0
          supporting North West businesses since April 2007
          0
          businesses supported across Greater Manchester and the North West
          0
          MTD submission windows a year now sit alongside the January deadline
          0
          offices, Manchester city centre and Oldham, with engineers on the road daily

          01

          Most businesses can absorb a bad IT week. An accountancy practice cannot absorb a bad January.

          Every business says its IT is critical. In a practice it is measurable. A file server that is slow in June costs you some patience. The same server slow on 29 January costs you filings, fee-earner hours you cannot bill and clients who watch you miss a statutory date on their behalf.

          That should change how the work is scheduled. Firmware updates, migrations, licence changes and hardware swaps belong in the quiet weeks. If your provider is proposing a server move in the third week of January, they are not thinking about your business.

          Work planned around the calendar

          We hold a copy of your filing calendar and schedule changes against it. Nothing disruptive lands in the fortnight before a deadline unless it is fixing something worse.

          Priority that reflects the date

          A printer fault in November is a printer fault. The same fault on the last Friday in January, when the practice is producing signed accounts, is not. Priorities move with the calendar.

          Capacity when you need it

          Peak weeks are when practices add temporary staff, extend hours and put more load on the same systems. That is a planning question, and it is easier answered in October than in January.

          Someone who knows the practice

          A named engineer who understands your software, your hosting arrangement and which partner needs what, rather than a call queue that starts from nothing every time.

          The day-to-day service behind this is described on our Managed IT Support page. Practices in the city centre can also use our IT Support Manchester team for onsite work.

          02

          What IT support for an accountancy practice should cover

          A useful agreement covers the user, the device, the identity, the practice software, the network and the recovery position together. It should also state plainly where our responsibility stops and where a software vendor, hosting provider or your professional body takes over.

          Helpdesk and escalation

          Outlook, Microsoft 365, devices, printing, access problems and daily faults, with a defined route from first-line triage to senior engineering.

          Onsite engineering

          Networks, servers, wireless, office moves, meeting rooms and the faults that cannot be fixed down a wire.

          Identity and access

          Microsoft Entra ID, multi-factor authentication, admin roles, and documented joiner, mover and leaver processes covering HMRC and software portals as well as email.

          HMRC agent account protection

          The controls around the accounts that reach every one of your clients' tax records. Covered properly in section 03.

          Practice and tax software

          The devices, hosting, Microsoft 365, network and integration requirements around your practice suite, with vendor coordination where the fault sits inside the product.

          Cyber security

          Endpoint protection, email security, patching, firewall management and support towards Cyber Essentials.

          Backup and recovery

          Agreed scope, retention matched to your statutory record-keeping period, isolated copies and restores that have actually been tested. See secure backup.

          Account management

          Open actions, recurring faults, renewals, budget and a roadmap the partners can read without translation.

          AI and Copilot controls

          Permissions, data boundaries and an approved-tool position before staff put client financial data into an AI tool. See AI Solutions.

          Connectivity

          Broadband, leased lines and resilience, which matter more once submissions are quarterly rather than annual. See connectivity.

          03

          Your agent services account is the most valuable thing on your network

          Not your accounts files. Not your email. The credentials that let you act for every client you hold. An attacker who reaches them can file returns, alter figures and redirect repayments across your entire client base from one login.

          HMRC has said openly that agent online service accounts and agent services accounts are a target for fraudsters, and that where it believes an account has been compromised it will act quickly, in some cases suspending the account without notice. A practice suspended in the run-up to a deadline cannot file for anyone.

          Two HMRC account models, with different permission controls

          In HMRC online services for agents, administrators can allocate clients and tax services to named users. In the Agent Services Account, HMRC's current guidance says the option to allocate clients and services is not available. Once a staff member is given direct access to the Agent Services Account, you cannot use that account to restrict them to an assigned client list.

