Skip to main content
Service 01

Written Information Security Plan (WISP) Enforcement

The IRS and FTC do not care if you bought a WISP template. They care if you can technically prove you enforce it.

The FTC Safeguards Rule Reality

Under the revised FTC Safeguards Rule (effective June 2023), any tax practice preparing more than a handful of returns is legally defined as a financial institution. This triggers mandatory compliance with IRS Publication 4557.

When a breach occurs—and in the accounting sector, it is when, not if—the investigating forensic unit will immediately request your WISP. If you provide a Word document that states you use Multi-Factor Authentication (MFA), but their logs show a partner logging in via RDP without MFA, you are facing negligence fines, not just breach remediation costs.

Core Technical Controls We Implement:

  • MFA Enforced at Identity Provider: No exceptions for senior partners. Conditional access policies that block logins from outside the US.
  • Endpoint Detection & Response (EDR): Replacing legacy antivirus with behavior-based monitoring.
  • Immutable Backup Architecture: Backups that cannot be deleted or encrypted by ransomware.
  • Data Loss Prevention (DLP): Preventing SSNs from being emailed to unencrypted domains.

Our Implementation Methodology

We bridge the gap between legal requirements and technical reality.

  1. Gap Analysis: We scan your network, Microsoft 365 tenant, and tax software stack against the 4557 controls.
  2. Technical Remediation: We instruct your MSP to implement the missing controls. If they lack the capability, we bring in specialized vendors.
  3. Policy Authoring: We write the WISP around the actual technology you use, ensuring it is a legally defensible document.
  4. Annual Testing: The FTC requires annual penetration testing or continuous vulnerability scanning. We manage this process.

Schedule a Compliance Audit

Common Mistakes in Compliance

A critical failure mode we observe is assuming that paying an MSP a monthly fee absolves the firm's partners of legal liability under FTC guidelines. (Reported by Ponemon Institute, Q3 2023).

Empirical Data & Metrics

Metric Industry Average Bureau Standard
MFA Adoption 42% 100% (Zero Exceptions)
Bare-Metal Restore Time 5+ Days < 12 Hours

Frequently Asked Questions

How does this impact our cyber insurance?

Insurance carriers now require attested proof of EDR and MFA. Failing to maintain these technically, even if stated on the policy application, can result in a denied claim.

Can we handle this internally?

Unless your firm employs a dedicated, full-time cloud security architect, attempting to self-manage enterprise compliance usually results in critical gaps.