ATL271: Why Your WISP Is Essential in 2026

Download MP3

Brian F. Tankersley, CPA.CITP, CGMA 00:00
Welcome to the Accounting Technology Lab, brought to you by CPA Practice Advisor, with your hosts Randy Johnston and Brian Tankersley.

Randy Johnston 00:09
Welcome to the Accounting Technology Lab. I'm your host Randy Johnston with co-host Brian Tankersley. We've been concerned about many security-related things lately, and one of those is why your written information security plan or WISP is needed in 2026 and beyond more than ever before. And what we'd like to do is step you through some of the key penalties and strategies that you can use inside your WISP. So, Brian, I know that you and I have taught this even before wisps were required by law. So, what do you think is the first things that our listeners should learn about today?

Brian F. Tankersley, CPA.CITP, CGMA 00:52
Well, the cost of the data breaches has continued to grow, and you know the risks associated with data breaches are legion. You know, just beyond the direct costs, there are a lot of IRS, FTC, and HHS penalties, and there are minimum penalties on some of these that are just really obnoxious. You also have huge reputational damage. You know, the we used to not talk about breaches before the notification things, and we've had enough time for those notified the first notified breaches to make their way through. And what we're seeing is that there were huge client exoduses. I was even listening to a podcast yesterday from that was Sean Ryan and the guy that founded Mandiant, the big IT security forensic company. And one of the things he said was that even he was kind of shunned by his bankers and others because they said, "Well, you're an idiot. Why did you have a breach? Okay, and the fact is that this is just something that happens in today, so you really need to be prepared for it. Where again, clients and referrals may dry up, attacks are escalating. There are a lot of AI-driven attacks going on, and so there are a lot of things happening. The firms get hit because you and I are the Fort Knox of confidential data. We're where financial data and tax data and identity data, everything else. Okay, the banks are heavily regulated, and most of them are big, or they use outside processors like you know Data Center Inc. or you know Jack Henry or others like that have crazy secure systems, and they have the FBI. That if you even think about hacking into a bank, the FBI is knocking on your door. On the other hand, the accounting firms don't have that, and most of them are relatively small. The number one entry point is still phishing and credential theft, and again, business email compromise and fraudulent wire instructions made made an appearance this year. We've seen a number of situations where people's where people's accounting software validation was taken over, and fraudulent wire instructions were issued, and the firms got pulled into potential litigation about that. We've also seen ransomware that showed up with data theft and extortion during tax filing season. We actually have w2 and client data scams and insider third party risk. Now I will tell you that this is part of a presentation that actually gave to a IPA 500 firm yesterday, and I will tell you that one of the things I actually did as part of this is I went through my inbox and I pulled out about 10 of the phishing emails that I had received in the previous week, and I will tell you that they are getting better. And you know, again, phishing is is legion, and so you need to be really on guard because the bad guys are getting better faster than the good guys are getting better.

Randy Johnston 03:38
So, Brian, just a thought too for our listeners, you know, you have taught other sessions on privacy laws and regulations, and you and I follow that pretty frequently. We have a prior podcast on that topic, but I was also thinking about my responsibilities on the banks, where we do vendor management, and we don't have anything like that in the CPA world, so unfortunately, any accounting-related systems we don't do as much vendor due diligence as the regulated industries like the banks do. So again, you start thinking about this concentration of confidential data; it does make our accounting firms and our legal firms real targets,

