Keep Your Firm Billing Through Tax Season: IT That Already Knows Lacerte, Drake, and ProSeries

Flat-rate managed IT and the written information security plan the IRS requires, for Columbia accounting firms with 1 to 50 employees.

Tax season puts every system in your firm under maximum stress with zero tolerance for downtime. And the managing partner or office manager is handling IT on top of their actual job.

Dealing with a problem right now? Call (803) 881-3771 — you’ll get a straight answer on whether we can help and what it would take. Not a sales pitch.

Locally owned in Irmo, SCFlat rate, locked 24 monthsFree on-site IT walkthroughBuilt for 1–50 employees

The daily cost

You Didn’t Open This Firm to Troubleshoot Software

Every hour a partner spends on a printer, a sync failure, or a password reset is an hour not spent on billable client work. Multiply that across your staff, across a filing season, and the cost stops being hypothetical.

Underneath the daily friction is an obligation most firms haven’t addressed. Every time you renew your PTIN, you sign Form W-12. Line 11 of that form states that you are aware paid tax return preparers are required by law to create and maintain a written information security plan.

Most firms know about the obligation. Few have the document.

The program

Six Controls. Nothing You Don’t Need.

The same six controls go into every managed agreement, mapped to what your framework requires and configured around the software your team already uses.

CONTROL 01

Multi-Factor Authentication

On every account that holds sensitive data — email, banking, accounting, practice management, cloud storage. Paired with a password manager so your team isn’t drowning in credentials.

CONTROL 02

Automatic Security Updates

Unpatched software is now the single most common way attackers get in. Patches applied when they’re released, not queued for a testing cycle that never happens.

CONTROL 03

Email Security & Training

Technical filtering in Microsoft 365 or Google Workspace, plus staff training built on education and positive reinforcement — not fake phishing tests designed to catch your employees failing.

CONTROL 04

Backup & Recovery, Tested Quarterly

Critical data backed up in two locations, tested every quarter, documented, and reported to you. A backup that’s never been tested isn’t a backup. It’s a hope.

CONTROL 05

Restricted Admin Access

Your employees don’t need the ability to install software or change system settings. Restricting admin access eliminates an entire category of problems before they start.

CONTROL 06

Your Three Core Documents

An incident response plan, a password policy, and an offboarding checklist. Who to call when something goes wrong, how your team handles credentials, and how to kill access the day someone leaves.

Compliance

IRS Publication 4557 and the FTC Safeguards Rule — What Your Firm Needs on Paper

Publication 4557 lays out what the plan has to contain. The FTC Safeguards Rule, which names “an accountant or other tax preparation service” explicitly in its definition of a covered financial institution, adds nine required elements — including a designated qualified individual, a written risk assessment, access controls, encryption, employee training, incident response, and service provider oversight.

Since May 13, 2024, the Safeguards Rule also carries a 30-day FTC notification requirement for security events affecting 500 or more consumers.

What we build, inside your managed agreement: six security controls covering both the IRS and FTC requirements on day one, a written information security plan, documented risk assessments, and the supporting artifacts an auditor or the IRS expects to see. The IRS publishes a WISP template as Publication 5709 — we build yours to that shape and keep it current.

What you actually get

Compliance Documentation That Exists on Paper, Not in a Sales Pitch

Most IT companies mention compliance and never deliver the documents. Every managed agreement produces real artifacts — the risk assessment, the written security plan, the incident response plan, the quarterly restore report. When a carrier audit or a regulatory inquiry arrives, the answer is already written.

Your stack

Software We Support Around

Lacerte · Drake · ProSeries · QuickBooks · client portals · and the tax preparation workflow that peaks between January and April.

Geoffrey Giles, founder of Soda City Systems

Geoffrey Giles
Founder · former Virtual CIO

Why us

Built by Someone Who Managed $24 Million in Annual IT Spend — and Saw What Wasn’t Working

Soda City Systems was founded by a former Virtual CIO at a national managed IT provider, where he managed $24 million in annual IT spend across South Carolina. That role made one thing clear: as IT firms grow and get acquired, businesses with 10 to 50 employees stop getting the attention they need.

Your problems stop repeating.

Every issue we resolve gets a second look — what caused it, and what would prevent it. The businesses that have worked with us longest call us the least.

You never start over with a stranger.

You have an accountant who already knows your books. You have an attorney who already knows your contracts. Now you have an IT team that already knows your technology.

Your IT company doesn’t outgrow you.

We’re not an enterprise firm that occasionally takes a small client, and not a solo consultant who disappears for a week. Founder-operated and locally owned, built for businesses your size and only your size.

Our guarantees

Three Commitments, in Writing

Guarantee 01

The 60-Day Out

If the relationship isn’t working, give us 60 days’ notice and walk. No penalties, no buyout fees. We hand off your documentation, credentials, and configuration to whoever comes next.

Guarantee 02

The Rate Lock

Your per-user rate is fixed for 24 months from signing. If our prices go up, yours doesn’t change until month 25.

Guarantee 03

The Quarterly Restore Test

Every quarter we restore your data from backup, document the result, and send you the report. If a restore fails, we fix the cause and re-test before the quarter closes, at no charge.

Questions

Common Questions

Do we really need a written information security plan?

Yes, and you’ve already attested that you know it. Line 11 of Form W-12 — the PTIN renewal form — says paid preparers are required by law to create and maintain one. It’s also required under the FTC Safeguards Rule, which explicitly covers tax preparation services.

Can you work around tax season?

That’s the point of scheduling the walkthrough now rather than in February. Deployment work happens in the off-season wherever possible, and during filing season we’re in maintenance-and-response mode, not migration mode.

How much does managed IT cost for a firm our size?

Starting at $100 per user, per month, locked for 24 months. Firms needing the full WISP build and annual maintenance typically sit above the floor.

What happens if the IRS or FTC asks for our security plan?

You produce it. That’s the whole reason it exists on paper. We build the plan, the risk assessments, and the supporting artifacts, and we keep them current so the answer is already written when someone asks.

We already have antivirus and a backup. Isn’t that enough?

Neither is a written information security plan, and neither covers stolen credentials, phishing, or admin access. If your existing tools are configured properly we leave them in place and build the rest around them.

Free IT walkthrough

Find Out Where Your Firm Stands

The right IT plan for a 12-person insurance agency looks nothing like the right plan for a 30-person dental practice. We’ll come to your office, look at your current setup, talk through what’s working and what isn’t, and give you a clear recommendation.

It takes about an hour. No pressure, no contracts, no 47-slide presentation.

Prefer to just call?
(803) 881-3771

Monday–Friday, 8am–5pm Eastern

Book your walkthrough

We’ll call you back within one business hour.

We’ll call you back within one business hour.

We don’t share your information with anyone, and we won’t add you to a mailing list you didn’t ask for.