AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

The WISP a CPA Firm Can Write in a Week, Before the January Rush Starts

A CPA WISP for tax season: what the FTC Safeguards Rule and IRS Publication 4557 expect, the Security Six, and the PTIN attestation you already signed.

Sam KhanSam Khan The Cyber ExpertFounder and CEODecember 21, 2026 · 6 min read

The screen that asks a question nobody prepared for

The managing partner of a nine-person CPA firm in Newton sits down on the Monday before Christmas to renew her PTIN. Twenty-two seasons behind her. Three CPAs, two enrolled agents, four seasonal preparers who come back every January, and about 1,400 individual returns plus 90 business clients.

The renewal screen asks her to confirm she is aware of her obligation to have a written data security plan. She clicks through it, the way she has before, and then stops. Because two weeks earlier a new client's controller asked her for a copy of the firm's WISP before sending over the payroll files, and she sent back a friendly note saying she would dig it out.

She has not dug it out. There is a Word document from 2019 that a former office manager downloaded from somewhere, with another firm's name still in the header on page four. It names a person who left in 2022.

Meanwhile the seasonal preparers arrive on 5 January. Two of them use their own laptops. The client portal password is written on a card in the front desk drawer, because clients call and cannot find their login and somebody has to help.

None of this has ever caused a problem. She has fifteen working days before it becomes somebody else's decision.

What the heck does this mean

A WISP is a written information security plan. It is the document that says what client data you hold, where it lives, who protects it, how, and what you do the day something goes wrong. IRS Publication 5708 exists specifically to help a small practice write one, and Publication 4557 is the underlying guidance on safeguarding taxpayer data.

The FTC Safeguards Rule is the federal regulation that makes it enforceable. Tax preparers and CPAs count as financial institutions under the rule, which surprises most of them. The rule wants a written program, a named qualified individual who runs it, multi-factor authentication, encryption, oversight of your vendors, and notice to the FTC within 30 days of discovering a breach affecting 500 or more consumers. There is no small-business exemption.

The qualified individual is one named person who owns the program. It can be the managing partner. It cannot be "IT".

The Security Six is the IRS shorthand for the basics: anti-virus, firewalls, multi-factor authentication, backup, drive encryption, and a VPN for remote work.

The numbers that matter

Business email compromise cost US victims USD 3.05 billion across 24,768 complaints in 2025, according to the FBI IC3 2025 Internet Crime Report. A firm that emails K-1s and wire instructions in February is standing exactly where that money went.

The human element was present in 62 percent of breaches in the Verizon 2026 Data Breach Investigations Report. Not stupidity. A seasonal preparer at 9pm on 12 April, moving fast, doing what the email asked.

Ransomware appeared in 88 percent of breaches at small and medium businesses in the Verizon 2026 report. A tax practice locked out for six days in March does not get those six days back.

What to do this week

  1. Write the data map first, on one page: the tax software database, the document management system, the client portal, email attachments, the scanner folder, the seasonal preparers' laptops, and the paper in the fireproof cabinet. Everything after this is easier once the map exists. (CIS 3 Data Protection)
  2. Name the qualified individual in a signed, dated sentence, and name a backup for the weeks she is in appointments twelve hours a day. If the technical work is outsourced, the inside owner is still inside. (CIS 6 Access Control Management)
  3. Turn on multi-factor authentication for the tax software, email, the client portal admin and the remote access, and end shared logins before 5 January. Burn the card in the front desk drawer. (CIS 6 Access Control Management)
  4. Decide the rule for seasonal staff on personal laptops: firm-issued machine, or a locked-down remote session where nothing is stored locally. Encrypt every drive that leaves the office. Massachusetts 201 CMR 17.00 requires that encryption for any firm holding data on a state resident. (CIS 3 Data Protection)
  5. List every vendor that touches client data: the tax software host, the portal, the payroll provider, the shredding company, the IT firm, the backup service. Get each one's security commitment in writing, with a renewal date, and record who reviewed it. (CIS 15 Service Provider Management)
  6. Train the whole team for twenty minutes on one scenario, the changed wire instruction, and write the callback rule into the WISP: verify by phone on a number you already had, never a number in the email. (CIS 14 Security Awareness and Skills Training)

Where AccuSights fits

We write WISPs for accounting firms in plain English, sized to the practice, with the FTC Safeguards Rule and Publication 4557 requirements traced to the pages that satisfy them. Our team then implements the controls at a reasonable rate: multi-factor authentication, drive encryption, data loss prevention that stops a K-1 leaving to the wrong address, scanning and protection for the machines that hold the returns. See what that looks like on our accounting industry page, or the local view for Boston-area firms. Take the three-minute Cyber Hygiene Test, then spend 15 minutes with an engineer before the season starts.

Questions people ask

Does a sole practitioner need a WISP? Yes. IRS Publication 4557 expects a written information security plan from every tax professional, and the FTC Safeguards Rule has no small-business exemption. A firm holding data on fewer than 5,000 consumers is relieved of a few written-document requirements, not of the safeguards. One preparer at a kitchen table with 300 returns is covered exactly like a 40-person firm.

What is the Security Six? It is the short list of basic protections in IRS Publication 4557: anti-virus software, firewalls, multi-factor authentication, backup software or services, drive encryption, and a virtual private network for anyone working outside the office. It is the floor, not the plan. The WISP is the document that says who owns each of the six, how you check them, and what happens when one fails.

Do Massachusetts rules add anything on top of the federal requirements? They do, for any firm holding personal information about a Massachusetts resident, wherever the firm sits. Massachusetts 201 CMR 17.00 requires a written information security program of its own, with encryption of personal information sent across public networks and stored on laptops and portable devices. A Boston-area CPA firm can satisfy the state and the FTC with one document, provided the encryption language is in it.

You already attested to having the plan. Spend one quiet week in December making the attestation true, and April becomes a busy month instead of a bad one.

Controls this post maps to

CIS 3 Data ProtectionCIS 6 Access Control ManagementCIS 15 Service Provider Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.