Brian F. Tankersley, CPA.CITP, CGMA 04:23
and I was actually looking at one of the accounting firms. I think it's YHB that's that has been one of your clients in the past, and they actually had on their website a portal where you could get to their information that they had accumulated about their systems, and they made that available for people that had to do that kind of due diligence. So you know this is something that's coming for big accounting firms, and you know again we we've got to bring the firms along because this complexity that we need to add here is is really is really being driven by the financial world and by the threat environment we live in. And so we have again four major sources of rules. We're going to cover the first three. We're not going to cover the state privacy and breach notification laws. We've covered those in previous technology updates. And frankly, there's just too many rules to cover in a single session, you know, for this. So, so we're going to talk a little bit about IRS and GLBA. We're going to talk about FTC safeguards, and then we're going to talk about HIPAA in this session. But again, the key things that you need to take away from IRS regulations are going to be pubs 4557, 50 708, and then the security six, which are their major things that they want you to do. Again, they want IRS when you sign your when you sign the form to get renew your P 10, you assert that your firm has a WISP, a written information security plan, and that is required for every firm, including sole practitioners. Written, okay. Only authorized individuals need to access e services. Credentials can never be shared. Multi-factor authentication is required for all these services and email access. Access is logged. Logs have to be reviewed, and the risk there's a risk assessment performed, and the plan reviewed at least annually. You know, Randy, you want to talk a little bit about some of the core tax data safeguards here?

Randy Johnston 06:18
Yeah. So on those, encryption is clearly needed everywhere. So SSL in transit and at rest, we are encouraging least privilege by role. Many of your firms do not have roles set up, and you know historically we've had the attitude that everybody can get to everything. I don't think that's the way it should be. And as we go forward, there's going to be even more of this with zero trust. We want strong authentication in place, including long, unique passwords, typically stored in a password manager in conjunction with your multi-factor authentication. Clearly, the system log should report who accessed what at what time, and potentially for how long? Also, if you're disposing of equipment, everything should be certified shredded and wiped. And this includes desktops, laptops, wireless access points, copiers, scanners, printers, UPSs. Pretty much everything needs to be wiped.

Brian F. Tankersley, CPA.CITP, CGMA 07:19
And I have to say that in my world, wiping is not enough. Okay, in my world, once it touches PII, personally identifiable information, it's either destroyed with a sledgehammer, with a high-powered rifle, or it is otherwise destroyed in a shredder. Okay, so those devices, you know, anything that touches client data is a death sentence for a hard drive in my office.

Randy Johnston 07:44
Yep, understood completely. And it turns out that there is concern that firms maybe rotate old equipment to employees for that very reason. I think I'm a little more comfortable with that because it's still in the possession of a professional. But that's a debatable point. Now, Brian will talk more about the security six here in a minute, but you should be running antivirus and any malware on every machine with firewalls between the network and the internet, and that's part of the reason we've been recommending the Ubiquiti Dream machines in homes, in addition to firewalls in the office.

Brian F. Tankersley, CPA.CITP, CGMA 08:18
The the other cool thing about those devices is that your IT MSP can remote into those and run those and see them remotely, and so you can have adult supervision on those home networks to make sure crazy things aren't happening, and they'll spit off logs that can be ingested as well.

Randy Johnston 08:37
And so we want multi-factor authentication everywhere with backups always encrypted and at least one kept offline, and that encryption should be on every device. But we are noting that all of the encryptions-BitLocker from Microsoft, Apple's encryption, the Linux encryptions-are all getting compromised with the AI tools, and we've reverted back to VPN for remote and public Wi-Fi access, we like the Dream Machines again because they have a hardware VPN device, but we are finding that the Microsoft VPN is not sufficiently strong. So we have a kind of an odd position that we're in again on VPNs.

Brian F. Tankersley, CPA.CITP, CGMA 09:17
Okay, so let's also. So Randy, you want to talk to us also a little bit about the two, the three governance slides?

