← Back to Blog

Lappu AI Journal

Is a WISP Enough for a Tax and Accounting Practice?

A Written Information Security Plan is an important compliance requirement for tax and accounting firms, but documentation alone does not secure client data. Real protection requires practical controls such as disk encryption, secure email practices, segmented Wi-Fi, password managers, and careful use of VPNs.

Vivek Uppal • March 13, 2026

Is a WISP Enough for a Tax and Accounting Practice?

Tax and accounting firms handle some of the most sensitive personal and financial information that exists. Social Security numbers, tax returns, bank details, and identity documents all pass through accounting offices every day.

Because of this, regulators require firms to maintain a Written Information Security Plan (WISP).

The IRS Safeguards Rule, the FTC Safeguards Rule, and many state data protection laws require tax and accounting practices to create and maintain a WISP designed to protect client information.

However, many firms misunderstand what a WISP actually accomplishes.

A WISP is an important compliance requirement, but creating a WISP alone does not guarantee that your firm is secure.

Based on our experience working with tax and accounting firms, there is much more to protecting client data than simply writing a security policy.

Below are several practical security controls every tax and accounting firm should implement in addition to their WISP.

What Is a WISP for Tax Preparers?

A Written Information Security Plan (WISP) is a document that outlines how a firm protects sensitive client information.

A proper WISP typically includes:

  • Risk assessments
  • Security policies and procedures
  • Employee responsibilities
  • Incident response planning
  • Safeguards for protecting taxpayer data

Under IRS guidance and the FTC Safeguards Rule, tax professionals must implement reasonable measures to protect client data from unauthorized access or disclosure.

But documentation alone does not stop cyber threats. The real protection comes from implementing technical safeguards that enforce the policies described in the WISP.

Disk Encryption: Protect Client Data if a Device Is Lost

One of the most common data breaches occurs when a laptop is lost or stolen.

Tax preparers often store highly sensitive information on their computers, including:

  • Social Security numbers
  • Tax returns
  • Bank information
  • Payroll records

If the computer's hard drive is not encrypted, the data can often be accessed by anyone who obtains the device.

Full disk encryption ensures that even if a device is stolen, the information on it cannot be accessed without proper authentication.

Most modern systems include built-in encryption:

  • Windows: BitLocker
  • Mac: FileVault

Every device used by employees should have full disk encryption enabled.

Secure Email Practices for Accounting Firms

Email is one of the biggest sources of data exposure in accounting firms.

Sensitive documents such as tax returns, W-2s, and financial statements are frequently sent through email.

Unfortunately, standard email is not designed for secure transmission of sensitive documents.

Firms should adopt safer practices such as:

  • Using secure client portals for document exchange
  • Avoiding unnecessary attachments containing personal information
  • Encrypting sensitive emails when possible
  • Implementing protections against phishing and email impersonation

Email attacks remain one of the most common entry points for cybercriminals targeting accounting firms.

Secure Your Office Wi-Fi Network

An insecure Wi-Fi network can expose your entire office to unauthorized access.

Tax and accounting firms should ensure their wireless network is configured properly.

Separate Guest and Employee Networks

Visitors and clients should never connect to the same network used by employees.

Instead, firms should maintain:

  • An employee network used for firm computers and systems
  • A guest network used for visitors and personal devices

This separation prevents unauthorized devices from accessing internal systems.

Use Strong Wi-Fi Encryption

Your Wi-Fi should use modern encryption standards such as:

  • WPA2
  • WPA3

Older protocols like WEP should never be used because they can be easily compromised.

Use Password Managers to Reduce Security Risks

Weak or reused passwords remain one of the leading causes of security breaches.

Employees often reuse the same password across multiple systems. If one account is compromised, attackers may gain access to other systems used by the firm.

Password managers help address this risk by:

  • Generating strong, unique passwords
  • Securely storing credentials
  • Reducing password reuse

Using a password manager is one of the simplest ways to significantly improve security in a tax or accounting practice.

Should Tax Firms Use VPNs?

Virtual Private Networks (VPNs) are often recommended for secure remote access.

However, many modern cloud-based systems already use strong encryption and identity-based access controls.

For many firms, VPNs are only necessary in specific situations, such as:

  • Accessing internal office servers remotely
  • Connecting to firm networks from public Wi-Fi
  • Accessing sensitive internal resources

VPNs should be used when they provide a clear security benefit, rather than being deployed automatically.

Compliance Is Only the First Step

Creating a WISP helps tax and accounting firms comply with regulatory requirements.

But compliance alone does not protect client data.

Real security comes from implementing the technical safeguards that support the policies described in your WISP.

Firms that take security seriously go beyond documentation and implement practical controls such as:

  • Disk encryption on all devices
  • Secure email practices
  • Segmented Wi-Fi networks
  • Password managers
  • Careful use of VPNs

These protections dramatically reduce the risk of data breaches and help safeguard client information.

Final Thoughts

Tax professionals are entrusted with extremely sensitive information. Protecting that data is both a legal requirement and a professional responsibility.

A WISP is an important foundation for security and compliance. But it should be seen as the starting point of your firm's security program, not the finish line.

By implementing practical security measures alongside your WISP, your firm can significantly reduce cyber risk while maintaining compliance with IRS and FTC requirements.