IRS warns tax pros: Your tax office needs a written security plan
The IRS and Security Summit are reminding tax professionals that protecting client data isn’t just good cybersecurity practice — federal law requires tax and accounting firms to maintain a Written Information Security Plan, commonly known as a WISP.
Why it matters: Tax preparers routinely possess some of the most valuable information an identity thief can obtain: Social Security numbers, dates of birth, addresses, bank information, income records and copies of tax returns.
A data breach can therefore become much more than an IT problem. It can become a compliance, financial and reputational crisis for the tax practice.
What’s happening
The IRS, state tax agencies and the tax industry — collectively known as the Security Summit — are again urging tax professionals to create and maintain a Written Information Security Plan.
And this isn’t optional.
The IRS notes that the Federal Trade Commission’s Safeguards Rule requires tax and accounting professionals covered by the rule to implement written information-security protections designed to safeguard customer information.
Translation for tax pros: If you handle taxpayer data professionally, cybersecurity needs to be part of your firm’s operating procedures — not something you think about only after an incident.
What exactly is a WISP?
Think of a WISP as your tax office’s cybersecurity playbook.
It documents what sensitive information your business maintains, where that information is stored, who has access to it, what protections are in place and what the business will do if something goes wrong.
According to the IRS, a security plan should address areas including:
- Employee management and training.
- Information systems.
- Detecting and managing system failures.
- Identifying and assessing risks to customer information.
- Designing safeguards to control those risks.
- Monitoring and testing the effectiveness of those safeguards.
- Selecting service providers capable of maintaining appropriate security protections.
- Adjusting the security program as the business and threats change.
The key point: A WISP shouldn’t be a document created once and forgotten in a folder.
It should reflect how your tax practice actually operates.
The IRS is giving tax pros a blueprint
Tax professionals don’t necessarily have to build a security plan from scratch.
The Security Summit created Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice, specifically to help tax and accounting firms develop their plans.
The template walks practices through major areas such as identifying responsible individuals, assessing risks, establishing safeguards and creating an implementation plan.
That makes Publication 5708 particularly useful for smaller independent tax offices that don’t have dedicated cybersecurity or compliance departments.
Why tax offices are attractive targets
Tax professionals are effectively data vaults.
One compromised preparer’s computer or cloud account could potentially expose information belonging to hundreds or thousands of taxpayers.
Criminals can use stolen taxpayer information to attempt identity theft, file fraudulent tax returns or conduct other financial fraud.
That’s why cybersecurity increasingly needs to be viewed similarly to tax due diligence.
A preparer may have excellent knowledge of the Internal Revenue Code and still expose the entire practice if employees are sharing passwords, using unsecured devices or clicking phishing links.
What a tax office should be thinking about
A WISP forces the owner to answer uncomfortable but necessary questions.
Who has access to client files?
Are employees using multifactor authentication?
Are laptops and devices encrypted?
How are backups maintained?
What happens when an employee leaves?
Which third-party software companies have access to taxpayer information?
How would the firm respond if ransomware locked every computer tomorrow morning?
If the answer is “I’m not sure,” that’s precisely the type of operational weakness a WISP is intended to identify.
Between the lines: Your vendors matter too
Cybersecurity doesn’t stop at your office door.
Modern tax practices increasingly rely on tax software, document portals, CRM systems, bookkeeping software, payroll platforms, cloud storage, email providers and remote employees.
That means protecting taxpayer information also requires understanding who else can access the data.
The FTC Safeguards Rule includes requirements surrounding service providers, making vendor selection and oversight part of the security conversation.
For tax professionals, the question isn’t simply:
“Is my computer secure?”
It’s:
“Is my entire technology ecosystem secure?”
Small firms aren’t exempt from the threat
There’s a dangerous assumption among small businesses:
“Hackers aren’t interested in my little tax office.”
The reality is almost the opposite.
Smaller practices may be attractive because criminals know they often lack dedicated cybersecurity teams, sophisticated monitoring systems and formal security procedures.
A tax office with one owner and two employees may hold hundreds of Social Security numbers.
To a cybercriminal, that’s valuable inventory.
The compliance issue tax pros shouldn’t ignore
The IRS warning also highlights something important for professional tax practices:
Cybersecurity is increasingly becoming a compliance responsibility.
Tax professionals are already accustomed to documenting due diligence around areas such as the EITC, Child Tax Credit and Head of Household filing status.
Data security requires a similar mindset.
Document the policies.
Train the employees.
Control access.
Monitor the systems.
Update the plan.
And document what happens when something goes wrong.
What tax pros should do now
Don’t wait until January.
Before the next filing season, tax practices should review or create their WISP, identify vulnerabilities, confirm employee access permissions, implement multifactor authentication where available, review vendor security practices, establish secure backup procedures and train employees to recognize phishing and social-engineering attacks.
Most importantly, test the plan.
A cybersecurity policy that nobody in the office understands won’t be particularly useful during an actual breach.
The bottom line
For tax professionals, a WISP should increasingly be treated as fundamental business infrastructure.
You wouldn’t operate a tax office without tax software.
You wouldn’t prepare returns without protecting your EFIN.
And you shouldn’t operate a tax practice containing hundreds or thousands of taxpayer records without a written plan explaining how that information will be protected.
The IRS message is straightforward:
Protecting taxpayer information isn’t simply an IT responsibility. It’s part of running a professional tax practice.
Go deeper: IRS Security Summit: Tax pros need a Written Information Security Plan

Learn More
Join us at Emprende Tax Las Vegas this September to learn more about how this will impact Tax Season 2027
WISP CYBERSECURITY
Day 2 – Tuesday September 15
3:30pm to 4:15pm
Responses