
If you own or manage an Accounting & Tax firm, you may have heard the term Written Information Security Plan, or WISP, from the IRS, your insurance provider, an industry association, or your IT provider.
But what exactly is a WISP, and does your firm really need one?
For tax professionals, the answer is generally yes. A WISP documents how your firm protects sensitive client information and provides a framework for managing information security over time.
The important thing to understand is that a WISP isn’t simply another document to create and put on a shelf. It should reflect how your firm actually protects client information.
What Is a WISP?
A Written Information Security Plan documents the administrative, technical, and physical safeguards your firm uses to protect sensitive information.
Depending on your firm, that may include areas such as:
- How employees access client information
- How passwords and multifactor authentication (MFA) are managed
- How computers and other devices are protected
- How email and Microsoft 365 are secured
- How data is backed up
- How employees are trained to recognize security threats
- How vendors with access to sensitive information are evaluated
- How the firm responds to a security incident
- How cybersecurity risks and safeguards are reviewed over time
The WISP helps turn cybersecurity from a collection of individual tools into an organized business process.
Why Does a WISP Matter to Accounting & Tax Firms?
Accounting & Tax firms routinely handle information that criminals want: Social Security numbers, tax returns, banking information, payroll records, financial statements, and other confidential client information.
Tax professionals also have responsibilities for protecting taxpayer information.
The IRS has repeatedly emphasized the importance of data security for tax professionals and provides guidance and resources to help firms develop a Written Information Security Plan.
A WISP helps your firm establish what information needs protection, identify potential risks, document safeguards, and determine who is responsible for maintaining them.
A WISP Is More Than Cybersecurity Software
Installing antivirus, enabling MFA, or purchasing a cybersecurity service doesn’t automatically create an information security program.
Technology is part of the solution, but a WISP should also consider people and business processes.
For example:
- Who is allowed to access sensitive information?
- What happens when an employee leaves the firm?
- How are employees trained about phishing?
- Who can authorize changes to accounts or permissions?
- What happens if a computer is lost or stolen?
- How will the firm respond if an email account is compromised?
- How often are security safeguards reviewed?
These are business questions as much as technology questions.
Your WISP Should Match Your Firm
A 10-person Accounting & Tax firm doesn’t operate like a national accounting firm with hundreds of employees.
Your information security program should reflect your firm’s actual size, technology environment, risks, and business operations.
That doesn’t mean ignoring important safeguards because your firm is small. It means developing a practical plan that makes sense for your organization and then improving it as your needs change.
The goal isn’t to make cybersecurity unnecessarily complicated. The goal is to understand your risks and put reasonable safeguards in place to protect your clients and your firm.
Start by Understanding Where You Are Today
You don’t have to solve everything at once.
A useful first step is understanding your current environment:
- What sensitive information does your firm maintain?
- Where is that information stored?
- Who has access to it?
- What cybersecurity safeguards are already in place?
- What risks or gaps need attention?
- Which improvements should be prioritized?
Once you understand where your firm stands, you can develop a practical plan for improving security over time.
For Accounting & Tax firms, much of that improvement can be planned outside of the busy tax season so important changes don’t unnecessarily disrupt your team.
A WISP Should Continue to Evolve
Creating the document isn’t the end of the process.
Businesses change. Employees change. Technology changes. Cybersecurity threats change.
Your WISP should be reviewed periodically and updated as your firm’s technology, operations, and risks evolve.
Regular technology and cybersecurity planning can help make this manageable by identifying what needs attention now, what should be budgeted for later, and what can reasonably wait.
Ready to Understand Where Your Firm Stands?
You shouldn’t have to become an IT or cybersecurity expert to lead your firm responsibly.
If you’re unsure whether your current cybersecurity safeguards align with your WISP or where your firm should begin, MicroNet can help you understand your current environment, identify opportunities for improvement, and develop a practical path forward.


