In most businesses, a slow morning is an annoyance. In an accounting firm during filing season, it’s a deadline moving closer while nothing gets done.
The calendar doesn’t negotiate. Extensions, quarter-end reporting, and April deadlines arrive whether the technology cooperates or not — and the weeks when your systems are under the most strain are precisely the weeks when failure costs the most.
Most Folsom firms we work with didn’t have an IT problem in October. They had one in March, and by then the options were limited to whatever could be done without disrupting active client work.
Why filing season breaks IT that seemed fine all year
The failure isn’t usually neglect. It’s that filing season changes the shape of the demand your systems face, in five distinct ways at once.
Everything runs simultaneously. Tax preparation software, QuickBooks, document management, email, client portals, scanning, and research tools — all at the same time, across every workstation, for weeks. Infrastructure that handles ordinary use with room to spare begins to strain when the load triples and stays there.
The team expands temporarily. Seasonal preparers arrive needing accounts, permissions, workstations, and access to client files on day one. Rushed provisioning is how permissions get set too broadly, how shared logins appear, and how accounts remain active for months after someone has finished.
Remote work intensifies. Preparers work evenings and weekends from home. VPN connections, remote desktop sessions, and cloud access get used harder in eight weeks than in the preceding eight months combined. Capacity that was never tested at scale gets tested at the worst possible moment.
File volume spikes sharply. Client documents arrive by the thousand — scanned, emailed, uploaded to portals. Storage fills faster than anyone projected, backup windows stretch longer, and scanning workflows become bottlenecks with people physically queuing.
Maintenance stops entirely. Updates get deferred. Warnings get dismissed. The failing drive that would normally be replaced gets left because nobody can afford downtime. Small problems accumulate precisely when there’s no slack in the schedule to absorb any of them.
The result is a pattern we see every year: firms that ran perfectly well all autumn start losing hours to technology in the exact weeks those hours are most valuable.
The arithmetic nobody runs
This is worth doing on paper, because the numbers are more significant than they feel in the moment.
A firm with fifteen preparers, each losing two hours to a slow or unavailable system, loses thirty billable hours in a single day. At typical seasonal rates, that’s several thousand dollars from one incident.
Now consider that most firms experience more than one such incident across a season. Add the returns that slip past their target date, the client calls that follow, the overtime spent clearing the backlog, and the extensions filed that weren’t planned for.
There’s also a quieter cost that doesn’t appear in any spreadsheet. Rushed work under time pressure is where errors happen, and technology friction adds pressure to a team already carrying a great deal of it. Firms that reduce that friction consistently report fewer corrections and less burnout in April — which matters for retention in a market where experienced preparers are difficult to replace.
What season-ready actually means
The firms that move through filing season smoothly aren’t lucky. They did specific work in the autumn, when there was room to do it properly.
Performance verified against peak load, not average load. This is the distinction that matters most. A system tested during a quiet week tells you very little about how it behaves when twenty people are hitting the same file server, running tax software, and scanning simultaneously. Bottlenecks identified in November are inexpensive to resolve. The same bottleneck found in March is expensive, disruptive, and often can’t be fixed until the season ends.
Storage checked for speed, not just capacity. Firms routinely add disk space when the actual constraint is how fast the storage responds under concurrent access. A drive that’s half empty but slow under load will throttle the entire team, and no amount of additional capacity helps.
Continuous monitoring on every system. Proactive monitoring catches a failing drive, a filling disk, a struggling server, or a saturated network link before it becomes an outage in the middle of a workday. This is the single largest practical difference between a managed and a reactive approach — and during a compressed season, catching a problem three days early is worth considerably more than fixing it quickly after the fact.
Remote access tested before it’s relied upon. Evening and weekend work should be as dependable as working in the office. VPN capacity, remote desktop performance, and cloud access all need verification under realistic load, not a single test connection from an empty office.
Support that answers in minutes. When a preparer can’t log in at 4pm on April 12th, “we’ll look at it tomorrow” isn’t an acceptable answer. A Help Desk that responds within minutes and can resolve issues remotely prevents individual problems from consuming afternoons.
Onboarding and offboarding handled properly. Seasonal staff should receive correct, appropriately limited access quickly — and have it removed cleanly when the season ends. This second step is the one firms routinely forget, leaving active accounts belonging to people who left months earlier. Those dormant accounts are among the most commonly exploited entry points into a firm.
Backups tested rather than assumed. Client financial data is the firm’s obligation, and the consequences of losing it extend well beyond inconvenience. Verified backups with tested recovery mean an incident becomes a delay rather than a catastrophe.
