AccuSights
PartnersBlogAbout
Book my 30-minute demo

Accounting & Tax Firms · Cybersecurity, compliance and GRC, in plain English

A WISP is the law. We build it, run it and keep it true.

Every paid preparer attests to a written information security plan at PTIN renewal, and the FTC treats CPA and tax firms as financial institutions. We deliver the WISP, implement the Security Six, and watch client and tax data 24/7 through the season.

WISP delivered, not templatedIRS Security Six implementedPublic pricing

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

March, the client list and the refund that almost went to the wrong account

the owner of a nine-person CPA firm

It is the second week of March and Karen’s firm on Ogden Avenue is doing what it does every March: 1,400 returns, nine people, coffee that never gets cold because nobody sits long enough. The client list is the firm. Twenty-two years of it.

A client emails to change the bank account for her refund, ‘we switched banks after the fraud thing.’ It is a good reason. The email is from her real address. The preparer updates the direct-deposit line and moves to the next return, because it is March.

In the version the IRS Stakeholder Liaison hears every spring, the refund lands in an account the client has never seen, six more clients ‘switch banks’ the same week, and somewhere a copy of the client list with Social Security numbers is being used to file returns before the real ones arrive. The FTC letter about the WISP comes in June.

In Karen’s version, any bank change is confirmed by phone on the number in the file, and the preparer makes the call before the return goes. The client has not switched banks; her mailbox was compromised in February. The engineer on watch checks the firm’s own mailboxes the same hour. Clean. The WISP, running in practice, logs its first incident. Karen files 1,400 returns.

The preparer updates the direct-deposit line and moves to the next return, because it is March.

What changes the ending

  1. Phone confirmation of any bank or refund change, written into the preparer checklist (CIS Control 14, Security Awareness and Skills Training)
  2. MFA on every mailbox and the tax software, with remote-access and tax applications patched through the season (CIS Controls 5, 6 and 7)
  3. A WISP that runs in practice, with the client list encrypted, access-limited and backed up offline (CIS Controls 3 and 11, and the FTC Safeguards Rule)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

A client’s own email asked us to change her refund account. How were we supposed to know?

From a rule, not from the email: any bank or refund change gets a phone call to the client on the number in the file before the return goes. The IRS asks preparers to do exactly that, and the assessment tests whether the rule exists in the checklist and in practice.

What if a preparer leaves in April with the client list?

The client list is the firm, so access to it is scoped by role, exports are logged, and accounts are disabled the hour notice is given. The same controls satisfy the FTC Safeguards Rule’s access requirements and give your non-solicitation clause its evidence.

We signed the WISP attestation at PTIN renewal. Is that not enough?

The attestation says the program exists; the FTC rule requires it to run: a qualified individual, a risk assessment, MFA, encryption, vendor oversight and an incident plan in operation. A signed template with nothing behind it is read as no program at all, which is the finding we close first.

What you hold, and why someone wants it

Your data protection needs, by the data.

Client tax files and Social Security numbers

Everything needed to file a fraudulent return in a client’s name before the real one arrives. Encryption, access limits and MFA protect them, and the FTC Safeguards Rule requires it.

Refund and payment instructions

The bank line on the return is the target of the March diversion. Phone confirmation and mailbox monitoring protect it.

The client list

Twenty-two years of relationships in one export. Role-based access, export logging and offboarding rules protect it.

Tax and remote-access software

The classic entry point when left unpatched through the busiest weeks. Patch management and monitoring protect it.

Firm mailboxes

Where the fake client, the fake IRS notice and the fake partner request arrive. MFA, forwarding-rule alerts and login monitoring protect them.

$3.05B
lost to business email compromise in 2025; refund and payment diversion in tax season is the accounting variant
Source: FBI IC3 2025 Internet Crime Report
31%
of breaches begin with an exploited vulnerability; unpatched tax and remote-access software is the classic entry
Source: Verizon 2026 Data Breach Investigations Report
69%
of ransomware victims refused to pay, because tested backups turn a crisis into a bad day
Source: Verizon 2026 Data Breach Investigations Report

What applies to you

The rules, in one page, with the dates that matter.

