What is a WISP? Written Information Security Plan (2026)

Written Information Security Plan (WISP)

Executive Summary

  • A security event involving the unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery [6].
  • Federal law now requires every tax and accounting firm, regardless of size, to maintain a Written Information Security Plan (WISP) [2] [3].
  • Non-compliance can result in loss of credentials, regulatory penalties, and severe reputational damage [4].
  • A WISP is more than a compliance checkbox: it protects your clients, your reputation, and your business continuity [1].
  • Verito delivers purpose-built, SOC 2-compliant cloud hosting and managed IT services to help firms implement and maintain effective WISPs [1].

Why Does Your Tax or Accounting Firm Need a WISP?

The Stakes: Data Breaches and Regulatory Pressure

Tax and accounting firms are prime targets for cybercriminals. Since May 2024, a security event involving the unencrypted information of at least 500 consumers must be reported to the FTC no later than 30 days after discovery [6], and the IRS asks tax professionals to report data theft to their IRS Stakeholder Liaison right away [7]. Regulatory bodies like the IRS, FTC, and state authorities now require every tax and accounting firm to maintain a Written Information Security Plan (WISP), regardless of firm size [2] [3].

What’s at risk if you don’t have a WISP?

  • Loss of PTIN credentials, which are required to practice as a tax professional [4].
  • Regulatory penalties and potential legal action
  • A mandatory 30-day FTC breach report: security events involving the unencrypted information of 500 or more consumers must be reported no later than 30 days after discovery [6].
  • Reputational damage and loss of client trust

Example: A small CPA firm without a WISP suffered a ransomware attack during tax season. The breach led to client attrition, regulatory fines, and months of operational disruption.

What Is a Written Information Security Plan (WISP)?

A Written Information Security Plan (WISP) is a comprehensive document that details how your firm protects sensitive information. The Federal Trade Commission defines it as a required written program designed to ensure the security and confidentiality of customer information, protect against anticipated threats, and prevent unauthorized access [2] [3].

For tax and accounting firms, a WISP covers:

  • Client financial information and tax documents
  • Personally identifiable information (PII)
  • Administrative, technical, and physical safeguards

Key regulatory requirements:

RegulationRequirementApplies To
FTC Safeguards RuleRequires a comprehensive information security programTax preparation firms, accounting firms, financial advisors
IRS Publication 4557Provides guidance for safeguarding taxpayer dataTax professionals
State Data Protection LawsVary by state (e.g., NY SHIELD Act, CCPA)Businesses with clients in those states

The IRS enforces these requirements through Publication 4557 and Publication 5708, which provide step-by-step guidance for creating a WISP [2] [5].

What Should a WISP Include? Key Components for Compliance and Security

1. Risk Assessment

Start by identifying what sensitive information your firm collects, where it resides, and how it’s protected. Evaluate current safeguards and identify potential threats and vulnerabilities. This assessment forms the foundation of your security program [1].

2. Administrative Safeguards

  • Security policies and procedures
  • Employee training programs
  • Access control policies
  • Vendor management procedures
  • Incident response plans
  • Regular security assessments

For example, policies on client data retention and secure communication protocols are essential for tax firms.

3. Technical Safeguards

  • Encryption for data at rest and in transit
  • Secure authentication methods (e.g., 2FA)
  • Firewalls and intrusion detection systems
  • Endpoint protection
  • Regular software updates and patch management
  • Secure backup solutions
  • Email security measures

As part of your safeguards, establish managed backup and instant recovery with clear restore objectives and routine validation.

Encrypted client portals and secure document management systems are especially important for accounting and tax firms.

4. Physical Safeguards

  • Secure office access and restricted areas
  • Clean desk policies
  • Secure shredding and disposal of physical documents
  • Locked filing cabinets and controlled access areas
  • Device protection

Physical safeguards remain critical, even as firms move toward digital solutions.

5. Monitoring and Testing

  • Regular vulnerability scanning
  • Penetration testing
  • Log monitoring
  • Security incident tracking
  • Compliance audits

Ongoing monitoring ensures your security measures remain effective as threats evolve.

