By Nate Olson, Fractional CIO & IT Director | N.O. IT Strategy LLC

The WISP: Turning Your Risk Assessment Into a Plan That Fits (Part 3 of 3)

By Nate Olson, Fractional CIO & IT Director | N.O. IT Strategy LLC

Every year, tax professionals are reminded to review and update their written information security plan. In the firms I’ve worked with and talked to, that isn’t usually how it goes. The WISP gets written once, filed in a drawer, and left alone for years.

I think of a WISP the way I think of a life jacket on a boat. You don’t need it most days, but on the day you do, it’s mission critical.

A life jacket only helps if it was made for the situation you’re in. If your boat capsizes on the high seas, you’d better hope you aren’t wearing the pool floaties you’d give a toddler learning to swim. You want a personal flotation device built for the serious situation you’re actually in.

The same can be said of your WISP.

The IRS numbers show how often that “serious” day comes. In the first half of 2025, the IRS reported nearly 300 data breaches affecting as many as 250,000 clients. By late 2025, the count had passed 546 incidents, involving more than 1,467 tax professionals and more than 400,000 taxpayers, according to a member of the IRS data breach team speaking at an IRS webinar.

In that same webinar, when the IRS walked tax professionals through what to do after a breach, the step right after calling their Stakeholder Liaison was to refer to their WISP. That’s the moment the plan was written for, and it’s the moment you find out whether it still fits.

That’s what this piece is about.

This is the final piece of a three-part series I wrote on the FTC Safeguards Rule. I built the series around the questions I see CPAs, tax firms, and bookkeepers running into, and it’s meant to be informational, not a sales pitch. My firm does offer FTC Safeguards Rule Readiness Reviews, and I’d rather say that up front than have it read like it’s hiding in the background.

Part 1 answered the question of who the rule actually applies to. There’s real confusion among smaller firms about the 5,000 consumer threshold, and some read it as meaning the rule doesn’t apply to them at all. It does. If you prepare returns for compensation, the rule applies to you, and being under the threshold only removes four of its requirements.

Part 2 covered the risk assessment, which is what a customized WISP gets built from and what keeps it current. You start with a full assessment, then reassess periodically as your firm changes, whether that’s new software, a new vendor, or new people handling client data.

This part picks up from there. Once you’ve completed your risk assessment, how do you take what it found and turn it into your WISP?

The IRS’s interest in all of this is that taxpayer data is protected. The FTC Safeguards Rule puts that into practice, setting out what firms like yours have to do to keep customer information secure and confidential. Cybersecurity has been part of my work my entire career, across 17 years in IT, and this is the ground where that experience applies most directly to your practice.

From findings to the plan

The rule is direct about the order of things. It says your information security program has to be based on a risk assessment. The assessment comes first, and the WISP is built from what it finds.

From a 10,000-foot view, that works like this. Your risk assessment tells you what client information you hold, where it lives, who can reach it, which vendors touch it, and what’s protecting it. The WISP takes each of those findings and records what your firm does about it, and who’s responsible for making sure it happens.

Some findings become safeguards, like who gets access to which systems, how client files are protected, or what your staff is trained to watch for. Others you may decide to accept. The rule contemplates that, with one limit: accepting a risk can’t be used to skip a safeguard the rule requires on its own, like multi-factor authentication. An accepted risk should be a decision someone made, not a gap nobody looked at.

If your firm is under the 5,000 consumer threshold, you aren’t required to put the assessment itself in writing, but your program still has to be based on one.

That’s what makes a WISP customized. It isn’t customized because your firm’s name is on the cover. It’s customized because every section traces back to something that’s actually true about your firm, which is also why it has to change when your firm does.

Where the IRS sample falls short

The IRS sample WISP is Publication 5708, and it’s a genuinely useful starting point. It lays out what a plan should cover, gives you sample policy language, and includes attachments for things like a hardware inventory and a breach notification list.

