Pittsburgh CPA Firm Cybersecurity and Cloud Case Study

PGH Networks is a Pittsburgh-based managed services provider that delivers cybersecurity, cloud, and compliance support to accounting firms across the metro, and this Pittsburgh CPA firm cybersecurity and cloud case study documents a representative engagement with a mid-sized public accounting practice headquartered in the South Hills. The firm approached us in the fall with two overlapping problems: a written information security program (WISP) that had not been updated to reflect current IRS Publication 4557 expectations, and a tax software stack still tethered to an aging on-premises server that could not survive another April.
This page anonymizes the client but preserves the technical shape of the engagement so other Pittsburgh-area partners and firm administrators can judge fit.
The buyer scenario: a 38-person Pittsburgh CPA firm
The firm employs 38 people across offices in Pittsburgh and Washington County, serves roughly 1,900 1040 clients and about 210 business returns, and runs CCH Axcess and Lacerte alongside QuickBooks Online, a document management platform, and a hosted portal for client deliverables. Two partners had recently received cyber-insurance renewal questionnaires demanding evidence of MFA on email and remote access, endpoint detection and response, encrypted backups, and a documented incident response plan. They had none of it formalized.
A CPA firm without a current WISP is not just out of compliance, it is uninsurable at renewal.

The challenge: GLBA, IRS WISP, and a tax-season deadline
Three constraints defined the project. First, the Gramm-Leach-Bliley Act Safeguards Rule and the IRS WISP requirement for paid preparers both demanded a written, tested security program naming a qualified individual, risk assessments, and vendor oversight. Second, CCH Axcess and Lacerte performance had degraded on the local server to the point that partners were logging in from home over a VPN just to escape daytime slowness. Third, the go-live had to happen before January 15, because no partner would authorize a cutover during tax season.
Layered on top: the firm's existing IT vendor was a generalist break-fix shop with no accounting vertical experience, no familiarity with tax-software hosting, and no compliance documentation practice. The partners wanted a provider that spoke both CPA and NIST.
How PGH Networks solved it
We structured the engagement in three parallel tracks so the January deadline was achievable.
Security baseline and WISP. A vCIO led a two-week risk assessment mapped to the FTC Safeguards Rule and IRS Publication 4557, then drafted the WISP naming the firm's IT partner as qualified individual, cataloguing systems that touch taxpayer data, and defining incident response roles. In parallel our cybersecurity team deployed managed EDR to every endpoint, enforced conditional-access MFA on Microsoft 365, rebuilt the firm's email security posture, and rolled out an encrypted, immutable backup target with 90-day retention.
TL;DR: The engagement paired a GLBA-aligned WISP with a CCH and Lacerte cloud migration so the firm cleared its insurance questionnaire and entered tax season on modern infrastructure.
Cloud migration for tax software. CCH Axcess is already SaaS, so the work there was identity, data-loss prevention through Microsoft 365 and Microsoft Purview, and disciplined offboarding. Lacerte was moved to an authorized hosting environment sized for the firm's concurrent-user count, with the local file server retired to a read-only archive. QuickBooks desktop files for a handful of write-up clients were migrated to a hosted profile keyed to the same identity provider so partners had a single sign-on across every tax and accounting application.
Operational handoff. Managed IT took over patch management, RMM, and help desk with a documented tax-season SLA: one-hour response on partner-impacting incidents from January 15 through April 20, and a named on-call engineer familiar with the firm's stack. We also stood up an AI readiness assessment and an acceptable-use policy so the firm could evaluate Copilot for research and drafting without exposing client data.
Outcomes: uptime, audit posture, and partner sign-off
The cutover completed on January 9, six days ahead of the partner-imposed deadline. Measured against the prior year:
Tax-season uptime on the hosted Lacerte environment held at 99.98 percent through April 15, with zero partner-impacting incidents lasting more than fifteen minutes. Login times for CCH Axcess dropped from a partner-reported "coffee break" to under ten seconds. The cyber-insurance renewal was signed at a lower premium than the prior year because the carrier accepted the WISP, EDR attestation, and MFA evidence without follow-up. The firm's managing partner used the WISP and vendor list to answer a client bank's third-party risk questionnaire in a single afternoon rather than the two-week scramble it had been the year before.
Perhaps most important: no partner had to call anyone at 6:30 a.m. during tax season. That is the metric CPA firms actually judge an MSP on.

Takeaway for other Pittsburgh accounting firms
Most Pittsburgh CPA firms in the 15-to-75-person range are sitting on the same three-part problem this client had: a WISP that exists only in theory, tax software running on hardware that is one bad Saturday away from a disaster, and cyber-insurance questionnaires that keep getting stricter. The playbook in this Pittsburgh CPA firm cybersecurity and cloud case study is repeatable, and the sequencing matters. The WISP and identity work has to lead, because it drives both the insurance answer and the migration design. The cloud move follows, because once identity and endpoint controls are trustworthy, hosting CCH, Lacerte, or ProSystem fx in a compliant environment is straightforward. Ongoing managed IT and a real tax-season SLA close the loop.
Firms exploring document automation or an internal custom AI application for engagement letters, PBC list handling, or 1040 organizer intake can layer that on once the compliance floor is in place, not before.
Talk to PGH Networks
If your firm is facing an insurance renewal, a WISP gap, or a tax-software migration you cannot risk during filing season, call 724.888.7007 or reach us through the contact form. We will scope the work against your January calendar, not ours.
Related reading

Microsoft 365 AitM Phishing Is Hunting Your Payroll Inbox
An active Microsoft 365 AitM phishing campaign is hijacking finance and payroll mailboxes at SMBs. Here is what Pittsburgh businesses should do this week.

Kali365 Device-Code Phishing: What M365 Tenants Should Do Now
Kali365 hijacks Microsoft 365 accounts via device-code phishing. What Pittsburgh SMBs should check in Entra ID this week, plus a 7-step action list.

Cloud Migration for Accounting Firms in Pittsburgh
Cloud migration for accounting firms in the Pittsburgh metro: secure lift of tax, audit, and practice management workloads with IRS Pub 4557 and SOC 2 in scope.