Every firm that prepares tax returns is required to have a Written Information Security Plan. Most do. The harder question is whether yours would survive the moment someone actually asks to see it. A client. An insurer. The IRS.

For a lot of firms, the honest answer is “probably not.” And it usually isn’t because anyone cut corners on purpose. It’s because the WISP got treated as a document you produce once, instead of a description of how your firm actually protects client data every day. Those are two very different things, and the space between them is where the risk lives.

What a WISP is really supposed to prove

The IRS requires a WISP under the safeguards rules of the Gramm-Leach-Bliley Act, and it reinforces that every year through Publication 4557 and the template in Publication 5708. If you’ve ever downloaded that template, you know it asks you to name who’s responsible for security, list where client data lives, describe how that data is protected, and spell out what happens if there’s a breach.

Here’s where firms get caught. The template produces a document. What regulators, insurers, and more and more clients actually want is proof that the things written in that document are real. A WISP that says “we use multi-factor authentication and keep secure backups” is only as good as whether those things are genuinely turned on, set up correctly, and checked. A plan that doesn’t match the systems sitting in your office isn’t a defensible WISP. It’s a liability with a cover page.

The questions that tell you the truth

You don’t need to be technical to test your own plan. A few honest questions usually tell you whether it holds up.

If a staff member’s email got compromised tomorrow, would you know? Catching a hacked account takes monitoring that a lot of small firms have never set up. If your gut answer is “we’d probably find out when a client called about a weird email,” that’s a gap your WISP most likely claims is handled.

Can you actually prove your backups work? “We have backups” and “we have backups we’ve tested, can recover from, and that a hacker can’t quietly delete” are not the same sentence. The first one is a hope. The second one is what a WISP is supposed to describe, and what a ransomware attack will find out for you.

Is multi-factor authentication really turned on everywhere, or just available? Available and enforced aren’t the same. Attackers go straight for the accounts where nobody ever switched it on.

When someone leaves the firm, how fast and how completely does their access disappear? Loose offboarding is one of the most common ways a former employee, or whoever ends up with their old login, keeps a door open to client data long after they’re gone.

If you’re not sure how to answer any of those, that’s not a reason to panic. It’s just the difference between a WISP that exists and a WISP that’s true.

Why this hits an accounting firm harder than most

Your whole practice runs on one thing that never shows up on a balance sheet: your clients trusting you with the most sensitive financial details of their lives. That trust took years to earn. It can come apart in a single afternoon. A spoofed email that goes out to your clients. A breach that exposes returns. A wire fraud that gets traced back to your systems.

And in a town like ours, the damage doesn’t stay quiet. One bad experience gets around. A firm can spend twenty years building a name and then watch how people see it change in a single season, over something a working security plan would have stopped.

You already do everything you can to protect your clients from tax trouble, audit exposure, and bad financial decisions. Protecting the data behind all of it is the same job, just pointed at your own firm. Your clients assume you’ve got it handled. A real WISP is how you make sure that assumption is actually true.

Turning paper into something that holds up

Closing the gap between a written plan and a real one doesn’t mean your team has to become security experts. It means the things the plan promises are actually in place and kept up:

  • Multi-factor authentication enforced on email and your key systems, not just offered
  • Monitoring that would genuinely catch a hacked account or unusual activity
  • Backups that are tested, recoverable, and protected from tampering
  • Email protections (SPF, DKIM, and DMARC) that stop someone from sending mail in your firm’s name
  • A clean, repeatable process for adding and removing access as people come and go
  • A response plan that’s written down before you ever need it

Every one of those lines up with something the WISP template asks you to sign off on. Together, they’re the difference between a plan you’d hand a client without flinching and one you’d rather nobody bring up.

A simple next step

If you’re not certain your WISP would hold up, the most useful thing you can do is find out quietly, before anyone else asks. That means looking at what’s actually running in your environment and lining it up against what your plan claims.

We work with CPA and accounting firms around the Shoals and North Alabama to close these exact gaps and keep them closed, so the plan on paper and the protection in real life finally say the same thing. If you’d like a straight answer on where your firm stands, we’re happy to take a look and walk you through it. No cost, no obligation, and no jargon.

You do everything you can to protect your clients. You owe your own firm the same.


Bankhead Technologies provides managed IT, cybersecurity, and compliance support for CPA and accounting firms across North Alabama. Call 256-415-6887 or visit https://bankheadtech.com/cpas/