Pittsburgh CPA Firm Cybersecurity and Cloud Case Study

PGH Networks is a Pittsburgh-based managed services provider that delivers cybersecurity, cloud migration, and compliance support to small and mid-market firms across the Pittsburgh metro, including Downtown, the South Hills, Cranberry Township, Robinson, Monroeville, and the broader Allegheny, Butler, Washington, and Westmoreland county footprint within 75 miles of 15220. This Pittsburgh CPA firm cybersecurity and cloud case study documents a representative engagement with a regional accounting practice that needed to modernize before tax season while closing gaps against IRS WISP and GLBA Safeguards Rule expectations.
The engagement described below is anonymized. No client names, headcounts tied to identifiable firms, or proprietary details are disclosed. Numbers reflect realistic project scope for a Western Pennsylvania CPA practice of this size.
The client: a Pittsburgh CPA firm heading into tax season
The client was a roughly 35-seat public accounting firm with offices in the Pittsburgh metro and a satellite location in the northern suburbs. The practice split its work between individual 1040s, closely held business returns, and audit/assurance for nonprofit and manufacturing clients. Staff relied heavily on CCH Axcess and ProSystem fx for tax and engagement work, Lacerte for a subset of individual returns, QuickBooks for bookkeeping clients, and a shared file server that had grown organically for a decade.
Two forcing functions triggered the project. First, the firm's cyber liability carrier issued a renewal questionnaire demanding written evidence of MFA on email and remote access, endpoint detection and response, encrypted backups, and a documented Written Information Security Plan (WISP) — the same WISP the IRS now requires of every paid preparer under Publication 4557 and the FTC Safeguards Rule. Second, the managing partner had lived through one too many March 15 outages caused by an aging on-prem tax server.

The challenge: WISP gaps, aging servers, and tax-app performance
A discovery review surfaced the pattern common to mid-sized CPA firms in the region. There was no written WISP. MFA was enforced on Microsoft 365 but not on the VPN or the remote desktop gateway. The endpoint agent was a consumer-grade AV product with no managed detection behind it. Backups ran locally to a NAS in the same server closet as production — a single fire or ransomware event away from total loss. GLBA-aligned access reviews, vendor risk documentation, and an incident response plan did not exist in any retrievable form.
On the productivity side, CCH Axcess performance was acceptable, but ProSystem fx and the firm's document management system were pinned to an on-prem Windows server that slowed noticeably under concurrent tax-season load. Remote staff tunneled in over a saturated VPN. Lacerte was installed workstation-by-workstation with return files living on the file server, creating a locking and versioning mess every April.
Compliance and tax-season uptime are the same problem in a CPA firm — you cannot separate the WISP from the server that runs ProSystem fx.
How PGH Networks solved it
TL;DR: PGH Networks delivered a written WISP, hardened identity and endpoints, and migrated the firm's tax and accounting stack to a resilient cloud posture before the January filing ramp.
Work was sequenced against the tax calendar. Between June and October, PGH Networks authored a WISP mapped to IRS Publication 4557 and the FTC Safeguards Rule, including the qualified individual designation, risk assessment, access controls, encryption standards, incident response plan, and annual employee training cadence the GLBA Safeguards Rule now enforces. The WISP was delivered as a living document the firm could hand directly to its cyber insurance underwriter and to any state board inquiry.
Identity was rebuilt around Microsoft 365 with conditional access, phishing-resistant MFA on every account with elevated privileges, and privileged access workstations for the two partners with domain admin rights. The consumer AV was retired in favor of a managed EDR platform monitored 24/7 by PGH Networks' security operations team, with tuned detections for the credential-theft and remote-access patterns most commonly used against tax preparers.
The application stack was migrated in stages. CCH Axcess was already SaaS; PGH Networks tightened its SSO and IP-restriction posture. ProSystem fx, the document management system, Lacerte, and the QuickBooks host were relocated to a Pittsburgh-region hosted private cloud with per-user published applications, immutable off-site backups, and a documented four-hour recovery time objective. The firm's tax-season uptime SLA was contractually set at 99.9% for January through April 15, with named on-call engineers.
Change management mattered as much as the technology. Staff received short, role-specific training on the new MFA flow, the phishing reporting button, and the new remote access path — delivered in November so muscle memory was in place well before January.

Outcomes for the accounting firm
The firm entered tax season with a signed WISP, a passing cyber-insurance renewal at a lower premium than the prior year, and MFA plus EDR coverage on 100% of production endpoints and identities. Through April 15, the hosted tax environment recorded zero unplanned outages during business hours. Help desk tickets tied to Lacerte file locking and ProSystem fx performance — the top two complaint categories the year prior — dropped to a handful of edge cases resolved same-day.
Just as important, the firm now had retrievable evidence. When a client's audit committee asked for the firm's security posture in writing, the managing partner forwarded a WISP, an EDR coverage attestation, and a backup test report the same afternoon.
PGH Networks served as the outsourced IT and security function for the firm, owning the WISP, the endpoint and identity stack, and the hosted tax application environment end-to-end.
Takeaway for other Pittsburgh accounting firms
Most Pittsburgh CPA firms in the 15-to-75-seat range are sitting on a version of this same problem: a WISP that exists only in intent, MFA that covers email but not remote access, and a tax application stack that was fine in 2018 and is now the bottleneck every April. The fix is not a single product. It is a sequenced program that treats IRS WISP and GLBA compliance, identity, endpoint, and the CCH/Lacerte/ProSystem fx environment as one system, delivered against the tax calendar rather than against a generic IT strategy roadmap.
That is the pattern this Pittsburgh CPA firm cybersecurity and cloud case study is meant to illustrate, and it is the engagement model PGH Networks runs for accounting firms across the Pittsburgh metro. If your firm is heading into a cyber-insurance renewal, a peer review, or another tax season on aging infrastructure, that is the conversation to have now — not in February. Call 724.888.7007 or reach us through the contact form to start scoping your WISP and cloud migration before the next filing ramp.
Related reading

Evilginx Phishing Kits Are Hunting Microsoft 365 Logins
A sloppy attacker exposed three live Evilginx phishing operations targeting Microsoft 365: here's what Pittsburgh SMBs should verify and fix this week.

Phishing Kits Bypassing Microsoft 365 MFA: What SMBs Should Do Now
Two new phishing kits are defeating Microsoft 365 MFA. Here's what Pittsburgh SMBs in legal, healthcare, CPA, and defense should do about it this week.

Azure Consulting in Pittsburgh, PA
Azure consulting in Pittsburgh, PA for small and mid-market firms: migration, security, FinOps, and Copilot enablement from a local team. Talk to an engineer.