Randy Johnston 09:24
Yeah. So it turns out, you know, governance was added into the 5293, 5447, regulation back in February of 24, as I recall, and the governance basically is trying to make sure that your policies are aligned with your firm's strategy, your risk appetite, and all these regulatory requirements we're talking about, and that also makes clear the accountability: who makes the security decision, who approves the changes, and who reports on the compliance. So you get risk managed proactively through a structured process, not just an incident response, which we also think should be in your whisk. Now compliance is sustained by integrating security into governance cycles. In other words, your partner review, board review, or executive oversight. Now, there are a number of governance steps that you can take. We're going to recommend six to you here. First, that you establish a governance structure, which is typically your steering committee, information IT steering committee, and that you have somebody in charge of security inside your firm. That there is a document that is approved and reviewed. That you have change control processes for updating the WISP, and we like to actually document those, that you link the WISP to the organization's enterprise risk framework, if you have one, and that the governance processes should allocate resources for high-risk areas. Now, beyond that, so Brian, if you want to go in advance, thank you. You know that oversight and reporting winds up being a big deal. So regular governance review, quarterly or annually, is what we suspect is needed on the WISP. Many of you are only doing annual security reviews, which may be sufficient. Think about security performance metrics and executive reports. One of our clients has a beautiful security dashboard that he's built for his firm and hands it to the partners on a regular basis. That you also in embed audit and compliance governance in the WISP so it can be maintained and accessible for IRS, FTC, or any other regulators, and that you have stakeholder partner owner engagement, including cross-functional governance for IT legal compliance and operations. So all of those things are supposed to be inside here. But now, what really got Brian's attention, I think, were the penalties. So you want to talk about the WISP penalties, Brian?

Brian F. Tankersley, CPA.CITP, CGMA 11:58
Yeah, the penalties are pretty ugly. We'll talk about the FTC's penalties, which are really where the FTC and HIPAA penalties are really where the money is, because there are minimum penalties there. But if you don't have an adequate WISP, you're in violation of the FTC safeguards rule. Now we'll talk about those, but those are potentially fairly nasty penalties. The bigger issue, though, is that you have potential civil and criminal penalties associated with unauthorized disclosure of tax information and IRS e-file participation issues, where you could get voted off the EFIN island and potentially not be able to electronically file, which is basically a death sentence for your tax practice. If with those issues, we can also we also have a requirement under FTC safeguards, where if you have an unauthorized acquisition that affects at least 500 consumers' unencrypted information, you have to notify the FTC within 30 days. So you have a duty to inform, and there are penalties upon penalties if you don't inform. And so you know, and you talk about 500 consumers, unencrypted information. That's really not much if you start thinking about all the W 2s you have, all the 1090 nines you have, all of those K ones you have. You know, again, just about every accounting practice that does any kind of 1090 nines or W 2s is going to have at least 500 of them in my mind. So one

Randy Johnston 13:17
other call out, Brian, on the 7216 reg, AI CPA has been trying to interpret what should be covered by 7216, including recent town halls, and they're still trying to work with legislators to understand what should be covered. There's even discussion around AI-enabled tools. Do you have to disclose that, you know. Our fundamental interpretation is anything that is offshore is included, or where there's third parties involved. But you know, again, you'll have to continue watch because that's a moving target. The day we've recorded this,

Brian F. Tankersley, CPA.CITP, CGMA 13:58
well, and we've been talking about 7216 for at least 20 years now, and you know the fact is that it's still not completely settled law. So you know we're not you know we're not sure where we're not sure exactly where it's going to go. But next rule, next thing to talk about is going to be FTC safeguards, and I want to get you started with the penalty in here. You know, and again, you have deficiencies where you can have investigations where you're going to have to have legal counsel involved. You can also have injunctions and mandated remediations. Consumers get after you, and potential civil penalties as well. Those civil penalties can also be calculated per violation and per day. $51,000 744 per violation per the FTC notice page after notice of penalty offenses, and the statutory penalties can be as much as 100,000 for a firm and 10,000 for officers and directors, depending on the different GLBA violations. So this is something this can easily bankrupt. Even the most well-funded firms, unless they came in as with you know eight-figure generational wealth, and they can deplete a lot of that. Who's covered again are going to be your firm. The rule does apply to your firm if you handle tax information for sure. Financial institutions or service providers, CPA firms, the whole customer financial information, tax preparers, bookkeepers, financial advisors, and again, any firm handling any kind of financial data for clients. So it doesn't have to be a tax return in there. So there are nine required elements of this. Randy, you want to talk about those?