It also says, on its second page, that it isn’t meant to replace your own research or to serve as a substitute for developing your own plan based on your firm’s needs. The IRS wrote that into the document itself.

The reason matters. Most of the sample’s policy sections are prewritten, which means they describe safeguards before you’ve assessed a single risk. Part 2 covered why that order is backwards. The rule says your program has to be based on a risk assessment, and a template can’t know what yours found.

Some of that prewritten language also sets a lower bar than the rule. The sample states that the firm will follow the rule’s MFA requirement, but its actual policy language only calls for MFA on remote logins. The rule requires multi-factor authentication for anyone accessing any information system, unless your Qualified Individual approves reasonably equivalent or more secure controls in writing. The sample also allows network files to be password-protected or encrypted, while the rule requires customer information to be encrypted at rest and in transit over external networks, unless encryption isn’t feasible and your Qualified Individual approves an alternative.

And some of it commits your firm to specific practices. As written, the sample says your firm tests its systems weekly to make sure antivirus protection is current, runs a security review at least every 30 days, reviews event logs at least every 90 days, and runs background checks on new employees who will have access to client data. Those may be good practices, but if your firm signs the sample without changing them, your WISP now says you do all of them.

Why a WISP that doesn’t match your firm is a problem of its own

In Part 2, I said a WISP that doesn’t match what your firm is running puts you in a worse position than not having one. To be clear, not having a WISP isn’t a legal option. The requirement applies either way, and my point is about what happens in practice.

A firm with no WISP knows it has a gap. A firm with a template WISP in a drawer believes it’s covered, so nobody goes looking.

Then something happens. The IRS tells you to refer to your WISP right after you call your Stakeholder Liaison, so that’s the document in your hands. If it names someone who left, lists vendors you don’t use, or describes safeguards your firm never put in place, you’re working from a plan for a different firm at the moment you most need your own.

And it’s signed. A template adopted as-is is a written statement, with your name on it, that your firm does things it may not do.

Keeping it fitted

A life jacket only protects you if it was made for you and still fits. That’s the whole idea behind this series. Part 1 established that the rule applies to you, Part 2 covered the assessment that tells you what’s true about your firm, and this part is about turning that into a plan that describes your firm as it actually runs.

Then it needs to stay that way. Your WISP is only current until your firm changes, so new staff, a new vendor, or new software is your cue to reassess and update the plan to match.

If you’d rather have someone else do that work, that’s what my FTC Safeguards Rule Readiness Review is for. Every review includes an evidence based written risk assessment, and the WISP is built from what it finds, so the plan traces back to your firm and not to a template. For firms that have completed a review, I also handle updates in the years that follow as the practice changes.

Whether you work with me or do it yourself, the goal is the same. When the day comes that you need to reach for your WISP, it should fit.

FTC Safeguards Rule Readiness Review for Tax Firms

Sources

• 16 CFR Part 314, Standards for Safeguarding Customer Information. Electronic Code of Federal Regulations. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314
• 16 CFR 314.4, Elements. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4
• 16 CFR 314.6, Exceptions. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.6
• IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice, Rev. 8-2024. https://www.irs.gov/pub/irs-pdf/p5708.pdf
• IR-2025-88, Security Summit, IRS remind tax pros to guard against identity theft as summer series wraps up, Aug. 26, 2025. https://www.irs.gov/newsroom/security-summit-irs-reminds-tax-pros-to-guard-against-identity-theft-as-summer-series-wraps-up
• IRS, NTSA Week: How to Protect Yourself, Your Business and Your Clients, webinar transcript. https://www.irs.gov/newsroom/ntsa-week-how-to-protect-yourself-your-business-and-your-clients-youtube-video-text-script
• IR-2026-92, IRS, Security Summit remind tax pros they need a Written Information Security Plan to protect client data, Aug. 18, 2026. https://www.irs.gov/newsroom/irs-security-summit-remind-tax-pros-they-need-a-written-information-security-plan-to-protect-client-data