For accounting & tax professionals

A Written Information Security Plan, built for your firm.

If your practice prepares tax returns or handles taxpayer data, a WISP isn't optional. It's expected under the FTC Safeguards Rule and IRS guidance. We create yours from scratch: practical, documented, and ready to show a reviewer. No templates you have to decipher alone.

What is a WISP?

The written plan that proves you protect client data

A Written Information Security Plan (WISP) is a formal document describing how your firm safeguards the sensitive information it collects: client names, Social Security numbers, financial records, and more. It sets out your security policies, who's responsible, the safeguards you use, and how you respond if something goes wrong.

More than paperwork, it's a working framework that reduces your real-world risk of a breach, and demonstrates due diligence if you're ever asked to show it.

The IRS references a WISP in Publication 4557 (Safeguarding Taxpayer Data) and provides a template in Publication 5708. We use these as our starting point, then tailor everything to your practice.
Why it matters

It's a requirement, and a real safeguard

  • Legal expectation. The FTC Safeguards Rule (under the Gramm-Leach-Bliley Act) requires financial institutions, a category that includes many tax and accounting professionals, to maintain a written information security program.
  • IRS expectation. Paid preparers are expected to have a data security plan, and the IRS asks preparers to confirm awareness of this responsibility.
  • Client trust. A breach can mean lost clients, reputational damage, and costly recovery. A WISP is the backbone of preventing one.
  • Peace of mind. Know exactly what to do before, during, and after an incident.
Who needs a WISP

If you handle taxpayer data, this means you

Firm size doesn't matter. A solo preparer has the same obligation as a large practice, and often less time to figure it out.

CPAs & accounting firms

Tax preparers & EAs

Bookkeepers

Financial & advisory offices

Our WISP service

Everything you need, done with you, not dumped on you

We don't just hand over a document. We assess your practice, build the plan around it, and make sure your team can actually follow it.

  • Security risk assessmentIdentify where sensitive data lives and where you're exposed.
  • Custom written planA complete WISP tailored to your firm, not a fill-in-the-blank template.
  • Safeguards mappingAdministrative, technical & physical controls aligned to the Safeguards Rule.
  • Designated point personHelp naming and equipping the individual responsible for your program.
  • Staff trainingPractical guidance so your whole team knows their role in protecting data.
  • Incident response planA clear, written playbook for what to do if data is compromised.
  • Vendor oversight guidanceKnow what to expect from the service providers who touch your data.
  • Annual review & updatesKeep your plan current as your firm and the threat landscape change.
How it works

WISP-ready in four straightforward steps

1

Discovery call

A free conversation about your practice, your systems, and your timeline.

2

Assessment

We review how you collect, store, and share sensitive data and flag the gaps.

3

Build & document

We write your WISP and put the recommended safeguards in place with you.

4

Train & maintain

We train your team and check in to keep the plan current year over year.

Questions

WISP questions, answered

Am I really required to have a WISP?

If your firm is considered a "financial institution" under the FTC Safeguards Rule (which includes many tax preparers, accountants, and similar professionals who handle customer financial information), you are expected to maintain a written information security program. The IRS also directs paid preparers to have a data security plan. Requirements vary by firm, so we'll help you confirm what applies to your specific practice.

Can't I just download the IRS template and fill it in?

You can, and the IRS template (Publication 5708) is a solid foundation. But a WISP is only useful if it reflects how your firm actually operates and if your team follows it. We start from the recognized frameworks, then tailor the plan to your systems, staff, and risks, and make sure it's genuinely usable rather than a document that sits in a drawer.

How long does it take?

For most small firms, we can complete an assessment and a tailored WISP within a few weeks, depending on your availability and how your systems are set up. If you're facing a deadline, tell us and we'll work to it.

What does it cost?

Pricing depends on the size of your firm and the state of your current systems. The initial scoping conversation is always free, and you'll get clear, honest pricing before any work begins, with no surprises.

Do you also fix the security gaps you find?

Yes. Beyond the written plan, we can implement the safeguards it calls for (multi-factor authentication, encryption, backups, secure email, and more) through our broader cybersecurity and IT services. You can do it all with us or take the plan and implement at your own pace.

Free resource

Want to see where you stand first? Grab the checklist.

Our free WISP Readiness Checklist walks through what the FTC Safeguards Rule and IRS guidance expect from a practice like yours, in plain English, in about ten minutes.

We'll send occasional practical security tips for firms like yours. Unsubscribe anytime; we never share your email.

Get started

Let's get your firm WISP-ready.

Tell us a little about your practice and your timeline. We'll schedule a free scoping call and lay out exactly what it takes to get compliant.

Based in Southern California · serving firms nationwide.

We'll respond within one business day. Your information stays private.