IT and cybersecurity for Accounting
You are held to FTC Safeguards Rule – penalty-backed – and, like most firms your size, you are expected to meet it without anyone in-house whose job it is to own it. We run the IT and the security program so the obligation is actually covered, not just acknowledged.
Where we usually start: FTC Safeguards Rule + IRS WISP.
If this sounds familiar
“We’re holding the most sensitive data our clients have, and one breach would end the firm.”
SSNs, bank details, entire financial lives – for a practice built entirely on trust and referrals, a data leak isn’t an IT incident, it’s the end of the business.
“Apparently we’re a ‘financial institution’ now and we’re supposed to have some security program – I don’t actually know if we’re compliant.”
The FTC Safeguards Rule and the IRS WISP requirement landed on the partners’ desks without anyone internal who can own them, and the penalties and breach-notification clock are real. There’s a low-grade, persistent anxiety that they’re exposed and wouldn’t pass an audit.
“If our systems go down in March, the whole season is at risk.”
During filing season every day of downtime is missed deadlines, blown client commitments, and a team already working nights and weekends – capacity they can’t get back and clients who remember.
Who this is for
Typical size: 10–100 employees (sweet spot 15–60), revenue $2M–$30M (concentrated $3M–$15M). If that is roughly you, the rest of this page will land.
What working with us looks like
A named team that knows your stack, monitoring and patching that happens whether or not anyone chases it, and a written security program kept current – with the evidence to back it up when a client, an auditor or an insurer asks. We report to the Managing/Ops Partner, not to a ticket queue.
Talk to us
Call 206-850-1496 or email mhasse@itwerx.net and we will set up a short call – no audit, no pitch deck, just a conversation about what you have and what is worrying you.