FTC Safeguards Rule (GLBA)
Federal Trade Commission
Written information security program, qualified individual, risk assessment, MFA, encryption, vendor oversight and an incident response plan; FTC notice within 30 days for events affecting 500 or more consumers.
Civil penalties are inflation-adjusted annually and exceed $50,000 per violation per day in 2026.
IRS Publication 4557 and Publication 5708
Internal Revenue Service
A WISP for every paid preparer, the Security Six (antivirus, firewall, MFA, backup, drive encryption, VPN), and data-theft reporting to the IRS Stakeholder Liaison.
State WISP and breach laws
State regulators
Massachusetts 201 CMR 17.00 and others require a WISP independently; all states require breach notification.
PCI DSS v4.0.1
PCI SSC
If clients pay by card, the standard applies in full.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • Refund fraud and client-impersonation emails timed to filing deadlines.
  • Remote-access and tax software left unpatched through the busiest weeks of the year.
  • A WISP template signed at PTIN renewal that nobody has implemented, which the FTC reads as no program at all.

Firms that start before January have a running WISP and the Security Six in place before the first return is filed.

It happened to businesses like yours

EY disclosed in 2026 that attackers were inside a third-party IT support platform used for its tax services from March 28 to April 12, 2026 and downloaded client tax documents; clients were notified about 81 days later.

March to April 2026 · Cybernews

PwC and EY confirmed in June 2023 that client data was exposed through the MOVEit file-transfer vulnerability exploited by the Clop gang, part of a campaign that hit more than 100 organizations.

June 2023 · Cybersecurity Dive

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a accounting business

We protect your people, every device, the servers and the website. Day and night.

  • We protect every preparer, partner and admin inbox, where the fake client and the fake IRS notice arrive.
  • Every laptop and workstation, in the office and at the preparer’s kitchen table in March.
  • The server and the file share holding client files and prior-year returns.
  • The website and the client portal, including document uploads and e-signature.
  • The cloud apps: tax software, practice management, accounting, email and remote access.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Accounting and Tax Firms

Built on the CIS Controls v8.1 IG1 and mapped to the FTC Safeguards Rule and IRS Publication 4557, scoped from what a firm stands to lose: the client list, the refunds and the license to prepare. The output is a WISP that runs, the Security Six set up, and a plan the owner can read before the season starts.

  • Inventory of every device, cloud app and remote-access path, including preparers’ home setups (CIS Controls 1 and 2)
  • Refund and bank-change workflow test with the phone-confirmation rule written into the preparer checklist (CIS Controls 14 and 17)
  • Mailbox security review: MFA, forwarding rules, legacy protocols, sign-in logs (CIS Controls 5, 6 and 9)
  • Security Six set up and verified: antivirus, firewall, MFA, backup, drive encryption, VPN (CIS Controls 3, 10, 11 and 12)
  • Tax and remote-access software patch status against the CISA Known Exploited Vulnerabilities list (CIS Control 7)
  • WISP drafted and implemented to the FTC rule, with the risk assessment and a ranked remediation plan
Start with the 3-minute test

Packages

Built for accounting businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

Mock Audit Package: SOC 2, HIPAA or CMMC

We run your audit before your auditor does: the same evidence requests, the same interviews, the same sampling, the same findings language.

Fixed feescoped in 30 minutes
1 to 3 weeks depending on framework and scope
Details →

SOC 2 Readiness: Type 1 and Type 2

Enterprise and government buyers ask for SOC 2 before they sign.

Fixed feescoped in 30 minutes
Type 1 readiness: 4 to 8 weeks
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

Is a WISP template enough?
The IRS template (Publication 5708) is a starting point, but the FTC rule requires the program to exist in practice: a qualified individual, a risk assessment, MFA, encryption and vendor oversight actually running. We deliver the document and implement the controls behind it.
How long does a WISP engagement take?
Two to three weeks for a small or mid-size firm: assessment, WISP drafting, Security Six implementation and staff training, then the 24/7 watch continues through the season.

People also search: WISP for tax preparers near me · cybersecurity for CPA firms in Chicago · for a nine-person accounting firm · for a solo enrolled agent · FTC Safeguards compliance help in the suburbs · cybersecurity for a bookkeeping firm · for a tax practice with two offices · accounting firm cybersecurity in the Midwest

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test