covers tax preparers and accounting firms that qualify as financial institutions under the rule. The FTC has already taken action against financial services firms — including tax preparers — for failing to implement required safeguards, and enforcement is active, not theoretical. IRS Publication 4557 sets the same expectations from the tax authority's perspective.

Together, they require:

  • Role-based access controls — each staff member can only see the client data their job actually requires, so a compromised login can't expose your entire database
  • Encrypted storage — taxpayer data scrambled so it's unreadable to anyone who intercepts it, both at rest and in transit
  • MFA on key systems — especially anything connected to client financial records
  • Documented incident response — a written plan for when something goes wrong

Trust, yet verify — and that applies here too. If your IT provider can't show you documentation of these controls, you're exposed to both attackers and regulators. And if a breach occurs and your cyber liability carrier finds those basic controls weren't in place, don't count on that policy paying out.

When a prospective client asks "how do you protect my data?" and you can hand them a written security program, that's a conversation your competitor without one simply cannot have. Firms with documented security controls win higher-value clients and keep them longer. That's not overhead — that's your compliance program doing double duty as a business development tool.

Watching a firm go from "we think we're covered" to holding a real, documented security program they're genuinely proud of — that's the outcome that matters.

For a deeper look at evaluating a cybersecurity-focused IT provider, read our checklist for accounting firms choosing an IT provider in Irvine.


Why a part-time tech or "the nephew" can't carry this

I say this with zero judgment — because I've seen it work out fine for basic stuff. Password resets. Printer issues. Setting up a new laptop. A part-time tech or a trusted family member who's good with computers can handle those things.

What they cannot handle is this:

FTC Safeguards documentation. The Safeguards Rule requires a written information security program — assigned to a qualified individual, reviewed at least annually, and backed by a risk assessment. That's not a checklist. It's an ongoing program. Building and maintaining it requires someone who does this full-time.

A ransomware response in the middle of the night. When ransomware hits your file server in the early hours of a Tuesday before a filing deadline, you need a team with an incident response plan, isolation procedures, and tested backups ready to execute. Not someone you're texting out of bed hoping they pick up. It's not if, it's when — and "when" is not a moment for improvisation.

Tested, verified restores. "We have backups" is not the same as "we can restore from backups." I've seen firms discover their backups were corrupt only when they needed them most. Keep paddling — but paddle with a restore plan that has been tested, logged, and verified by someone accountable for the result. That's not a one-person job.

For a firm carrying your clients' financial futures, that gap is not a small one. The nephew solution works right up until it catastrophically doesn't — and in a CPA practice, the fallout lands on your clients, your license, and your reputation. That's too much to risk.


Onboarding: what a proper IT transition looks like

Switching IT providers feels risky. It doesn't have to be. And when it's done right, the relief on the other side is real — I see it every time, and it never gets old watching a firm finally exhale.

A disciplined onboarding follows the first phase of the Lifeguard Loop™ — Listen and Learn:

  1. Full inventory of every device, software license, and user account before we touch anything
  2. Documentation of your current state — what's working, what's vulnerable, what needs to change
  3. A prioritized remediation plan in plain English, with no surprises

Walking a firm through their first security gap assessment — watching the full picture of their environment come into focus for the first time — is exactly the kind of work that matters. No jargon. No finger-pointing. Just a straight picture of your environment and a clear path forward.

You shouldn't have to decode technical language to understand what's happening in your own systems. That's the Plain-English Promise™ — you always know where you stand.


What Irvine firms near you are already experiencing

"Efficient and effective! H&D is our MSP delivering service and support that is proactive, scalable, professional, and reliable. We have successfully relied on them for consistent uptime, migrations, and project support." — Jeff (JP) Patstone, IS Manager, Roland DGA, Irvine

Irvine's business community is competitive. Firms that build a reputation for protecting client data win the clients their competitors can't keep. That reputation doesn't come from antivirus software and good intentions. It comes from a partner who's watching your systems, documenting your controls, and standing behind the work.

To understand how a managed IT engagement for accounting and CPA firms works end-to-end, review our breakdown of IT services vs. managed services.

The only question is whether you're ready before it happens — not after.


Frequently Asked Questions

Here's what I tell every firm owner who asks this — the Safeguards Rule isn't a checklist you hand off and forget. It's an active, documented program your firm is accountable for maintaining. The FTC Safeguards Rule requires a written security program, risk assessments, access controls, encrypted client data, MFA on systems with client financial records, and a documented incident response plan — with no blanket small-business exemption for covered entities. If your IT provider can't show you documentation of these controls, you're exposed to both attackers and regulators.

You need both. Managed IT reduces your attack surface (the total number of ways an attacker can get into your systems) and documents your controls — cyber liability covers what still lands even when you do everything right: breach notification, legal fees, and client remediation. Carriers require documented controls as a condition of coverage, so your managed IT program directly protects your ability to collect on a claim.

Trust, yet verify — and that starts before you sign. Ask: Do you have experience with FTC Safeguards Rule compliance? How do you test and verify backups? What is your guaranteed response time for critical issues? A provider who hesitates on any of these is telling you something important.

I've watched this shift happen in real time, and it's the threat I'm most focused on right now for accounting firms. AI has made phishing emails far harder to detect. Attackers generate emails that mimic real clients, partners, or vendors — no typos, no awkward phrasing — and legacy email filters aren't built to catch them. For CPA firms, that means fake client portal requests and spoofed wire instructions slip straight through your defenses. Your team needs layered protection and regular training to close that gap.

A disciplined transition can be completed efficiently. We start with a full inventory of every device, license, and user account, document your current environment, identify gaps, and deliver a prioritized remediation plan in plain English — with zero disruption to your team.


Your firm handles the financial futures of your clients. Your IT provider should handle yours. If you're not confident your current setup would survive a ransomware event or a failed audit, it's time to find out where you stand.

Don't be a casualty — be exceptional.

Book your free Cyber Preparation Assessment with HD Tech — no jargon, no pressure, just a straight answer about where your firm is exposed and what it takes to fix it.


Cybercrime is surging. According to the FBI IC3 2025 Internet Crime Report, IC3 recorded 1,008,597 complaints in 2025 with total losses of $20.877 billion — 26% higher than the 2024 level, at an average loss of $20,699 per complaint. AI-related complaints accounted for more than 22,000 complaints and nearly $900 million in associated losses. Business email compromise alone drove approximately $3.046 billion in adjusted losses. IC3 also received 3,611 ransomware reports in 2025. The volume and sophistication of attacks aren't slowing down — and accounting firms are squarely in the crosshairs.

managed IT for CPA firms in Irvine
Tom Hermstad, President of HD Tech

Tom Hermstad

President & CMO, HD Tech

Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.

Need Help With Your IT?

Get a free, no-pressure IT health check. We'll show you exactly where you're exposed — in plain English.