Security deserves particular attention in season
Filing season is also open season for attackers, and the reason is straightforward: firms are busy, distracted, and moving quickly. Those are precisely the conditions under which a fraudulent invoice or a convincing payment redirection slips through.
Accounting firms hold exactly what attackers want — Social Security numbers, bank account details, and complete financial pictures for hundreds of clients, concentrated in one place. A single compromised mailbox can expose all of it.
The specific risks worth naming:
Credential phishing spikes. Fake Microsoft 365 login pages, portal notifications, and IRS-themed messages arrive in volume during season. A preparer working at 9pm is less likely to scrutinize one carefully.
Wire fraud and payment redirection. An attacker with access to a mailbox can see pending transactions and send convincing instructions from a legitimate firm address. Verifying any payment change by phone — using a number already on file, never one from the email — prevents most of these losses.
Client data requests. Attackers impersonate clients requesting copies of returns or financial documents. During a busy week, these get fulfilled without verification.
Layered cybersecurity — Multi-Factor Authentication enforced across every account, email threat filtering, endpoint detection and response, DNS protection, and automated patching — addresses the substantial majority of this. It matters most during the weeks when everyone’s guard is naturally lowest.
The compliance dimension
There’s a further consideration that has grown noticeably in recent years. Accounting firms are increasingly asked to demonstrate their safeguards rather than simply assert them.
Cyber insurers now require evidence of specific controls before issuing or renewing coverage — MFA, monitored backups, endpoint protection — and claims have been reduced where a firm attested to controls it didn’t actually have. Larger clients send security questionnaires. The IRS expects tax professionals to maintain a written information security plan.
The practical implication is that the work described above produces documentation as a by-product. A firm running monitored, tested, documented systems can answer these requests in an afternoon. A firm without them faces an uncomfortable scramble, usually at the least convenient time.
What we typically find when we assess a firm
Assessments across accounting practices turn up a remarkably consistent set of findings. None of them are unusual, and none reflect poorly on the firms involved — they’re simply what happens when a business grows faster than the infrastructure supporting it.
Patch compliance somewhere between 55% and 70%. Almost always accompanied by the belief that Windows Update was handling things automatically. It generally isn’t, particularly for third-party applications like PDF readers and browsers, which are among the most commonly exploited software on any network.
Backups that have never been restored. The job runs, the log says success, and nobody has attempted an actual recovery. When we test one, the failure rate is higher than most firms expect.
MFA enabled selectively. Often on the administrator account and a partner or two, not enforced across the firm. Every account without it is a potential entry point, and attackers specifically look for the exceptions.
Seasonal accounts still active. Logins belonging to preparers who finished the previous April, still enabled, often with the original password. These are attractive targets precisely because nobody is monitoring their use.
Storage approaching capacity. Usually above 80%, which affects performance well before it causes an outage, and lengthens backup windows in a way nobody notices until they matter.
One person who knows how everything works. Not a technology finding exactly, but a real risk. Firms frequently depend on a single staff member’s informal knowledge of how systems fit together, with nothing documented.
The value of an assessment isn’t discovering something dramatic. It’s converting a set of vague assumptions into a specific, prioritized list — which is what allows a firm to fix the things that matter before the season, rather than discovering them during it.
Questions worth asking before the season starts
You don’t need technical knowledge to pressure-test your firm’s readiness. Ask whoever manages your technology:
- Has our system performance been tested at peak load, or only under normal use?
- What’s our current patch compliance percentage across all workstations and servers?
- When did we last perform an actual restore from backup — what was the date?
- Is MFA enforced on every account, without exceptions?
- Which accounts belonging to former seasonal staff are still active?
- How much free space is on our primary storage right now?
- If someone can’t work at 4pm on April 10th, how quickly do we get help?
- Could we produce documentation of our security controls if an insurer asked?
Vague answers to any of these are worth resolving in November rather than discovering in March.
The best time to address this is now
Very little in this article helps a firm reading it in March. Preparing systems for peak season is autumn and early-winter work, done quietly, when there’s room to test properly and resolve what testing reveals.
The sequence that works: assess against realistic peak load, fix the bottlenecks that assessment reveals, put monitoring in place so problems surface early, verify backups actually restore, close the security gaps, and establish a support arrangement that responds in minutes rather than days. Done between October and January, none of it disrupts client work.
RJ PRO Tech Group works with Folsom financial and accounting firms to make filing season predictable rather than precarious — performance verified in advance, systems monitored continuously, client data protected and recoverable, and support that answers when the clock is unforgiving.
Schedule a complimentary IT assessment for your Folsom firm. Considerably better now than the second week of April.