OPSWORQ

Industries · Accounting & tax

Tax season is when your IT can least afford to fail.

A written security plan to IRS Publication 5708, the controls it describes actually in place, and systems that stay up from January to April.

WISP · IRS Publication 5708 · FTC Safeguards Rule

A quiet accounting office with a desk, binders and a laptop, and one orange cable running along the wall.

What’s different here

Your clients hand you the data criminals want most.

Social Security numbers, bank details and last year’s return are exactly what fraudsters need to file in someone else’s name.

A plan that’s required, not optional

The law treats tax and accounting practices as financial institutions, so a written security plan isn’t a nice-to-have.

A calendar that doesn’t move

Changes are planned around your deadlines. Nothing risky is scheduled in the middle of the season.

Email is the attack

Fake client emails, fake IRS emails and redirected refunds all start in the inbox.

Seasonal staff

People who join in January and leave in April need access that starts and ends on the right day.

The obligation

A WISP isn’t a template. It’s the controls, written down.

The Gramm-Leach-Bliley Act treats tax and accounting professionals as financial institutions, and the FTC’s Safeguards Rule requires them to protect customer data under a written information security plan. The IRS and its Security Summit partners repeated the point in August 2026, pointing firms to Publication 5708 as a starting template.

Under the Safeguards Rule, a security event affecting 500 or more people has to be reported to the FTC, generally within 30 days of discovery.

We write the plan with you and put the controls it describes in place: multi-factor authentication, encryption, access that ends when employment does, monitored and tested backups, and a response plan that says who calls whom. Then we keep the evidence, so the plan stays true.

Sources: IRS news release IR-2026-92, 18 August 2026; IRS Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice.

We support your compliance program with the controls and the evidence. We don’t certify compliance, and we’re not your attorney.

The calendar

Planned around the season, not in the middle of it.

The work that changes things happens before January. The work during the season is keeping it running.

  1. Oct – Dec

    Get ready

    Plan reviewed, patches current, restore tested, seasonal accounts prepared.

  2. January

    Season opens

    Seasonal staff start with the right access on their first morning.

  3. Feb – Apr

    Keep it running

    Nothing risky scheduled. Fixes only, inside the response clocks.

  4. After April

    Close it down

    Seasonal access removed, the year’s lessons written into the plan.

What we set up

Built into the Secured plan, and documented.

Every item below is part of Secured, with the evidence kept for whoever asks.

  • A written information security plan, kept current with the controls it describes.
  • Multi-factor authentication on email, tax software portals and remote access.
  • Encrypted laptops and phones, so a lost device is an inconvenience, not a breach.
  • Access that starts and ends on the right day, including seasonal staff.
  • Backups restore-tested monthly, with the file opened and the time recorded.
  • Email authentication and filtering, so fake client and IRS emails are caught, and nobody can send as you.
  • An incident plan that includes who reports to the FTC, and when.
  • A monthly report that doubles as evidence for the plan.

A price example

A 12-person office on Secured: from $2,100 a month.

12 people × $175, the published floor. Month to month, unlimited remote support, and everything on this page included. Your number comes from a 20-minute review and holds after you sign.

Monthly floor, Secured

12 people× $175

$2,100 / month

Month to month. $750 monthly minimum. About 10% less with a twelve-month commitment.

Questions

Straight answers.

Is a WISP really required for a small practice?
Yes. The requirement comes from federal law, not firm size. The IRS’s own Publication 5708 is written with small practices in mind.
Can we just use the IRS template?
It’s a good start. A plan only protects you if the controls it describes are actually in place and someone keeps it current. That’s the part we do.
Do you work with our tax and accounting software?
Yes. We’re QuickBooks certified, and we support Xero and Wave as well. We secure access to your tax software, keep the machines it runs on patched, and work with the vendor when the fix is theirs.
What about remote staff?
Same controls at home as in the office: multi-factor authentication, an encrypted, managed laptop, and nothing stored where we can’t back it up.

Get started

Talk to an engineer, not a salesperson.

1‑855‑OPSWORQ

855‑677‑9677 · Mon–Fri, 8am–5pm ET

If the business has stopped, call. Don’t use the form.

Pick a time for a 20-minute review of what you run, or write to us and a person replies within one business day. Then a written quote with a start date on it.

What’s it about? Select all that apply.

A sentence is plenty.

A person replies within one business day. Nothing is sold, and you’re not added to a mailing list.

Prefer to talk? Pick a time for a 20‑minute review Or call 1‑855‑OPSWORQ.

Call Get your price