May 12, 2025 Updated August 10, 2026 #Business IT
Cloud Storage for Accountants: A Practical Firm Guide
How accounting firms should handle cloud storage: FTC Safeguards Rule and IRS Pub 4557 duties, client portals, tax app hosting, and setup.
Brian Garner IT Services Lead
Reviewed by Reade Taylor, Founder & President Supporting accounting firms through more than a few tax seasons teaches you something most articles about cloud storage for accountants never mention: the storage itself is the easy part. The hard parts are the rules that apply to tax data, the way files actually move between your firm and hundreds of clients every spring, and keeping all of it running the week of a deadline. Here is what we set up for accounting firms and why.
The rules changed: you are required to have a security program
If your firm prepares returns, two documents define your obligations:
- The FTC Safeguards Rule treats tax preparers as financial institutions and requires a written information security plan (WISP), multifactor authentication for anyone touching customer information, encryption of that data at rest and in transit, and a designated person responsible for the program. This is enforceable law, not guidance.
- IRS Publication 4557 is the IRS’s checklist version of the same duties, and IRS e-file providers attest to security practices when renewing.
Cloud storage decisions flow directly from those obligations. Consumer-grade accounts (personal Dropbox, a partner’s Google Drive) fail them on several counts: no centralized access control, no audit trail, no way to revoke a departed employee’s access to twenty years of client files. We help firms build and document the program these rules require; the storage layer below is where it becomes real.
Stuck on something like this right now?
Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.
Book a Free Strategy SessionWhat good firm storage actually looks like
For most small and mid-size firms, the practical answer is Microsoft 365: SharePoint for the firm’s document library, OneDrive for individual working files, with the firm’s retention and access rules enforced on top. Firms with heavier document workflows step up to purpose-built platforms, but the structure matters more than the brand:
- One library per function (clients, workpapers, admin), with client folders created from a template so permissions are inherited, not improvised
- Access by role, reviewed at least annually, revoked the day someone leaves
- Versioning and retention on, so an overwritten workpaper or a deleted folder is a five-minute restore, not a crisis
- Encryption and audit logging enabled and, more importantly, someone actually reviewing the logs
Our Microsoft 365 practice handles this build regularly, including the migration from whatever grew organically over the years.
Email is not a client portal
Every spring, sensitive documents move between clients and preparers by the thousands: W-2s, 1099s, bank statements, prior returns. Sent by plain email, each one is an exposure, and the FTC’s encryption expectation applies in transit. A proper client portal (or at minimum, encrypted file exchange) solves this, and modern ones are simple enough that clients over 70 use them successfully, which is the real adoption test.
The related threat is more dangerous than most firms realize: during filing season, phishing emails dressed as client document deliveries (“here are my tax documents, download attached”) target preparers specifically, and a compromised preparer account is a gold mine, enough to file fraudulent returns under your clients’ names. Multifactor authentication, endpoint detection, and a healthy suspicion of unexpected attachments are the standing defenses; our cybersecurity team monitors for the account-takeover patterns behind these campaigns.
Tax applications and where they live
Storage rarely travels alone. Firms running desktop tax software (Drake, Lacerte, UltraTax) eventually confront hosting: keep it on an office server, move to the vendor’s hosted edition, or run it on a managed cloud desktop. The right answer depends on firm size, remote work needs, and how much deadline-week risk you are willing to carry on a single office server. What we tell firms honestly: the office server is fine until the week it is not, and the week it is not is always the second week of April. Whichever direction you choose, size it in the fall, not February.
Backup is separate from storage, even in the cloud
A common and expensive assumption: “it’s in Microsoft 365, so it’s backed up.” Microsoft replicates your data for availability, but retention against deletion, ransomware, or a malicious insider is limited unless you add real backup with independent copies and defined retention. For a firm whose entire work product is files, this is not optional. It is also where disaster recovery starts; our backup and disaster recovery work covers the firm-wide version of the question.
A sane order of operations
- Multifactor authentication on email and anywhere client data lives, today.
- Move client files from consumer accounts into firm-controlled storage with role-based access.
- Stand up a portal or encrypted exchange before the next filing season, not during it.
- Add true backup with retention, and test a restore.
- Write the WISP the Safeguards Rule requires, using what you just built as its substance.
If you want an honest assessment of where your firm stands before next season, book a technology strategy session. We support accounting firms alongside the other professional services every day, and the first conversation costs nothing.
This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.