Randy Johnston 15:35
Yeah. So you have to designate a qualified individual accountable for the program. You have to conduct a written risk assessment. You have to design and implement the safeguards. You have to regularly monitor and test the controls, and you have to train your people. Further, you have to oversee your service providers, keep the program updated and current, and you include a written incident response plan. And you have to report to the board or senior leadership annually, and if you are small, you have less than 5000 consumers. You do not have to do the written risk assessment or the written incident response plan or report to the border senior leadership. Now, just for what it's worth, department, I can't imagine running a firm without an incident response plan. So I'm not sure I'd not do number eight, right? The written risk assessment, okay. I could kind of see that you might be able to in a smaller firm be okay without that, but you know, reporting to your board or your partner group on a regular basis that just seems logical. So the things that are waived when you're small aren't necessarily things I'd skip.

Brian F. Tankersley, CPA.CITP, CGMA 16:47
And I'm going to suggest here that maybe you need to, instead of reporting to your board, if you've done something yourself, maybe you need to put it in front of your managed service provider and let them look at it and review it. Now, four categories of safeguards: administrative, physical controls, technical safeguards, and vendor management. And so, when we look at these administrative and physical things here, administrative includes risk assessment, incident response plan, training policies. Physical is, of course, physical access. Their sensitive data should not be stored anywhere that's not behind lock and key. So, you know, device security, secure disposal, things like that. Your backup drives. You know, if you have backup drives that you carry offsite, like a lot of small firms do, you ought to put them like in a gun safe or in some other kind of secure location. Technical multi-factor authentication, encryption, firewalls, logging, and monitoring. The logging and monitoring is particularly important because we need to be able to know who did what, and the vendor management we need to vet vendors, require safeguards, and reassess.

Randy Johnston 17:50
And notice this particular element is required in banking regulations, but not required here in CPA regulations, which is kind of fascinating. But to me, trying to vet vendors, particularly the smaller vendors, I'm less worried about the bigs, the Walters Clear, the Thomson Reuters. I'm less worried about those providers. But you get somebody that's a new startup; they can be risky to your firm, and just be aware that you've got risk on any provider.

Brian F. Tankersley, CPA.CITP, CGMA 18:23
We also have mandatory self-reporting to the FTC 30 days as soon as possible, no later than 30 days after discovery of a notification event. Notification event is an unauthorized acquisition of encrypted customer information with at least 500 customers. Starts as soon as you discover the event, not when you finish counting customers. So as soon as you know something's happened, the clock is ticking. The other thing about this is you need to get some incident response and some PR response folks in your response plan because the FTC says they're going to publish these in a public database, which means that when it's a slow news day, it's entirely likely that your local TV station is going to go search this database, and if they see your firm listed in here, you know they can make a big hullabaloo out of it. And again, the they may have some help from trial lawyers if, in your jurisdiction, the attorneys have the you know the the attorneys can sue you on behalf of the aggrieved parties. So you know, again, we've got potential all kinds of nastiness that can occur here. So, Randy, you want to talk about HIPAA?

