Most IT problems are the same everywhere. A few are not — and the ones that are not tend to be the expensive ones, because they come with obligations that land on you rather than on your IT provider.

These are the sectors where we know the specific rules, the specific software and the specific times of year when nothing may be allowed to break.

Accounting and tax firms

The FTC Safeguards Rule treats tax preparers as financial institutions. IRS Publication 4557 sets out what safeguarding taxpayer data should look like, and PTIN renewal asks you to confirm you have a written security plan.

We build that plan with you, put the technical controls behind it, and schedule every disruptive change outside January through April.

Professional offices

Law firms, architecture and design studios, consultancies and small medical practices. Confidential work product, immovable deadlines, and — for design practices especially — files large enough that they should determine your entire infrastructure decision.

Home and personal

Not a business at all, but we do this too, and we keep it separate rather than pretending a household and a twelve-person firm need the same thing.

Everyone else

If your business is not on this list, that is not a problem — most of our work is ordinary offices that need their systems to work. The list exists because these sectors have requirements worth naming, not because we only serve them.

Massachusetts 201 CMR 17.00 applies far more broadly than most owners realise: any business holding personal information about a Massachusetts resident is covered, and if you have employees here, you already are. See cybersecurity.