By Vincent Howard, CPA | Managing Partner, Howard, Howard and Hodges | SkillAbility for Accounting Firms
Last updated: August 21, 2026 | 27-minute read
- What WISP training for tax professionals means
- The current federal WISP / Safeguards Rule baseline
- What the under-5,000-consumer exception does—and does not—mean
- The 2026 threat environment for tax professionals
- Why a written plan does not equal staff behavior
- The WISP READY behavior framework
- Know what data exists and where it can go
- Identity, access, MFA, and least privilege
- Secure handling, transfer, printing, and remote work
- Phishing, new-client scams, and verification behavior
- Incident recognition and immediate reporting
- Devices, apps, vendors, and service providers
- Retention and secure disposal
- Scenario drills and security practice
- Evidence that WISP training is actually operating
- Role-based WISP training by employee level
- 100-point WISP behavior-readiness scorecard
- 30/60/90-day WISP training plan
- 15 realistic tax-firm security scenarios
- What firms should measure
- Frequently asked questions
What Is WISP Training for Tax Professionals?
WISP training is the process of teaching employees, contractors, and other authorized users how to perform the security responsibilities contained in a tax or accounting firm’s Written Information Security Plan—and validating that they can perform them under realistic conditions.
A WISP is not merely a policy acknowledgement.
It is supposed to drive an information security program.
For staff, that means converting statements such as:
- “Use multi-factor authentication.”
- “Protect customer information.”
- “Report suspected security incidents.”
- “Use approved service providers.”
- “Dispose of information securely.”
into operational behavior:
- Which systems require MFA?
- What should the employee do if MFA prompts arrive unexpectedly?
- May a client tax document be downloaded to a personal device?
- May a staff member email an unencrypted PDF containing taxpayer information?
- What is the approved method for sending a return or source documents?
- How does the employee verify a “new client” attachment?
- What should happen if a laptop is lost?
- Who must be notified when suspicious account activity appears?
- Can staff add a browser extension or AI tool that sees client data?
- Where do discarded paper tax documents go?
The Current Federal Baseline: Tax Preparers Are Covered
The IRS said again in June 2026 that tax professionals are required by law to have a Written Information Security Plan and that a WISP is most effective when tailored to the size, scope, complexity, and sensitivity of the information the business handles.
IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice, states that under the Gramm-Leach-Bliley Act and FTC Safeguards Rule, tax and accounting professionals are considered financial institutions regardless of size.
The FTC Safeguards Rule guidance expressly identifies tax preparation firms as covered financial institutions.
The Safeguards Rule is an operating-program requirement
The FTC describes an information security program as administrative, technical, and physical safeguards designed to protect customer information.
The current rule includes requirements relating to:
- A Qualified Individual to implement and supervise the information security program
- Risk assessment
- Access controls
- Data, system, device, platform, and personnel inventory
- Encryption of customer information at rest and in transit, or approved alternative controls where permitted
- Evaluation of apps that access customer information
- Multi-factor authentication for access to customer information, subject to the rule’s limited alternative-control provision
- Secure disposal
- Change management
- Logging and monitoring authorized-user activity
- Monitoring and testing safeguards
- Security awareness training and regular refreshers
- Specialized training for people responsible for the security program
- Service-provider selection, contractual safeguards, monitoring, and reassessment
- Keeping the information security program current
- Incident-response planning
- Governance reporting
- FTC notification for qualifying security events
For this article, one requirement matters especially: the FTC specifically requires security awareness training and regular refreshers for staff.
A signed policy receipt is not the same thing as security awareness training.
2024 breach-reporting requirement remains in effect
The FTC Safeguards Rule’s breach-notification amendment took effect May 13, 2024.
Covered financial institutions generally must notify the FTC as soon as possible and no later than 30 days after discovering a notification event involving the unauthorized acquisition of unencrypted customer information of at least 500 consumers, as defined by the rule.
The rule also treats encrypted information as unencrypted for this purpose when the encryption key was accessed by an unauthorized person.
That requirement belongs in leadership’s incident-response design.
Staff behavior must support it by ensuring suspected events are reported internally immediately—not after someone spends days investigating alone.
