Resources for Tax Firms
Practical cybersecurity guidance written specifically for tax preparers and CPAs in Northeast Alabama.
What is the IRS WISP
and do I need one?
Required by the IRS: The Written Information Security Plan (WISP) is mandatory for all tax preparers under the Gramm-Leach-Bliley Act. The IRS actively enforces this requirement and includes WISP checks in preparer audits. If you don’t have one, you’re out of compliance.
A WISP documents how your firm protects client data. It covers who has access to sensitive information, how devices are secured, what happens if there’s a breach, and how employees are trained.
What your WISP must cover
- Designation of a data security coordinator
- Inventory of all devices that access taxpayer data
- Description of data encryption methods in use
- Password policies and multi-factor authentication requirements
- Procedures for detecting and responding to data breaches
- Employee cybersecurity training program
- Physical security measures for your office and equipment
- Plan for secure disposal of client records and devices
MMIT helps tax firms create and maintain a compliant WISP as part of our managed services. We’ll draft it, keep it updated, and make sure your whole team understands it.
📅 Get Help With Your WISPTop cyberthreats
targeting tax firms
Tax preparers are one of the most targeted groups for cybercrime. Here’s what you need to know.
Business Email Compromise
Attackers impersonate the IRS, clients, or software vendors to trick your staff into revealing credentials or wiring money. These emails look convincing and arrive year-round, but spike during tax season.
Protect yourself: Employee training + email filtering + multi-factor authentication
File Encryption Attacks
Ransomware infiltrates your network and encrypts every file — client returns, financial records, everything. The attackers demand payment to restore access. Average ransom demand for small businesses: $50,000+.
Protect yourself: Endpoint protection + cloud backup + network segmentation
Stolen Logins & Dark Web Exposure
Your employees’ email and software passwords may already be for sale on the dark web from previous breaches. Attackers use these to log directly into your tax software or email accounts.
Protect yourself: Dark web monitoring + password manager + MFA enforcement
Accidental Data Exposure
Most breaches at small firms aren’t malicious — they’re accidents. An employee emails a file to the wrong person, uses a personal device on public Wi-Fi, or stores client data in an unsecured folder.
Protect yourself: Security training + device management + access controls
Unpatched Tax Software
Outdated software — including tax prep applications, operating systems, and browsers — contains known security holes that attackers actively exploit. Unpatched systems are one of the top attack vectors.
Protect yourself: Automated patch management + vulnerability scanning
Device Theft & Unauthorized Access
A stolen laptop or unlocked workstation can expose thousands of client records. Physical security is often overlooked but required under the IRS WISP guidelines.
Protect yourself: Full-disk encryption + screen locks + device tracking
Tax season IT checklist
Run through this checklist before January each year to make sure your firm is ready for the surge in activity — and the surge in cyberattacks that comes with it.
- Confirm antivirus and endpoint protection is current on all devices
- Run a dark web scan for exposed employee credentials
- Verify multi-factor authentication is enabled on all accounts
- Review who has access to client data — revoke old permissions
- Refresh employee phishing awareness training
- Update all software including tax prep applications and OS patches
- Test your backup restore process — confirm it actually works
- Confirm off-site or cloud backup is current and encrypted
- Check internet bandwidth — upgrade if needed for the busy season
- Review your WISP and update any outdated sections
MMIT offers an annual Tax Season IT Readiness Review for clients. We run through this checklist and more — so you go into busy season knowing your systems are solid.
📅 Schedule a Readiness ReviewOfficial resources
for tax professionals
These are the authoritative sources for IRS cybersecurity guidance and requirements.
IRS WISP Template & Guide
The IRS provides a free WISP template and implementation guide specifically for tax professionals. A good starting point before working with MMIT to customize it for your firm.
Visit IRS.gov →Security Summit Resources
The IRS Security Summit is a coalition of the IRS, state tax agencies, and tax industry that shares cybersecurity guidance and alerts specifically for tax professionals.
Visit IRS.gov →Protect Your Clients, Protect Yourself
IRS awareness campaign with practical steps tax professionals can take to secure client data and reduce identity theft risk.
Visit IRS.gov →Safeguards Rule for Tax Preparers
The FTC’s Safeguards Rule requires financial institutions — including tax preparers — to develop, implement, and maintain a comprehensive data security program.
Visit FTC.gov →Ready to put this knowledge
into action?
Schedule a free security review. We’ll assess your current setup and show you exactly what MMIT can do for your firm.