PGH Networks

IT Support for CPA and Accounting Firms in Pittsburgh

August 6, 2026· PGH Networks Team· 5 min readManaged IT
IT Support for CPA and Accounting Firms in Pittsburgh

PGH Networks is a Pittsburgh-based managed services provider delivering IT support for CPA and accounting firms across Allegheny, Washington, Westmoreland, Butler, and Beaver counties, with deep experience in the tax and audit software stack that public accounting depends on. This page walks through an anonymized engagement with a Pittsburgh-area CPA firm and how we approach IT support for CPA and accounting firms in Pittsburgh differently from a generic MSP.

The scenario: a 22-person CPA firm heading into tax season

A 22-person CPA firm with offices in the South Hills and a satellite in Cranberry Township came to us in early Q4. They had roughly 1,900 1040 clients, a growing business-advisory practice, and a partner group that had just been asked by their cyber-liability carrier for a written information security program (WISP) aligned to IRS Publication 4557 and the FTC Safeguards Rule. Their prior IT vendor was a generalist break-fix shop that did not understand Lacerte multi-user locking, CCH ProSystem fx Document, or why a sluggish SMB share can cost a preparer twenty minutes per return during the March crunch.

They needed answers, not a sales deck, before January 15.

man in blue dress shirt sitting on rolling chair inside room with monitors

The challenge

The technical footprint was typical for a mid-size Pittsburgh accounting firm: Lacerte and UltraTax CS on a Windows Server file share, CCH ProSystem fx Tax hosted through a mix of on-prem and Rightworks (formerly Right Networks) application cloud, QuickBooks Enterprise for write-up work, Drake for a handful of legacy returns, and SmartVault plus ShareFile for client document exchange. Microsoft 365 Business Premium was in place but under-configured — no Conditional Access, no Purview data-loss policies, MFA only on partners.

The compliance picture was worse. There was no formal WISP, no documented incident-response plan, and no evidence log the firm could hand an examiner. The FTC Safeguards Rule amendments require designated qualified individuals, risk assessments, and multi-factor authentication on any system containing customer information — none of which was documented. The carrier had given the firm 90 days.

Layered on top: tax season was ten weeks away. Any remediation had to happen without breaking preparer workflows.

A generalist MSP can keep the lights on; an accounting-literate MSP knows that a five-minute Lacerte lock during March costs a firm more than a month of managed services fees.

How it was solved

We started with a two-week discovery that produced three deliverables: a documented technology roadmap from our vCIO practice, a risk assessment mapped to IRS Publication 4557 and the FTC Safeguards Rule, and a written WISP the qualified individual (the managing partner) could sign.

On the infrastructure side, we rebuilt the tax-application tier. Lacerte and UltraTax CS data paths were moved to an SSD-backed file server with SMB3 multichannel and per-user profile redirection tuned for the way preparers actually work. CCH ProSystem fx workflows that had been split between on-prem and Rightworks were consolidated into the Rightworks Application Cloud, which removed a class of "which copy is current" errors the firm had lived with for years. QuickBooks Enterprise multi-user hosting was normalized. Drake stayed on a dedicated workstation for the two preparers who still used it.

For cybersecurity, we deployed EDR on every endpoint with 24/7 MDR monitoring, enforced phishing-resistant MFA across all Microsoft 365 accounts, and rolled out Conditional Access policies that blocked legacy authentication and required compliant devices for mailbox access. In Microsoft 365, Purview sensitivity labels were configured for tax return PDFs and engagement letters, and ShareFile plus SmartVault were retained as client-facing exchange with SSO through Entra ID.

The compliance work produced a WISP that maps line-by-line to IRS Pub 4557's security six, an incident-response runbook the firm can actually execute, and quarterly evidence collection (access reviews, backup restore tests, phishing simulation results) stored in a portal the carrier and any future examiner can review.

Finally — and this is the piece generalist MSPs consistently underweight — we put a tax-season SLA in place: 24/7 coverage from January 15 through April 30 and again in late September through October 15, a named on-call engineer who knows the firm's stack, and a 15-minute response target on Lacerte, UltraTax, and CCH ProSystem fx tickets during those windows. Standard managed IT, patch management, and help desk continue year-round.

Outcomes

TL;DR: After remediation, the firm ran its heaviest tax season on record with 99.98% file-server uptime, a 12-minute average ticket response during peak, zero preparer-hours lost to tax-software downtime, and a signed WISP that satisfied the cyber-liability carrier.

Concretely, across the January-through-April window: the file share carrying Lacerte and UltraTax data measured 99.98% uptime; average first-response on P1 tickets was 12 minutes; the firm processed roughly 12% more returns per preparer than the prior year, which the partners attributed partly to the elimination of file-lock stalls and partly to a Copilot-assisted review workflow we piloted with three senior staff.

The compliance deliverables — WISP, risk assessment, IR plan, evidence log — were accepted by the carrier at renewal without conditions, and the firm's premium held flat in a market where accounting-firm cyber premiums generally rose.

man standing beside another sitting man using computer

Why this matters for other Pittsburgh accounting firms

Most CPA firms in the Pittsburgh region are running some combination of Lacerte, UltraTax CS, CCH ProSystem fx, Drake, and QuickBooks against Microsoft 365, with Rightworks or a similar application cloud in the mix. The technical problems are consistent (SMB tuning, profile bloat, multi-user locking, backup coverage on hosted apps), and the compliance obligations — GLBA, the FTC Safeguards Rule, IRS Publication 4557, and increasingly state-level breach-notification statutes — are the same whether the firm has eight people or eighty.

What is not consistent is whether the firm's IT provider has actually worked inside those applications during a March 15 deadline. That is the gap this page exists to close.

We also help firms move cautiously into AI: an AI readiness assessment that produces an acceptable-use policy consistent with client-confidentiality obligations, and — for firms ready to go further — document automation for engagement-letter intake, K-1 extraction, and standard review checklists.

Talk to PGH Networks

If you run a CPA or accounting practice anywhere from Downtown to Cranberry, Monroeville to Washington, and you want IT support for CPA and accounting firms in Pittsburgh from a team that already speaks Lacerte, UltraTax, and CCH ProSystem fx, we would like to talk before your next tax season.

Call 724.888.7007 or reach us through the contact form.

Share

Related reading

Choosing an MSP for a Pittsburgh Law Firm

How Pittsburgh law firms should evaluate a managed service provider: ABA 477R duty of competence, legal-app expertise, 24/7 security, and local response.