Small Tax Firm? The 5,000-Consumer Exception Is Not a WISP Exemption
This is an important point to get right.
Under 16 CFR § 314.6, financial institutions maintaining customer information concerning fewer than 5,000 consumers are exempt from specific provisions:
- § 314.4(b)(1)
- § 314.4(d)(2)
- § 314.4(h)
- § 314.4(i)
That is not the same as being exempt from the Safeguards Rule.
For example, the staff-training provision, access-control provisions, MFA requirement, encryption provisions, service-provider requirements, and other safeguards are not erased simply because the firm is small.
Do not train small firms with the message, “We have fewer than 5,000 clients, so the Safeguards Rule does not apply.”
The exception is limited to specified provisions. Firms should evaluate their exact legal obligations with qualified counsel/cybersecurity advisers and the current rule.
Why WISP Training Is Especially Relevant in 2026
The IRS and Security Summit launched their eleventh annual “Protect Your Clients; Protect Yourself” summer series in July 2026 specifically to address evolving threats against tax professionals.
The IRS warned about:
- IRS impersonation by email, text, phone, direct messages, spoofed caller ID, and computer-generated calls
- “New client” spear-phishing schemes using malicious links or attachments disguised as tax documents
- Attempts to steal EFINs, PTINs, CAF numbers, and related documents
- Malware and credential theft
- Social-engineering requests that appear to come from trusted people
In August 2026, the IRS again warned tax professionals about phishing emails and other attacks aimed at stealing sensitive taxpayer data.
The firm’s threat model therefore cannot be limited to a hacker “breaking into the network.”
The attacker may simply convince a busy employee to open a document, approve an MFA prompt, share a credential, move a client file into an unsafe application, or respond to a fraudulent request.
Tax season creates perfect social-engineering conditions
Attackers benefit from:
- High email volume
- New clients
- Attachments from unfamiliar senders
- Urgent deadlines
- Staff working remotely
- Temporary employees
- Clients sending documents in inconsistent ways
- Partners asking for fast turnaround
That means tax firms should train the behavior under the conditions in which the mistake is likely to occur.
The WISP-to-Behavior Gap
A firm can have a thoughtful written plan and still be operationally exposed.
Policy says:
“All employees must protect customer information from unauthorized access.”
Staff member experiences:
A long-time client emails: “I’m traveling and can’t access the portal. Please send my return to this Gmail address today. My banker is waiting.”
Now the employee has to know:
- Whether the request must be independently verified
- Whether ordinary email is approved
- What secure transfer method to use
- Whether the new address can be trusted
- Who can approve an exception
- What to document
That gap between policy language and live decision-making is where training belongs.
A good WISP states the rule.
A good procedure tells employees what to do.
Good training lets them practice when the answer is not obvious.
Good governance gives the firm evidence that the process is actually operating.
The WISP READY Framework: Turn the Plan Into Nine Staff Behaviors
| Stage | Behavior Question | Evidence |
|---|---|---|
| W — Where is customer information? | Do staff know approved systems, locations, devices, and transfer paths? | Data map, approved-system list, clean-desk/download rules |
| I — Identity & access control | Can the right person get the right access—and only that access? | MFA, access approvals, periodic access review, offboarding |
| S — Secure handling & transmission | Can staff safely open, store, print, share, and move client information? | Portal/encryption procedures, device rules, physical safeguards |
| P — Phishing & verification | Can employees pause and verify unusual requests before acting? | Simulations, verification protocol, phishing-report behavior |
| R — Report incidents immediately | Does the employee know the first action and first contact? | Incident card, hotline/channel, drill results, response log |
| E — Evaluate devices, apps & vendors | Do people avoid unapproved tools and route new technology for security review? | Approved-app list, vendor review, change-control process |
| A — Apply retention & disposal rules | Do staff keep what is required and securely dispose of what is not? | Retention schedule, shred/destruction procedure, disposal evidence |
| D — Drill realistic decisions | Have employees practiced likely security events before tax season? | Scenario scores, phishing exercises, tabletop drills |
| Y — Year-round proof & updates | Can the firm show training, corrective actions, access changes, incidents, and plan updates? | Training log, acknowledgements, test results, review cadence |
WISP READY is not a replacement for the firm’s WISP or the FTC rule.
