For tax preparers, CPAs, bookkeepers, RIAs, mortgage brokers, and dealerships

Your Qualified Individual, on retainer.

The FTC Safeguards Rule and IRS Publication 4557 require every tax and financial firm to have a written security plan and a named person responsible for it. I build the plan, and I can be the person.

  • FTC Safeguards Rule (16 CFR Part 314)
  • IRS Publication 4557
  • IRS Publication 5708 (WISP)
  • SEC Regulation S-P

This is enforced, not aspirational

Verified September 2026

The amended Safeguards Rule has been fully in force since June 2023, and breach notification to the FTC within 30 days became mandatory in May 2024. The IRS asks every preparer to attest to a data security plan at PTIN renewal. Fines run up to $100,000 per violation, and a preparer without a plan risks their PTIN.

Who this is for

  • Tax preparers and enrolled agents (11+ returns a year)
  • CPA and bookkeeping firms
  • Registered investment advisers
  • Mortgage brokers and lenders
  • Auto and boat dealerships that arrange financing
  • Collection agencies and finance companies

What usually goes wrong

You have a "WISP" that is a downloaded template

A template with your firm name pasted in does not satisfy the Rule. It requires a written risk assessment specific to your firm, a designated Qualified Individual, and an annual report to ownership. An examiner or an insurer will notice.

Nobody is actually the Qualified Individual

The Rule says one person must own the program. In most small firms that is the owner, who has no time and no security background. That is the gap this service closes.

Your insurer sent a questionnaire you cannot answer honestly

Cyber-insurance renewals now ask about MFA, encryption, backups, vendor oversight, and incident response. Answering "yes" to things you have not done is how claims get denied.

Tax season is the worst possible time to figure this out

Phishing and account-takeover attempts against preparers spike January through April. The plan needs to exist and the controls need to be on before the returns start.

What you end up with

Deliverables, not deliverable-shaped PDFs.

A WISP that survives scrutiny

Mapped element-by-element to 16 CFR 314.4 and to Pub. 4557, with a risk assessment specific to your firm.

A named Qualified Individual

Me, of record, with the annual written report the Rule requires delivered to your ownership.

Controls that are actually on

MFA everywhere it matters, encryption for client data, tested backups, and a vendor list you can defend.

A plan for the bad day

A written incident response plan and a person to call at 7 a.m. when something looks wrong.

How the engagement runs

  1. 01

    Discovery call (20 minutes)

    What you file, how many people, what software, what your insurer asked for. I tell you honestly whether you need the Build, the Retainer, or just a couple of fixes.

  2. 02

    Risk assessment (week 1-2)

    I inventory your systems, data flows, and vendors and score the actual risks. This becomes the backbone of the WISP.

  3. 03

    WISP and controls (week 2-4)

    Written plan, incident response plan, vendor oversight, and a short fix list with owners and dates. I do or coordinate the technical fixes.

  4. 04

    Training and handoff

    One live session for your staff. Then either you run it, or I stay on as your Qualified Individual and run it for you.

Pricing

WISP & FTC Safeguards

WISP Build

$3,500 one-time

A real Written Information Security Plan built for your firm, not a template with your name typed in.

  • Written risk assessment (required by the Rule and by IRS Pub. 4557)
  • WISP document mapped to all nine Safeguards Rule elements
  • Written incident response plan
  • Service-provider (vendor) inventory and oversight process
  • MFA, encryption, and access-control gap list with fixes
  • Live staff security training session (45 minutes)
  • PTIN-renewal data-security attestation support

Best for: Firms that need to be compliant this season and have never had a plan.

Most common

Qualified Individual Retainer

from $750 /month

The Rule requires you to designate a Qualified Individual. That can be me.

  • Named Qualified Individual of record
  • Annual written report to ownership (required by the Rule)
  • Semi-annual vulnerability scans and an annual testing plan
  • Quarterly WISP review and updates as your firm changes
  • Vendor contract review as you add tools
  • Breach triage and the 30-day FTC notification clock, if it ever happens
  • A direct line to me.

Best for: Any covered firm that would rather not become a part-time security officer.

Pricing assumes a firm of up to 15 people at one location. Larger or multi-office firms get a fixed quote after a 20-minute call.

FAQ

WISP & Safeguards: questions people ask

We only prepare a few hundred returns. Does this apply to us?

If you prepare 11 or more federal returns for compensation, the IRS expects a written data security plan. The FTC Safeguards Rule applies to tax preparers regardless of size, with lighter requirements only for firms holding data on fewer than 5,000 consumers.

Can you be our Qualified Individual if you are not an employee?

Yes. The Rule explicitly allows the Qualified Individual to be an outside service provider, as long as a senior member of your firm retains oversight and I report to them. That report is part of the retainer.

Our IT company says they handle security. Is this redundant?

Usually not. Your IT provider keeps systems running and may run the tools. The Rule requires a written program, a risk assessment, vendor oversight, and a responsible person. That is governance, not helpdesk, and most IT firms will tell you the same if you ask directly.

How fast can this be done before tax season?

A WISP Build is typically three to four weeks from the discovery call. Starting in the fall is ideal. Starting in January is possible but rushed.

Get your program started

Talk to Ed

[email protected] · (772) 403-3088