6. Incident Response Plan

  • Roles and responsibilities during an incident
  • Steps for containing and mitigating breaches
  • Communication protocols
  • Documentation requirements
  • Recovery procedures
  • Post-incident analysis

Include specific procedures for notifying affected clients and authorities like the IRS if tax data is compromised.

How to Build and Maintain a WISP: Practical Steps

Getting Started

  1. Use templates: The IRS and FTC provide guidance documents and templates to help you get started [2] [3].
  2. Customize for your firm: Adapt templates to reflect your operations, client base, and technology.
  3. Involve key stakeholders: Security is everyone’s responsibility.
  4. Consider expert assistance: Information security consultants can provide valuable guidance.

Making It Effective

  • Train your team on the WISP and their roles
  • Make the plan accessible to those who need it
  • Review and update regularly as threats and regulations change
  • Test your safeguards to confirm they work as intended
  • Document all security activities, training, incidents, and updates

Common WISP Mistakes to Avoid

  • Treating the WISP as a “set and forget” document
  • Overlooking third-party risks (e.g., software vendors)
  • Focusing only on digital threats and ignoring physical security
  • Neglecting employee training
  • Making the plan too complex to follow

How Verito Supports Your WISP and Security Goals

Verito specializes in secure cloud hosting and managed IT services designed for tax and accounting firms. Our solutions help you implement and maintain the technical safeguards required by your WISP, including:

Why firms choose Verito:

  • Purpose-built for tax and accounting software
  • SOC 2 Type II compliant infrastructure
  • Transparent pricing with no surprise fees
  • Live 24/7 expert support
  • Secure migrations, handled for you: Setup on our side takes as little as 24 to 48 hours once your data is available.

With Verito, your technology just works. Securely.

Comparison: WISP Implementation Approaches

CriteriaDIY ApproachVerito Solution (Managed)
Compliance ExpertiseRequires in-house researchDesigned to support IRS/FTC requirements
Uptime GuaranteeVaries, often <99%100% SLA, track record since 2016
Security MonitoringManual or periodic24/7 proactive
Data IsolationShared or mixed environmentsDedicated, isolated servers
Support ResponseHours to daysSub-60-second, 24/7
Cost PredictabilityVariable, hidden feesTransparent, all-inclusive

Key Takeaways

  • Every tax and accounting firm is legally required to maintain a WISP [2] [3].
  • A WISP protects your clients, your reputation, and your business continuity [1].
  • Effective WISPs include risk assessment, administrative, technical, and physical safeguards, ongoing monitoring, and incident response planning [1].
  • Avoid common mistakes like neglecting third-party risks or treating your WISP as a static document.
  • Verito provides dedicated cloud hosting and managed IT designed to support the safeguards your WISP requires [1].

A WISP isn’t a form you fill out once. It’s a handful of decisions: which IRS publication applies, what your plan has to cover, and the conduct rules sitting around it. These break down each piece so you can build the plan instead of guessing at it.

Keep reading: build your WISP, step by step

Writing the plan is the paperwork. Proving the controls run every day is the infrastructure, and one isolated, dedicated environment is the clean way to answer for it.

Add once confirmed live: an IRS compliance self-check · what SOC 2 means for your data.

Ready to protect your firm and clients with a WISP that just works? Secure your data and compliance with Verito’s dedicated cloud hosting and managed IT services. Contact us today or schedule a demo to see how we can help your firm stay secure, compliant, and focused on what matters most.

Citations

Keep reading: building your WISP and meeting Safeguards

7 client-data-protection standards every tax firm must meet. What a compliant baseline looks like.

WISP for bookkeepers: FTC Safeguards requirements 2026. The plan smaller practices need on file.

Sponsored by Verito Verito hosts Drake, Lacerte, UltraTax, and QuickBooks on private dedicated servers — with 24/7 support from techs who actually know tax software. Used by 1,000+ accounting firms. See plans from $69/user

Want the next step based on this article?
Continue in your favorite AI assistant using this page as the source.
You May Also Like