(949) 831-8821 • [email protected]

WISP Services

Written Information Security Program (WISP)

Examiner-ready WISPs built around risk, evidence, and real operations for tax professionals, accounting firms, and other small financial businesses.

Powered by SafeguardNeroEvidence-aligned documentationBuilt for real operations

More than a template

A WISP is a working security program.

A Written Information Security Plan documents who is responsible for protecting customer information, the risks your firm faces, the safeguards you use, and how you respond when something goes wrong. We build the plan around your actual systems, people, workflows, and data—not a generic document that sits in a drawer.

Tax & accounting

Tax preparers, EAs, CRTPs, CPAs, bookkeepers, seasonal practices, and small accounting firms.

Financial businesses

Mortgage firms, auto dealers arranging financing, money services businesses, and other covered financial institutions.

Small teams

Programs scaled to the size, complexity, and sensitivity of the information your organization handles.

Why it matters

The requirement is real. The program should be practical.

Tax professionals are required to maintain a written information security plan. The FTC Safeguards Rule also requires covered financial institutions to maintain a written information security program appropriate to their operations.

  • Know what applies. Smaller firms may qualify for exemptions from certain Safeguards Rule provisions, but not from the security-program requirement itself.
  • Build around required safeguards. Depending on applicability, this can include access controls, encryption, MFA, monitoring, training, vendor oversight, incident response, and leadership reporting.
  • Prepare for breach reporting. Covered notification events involving at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery.
  • Keep it current. Your program should evolve as software, staff, vendors, threats, and business operations change.

What your WISP covers

From responsibility to evidence.

Program ownership

Qualified Individual responsibilities, internal oversight, and accountability.

Risk assessment

Where customer information lives, foreseeable risks, and how risks are evaluated and treated.

Safeguards

Access controls, data inventory, encryption, MFA, secure disposal, change management, and activity monitoring.

Testing & monitoring

A documented approach to validating whether safeguards are working as intended.

People & providers

Security awareness training plus selection, contracting, and review of service providers.

Response & reporting

Incident response procedures, escalation, leadership reporting, and applicable FTC notification steps.

Built for tax-practice reality: e-file workflows, client portals, email, remote staff, cloud applications, paper records, and the vendors that touch taxpayer data.

Our process

A clear path from assessment to an operating program.

1

Compliance Snapshot

A guided first look at your obligations, current safeguards, and priority gaps.

2

Assessment & inventory

We map where client data lives, how it moves, and the controls already in place.

3

Custom WISP development

We document your program in plain English and tailor it to your actual environment.

4

Training & implementation

We connect the written program to staff responsibilities and practical safeguards.

5

Validation

We help verify controls and evidence with your IT provider or through RebootTwice managed security.

6

Ongoing compliance

Annual reviews and updates after material business, technology, vendor, or security changes.

What you receive

Documentation you can use—and maintain.

  • A WISP tailored to your organization and ready for internal approval.
  • Risk assessment and data inventory appropriate to the engagement.
  • Safeguards matrix tying controls to requirements and supporting evidence.
  • Incident-response and applicable notification procedures.
  • Service-provider, training, and policy-acknowledgment documentation.
  • Leadership-reporting templates and a SafeguardNero workspace for ongoing evidence.

Why RebootTwice

Security documentation grounded in how small regulated firms actually work.

Tax & financial-office context

Our team understands the operational realities behind bookkeeping, tax preparation, financial administration, and small professional practices.

Governance depth

Our GRC experience connects policy, risk, evidence, audit readiness, and practical security controls.

Implementation support

We can work with your existing IT provider or connect the program to RebootTwice Managed Security Services.

Frequently asked questions

WISP questions, answered plainly.

I downloaded an IRS sample WISP. Isn’t that enough?

It is a useful starting point, but your plan should reflect your actual risks, systems, safeguards, responsibilities, and operating practices. A template alone does not demonstrate that those elements have been assessed or implemented.

I’m a solo preparer. Do I really need a WISP?

Yes. IRS guidance states that tax professionals are required by law to create a WISP. The scope can be proportionate to a solo practice, but the plan should still reflect how you actually protect client information.

Can a service provider be the Qualified Individual?

The FTC Safeguards Rule permits the Qualified Individual to work for a service provider, while responsibility remains with the financial institution and a senior employee must oversee that provider. RebootTwice can help you structure the appropriate oversight model for your organization.

How often should our WISP be updated?

Review it regularly and update it when material changes affect your risks or safeguards—for example, new software, remote staff, vendors, workflows, or a security event.

Does having a WISP make us compliant?

No document does that by itself. Compliance depends on implementing and maintaining the program the document describes. Our work connects assessment, documentation, evidence, and implementation.

Ready to build a WISP that reflects your real business?

Start with a Compliance Snapshot and identify what applies, what is already in place, and what needs attention.