          That makes the controls around the service unusually important: give each person their own sign-in, use HMRC multi-factor authentication, limit direct access to the people who need it, and remove access on the day someone leaves or changes role.

          Individual sign-ins and HMRC MFA

          HMRC recommends individual credentials for every member of staff. Shared logins remove accountability and make a compromised account much harder to contain.

          Protect recovery routes

          The email addresses, telephone numbers and authenticator methods used for recovery must belong to the practice, stay current and be removed when a member of staff leaves.

          Watch for remote-access tools

          A common route in is a phishing email that persuades someone to install genuine remote-support software. It is not malware, so it does not always trip antivirus. We alert on unexpected remote-access installs.

          Limit who holds access

          Review the list of staff with direct account access at least each quarter, and remove it the day someone changes role or leaves rather than at the next audit.

          Harden the devices

          The account is only as safe as the laptop it is opened on. Patching, encryption, endpoint protection and controlled admin rights on every device that signs in.

          Reconcile submissions

          If a return appears in your agent account with no matching receipt in your practice software, that is a signal worth acting on the same day.

          HMRC explains the permission difference in its guidance on giving staff access to online tax agent accounts. ICAEW also covers keeping HMRC agent account details safe. If you want the surrounding configuration tested rather than assumed, see our penetration testing service or start with the free cyber risk check.

          04

          Practice software problems usually sit between suppliers, not inside one

          A typical practice runs a tax and accounts suite, a bookkeeping platform, payroll software, a document portal, a receipt-capture tool and Microsoft 365, some hosted by the vendor and some on your own kit. When something breaks, each supplier can reasonably say the problem is somewhere else.

          We support the environment and chase the vendor

          For suites such as IRIS, CCH, Xero, Sage, QuickBooks, TaxCalc and BrightPay, we handle the devices, identities, Microsoft 365, network path, hosting connection, printing, browser requirements and integrations. Where the fault is genuinely inside the product, we open the vendor case and keep it moving rather than handing you a reference number.

          At onboarding we record, for each application: who owns it, the support contact, the licence position, how staff authenticate, what it integrates with, who backs it up and what the escalation route is. Most practices have never had that written down in one place.

          Hosted does not mean handled

          • If the suite is hosted by the vendor, confirm what they back up and for how long.
          • If it runs on your server, confirm it is in your backup scope and that a restore has been tested.
          • Either way, confirm who holds the administrator account. It should be the practice.
          IT-Support-for-Accountants
          One support route across practice software, Microsoft 365, hosting and the network underneath.

          Microsoft 365 configured for a practice

          • Shared mailboxes for tax, payroll and accounts with permissions that reflect who should see what.
          • SharePoint and Teams structured by client or department rather than one open library.
          • External sharing controlled, so client records are not sent as unmanaged attachments.
          • Retention and audit settings that match how long the practice keeps records.
          • Copilot readiness assessed against the permissions staff already hold, not assumed.

          05

          Making Tax Digital turns one annual peak into five

          Making Tax Digital for Income Tax started on 6 April 2026 for sole traders and landlords with qualifying income over £50,000. HMRC put more than 864,000 taxpayers in scope for the first year, and the first quarterly update is due by 7 August 2026. The threshold falls to £30,000 in April 2027 and £20,000 in April 2028.

          The tax return has not gone away. Quarterly updates sit on top of it. For a practice that means four additional submission windows a year, each with its own crunch, and a client base that is about to get considerably larger as the thresholds drop.

          The infrastructure question nobody asks until the week before

          Quarterly filing multiplies the number of times your staff need software to be responsive, your connection to be up and your authorisations to be in order. A hosted desktop that is merely tolerable in a normal week becomes the bottleneck when forty people are submitting at once.

          Worth checking before the next window rather than during it: connection capacity and whether there is a fallback, hosted-desktop performance under real concurrent load, device age across the team, licence coverage for temporary staff, and whether agent authorisations are actually in place for every client you expect to file for.