It is a training translation layer.
W — Train Staff to Know Where Customer Information Is Allowed to Exist
The FTC requires covered businesses to understand the information ecosystem, including where customer information is collected, stored, and transmitted, and to maintain an accurate inventory of systems, devices, platforms, and personnel.
Staff do not need to memorize the entire enterprise inventory.
They do need to know the approved path for the data they touch.
Train the data path
Questions staff should answer without guessing
- Where should incoming client documents be saved?
- Can files remain in the Downloads folder?
- Can a document be saved to the desktop?
- Can tax data be copied into a personal note app?
- Can the employee upload a document to a free PDF converter?
- Can client data be pasted into a public AI tool?
- Can the employee sync a client folder to a personal cloud account?
- What happens to temporary scan files?
- Where may printed taxpayer documents be left?
The security plan becomes useful when the answer is explicit.
I — Identity, Access, MFA, and Least Privilege
The FTC Safeguards Rule requires periodic access-control review and multi-factor authentication for anyone accessing customer information on covered systems, subject to the rule’s limited written alternative-control provision.
For staff, the training should be behavioral.
MFA behavior
Employees should know:
- Never approve an MFA prompt they did not initiate
- Unexpected MFA prompts may indicate credential compromise
- Report repeated unexpected prompts immediately
- Do not share MFA codes
- Do not let another employee use their authenticated session
- Do not bypass controls to meet a deadline
Access behavior
Train:
- Use only assigned credentials
- Do not share passwords
- Lock devices when stepping away
- Request access through the approved process
- Do not keep access because “I might need it later”
- Report access that appears broader than job need
- Report a terminated employee or contractor access issue immediately
New-hire readiness should include security readiness before production access. SkillAbility’s Staff Accountant Competency Checklist uses the same principle: controlled client work should begin only when the employee has demonstrated the required technical, workflow, documentation, judgment, and client-information behaviors.
S — Secure Handling, Transmission, Printing, and Remote Work
The FTC guidance requires encryption of customer information on systems and in transit, or effective alternative controls approved as provided by the rule when encryption is infeasible.
Employees need the firm’s exact procedures.
File transmission
Train staff to distinguish:
- Approved secure client portal
- Approved encrypted-email process
- Approved secure file exchange
- Ordinary email
- Text message
- Personal cloud links
- Consumer file-transfer services
A firm policy that says “use secure methods” is not enough.
Name the approved methods.
Remote work
Role-specific training should address:
- Firm-owned versus personal devices
- VPN use where required
- Public Wi-Fi
- Home router security
- Screen privacy in shared spaces
- Local downloads
- Home printing
- Paper disposal
- Device locking
- Lost or stolen equipment
Physical data still counts
The Safeguards Rule covers customer information in paper as well as electronic form.
Staff should know:
- Where paper files may be stored
- Whether desks must be cleared
- How printouts are retrieved from shared printers
- Where sensitive paper is shredded
- What may be taken home
- What happens to handwritten client notes
P — Phishing, “New Client” Scams, and Verification Before Action
The IRS warned again in 2026 about spear-phishing aimed specifically at tax professionals.
One recurring method is the “new client” scam: a criminal poses as a prospective client and sends a malicious attachment or link disguised as tax information.
Do not train phishing as a list of ugly-email clues
Modern phishing can have:
- Correct grammar
- A believable signature
- A familiar brand
- A realistic PDF or document name
- A spoofed or lookalike domain
- Urgent but plausible business context
- AI-generated personalization
Train verification behavior instead.
The VERIFY-before-action rule
| Trigger | Required Behavior |
|---|---|
| Unexpected attachment from new prospect | Use the firm’s new-client intake/verification process before opening or downloading |
| Client changes email or bank information | Independently verify through an established trusted channel |
| Partner requests unusual sensitive file transfer | Verify if the request is inconsistent with normal procedure—even when the sender appears internal |
| Unexpected MFA prompt | Deny; do not approve; report |
| Message asks for EFIN/PTIN/CAF document | Pause and route through the firm’s verification/escalation procedure |
This is professional skepticism applied to security.
