Resources
Helpful information to keep you informed, prepared, and protected.
What is a WISP?
A Written Information Security Plan (WISP) is more than a document; it is a comprehensive, formal strategy that dictates how your organization safeguards sensitive taxpayer data. Mandated by the FTC Safeguards Rule, a WISP serves as your firm’s primary defense against data breaches and is the first document requested during an IRS or FTC audit.
Core Components of an Effective WISP
Designated Security Program Coordinator
Identifying the specific individual responsible for overseeing and implementing your security protocols.
Internal & External Risk Assessment
A deep-dive analysis into where your data lives, who has access, and where your vulnerabilities exist—from your local network to the cloud.
Technical Safeguards & Encryption
Defining the specific encryption standards used to protect data “at rest” on your servers and “in transit” during client communications.
Incident Response & Disaster Recovery
A step-by-step roadmap for your team to follow in the event of a security event, ensuring rapid mitigation and minimal downtime.
Service Provider Oversight
Documenting the security standards required for your third-party vendors (like software providers and cloud hosts) to ensure they meet your compliance levels.
Why This Matters for Your Firm
Legal Mandate: Under IRS Publication 4557 and the FTC Safeguards Rule, failing to maintain an active WISP can lead to significant fines and the revocation of your e-file privileges.
Audit Readiness: If the IRS requests proof of compliance, a vague plan isn’t enough. A professional WISP proves you have implemented the “Technical Integrity” required to protect sensitive data.
Client Trust: Your reputation is your most valuable asset. A WISP demonstrates to your clients that you treat their financial privacy with enterprise-grade seriousness.
The Hidden Cost of Non-Compliance
Our Partners
Stay connected for the latest cybersecurity trends and regulatory shifts.