          Threshold Qualifying income above Mandated from
          Phase 1 £50,000 6 April 2026
          Phase 2 £30,000 6 April 2027
          Phase 3 £20,000 6 April 2028

          HMRC has confirmed there are no penalty points for late quarterly updates during the first year, which buys the profession one cycle of grace and no more. The habits and systems set now carry into a regime with real penalties.

          Details are on GOV.UK: find out if and when you need to use Making Tax Digital for Income Tax and the first quarterly update deadline.

          06

          Anti-money laundering duties put a pile of identity documents on your network

          Customer due diligence means collecting passports, driving licences, proof of address, ownership structures and source-of-funds evidence, then keeping it for as long as the regulations require. That obligation quietly turns every accountancy practice into a holder of exactly the material identity thieves want most.

          In a lot of practices those documents end up as email attachments, phone photographs and files in a general shared folder. That is a problem you can fix without changing a single AML procedure.

          One controlled locationIdentity evidence stored in a defined place with restricted access, not scattered across mailboxes and desktops.
          Collected securelyA secure upload route for clients, so passports are not arriving as unencrypted email attachments.
          Access on needThe staff who perform due diligence, not everyone who can open the shared drive.
          Retention that endsRecords kept for the required period and then actually removed. Indefinite retention is a growing liability, not caution.
          Logged accessA record of who opened what, so a question about a document has an answer.
          Secure disposalDeletion that covers backups, archives and any local copies, not just the visible file.

          Where the line sits

          Your AML obligations under the Money Laundering Regulations belong to the practice and its supervisor, whether that is HMRC or a professional body. We do not advise on compliance. We build and evidence the technical controls around the records, so that when a compliance visit asks how the material is protected, the answer exists in writing.

          The sector guidance is published by GOV.UK: accountancy sector guidance for money laundering supervision, alongside HMRC's risk assessment for accountancy service providers.

          07

          Microsoft 365 keeps the service running. It does not keep your records.

          Microsoft undertakes to keep the platform available. It does not undertake to hand back a mailbox a leaver deleted eight months ago, or a client folder someone overwrote in March. Retention policies help, but a policy is a setting, and settings can be changed by anyone holding the right admin role.

          A practice has to keep records for statutory periods measured in years. Backup retention should be set against that period deliberately, as a decision the partners have made, rather than left at whatever the software defaulted to.

          What needs protecting Typical approach What we actually check
          Exchange Online mailboxes Daily backup, retention matched to the practice's record-keeping period A single-item restore and a full mailbox restore, not a green tick on a dashboard
          SharePoint, OneDrive and Teams Versioned backup of libraries, channel files and permissions Whether permissions return with the data, which is where most restores disappoint
          Practice and tax software Scope agreed with the vendor, since it varies by product and hosting model Who holds the backup, where it sits, and how a restore is requested in practice
          Servers and local data A local copy for speed plus an offsite copy unreachable from the production network Recovery time measured against what the practice can tolerate in January

          An isolated copy is the part that matters

          Attackers look for the backup before they encrypt anything. A backup reachable with the same administrator credentials as the live environment is not a recovery position, it is a second target. Immutable or network-isolated copies with separate credentials are what turn a serious incident into a bad week.

          Test the restore in the quiet months

          The only meaningful test of a backup is a restore. We schedule those deliberately, in the parts of the year where the practice can afford the attention, and we write down how long it took. A recovery time nobody has measured is a guess.

          Scope, retention and restore testing are described further on our secure backup page.

          08

          Peak season adds people, hours and devices, usually at short notice

          Practices flex. Temporary staff arrive for the busy period, existing staff work late from home, and someone always needs access to a client's records from a kitchen table at nine in the evening. The security model has to handle that without either blocking the work or quietly opening the practice up.

          Seasonal joiners and leavers

          Temporary staff need accounts created quickly and removed the day they finish. The removal is the half that gets forgotten, and it is the half that matters.

