MFA blocks a stolen password from becoming a login, EDR catches an attacker who gets in anyway, and encryption makes stolen data unreadable. IRS Publication 4557 treats all three as baseline controls a firm’s Written Information Security Plan (WISP) has to document, not optional extras.
Key takeaways
MFA stops credential theft, the most common way tax preparers get breached.
EDR watches behavior and catches ransomware that antivirus alone misses.
Encryption protects data in transit and at rest so a stolen device isn’t a readable breach.
IRS Pub 4557 requires all three as documented WISP controls, not suggestions.
VeritSpace and VeritComplete include all three by default; VeritShield WISP documents them in 5 business days.
Table of Contents
What Is MFA and Why Does the IRS Require It?
Multi-factor authentication (MFA) requires a second proof of identity, usually a code sent to a phone or app, before anyone can log in. It matters because passwords get stolen constantly through phishing and data breaches, and MFA means a stolen password alone can’t get an attacker into your systems.
Credential theft is the single most common way tax preparers get breached. A password can leak from a phishing email, a breach at an unrelated site, or simple guessing, and none of that matters if the login also needs a code from a device the attacker doesn’t have.
Publication 4557 lists MFA as one of the baseline controls a WISP must document. It’s not framed as a recommendation. An auditor or an insurer reviewing your WISP will ask whether MFA is enabled on email, remote access, and any system touching client data, not whether you’ve considered it.
What Is EDR and How Is It Different From Antivirus?
Endpoint Detection and Response (EDR) watches behavior instead of matching known malicious files. It flags a program doing something suspicious, like suddenly encrypting hundreds of files, even if that specific program has never been seen before. Antivirus can’t do that.
Ransomware increasingly uses techniques that don’t trip traditional antivirus, because antivirus is built to recognize known threats, not new behavior. EDR catches the pattern of an attack in progress, which is often the only way to stop it before it spreads across a network.
Ransomware against tax preparers isn’t a hypothetical. It’s one of the most common breach types reported to the IRS Identity Theft office each year, and EDR is the control most likely to interrupt an attack mid-execution rather than after the damage is already done.
What Does Encryption Protect and When Does It Matter Most?
Encryption scrambles data so a stolen file, laptop, or backup is unreadable without the key. It matters in two states: encryption in transit, for data moving between systems, and encryption at rest, for data sitting on a server or backup drive.
A stolen laptop or a hacked backup only becomes a breach if the data on it is readable. Encrypted data that falls into the wrong hands is functionally useless to whoever took it, which is why encryption is one of the few controls that limits damage after something has already gone wrong.
Client Social Security numbers, bank details, and tax records are exactly what encryption is built to protect. That’s also why it shows up in nearly every compliance framework a firm might face, not just the IRS’s.
How Do MFA, EDR, and Encryption Work Together in a WISP?
None of the three controls works alone. MFA stops someone from getting in with a stolen password, EDR catches an attacker who gets in anyway, and encryption limits the damage if data is accessed or stolen despite both. A WISP that lists all three without implementing them fails an IRS audit or an insurer’s questionnaire.
Each control covers a different stage of an attack:
MFA stops unauthorized login even when a password is compromised.
EDR detects and interrupts malicious behavior already inside the network.
Encryption limits exposure if data is accessed or removed regardless of the first two controls.
Control
Stage it protects
What it stops
IRS/insurer relevance
MFA
Login
Stolen or guessed passwords
Baseline WISP control under Pub 4557
EDR
In-network activity
Ransomware and novel attack behavior
Increasingly required on cyber insurance applications
Encryption
Data at rest and in transit
Readable data after theft
Protects SSNs, bank details, and tax records specifically
An insurer’s questionnaire increasingly asks about the same three controls the IRS requires in a WISP. Firms that treat them as three separate checkboxes instead of a stacked system tend to fail both reviews at once.
“I value the robust firewall that Verito provides, helping me maintain compliance with WISP and ensuring the protection of client data.”
Carrol G., Owner, Gatlin Tax, Ltd · G2, Nov 2025
Do VeritSpace and VeritComplete Include MFA, EDR, and Encryption by Default?
Yes. Firms hosted on VeritSpace or bundled under VeritComplete get MFA, EDR, and encryption built into the environment from day one, not a separate project the firm has to manage. VeritShield WISP produces audit-ready documentation of those controls in 5 business days.
That means a firm doesn’t configure these controls piecemeal across a patchwork of vendors. They’re part of the hosting environment itself, alongside 256-bit encryption, SOC 2 certification, and IRS Pub 4557 compliance built into every VeritSpace tier.
If something does go wrong, support isn’t a ticket queue. Every request reaches a real person in under 60 seconds, with 92% resolved on the first touch.
“The customer support team at Verito is very quick to respond and consistently courteous, providing excellent support that enhances my overall experience.”
David C., Owner, David Cleaver-Bartholomew, EA · G2, Oct 2025
How Do I Know If My Firm’s Current Setup Would Pass an IRS or Insurer Review?
The fastest check is matching your current MFA, EDR, and encryption setup against what Pub 4557 and a typical insurer questionnaire ask for by name, not by whether you have generic security software installed. A firm running all three, documented in a current WISP, passes both. A firm missing documentation, even with the controls in place, often doesn’t.
Not sure whether your firm’s current setup would hold up? Get a compliance check-in with Verito and find out what an IRS review or an insurer’s questionnaire would actually flag.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.
Practice management software runs your firm's clients, projects, deadlines, and time in one place. How to pick the right tool for your firm and host it securely.