See Professional Skepticism Training for Junior Accountants: the employee needs permission and practice to challenge something that looks complete or legitimate before trusting it.
R — Reporting a Suspected Incident Must Be Easier Than Hiding It
Security training fails if the employee’s first thought after a mistake is:
“Maybe nothing happened. I don’t want to get in trouble.”
The firm needs immediate reporting.
IRS guidance says tax professionals that experience data theft should report it to their local IRS Stakeholder Liaison immediately; speed is critical because the IRS may be able to take steps to block fraudulent returns. The IRS also directs tax professionals to appropriate state tax-agency reporting resources.
Train the first five minutes
Employees should know:
- Stop the risky activity
- Do not delete evidence or “clean up” the problem unless instructed
- Disconnect a device if the firm’s response procedure requires it
- Call or message the designated internal security contact immediately
- State what happened, what system/data may be involved, and when
- Follow instructions from the incident-response team
Examples of reportable internal events
- Clicked suspicious link
- Opened unexpected attachment
- Approved unexpected MFA request
- Entered credentials into a suspicious site
- Lost device
- Sent taxpayer data to wrong recipient
- Used unapproved cloud/AI tool with client information
- Client says they received an email the employee did not send
- Unexplained e-file rejection
- Unexpected software behavior or remote cursor movement
- Unauthorized account login alert
E — Devices, Apps, Vendors, and Service Providers
One of the fastest ways around a firm’s security program is an unapproved convenience tool.
Examples include:
- Free PDF tools
- Browser extensions
- AI assistants
- Personal cloud drives
- Document-signing apps
- File converters
- Texting platforms
- Remote access tools
The FTC requires covered businesses to assess apps that store, access, or transmit customer information and to select and monitor service providers capable of maintaining appropriate safeguards.
Staff training rule
Train staff to:
- Use only approved applications
- Request review before adding a tool that may receive client data
- Never upload customer information merely to “test” a new service
- Understand which AI tools, if any, are approved for sensitive information
- Report an app or integration behaving unexpectedly
This is increasingly important as AI is embedded into tax and accounting workflows. See AI Accounting Training: Building Judgment in New Staff for training people to validate automated systems rather than treating output or convenience as proof of safety.
A — Apply Retention and Secure Disposal Rules
The FTC guidance requires secure disposal of customer information no later than two years after the most recent use to serve the customer unless a legitimate business need, legal requirement, or feasibility exception applies under the rule.
That does not mean tax firms should blindly destroy every record at two years.
Tax, professional, litigation, insurance, state, client, and other retention requirements may justify longer retention.
The staff behavior is simpler:
- Follow the firm’s approved retention schedule
- Do not make personal archives
- Do not keep client files “just in case” outside approved systems
- Use approved paper destruction
- Use approved electronic disposal
- Do not repurpose old devices before the firm’s secure-disposal process
D — Drill the Security Decisions Tax Staff Will Actually Face
Annual awareness slides are not enough.
WISP training should include scenarios.
Scenario-Based Training for Accountants is built around the principle that professional judgment develops when people practice realistic decisions with incomplete information and consequences before live client work.
Security should be trained the same way.
Scenario design
A strong exercise requires the learner to:
- Recognize the risk
- Identify the policy/procedure
- Choose an action
- Explain why
- Communicate appropriately
- Escalate when required
- Document the event or exception
Practice under time pressure
Do not make every scenario obvious.
Use:
- Busy tax deadline
- Partner requesting urgent turnaround
- VIP client
- New-client attachment
- Employee working from home
- Client who refuses portal use
- Temporary employee
- Unexpected MFA prompt
- New AI tool
Security behavior becomes reliable when employees have practiced choosing the secure action even when the insecure action is faster.
Y — Build Evidence That WISP Training Is Operating
The goal is not paperwork for paperwork’s sake.
The firm should be able to show how security responsibilities are trained, monitored, corrected, and updated.
Useful evidence can include
- Training completion records
- Role-based training assignments
- Policy acknowledgements
- Scenario scores
- Phishing simulation results
- Remedial coaching
- MFA enrollment status
- Access approvals and periodic reviews
- Onboarding/offboarding checklists
- Approved software/app list
- Service-provider review records
- Security incident log
- Tabletop-exercise notes
- WISP update history
- Corrective action documentation
A signed acknowledgement proves the employee received a document.