          Conditional access

          Access granted on the strength of the account and the device rather than the network. Multi-factor passed, device known and encrypted, sign-in not obviously unreasonable.

          Personal devices

          A stated position on what may be done on an unmanaged laptop or phone, whether practice data can be stored locally, and how it is removed when someone goes.

          Licensing that flexes

          Short-term licences added for the season and removed afterwards, so the practice is not still paying in June for people who left in February.

          Printing at home

          Draft accounts and client correspondence printed on a domestic printer create a paper file nobody is tracking. Worth an explicit rule.

          Capacity under load

          Hosted desktops and connections behave differently with everyone on them at once. Better to find the ceiling in a test than in a submission window.

          09

          Partners should be able to see the IT position without asking for it

          Practices get asked to evidence their controls more than they used to. Professional indemnity renewals ask. Cyber insurance asks. Larger clients send security questionnaires before they instruct. A practice that has to chase its IT provider for answers each time is paying twice for the same information.

          Asset and licence register

          What you own, who uses it, how old it is, what it costs and when support ends. This is the document that makes a capital budget possible.

          Recurring faults, grouped

          Tickets grouped by cause rather than counted. Twelve tickets about one scanner is one problem, and it should be fixed rather than reported every month.

          Security position

          Multi-factor coverage, admin accounts, patch status, backup success and the date of the last tested restore, stated plainly enough for a partners' meeting.

          Questionnaire and renewal support

          When an insurer or a client sends a security questionnaire, we complete the technical sections with evidence rather than leaving the practice to guess at the answers.

          Renewal calendar

          Software, connectivity, hardware warranties and licences tracked so nothing auto-renews unnoticed at a price nobody agreed.

          Roadmap and budget

          What needs doing, what it costs, what the risk is of leaving it, and which financial year it belongs in.

          Logging turns a suspicion into an answer

          When a practice needs to establish whether a mailbox was read or a client file was copied, the answer depends entirely on what was being logged at the time and how long it was kept. Default retention in Microsoft 365 is shorter than most people assume. We set this at onboarding rather than discovering the gap mid-incident.

          Practices working towards Cyber Essentials find most of this reporting is already what the assessment asks for. The scheme covers five technical controls, is renewed annually, and starts at £320 plus VAT through the NCSC scheme.

          10

          Practices stay with a provider they have outgrown because the handover looks risky

          The risk is real, but it is rarely the cutover itself. It is discovering afterwards that the outgoing provider still holds the domain, that the Microsoft tenant was created under their account, that nobody has the practice software support contact, or that a backup everyone assumed was running stopped two years ago.

          We work through it in a fixed order and write down what we find, including the things we cannot get.

          01. Handover

          We request access, documentation and system ownership from the outgoing provider, and give the practice a date by which it knows what has and has not been supplied.

          02. Verify

          We confirm the practice owns its Microsoft tenant, domains, DNS, backups, licences and software accounts. Ownership sitting in a provider's name is the most common problem we find.

          03. Stabilise

          Support routes go live, urgent faults are cleared and monitoring is deployed before the previous provider steps back, not after.

          04. Improve

          We produce the first roadmap, so the change leaves the practice in a better position rather than with a different number to ring.

          We will not move a practice in January

          Transitions belong in the quiet part of the year. If you are unhappy with your current provider in the middle of a filing peak, the right answer is usually to start the groundwork now and cut over once the deadline has passed. Any provider that offers to migrate you next week during peak season is selling, not planning.

          What the practice should own at the end

          • The Microsoft 365 tenant, in the practice's name, with the practice holding a global administrator account.
          • The domain registration and DNS control.
          • Direct contracts with the practice software and hosting vendors.
          • Backups the practice can have restored on request, with retention it has agreed.
          • Documentation good enough for a third provider to pick up if the practice ever leaves us.

