Understand the environment
Map systems, information flows, service providers, staffing, and responsibilities.
WISP development and review
Your written security plan should describe how your firm actually protects taxpayer data. Build or update a WISP around your systems, people, vendors, and responsibilities, then identify where documented safeguards are supported by evidence—and where work remains.
Start with the requirement
Covered firms need a written information security program appropriate to their operations and the sensitivity of the information they handle. The FTC Safeguards Rule identifies tax preparation firms among covered financial institutions, while coverage and specific obligations depend on the firm's activities and applicable jurisdiction.
We provide cybersecurity consulting, not legal advice. The IRS provides free WISP guidance, including Publication 5708 and Publication 4557. Review the official sources and involve qualified counsel where needed.
A plan should reflect actual practices. Buying or completing a document does not establish compliance or make an unimplemented safeguard real.
The IRS resource is useful. Paid assistance can make the plan specific to the way your firm works and make the gap between written safeguards and implemented safeguards visible.
Map systems, information flows, service providers, staffing, and responsibilities.
Tailor procedures, incident responsibilities, vendor oversight, and review triggers to actual operations.
Record gaps honestly and give leadership and the IT provider practical, ordered next steps.
A scoped engagement
Inclusions are agreed before work begins. We distinguish planned safeguards from safeguards that are implemented and verified.
A document-only engagement does not include technical verification. We can scope evidence review separately.
The process
Review the firm, existing plan, current practices, and goals.
Confirm scope, evidence, fixed price, deliverables, and schedule before work begins.
Assess documentation and agreed technical evidence, then develop or revise the plan.
Identify implementation gaps, responsibilities, and treatment actions.
Walk leadership through the agreed deliverables and maintenance triggers.
Timing depends on scope and evidence readiness. No guaranteed turnaround is implied.
Subject to the agreed scope, deliverables can include:
Your team or IT provider can implement needed changes, or we can discuss a separate, defined remediation engagement. See the Business Security Baseline for essential-control verification.
Pricing depends on firm complexity, existing documentation, requested verification, and deliverables. The WISP service is quoted after scoping; the Business Security Baseline remains a separate fixed-scope offer.
Discuss My WISPYes. Publication 5708 is a free starting resource. Tailored assistance can help adapt it to your actual systems, responsibilities, vendors, and evidence; professional assistance is not mandatory.
Yes. We can compare an existing plan with your current operations and agreed evidence, identify stale or unsupported safeguards, and recommend focused updates.
No. A document does not make safeguards operational. We distinguish planned, implemented, and verified safeguards and do not provide a legal compliance opinion or guarantee regulator acceptance.
Coverage depends on the firm's activities and applicable jurisdiction. The FTC's exception for institutions maintaining information about fewer than 5,000 consumers applies to certain provisions, not as a blanket exemption from the Safeguards Rule. Confirm your situation with qualified counsel.
Review it when systems, vendors, staffing, remote-work practices, risks, or responsibilities materially change, and on a periodic schedule appropriate to your operations. There is no universal annual filing requirement described here.
Only when included in the agreed scope. A document-only engagement is not technical verification; the Business Security Baseline or a separately scoped review can address agreed evidence.
Yes. We can clarify responsibilities, request agreed evidence, and provide prioritized implementation actions for your team or IT provider. We do not replace ongoing managed IT.
Share your firm size, whether a plan already exists, your general technology environment, goals or deadline, and any known changes. Do not send taxpayer records, credentials, or other sensitive data for initial scoping.
See also cybersecurity for accounting and tax firms and the Business Security Baseline.