Randy Johnston 19:27
Yeah. So, of course, I've been around HIPAA, having written paperless claims in that environment, working starting as early as the 70s, and I taught a lot of people about HIPAA. But I think the idea of who's at risk for HIPAA is far beyond your healthcare providers. It's our belief that all CPA firms have risk here. We'll explain why, but there's also minimum and maximum violations. So in the tier one, where you didn't know and couldn't reasonably know, minimum violations 140. $5, but the max is 73,011. Reasonable cause, not willful neglect, has a minimum fine of 1461 with the same max of 73 011. Tier three is willful neglect corrected within 30 days. That's 14,006 18, same max of 73,011, but if you have tier four willful neglect not corrected, that gets out of hand real quickly. $73,011 minimum, and two point 1,000,002 2,000,190 294,000 for a max. So you got real dollars here in HIPAA. So as you reflect, then if you audit health plans or hospitals or healthcare providers, or you handle health-related audit evidence or claims data, or if you act as a business associate to a covered entity, if you create, receive, maintain, or transmit protected health information, you know, then you are at risk. And the firm rule is no business associate agreement, no personal health information. Now I want to flip this upside down because many of you who do tax know that you receive a fair bit of medical information on personal tax, so I might suggest that a good portion of your personal tax practice has HIPAA data. So you know this effort of getting a signed business associate agreement is critical. Most of the AI providers won't do a business associate agreement, which tells you something right off the back, where Microsoft will provide one for Copilot, but many of the hosting providers also will not provide a BAA. So all of those things are critical. Of course, PHI data has to be encrypted in transit at rest. Using unique IDs and having no shared credentials is a big deal. It is in the medical profession termination of medical license to share credentials. Just so you're aware, they're that serious about it in the medical profession. And you know, I'm aware of physicians who have lost their license to practice because they were reprimanded for sharing credentials and didn't stop. So audit logs of PHI access become a big deal, and you really have to keep thinking about where the risk is at. So, can you actually run the risk on assets? You know, what sensitive data do you hold? Where does it live? The threats. You know, with the new AI threats in particular, who might try, who might try and reach the data in your firm, whether it's hosted in the cloud or whether it's hosted locally, and how do you assess your vulnerabilities and gaps? It's been clear in 2026 as we've watched the gaps that AI is finding more of those, so we think there are five quick wins that are high impact with low effort, and so Brian, you want to bring us home with those?

Brian F. Tankersley, CPA.CITP, CGMA 23:11
Yes. So these five things, four or five of them, again satisfy the IRS, the FTC, and HIPAA. Multi-factor authentication, which neutralizes stolen password attacks, full disk encryption, tested backup strategies, written incident response plans, vendor security questionnaires. The only one of those that you don't have to have is a tested backup strategy to satisfy IRS, FTC, and HIPAA. And the business risk associated with that backup strategy, I think, means that you have to have that anyway. Now, when we,

Randy Johnston 23:38
by the way, on the full disk encryption, you've already know. I've already noted that I'm worried about encryption being broken by these AI tools.

Brian F. Tankersley, CPA.CITP, CGMA 23:47
For the calendar in here, quarterly, you need to run. You need to review your access logs, test a backup, restore, run phishing simulation, and confirm that terminated user access was revoked. Twice a year, you need to review the run vulnerability scans, review the vendor list and BAAs and recheck your multi-factor authentication coverage once a year. You need to run the risk assessment, deliver security training, update the WISP, and report to leadership. And then, on an ongoing basis, we need to have patch management, alert, monitoring, secure, and security training for new hires on day one. So, Randy, you want to kind of wrap us up here. Yeah.

Randy Johnston 24:21
So, Brian, I'll just mention to our listeners: in June, I actually took the effort to rewrite my AI policies and WISP policies, and I was trying to incorporate governance and the new AI pieces and so forth. If you have paid for a WISP by somebody else, the probability is that it's weak. That's my general rule of thumb, and this iteration may have pretty significant revisions because of governance and some of the new regulations. So make sure that you've got your wisp dust. Pulled out, dusted off, and updated for this year's regulations. Brian and I appreciate your thoughtfulness in structuring this, and I'm glad that you were able to teach another firm on this. But I thought the content was so good it was worth sharing with all of our listeners. We appreciate you listening in today, and we look forward to having you in another accounting technology lab. Good day.

Brian F. Tankersley, CPA.CITP, CGMA 25:22
Thank you for sharing your time with us. We'll be back next Saturday with a new episode of the Technology Lab from CPA Practice Advisor. Have a great week.

Creators and Guests

Brian F. Tankersley
Host
Brian F. Tankersley
Nationally recognized speaker (K2 Enterprises, 48 states in US + Canada) podcaster & author on accounting tech. I’m also a beekeeper, a husband, and a dad.
Randy Johnston
Host
Randy Johnston
Randy Johnston is a nationally recognized educator, consultant, and writer with over 40 years experience in Strategic Technology Planning, Systems and Network Integration, Accounting Software Selection, Business Development and Management, Disaster Recovery and Contingency Planning, and Process Engineering.
ATL271: Why Your WISP Is Essential in 2026
Broadcast by