          The same principle runs through our Managed IT Support service. We also support neighbouring professions, including solicitors and law firms and insolvency practitioners.

          11

          Book a practice IT review

          A working session, not a sales call. We look at how the practice is actually set up and tell you what we find, including the parts that are fine.

          • Who holds HMRC agent account access, and what protects the mailbox behind it.
          • Microsoft 365 configuration, admin roles, multi-factor coverage and external sharing.
          • Backup scope, retention against your record-keeping period, and whether a restore has been tested.
          • Practice software hosting, performance under load and who owns the contracts.
          • Where client identity documents are stored and who can reach them.

          You get a written summary of the gaps, ranked by risk, with an honest note on which ones cost money and which are a configuration change.

          Book a practice IT review

          Or call 0330 66 00 281 and ask for the business team. If you would rather start anonymously, our free cyber risk check takes a few minutes.

          12

          IT support for accountants: FAQs

          What IT support does an accountancy practice need?+
          Most practices need helpdesk support, Microsoft 365 administration, identity and access controls including protection of HMRC agent accounts, support for practice and tax software, endpoint and email security, backup and recovery, network management and a clear escalation route during peak filing periods.
          Can you help protect our HMRC agent services account?+
          Yes. We can help establish individual sign-ins, prepare users for HMRC multi-factor authentication, restrict direct Agent Services Account access to the people who need it, protect account recovery routes and the devices used to sign in, and monitor for suspicious mailbox rules and remote-access tools. Account controls within HMRC's own service remain subject to HMRC.
          Do you support practice software such as IRIS, Xero, Sage or CCH?+
          We support the environment those applications depend on: devices, Microsoft 365, identity, network, hosting, printing and integration. Where a fault sits inside the application we work with the vendor and keep the case moving. Exact responsibilities are recorded during onboarding.
          Will our systems cope with Making Tax Digital quarterly updates?+
          MTD for Income Tax replaces one January peak with four submission periods a year. We review connectivity, hosting performance, device capacity, licence coverage and the agent authorisation setup so the practice is not discovering a bottleneck a week before a quarterly deadline.
          Does IT support help with our anti-money laundering obligations?+
          It supports them. AML compliance is the practice's responsibility. We can implement and evidence the technical side, including controlled storage of client identity documents, access restrictions, encryption, retention, logging and secure disposal, so the practice can show how the records are protected.
          How quickly do you respond during self assessment season?+
          Support priorities are agreed in advance so that anything blocking a filing deadline is treated as business critical. We plan changes, updates and project work around January and the quarterly MTD dates rather than into them.
          Is Microsoft 365 enough of a backup for client records?+
          No. Microsoft keeps the service available but does not undertake to restore data a user or administrator deleted months earlier. Practices holding records for statutory retention periods need a separate backup with retention set to match, plus tested restores.
          Can you take over from our current IT provider?+
          Yes. We document the environment, confirm the practice owns its Microsoft tenant, domains and backups, review software contracts and hosting, transfer monitoring and security tools, and keep a written register of anything the outgoing provider does not hand over. We avoid moving during peak filing periods.

          IT Support Manchester - Remedian IT Services

          IT Support Manchester

          Click below to view our services:

          Testimonials

          As a long-term client of Remedian, Ashworth Electrical Services have nothing but the highest praise for their assistance in managing our IT systems.
          The service Remedian provide is professional and efficient. The staff are always helpful and friendly.
          Remedian have been our IT support providers now for almost 6 years. During that time they have demonstrated a high level of customer service and value for money support and IT equipment.
          Remedian have helped us grow into the company we are today. The standard of service and expertise Remedian provide us with is second to none, whether it is remote helpdesk support or onsite maintenance.
          The Remedian team have provided weekly on-site technician services and have also provided strategic direction in relation to the Trust's infrastructure which has been invaluable. When issues arise the Remedian team are fast to respond and are proactive in recommending solutions to mitigate any potential issues.