PGH Networks

Pittsburgh CPA Firm Cybersecurity and Cloud Case Study

July 29, 2026· PGH Networks Team· 5 min readCloud & Microsoft 365
Pittsburgh CPA Firm Cybersecurity and Cloud Case Study

PGH Networks is a Pittsburgh-based managed services provider that delivers cybersecurity, cloud, and compliance support to accounting firms across the metro, and this Pittsburgh CPA firm cybersecurity and cloud case study documents a representative engagement with a mid-sized public accounting practice headquartered in the South Hills. The firm approached us in the fall with two overlapping problems: a written information security program (WISP) that had not been updated to reflect current IRS Publication 4557 expectations, and a tax software stack still tethered to an aging on-premises server that could not survive another April.

This page anonymizes the client but preserves the technical shape of the engagement so other Pittsburgh-area partners and firm administrators can judge fit.

The buyer scenario: a 38-person Pittsburgh CPA firm

The firm employs 38 people across offices in Pittsburgh and Washington County, serves roughly 1,900 1040 clients and about 210 business returns, and runs CCH Axcess and Lacerte alongside QuickBooks Online, a document management platform, and a hosted portal for client deliverables. Two partners had recently received cyber-insurance renewal questionnaires demanding evidence of MFA on email and remote access, endpoint detection and response, encrypted backups, and a documented incident response plan. They had none of it formalized.

A CPA firm without a current WISP is not just out of compliance, it is uninsurable at renewal.

Padlock and keys resting on a computer keyboard.

The challenge: GLBA, IRS WISP, and a tax-season deadline

Three constraints defined the project. First, the Gramm-Leach-Bliley Act Safeguards Rule and the IRS WISP requirement for paid preparers both demanded a written, tested security program naming a qualified individual, risk assessments, and vendor oversight. Second, CCH Axcess and Lacerte performance had degraded on the local server to the point that partners were logging in from home over a VPN just to escape daytime slowness. Third, the go-live had to happen before January 15, because no partner would authorize a cutover during tax season.

Layered on top: the firm's existing IT vendor was a generalist break-fix shop with no accounting vertical experience, no familiarity with tax-software hosting, and no compliance documentation practice. The partners wanted a provider that spoke both CPA and NIST.

How PGH Networks solved it

We structured the engagement in three parallel tracks so the January deadline was achievable.

Security baseline and WISP. A vCIO led a two-week risk assessment mapped to the FTC Safeguards Rule and IRS Publication 4557, then drafted the WISP naming the firm's IT partner as qualified individual, cataloguing systems that touch taxpayer data, and defining incident response roles. In parallel our cybersecurity team deployed managed EDR to every endpoint, enforced conditional-access MFA on Microsoft 365, rebuilt the firm's email security posture, and rolled out an encrypted, immutable backup target with 90-day retention.

TL;DR: The engagement paired a GLBA-aligned WISP with a CCH and Lacerte cloud migration so the firm cleared its insurance questionnaire and entered tax season on modern infrastructure.

Cloud migration for tax software. CCH Axcess is already SaaS, so the work there was identity, data-loss prevention through Microsoft 365 and Microsoft Purview, and disciplined offboarding. Lacerte was moved to an authorized hosting environment sized for the firm's concurrent-user count, with the local file server retired to a read-only archive. QuickBooks desktop files for a handful of write-up clients were migrated to a hosted profile keyed to the same identity provider so partners had a single sign-on across every tax and accounting application.

Operational handoff. Managed IT took over patch management, RMM, and help desk with a documented tax-season SLA: one-hour response on partner-impacting incidents from January 15 through April 20, and a named on-call engineer familiar with the firm's stack. We also stood up an AI readiness assessment and an acceptable-use policy so the firm could evaluate Copilot for research and drafting without exposing client data.

Outcomes: uptime, audit posture, and partner sign-off

The cutover completed on January 9, six days ahead of the partner-imposed deadline. Measured against the prior year:

Tax-season uptime on the hosted Lacerte environment held at 99.98 percent through April 15, with zero partner-impacting incidents lasting more than fifteen minutes. Login times for CCH Axcess dropped from a partner-reported "coffee break" to under ten seconds. The cyber-insurance renewal was signed at a lower premium than the prior year because the carrier accepted the WISP, EDR attestation, and MFA evidence without follow-up. The firm's managing partner used the WISP and vendor list to answer a client bank's third-party risk questionnaire in a single afternoon rather than the two-week scramble it had been the year before.

Perhaps most important: no partner had to call anyone at 6:30 a.m. during tax season. That is the metric CPA firms actually judge an MSP on.

Security, privacy, and performance status with fix options.

Takeaway for other Pittsburgh accounting firms

Most Pittsburgh CPA firms in the 15-to-75-person range are sitting on the same three-part problem this client had: a WISP that exists only in theory, tax software running on hardware that is one bad Saturday away from a disaster, and cyber-insurance questionnaires that keep getting stricter. The playbook in this Pittsburgh CPA firm cybersecurity and cloud case study is repeatable, and the sequencing matters. The WISP and identity work has to lead, because it drives both the insurance answer and the migration design. The cloud move follows, because once identity and endpoint controls are trustworthy, hosting CCH, Lacerte, or ProSystem fx in a compliant environment is straightforward. Ongoing managed IT and a real tax-season SLA close the loop.

Firms exploring document automation or an internal custom AI application for engagement letters, PBC list handling, or 1040 organizer intake can layer that on once the compliance floor is in place, not before.

Talk to PGH Networks

If your firm is facing an insurance renewal, a WISP gap, or a tax-software migration you cannot risk during filing season, call 724.888.7007 or reach us through the contact form. We will scope the work against your January calendar, not ours.

Share

Related reading