A simulated new-client phishing exercise provides evidence the employee can apply the rule.
WISP Training Should Be Role-Based
| Role | Minimum Training Emphasis |
|---|---|
| All staff | MFA, phishing, approved systems, client-data handling, incident reporting, physical security, remote work |
| Tax preparers / accountants | Source-document intake, secure transfer, tax software access, e-file credentials, new-client verification, sensitive workpapers |
| Seniors / reviewers | Detect unsafe workarounds, review access/process exceptions, coach staff, escalate suspicious patterns |
| Managers | Access approvals, vendor/app exceptions, incident escalation, staff compliance, remote team controls, corrective action |
| Partners / leadership | Governance, WISP ownership, risk acceptance, service providers, incident decisions, regulatory reporting, resourcing |
| Qualified Individual / security leads | Specialized current security training, safeguards, monitoring/testing, threat changes, incident management, program updates |
| Temporary / seasonal staff | Same applicable security behaviors before access; short tenure is not a security exception |
WISP Training Should Be Event-Based, Not Only Annual
Annual refreshers are useful.
They are not enough by themselves.
Trigger additional training when:
- Employee starts
- Role/access changes
- New application is deployed
- Remote-work process changes
- New service provider handles client data
- Firm adopts an AI tool
- Security incident occurs
- Phishing campaign changes
- Testing exposes a weakness
- WISP changes materially
- Tax season begins
Turn Onboarding Into a Security Gate
Do not give a new employee broad client access and then schedule security training for Friday.
Before client access, validate:
- Security awareness training
- MFA enrollment
- Approved-device configuration
- Password/access procedure
- Portal and file-transfer procedure
- Phishing/new-client verification
- Incident-report channel
- Remote-work rules
- Approved application list
This supports the broader SkillAbility principle in How to Train Accounting Staff: live client work should test readiness, not host the employee’s first attempt at a critical behavior.
Create a Security Exception Queue
Not every security issue is an incident.
Some are unresolved control exceptions that need ownership.
| Exception | Risk | Owner | Due | Status |
|---|---|---|---|---|
| Seasonal user retains prior-year access | Unauthorized access | IT / manager | Immediate | Open |
| Unapproved PDF tool used once | Data exposure | Security lead | Immediate assessment | Investigating |
| Shared printer output left overnight | Physical disclosure | Office lead | Today | Correcting |
| New integration requests full client-drive access | Third-party access | Qualified Individual | Before activation | Blocked pending review |
100-Point WISP Behavior-Readiness Scorecard
| Capability | Points | Observable Evidence |
|---|---|---|
| Approved data location & handling | 12 | Employee stores and moves client data only through approved paths |
| Identity / MFA / access | 12 | MFA used correctly; no shared credentials; access exceptions reported |
| Secure transfer & remote work | 12 | Approved portal/encryption/device procedures followed |
| Phishing / verification judgment | 15 | Suspicious requests are paused, verified, and reported |
| Incident recognition & reporting | 15 | Employee reports immediately without self-investigating or concealing |
| Approved apps / vendor behavior | 10 | No client data enters unapproved tools; new tools routed for review |
| Physical security / disposal | 7 | Paper, devices, and records follow retention/destruction controls |
| Scenario-drill performance | 8 | Employee applies security rules under realistic tax-work pressure |
| Role-specific responsibilities | 5 | Employee knows additional duties attached to reviewer/manager/admin role |
| Documentation & refresh | 4 | Training and corrective action are documented and current |
Suggested interpretation
- 90–100: Ready for normal client-data access within role and controls.
- 80–89: Generally ready; remediate identified gaps promptly.
- 70–79: Controlled access and targeted retraining recommended before broader responsibility.
- Below 70: Additional structured practice before routine sensitive-data access.
A serious security event, deliberate bypass of controls, concealed incident, shared credentials, unsafe client-data upload, or repeated failure to report suspicious activity should override the numerical score.
