
If your firm prepares tax returns or handles client financial records, a Written Information Security Plan, or WISP, is not optional. Federal law requires it, and the IRS now ties it directly to renewing your preparer credentials. Small firms are squarely in scope, and attackers know these offices hold Social Security numbers, bank details, and full financial histories. In Verizon's 2025 Data Breach Investigations Report, ransomware or extortion appeared in 88% of small-business breaches, versus 39% at large organizations. Here are the questions accounting and tax firm owners ask us most, answered plainly.
What is a WISP?
A Written Information Security Plan is a documented set of safeguards describing how your firm protects client data: who is responsible, what the risks are, and the specific controls you use to reduce them. It is a living document you maintain and follow, not a one-time form you file and forget about.
Is a WISP actually required, or just recommended?
Required. Under the Gramm-Leach-Bliley Act, tax and accounting firms count as financial institutions, so the FTC Safeguards Rule obligates them to maintain a written security program. The IRS reinforces it: when you renew your PTIN on Form W-12, Question 11 asks you to confirm a WISP is in place. IRS Publications 4557 and 5708 spell out the details.
Who has to have one?
Any firm that handles taxpayer or customer financial information. That covers tax preparers, CPAs, enrolled agents, and bookkeepers, whether you are a solo practitioner or a multi-office firm. Size does not exempt you. A single-preparer shop is as much a financial institution under the rule as a large practice is.
What must a WISP include?
The core elements are a designated security coordinator, a written risk assessment, access controls, encryption of data at rest and in transit, multifactor authentication, staff training, vendor oversight, and an incident response plan. The Safeguards Rule also calls for regular testing of your defenses. The plan should reflect what your firm actually does, not a generic checklist.
What happens if we do not have one?
The exposure is real. The FTC can pursue enforcement, your PTIN renewal is in jeopardy, and falsely certifying that you have a WISP when you do not can carry serious consequences. A cyber insurer may also deny a claim if you cannot show a plan was in place. And that is before the cost of the breach itself, which for a small firm can be existential.
Is a downloadable template enough?
A template is a starting point, not the finish line. The IRS offers a WISP template in Publication 5708, and it is genuinely useful. But an unedited document that does not match your systems, staff, and vendors will not hold up in an audit or after an incident. You have to tailor it, implement the controls it describes, and keep it current.
Do we specifically need MFA and encryption?
Yes. The 2023 update to the Safeguards Rule made multifactor authentication and encryption explicit requirements, not suggestions. Every login that touches client data should require MFA, and client files should be encrypted on your devices and whenever they move. Those two controls alone stop a large share of common attacks.
How does a managed IT provider help?
A provider can implement and document most of the plan for you: MFA, encryption, access controls, monitoring, backups, an incident response plan, annual staff training, and the vendor records auditors ask for. Just as important, they keep it current as rules and threats change. Our managed IT and security services are built for exactly this, and our overview of the controls that actually stop attacks shows where to start. If the worst happens, an incident response plan is what limits the damage.
By The NetSys Group Team. The NetSys Group has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Need a WISP that would actually pass review? Schedule a complimentary assessment and we will map your firm's controls against the Safeguards Rule and close the gaps.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



