Protect client records through filing season and beyond

Secure seasonal staff access, protect client documents, and coordinate planned maintenance around filing deadlines.

Or email hello@teclara.tech

Security risks

Plan security work around the filing calendar.

Seasonal hiring and increased document sharing change the security needs of an accounting practice. We coordinate access reviews, planned changes, and recovery testing around your filing schedule.

  1. January

    Seasonal preparers start

    Give each preparer a named account with access limited to assigned engagements. Document when that access should end so it can be removed when seasonal work finishes.

  2. February to April

    Client documents arrive by email

    Staff receive tax slips, statements, and identification documents through email attachments and links. Email filtering and sign-in monitoring help detect phishing attempts that impersonate clients or the CRA.

  3. April 30 and June 15

    Prepare for filing deadlines

    An outage near a filing deadline can disrupt client work. Routine updates and recovery tests follow an agreed schedule that accounts for the practice’s busiest periods.

  4. May onward

    Remove seasonal access

    Review seasonal accounts and client-folder links when filing work ends. Remove permissions that are no longer needed for active engagements.

Security controls

Closed engagements can leave open access behind

Accounting practices have to protect confidential client information while partners, staff, and seasonal preparers need different access at different times. We review permissions by engagement and remove access when it is no longer needed.

  • Access

    Match access to the engagement

    Where client folders live in Microsoft 365 or Google Workspace, access is limited to the people assigned to the work. External links and inherited permissions are reviewed when the engagement closes.

  • Sign-in

    Protect every named account

    Multi-factor authentication, administrator controls, and sign-in policies protect staff accounts. Staff access shared mailboxes through their own accounts, so permissions can be reviewed and removed individually.

  • Devices

    Secure the devices used for client work

    Supported laptops and phones receive managed endpoint protection, encryption, and security updates. The security team reviews alerts, investigates suspicious activity, and coordinates the response.

  • Email

    Reduce impersonation and payment fraud

    Email controls filter common phishing and impersonation attempts. Domain protection and payment-change procedures can be added where the practice needs stronger controls for email sent from its domain and payment requests.

  • Calendar

    Plan routine work around filing deadlines

    Patching, configuration changes, and planned maintenance follow an agreed schedule. We account for filing deadlines when scheduling routine work.

  • Recovery

    Confirm what your backups cover

    We maintain independent backups of Microsoft 365 or Google Workspace data and test restores.

Security documentation

Document how client records are protected.

Clients, insurers, and practice reviewers may request different information. Current access reports, backup records, and alert histories help the practice respond accurately.

Cyber insurer, at renewal
Is MFA enforced on email and remote access? Are backups kept separate and tested?
Current MFA coverage and sign-in policy reports, the backup scope, and the date and result of the last restore test.
Business clients
How are our financial records protected, and who at your firm can open them?
A plain description of the controls in place, with access limited by engagement and reviewed when the work closes.
Practice inspector for assurance firms
How does the firm manage the technology its quality management system relies on?
Records of patching, access reviews, backup, and monitoring for the systems we manage, which the firm can reference in its CSQM 1 documentation.

Your responsibilities

The practice decides how long records are kept and which professional, privacy, and tax requirements apply. Teclara manages and documents security controls for the agreed systems. The practice or its software provider remains responsible for CRA portals, tax applications, workstations, file servers, and local working papers unless backup, recovery, or administration for those systems is added explicitly.

Managed Security & Compliance

Ongoing security for your accounts, devices, and data.

The security controls on this page run on the platform you use, with access controls, reporting, and maintenance schedules adapted to your practice.

On Microsoft 365

  • SharePoint and OneDrive engagement folders with permissions based on each person’s role
  • MFA, Conditional Access, and administrator access controls
  • Managed endpoint protection on supported devices
  • Update schedules planned around filing deadlines

On Google Workspace

  • Shared drives with permissions based on each person’s role
  • Gmail phishing and impersonation protection
  • External sharing links reviewed when work closes
  • Google Vault aligned with retention policy where licensed

Configuration updates are part of the service. When our security baseline changes, your environment is updated without a separate project fee.

See the full service

Frequently asked questions.

Can you help with a cyber insurance application or renewal?

Yes. We review the insurer’s questions and provide current evidence for the sign-in controls, device protection, monitoring, and backups we manage. Requirements vary by insurer and policy, so the work supports the application but does not guarantee approval or coverage.

What support is available during filing season?

Under Managed Security & Compliance, the security team reviews alerts around the clock and responds according to the service agreement. Day-to-day user support and administration require Managed IT, which includes Managed Security & Compliance. Planned changes are coordinated around known filing deadlines.

Can you work alongside our current provider or take over?

Yes. Managed Security & Compliance can work alongside your provider. For a handover, we document the current environment, confirm responsibilities, and schedule the transition around the practice’s deadlines. If you want to delegate day-to-day IT as well, Managed IT includes Managed Security & Compliance and adds user support, device administration, onboarding, and platform management.

What documentation do you provide?

Reporting can include sign-in and access records, backup and restore evidence, patching and vulnerability status, alert response records, and written control descriptions. The reports cover the systems and services in your agreement. This documentation supports client, insurance, or professional reviews but does not replace legal or accounting advice.

Do you support both Microsoft 365 and Google Workspace?

Yes. We secure accounts, administrator access, email, sharing, supported devices, and independent backup on both platforms. Available controls can depend on licensing, so we confirm what the practice already has and what the agreed security baseline requires.

Client feedback

What a client says about working with us.

“Teclara materially improved both our operational responsiveness and our security posture.”

E.C.

Senior Leadership, GTA Consulting Firm

Wadhah Hussain, Founder of Teclara

Led by Wadhah Hussain, Teclara's founder

20+ years enterprise IT · Big Four alumnus · Microsoft & Google Cloud specialist

Short on time? Let your favourite AI sum up Teclara.

Review your security before filing season

In a 30-minute conversation, we discuss filing deadlines, seasonal access, and any client or insurer requests. We agree on the next step. Technical checks and written findings belong to a separately scoped engagement.

hello@teclara.tech