
August 2026 | CPA Firm Managed IT Salt Lake City | Backup & Disaster Recovery | Accounting Firm IT Services Utah
Mike Tyson once said, "Everyone has a plan until they get punched in the mouth."
For CPA firms in Salt Lake City, that punch often arrives as a tax season disruption no one saw coming — a failed backup, a ransomware attack targeting client SSNs, or a system failure that makes UltraTax CS or Lacerte inaccessible right when your accounting staff needs it most. These disruptions do not catch firms off guard because they were careless. They catch firms off guard because certain assumptions felt like facts right up until they were tested.
These are the four assumptions that most often cause the real damage for Salt Lake City CPA firms — and why addressing them now is far less expensive than discovering them during filing season.
Assumption #1: "Our Tax Software Vendor Handles Our Backups"
This is the most common — and most costly — assumption CPA firms make. UltraTax CS, Lacerte, Drake Tax, and CCH Axcess all maintain their own platform infrastructure and uptime. What they do not do is back up your firm's specific client data configurations, custom settings, or the local and network-hosted databases that store years of client tax returns.
When something goes wrong — a corrupted database, a ransomware attack that encrypts local files, or a hardware failure — the software vendor's platform backup does not restore your client records. That responsibility belongs to your firm. Without a verified backup strategy managed separately from the software platform, your client tax records and prior-year return archives may be unrecoverable.
The most dangerous backup is the one you believe exists but have never tested. Knowing that your tax software has a backup system is not the same as knowing that your specific client data, in its current state, can be fully restored.
Assumption #2: "Our Monitoring Would Notify Us If Something Was Wrong"
Monitoring tools are valuable — but confusing detection with protection is a costly mistake for any CPA firm.
A severe weather alert tells you a storm is coming. It does not board up your windows or move your family to safety. The alert is only useful if you already know exactly what to do next — and you have already decided who does it. Your IT monitoring works the same way.
When an alert fires — whether it is a failed backup job, a suspicious login attempt on your client portal in TaxDome or ShareFile, or a storage system approaching capacity — what happens next is entirely up to your firm. Without a documented incident response plan and a capable IT support partner in Salt Lake City, those alerts become noise instead of action. In a CPA practice where client tax records are among the most valuable targets for identity thieves, an unaddressed alert can quickly become a far larger problem.
Detection is the beginning of the response — not the end of it. The plan for what happens after the alert fires needs to exist before the alert fires.
Assumption #3: "Our Accounting Staff Knows What to Do"
Every team looks prepared — until the situation is real and the pressure is on.
Picture this: it is a Friday afternoon during tax season. Your UltraTax environment goes offline. Client returns scheduled for filing the next day are inaccessible. Suddenly no one can agree on who is responsible for initiating recovery, which systems need to come back online first, or how long the restore will take.
When there is no documented plan and no prior practice run, even an experienced accounting team is starting from zero under deadline pressure. IRS Publication 4557 specifically requires that firms designate who is responsible for data security and incident response. That designation means nothing if the designated person has never actually worked through the steps — and no one else knows what to do while they figure it out.
You do not run a fire drill because you expect the building to burn down. You run it so that when something does go wrong, your accounting staff is executing a plan they already know — not figuring things out in real time while client deadlines pass and IRS filing windows close.
Assumption #4: "CPA Firms Are Not Targeted by Cybercriminals"
This assumption is expensive. And it is wrong.
CPA firms are among the most attractive targets for ransomware groups and identity thieves — not because firms are careless, but because the data they hold is extraordinarily valuable. A single client file can contain a Social Security number, bank account details, W-2 information, years of financial history, and enough personally identifiable information to commit tax fraud and open fraudulent lines of credit. That data is worth far more on the dark web than a credit card number alone.
The FBI and IRS have issued repeated warnings specifically to tax professionals about phishing campaigns designed to look like IRS notices or correspondence, credential theft targeting tax software portals like TaxDome and ShareFile, and ransomware attacks timed to coincide with tax deadlines — when accounting staff is under the most pressure and most likely to click something they should not.
Cybercriminals are not targeting CPA firms by accident. Client SSNs and financial records are the goal. The question is not whether your firm will be targeted — it is whether your defenses and your recovery plan are ready when an attack comes.
Frequently Asked Questions
What is the difference between backup and disaster recovery for CPA firms?
Backup is the process of copying and storing your client tax records, return archives, and software configurations. Disaster recovery is the documented plan for restoring that data and getting your tax software environment back online after an incident. You need both — and both need to be tested before a real disruption reveals the gaps, particularly before each major tax deadline.
Do you offer cybersecurity and IT support for CPA firms in Salt Lake City?
Yes. Qual IT provides managed IT services, cybersecurity, backup and disaster recovery planning, and IRS Publication 4557 compliance support for CPA firms across Salt Lake City and the greater Wasatch Front. We help accounting firms address the assumptions above before they become real problems during tax season.
How often should CPA firms in Salt Lake City test their backups?
At minimum, quarterly — and ideally before each major filing deadline. The goal is to verify that backups of client returns and records restore completely and within an acceptable time frame before an actual incident forces the question. High-compliance environments handling large volumes of client tax records should test more frequently.
You Cannot Recover From an Assumption
It is rarely a sophisticated cyberattack that catches CPA firms unprepared. More often, it is the ordinary disruptions — a corrupt database, a failed hard drive, an accounting staff member who clicked the wrong link in a phishing email disguised as an IRS notice — that hit on a Tuesday when no one is expecting it.
The good news is that most of these risks can be identified and addressed before they become serious problems. That is exactly what Qual IT helps Salt Lake City CPA firms do. We work with your accounting staff to document the recovery plan, test the backup strategy, and close the gaps before tax season puts everything under pressure.
We work with Salt Lake City CPA firms to protect client data and keep systems running through tax season.
Schedule a 10-minute discovery call to walk through your backup strategy, incident response plan, and IRS Publication 4557 compliance posture. We will identify what has been tested, what has not, and where gaps may exist before they surface during filing season. Book your discovery call here.

