Skip to nav Skip to content
{{ headerItems.greeting }} {{ headerItems.firstName }} Log In
{{ itemUpdatedMessage }}

Build a working WISP for your tax firm in one afternoon

Published:
By: NATP Staff
Tax professional working at an adjustable desk while building a firm-specific written information security plan.

You know your tax firm needs a written information security plan (WISP). The IRS and its Security Summit partners have been urging tax professionals for years to put real safeguards in place to protect taxpayer data, and a WISP is at the center of that effort. You may even have a sample plan or an IRS template saved somewhere, waiting for the quiet afternoon that never arrives.

This workshop is that afternoon.

During NATP’s Modernizing Your WISP and Securing Client Data online workshop, you won’t just listen to another lecture about cybersecurity or FTC rules. You’ll work through a practical, plain-English template, connect the requirements to the way your own firm operates and draft your WISP section by section. A good WISP should reflect your firm’s actual scope and systems; there is no one-size-fits-all plan.

By the end of the workshop, you can leave with a complete or near-complete WISP built around how your firm handles client data today.

What comes off your to-do list

  • Build or update your WISP during the workshop using a customizable template.
  • Map how taxpayer information flows through your firm, from intake to e-file to archiving.
  • Address modern risks from cloud storage, AI tools, remote staff and third-party software.
  • Draft a practical incident response plan that reflects applicable IRS guidance and Federal Trade Commission (FTC) requirements.
  • Leave with a complete or near-complete WISP and a simple process for keeping it current.

What you’ll build during the workshop

1. A clear picture of how client information moves through your firm

We’ll start by diagramming how taxpayer data enters and moves through your systems: via paper, portals, email, cloud tools and tax software. This “data map” becomes the backbone of a WISP that matches your real workflows rather than an abstract checklist.

2. A risk assessment tied to your actual tools and processes

Next, you’ll identify risks created by the way you work, including remote access, shared passwords, vendor connections, data in transit and data at rest. IRS and Security Summit guidance emphasizes that safeguards must fit your practice’s size, scope and complexity and the sensitivity of the customer data you handle. We’ll translate that into straightforward language you can use with your team.

3. Firm-specific policies for protecting and accessing information

Using the template, you’ll draft policies for passwords, encryption, backups, physical office security, vendor selection and staff training, all core elements of a strong information security program. Rather than generic statements, you’ll write the specific rules your firm will follow on a daily basis.

4. A workable incident response plan

The IRS and FTC expect tax professionals to be prepared to respond quickly if taxpayer data is compromised. Together, we’ll outline whom to contact, how to communicate with affected clients, and the steps your firm will take to contain and investigate a breach. You’ll leave with a response plan you can keep alongside your WISP.

5. A schedule for reviewing and updating your WISP

A written security plan is meant to be an evergreen document that evolves as your practice and technology change. You’ll decide when and how your firm will revisit the WISP and document the process so the plan becomes a living part of how your firm runs.

Give your WISP one focused afternoon

You could spend another year intending to update your WISP, or you could simply use one guided workshop to get it done. Bring what you already have, even if that’s only an unfinished template, and leave with a plan built for the way your firm operates today.

Get registered for NATP’s Modernizing Your WISP and Securing Client Data online workshop on Sept. 25 or on demand and put those WISP woes and worries behind you.

About the author(s)

"NATP team committed to supporting tax professionals with expert insights, industry updates, and resources, shown with green triangle design element representing the organization's brand.

NATP Staff

The NATP team is dedicated to supporting tax professionals with expert insights, industry updates and resources that help them serve their clients with confidence.

Information included in this article is accurate as of the publication date. This post does not reflect tax law changes or IRS guidance that may have occurred after the publishing date.

Loading content...