Introduction Tax and accounting firms handle some of the most sensitive information belonging to their clients, including Social Security numbers, financial records, bank information, tax documents, and other personal data. Because of this, having a proper Written Information Security Plan (WISP) is an important part of maintaining a strong security and compliance program. A WISP explains how a firm protects client information, manages technology, controls access, responds to security incidents, and reviews its safeguards. For CPA firms and tax professionals, understanding the requirements can help prevent security gaps and improve overall data protection. What Is a WISP? A Written Information Security Plan is a documented security program that describes how an organization protects sensitive information. A useful WISP should reflect the firm’s actual technology environment and business processes rather than relying entirely on generic wording. It can cover areas such as: Data and technology inventory User access controls Multi-factor authentication Encryption Employee security training Vendor management Incident response Risk assessments Backup and recovery Annual security reviews For accounting and tax practices, these areas are especially important because employees regularly access confidential financial and taxpayer information. Why CPA Firms Need a WISP A WISP is more than an IT document. It provides a structured way for a firm to identify security risks and document the safeguards being used to address them. IRS guidance and the FTC Safeguards Rule are important considerations for firms handling taxpayer and financial information. The TechFiscal WISP guide notes that a security program should include documented safeguards, responsible personnel, risk assessment procedures, employee training, vendor oversight, and periodic review. Having documentation also makes it easier for a firm to understand what security measures are currently implemented and where improvements may be necessary. Important Components of a WISP Identify Your Technology Start by documenting the systems and devices that handle sensitive information. This may include: Computers and laptops Tax preparation software Email accounts Cloud storage Servers Mobile devices Backup systems Remote-access tools Creating an inventory gives the firm a clearer picture of where important information exists. Perform a Risk Assessment A risk assessment helps identify realistic threats to the business. For example, a CPA firm might consider: Phishing attacks Stolen or lost laptops Weak passwords Unauthorized account access Malware and ransomware Cloud-service compromise Third-party vendor risks Employee mistakes The goal is not simply to list threats. The firm should determine which risks are most relevant and what controls can reduce them. Control Access Not every employee needs access to every system or client record. Firms can use role-based access, strong passwords, multi-factor authentication, and account-management procedures to reduce unnecessary exposure. When an employee leaves the organization, access should also be removed promptly. Protect Data Sensitive information should be protected both while it is stored and when it is transmitted. Encryption, secure connections, endpoint protection, reliable backups, and appropriate access controls can all contribute to a stronger security environment. Manage Vendors Modern accounting firms often depend on external providers for tax software, cloud platforms, IT services, email, storage, and other technology. A WISP should therefore consider third-party security. Firms should understand what information vendors can access and what security protections those vendors provide. Prepare for Incidents Even strong security programs cannot guarantee that an incident will never occur. A written incident response procedure can help employees understand what to do when something goes wrong. The plan should identify: Who is responsible for responding How incidents are reported internally Which systems should be isolated Who should be contacted How evidence should be preserved What notification requirements may apply Having these details documented before an incident occurs can reduce confusion during an emergency. Annual WISP Reviews Matter A security plan should not be treated as a document that is created once and forgotten. Technology changes. Employees change. Vendors change. Firms may move applications to the cloud or introduce new remote-work systems. These changes can create new risks. Regular reviews help ensure that the WISP continues to describe the firm’s actual environment. For a small practice, the review process may be relatively straightforward. Larger firms may need a more detailed assessment involving multiple systems, departments, and locations. Common WISP Mistakes One common mistake is downloading a template and leaving the information unchanged. A template can be a useful starting point, but generic language may not accurately describe the firm’s technology or security practices. TechFiscal similarly emphasizes that a WISP should reflect the specific environment, staffing, and workflows of the practice. Other common problems include: No documented risk assessment Outdated employee information Missing vendor details No clear incident-response contacts Weak access-control procedures Failure to document employee training Not reviewing the plan regularly The purpose of a WISP is to document real security practices, not simply to have a document saved on a computer. WISP for Small and Solo Tax Practices Smaller firms sometimes assume that security requirements are mainly intended for large accounting organizations. However, the size of a business does not eliminate the importance of protecting client information. A solo tax professional may have fewer employees and fewer systems, but the information handled can still be highly sensitive. A small firm’s WISP can be appropriately scaled to its environment. It might cover a limited number of computers, a cloud tax platform, email, backup services, and a small number of employees. The important point is that the plan should accurately describe how information is handled and protected. Building a WISP Step by Step A practical approach can be divided into five stages: Step 1: Inventory Identify systems, applications, devices, data, and vendors. Step 2: Assess risks Determine the most realistic threats to the firm and its clients. Step 3: Establish safeguards Document controls such as MFA, encryption, backups, access management, and security training. Step 4: Create an incident plan Define how the firm will respond if information is lost, stolen, or compromised. Step 5: Review and update Revisit the plan regularly and whenever major technology or operational changes occur. This process can make WISP development much easier to manage. How Technology Supports WISP Compliance Technology is only one part of a WISP, but the right infrastructure can support the security controls documented in the plan. TechFiscal’s broader technology services include cybersecurity, cloud migration, backup and disaster recovery, secure remote work, email security, infrastructure consulting, and WISP compliance for accounting firms. For example, secure remote access can help employees work away from the office while maintaining appropriate controls. Backup and disaster recovery systems can help organizations prepare for data loss or ransomware incidents. Email security can also reduce exposure to phishing and malicious messages. Final Thoughts A Written Information Security Plan gives CPA firms and tax professionals a structured way to document how they protect sensitive client information. The most useful WISP is not necessarily the longest one. It is the one that accurately represents the firm’s systems, identifies realistic risks, documents appropriate safeguards, assigns responsibilities, and is reviewed as the business changes. For firms preparing for the 2026 filing season, reviewing the current WISP can be a practical step toward stronger information security and better compliance awareness. TechFiscal’s WISP Guides provide additional educational resources covering WISP requirements, CPA-firm security, IRS considerations, and FTC Safeguards Rule topics.