INDUSTRIESI03Professional Services
Every hour lost to IT
was billable.
IT for accountancy practices, consultancies, and agencies. In a firm that sells time, downtime has a rate attached, and the arithmetic is uncomfortable once somebody does it.
WHAT WE HEAR
The four sentences we hear most in your sector.
- 01
Our busiest fortnight is the one we cannot afford an outage in.
Tax season, year end, and reporting deadlines concentrate the risk into a few weeks. That is when the resilience you did or did not buy shows up.
- 02
Client documents are in four places.
The practice management system, a file share, somebody’s email, and a personal cloud account set up to get a large file to a client. Only one of those is defensible.
- 03
Partners work from everywhere.
Home, client sites, and the bach. The security model has to follow the person rather than assume they are at a desk in the office.
- 04
We are being asked security questions by our own clients.
Larger clients now send supplier security questionnaires to their accountants and advisers. Answering them credibly is becoming part of winning the work.
THE STACK
The systems you actually run.
Not a list of logos. These are the platforms we support, migrate, and get called about in this sector. If yours is missing, it usually means we have not worked with it, and we will say so rather than nod along.
Practice and workflow
The system that decides whether a job is on track. Downtime here stops the whole firm rather than one person.
- Xero Practice Manager
- Karbon
- WorkflowMax
- FYI Docs
- MYOB Practice
- APS
- Iris
Client accounting and advisory
You run these on behalf of clients, which means their data sits inside your obligations as well as theirs.
- Xero
- MYOB
- Sage
- Fathom
- Spotlight Reporting
- Hubdoc
- Dext
Documents and collaboration
Where confidentiality is actually won or lost, and where most firms have the least deliberate structure.
- SuiteFiles
- SharePoint
- Microsoft 365
- NetDocuments
- Google Workspace
- DocuSign
Client communication
Email is the channel your clients use to send you bank details and identity documents, which makes it the channel attackers target.
- Microsoft 365 email security
- Secure client portals
- Annature
- Digital signature workflows
WHERE WE HELP
Four things we do for professional services specifically.
- 01
Uptime measured against your calendar
We plan resilience and maintenance around your deadlines rather than around ours. Nothing gets changed in the fortnight before a filing deadline, and the connectivity and failover conversation happens well before the season that would expose it.
- 02
One place for client documents
A structure that reflects how the firm works, with access by role and retention applied automatically. The test is whether a partner can find a client file from a phone without asking anyone, and whether a departing staff member takes nothing with them.
- 03
Answering client security questionnaires
We build the evidence once, keep it current, and answer from it. Firms that do this answer a supplier questionnaire in a day. Firms that do not lose a week of senior time to each one, usually in the middle of something else.
- 04
Security that fits how partners work
Access decided by identity and device rather than by whether someone is on the office network, so working from a client site or from home is normal rather than an exception somebody has to work around.
WHAT YOU ANSWER TO
The obligations that shape the work.
We make the systems match your obligations. We are not your lawyer or your compliance adviser, and where a question turns on interpretation we will tell you to take advice rather than guess on your behalf.
Privacy Act 2020
You hold a great deal of personal information about your clients and, through them, about their staff. That brings collection, storage, retention, and breach notification duties, and the notification clock starts when you become aware of a breach causing serious harm.
Professional and body requirements
CA ANZ, CPA, and similar bodies set expectations around client confidentiality, record retention, and increasingly around technology controls. These sit alongside the law rather than instead of it.
Client contractual obligations
Larger clients now flow their own security requirements down to advisers through engagement terms. It is worth reading what you have already agreed to before a questionnaire asks you to evidence it.
WHAT IT COSTS
Per user, per month
Priced per user per month so the cost tracks head count, which is how a professional services firm thinks about most of its overheads anyway. The useful comparison is not against another provider’s monthly fee but against your charge-out rate multiplied by the hours your people currently lose. Projects such as a document restructure or a platform migration are quoted separately.
WHERE TO START
The services that matter most here.
FAQ
Questions from your sector
01What does IT downtime actually cost an accountancy practice?
Take your average charge-out rate, multiply by the number of fee earners affected, and multiply by the hours lost. Most firms have never done that arithmetic and find the result uncomfortable, particularly once they include the smaller losses: the twenty minutes a slow machine costs someone every day, or the afternoon a partner spends on a technology problem instead of on client work.
02Where should client documents live?
In one system, with access by role and retention applied automatically. For most New Zealand firms that is SuiteFiles or SharePoint alongside the practice management system, with a clear rule about which one holds what. The failure mode is not choosing a bad system, it is running three and letting people decide case by case.
03A client has sent us a security questionnaire. Can you help us answer it?
Yes, and it is becoming a regular request. The questions are usually specific and answerable: multi-factor authentication, tested backups, endpoint protection, an incident response plan, and staff training. We establish where you genuinely stand, close the gaps that matter, and give you documented answers you can stand behind. Answering optimistically is worse than answering honestly, because you are signing up to it contractually.
04How do we stop invoice fraud and email interception?
The technical layer is domain authentication and email security so nobody can send mail that appears to come from you and targeted messages are caught. The layer that actually stops the loss is a rule in your finance process: every change of payment details is verified by phone on a number you already hold, without exception, no matter how normal the email looks. Firms that apply that rule rigidly almost never lose money this way.
05Can you support partners working from home and client sites?
Yes, and it should be the default rather than a concession. Access tied to identity and device health means someone working from a client site gets the same experience and the same protection as someone at a desk. Where firms get into trouble is a halfway position, where remote access exists but nobody designed it, so people work around it.
06We are a small firm. Is this over-engineered for us?
It should be proportionate. A ten-person practice does not need what a hundred-person firm needs, but it does need the same foundations: multi-factor authentication everywhere, a tested backup, managed devices, and one place for client files. Those cost very little and they are the ones that matter. We will tell you what to skip.
Start before your busy season.
The worst time to discover a resilience gap is the fortnight everything is due. Tell us when your peak is and we will work backwards from it.
← All industries