A 30/60/90-Day WISP Training Plan
| Period | Goal | Practice | Evidence |
|---|---|---|---|
| Days 1–30 | Secure access & handling | MFA, data map, approved systems, portal, remote work, physical security, incident channel | Access gate + scenario validation |
| Days 31–60 | Threat recognition & verification | Phishing, new-client scams, unusual requests, vendor/app decisions, misdirected data | Scenario scores + corrective coaching |
| Days 61–90 | Incident behavior & role ownership | Tabletop incident, lost device, access change, new app, manager escalation, after-action review | Observed response + documented readiness |
Days 1–30: Security before production
Require the employee to demonstrate:
- Correct login/MFA
- Approved source-document intake
- Secure delivery
- Proper file storage
- Lock-screen behavior
- Remote-work procedure
- Incident-report contact
- Prohibited tool examples
Days 31–60: Make the scenarios believable
Use:
- New prospective client
- Changed email address
- Partner impersonation
- Unexpected SharePoint/Dropbox-style link
- MFA fatigue prompt
- EFIN request
- Client refusing the portal
- AI tool suggesting upload
Days 61–90: Practice recovery behavior
Do not train only prevention.
Practice:
- Clicked link
- Credential exposure
- Lost laptop
- Misdirected email
- Suspicious e-file activity
- Unapproved app usage
The learner should know the first action and the first internal contact without consulting the WISP.
15 Realistic WISP Training Scenarios for Tax Professionals
Scenario 1: The new-client ZIP file
A prospect sends “2025 Tax Docs.zip” and says they found the firm on Google. The learner must use the firm’s intake/verification process before interacting with the attachment.
Scenario 2: The unexpected MFA prompt
The employee receives three MFA requests while not logging in. The correct response is not “approve one to make them stop.”
Scenario 3: The client changes email
A long-time client asks for a return at a new personal email address. The learner must independently verify the change using the firm’s trusted-channel procedure.
Scenario 4: The partner needs it now
A message appearing to come from a partner asks the employee to send a client tax package outside the normal portal because “the deal closes in 20 minutes.”
Scenario 5: The free PDF converter
A secured PDF will not open correctly, and a web search produces a convenient online converter. The learner must not upload client data to an unapproved tool.
Scenario 6: The public AI tool
The employee wants help summarizing a client’s tax notice and considers pasting the notice, including taxpayer information, into an unapproved AI assistant.
Scenario 7: The home printer
A remote employee prints source documents for easier review. Training must address whether this is allowed and how paper is secured and destroyed.
Scenario 8: The wrong recipient
An employee sends an attachment to the wrong John Smith. The scenario evaluates immediate incident reporting rather than whether the employee can “recall” the email.
Scenario 9: The lost laptop
A firm laptop is left in a rideshare. The learner must know the immediate internal contact and response steps.
Scenario 10: The seasonal employee returns
A seasonal preparer still has active access from the prior year before formal re-onboarding. Staff should recognize access as a security-control issue.
Scenario 11: The EFIN document request
An email appearing to come from a software provider requests the firm’s EFIN documentation to avoid suspension.
Scenario 12: The suspicious e-file rejection
A client’s return rejects because a return using the taxpayer’s Social Security number may already have been received. The employee must escalate immediately.
Scenario 13: The new browser extension
A staff member wants a productivity extension that can read page content in the browser where tax documents are displayed.
Scenario 14: The old hard drive
An office computer is being replaced and someone suggests donating it after deleting the client folders.
Scenario 15: The employee clicked
The learner clicked a suspicious new-client link 10 minutes ago and sees nothing unusual. The test is whether they report now—not whether they wait for evidence of compromise.
What Should a Tax Firm Measure?
Do not measure WISP training only by completion rate.
| Metric | What It Reveals |
|---|---|
| Security training completion | Baseline participation—not behavior by itself |
| MFA enrollment / compliance | Identity-control implementation |
| Phishing simulation report rate | Whether employees recognize and report suspicious activity |
| Phishing simulation click / credential rate | Where targeted retraining is needed |
| Time from suspected event to internal report | Incident-response behavior |
| Unapproved-tool exceptions | Shadow IT / AI risk |
| Access-review exceptions | Least-privilege / offboarding quality |
| Scenario-readiness score | Ability to apply policy under realistic conditions |
| Repeat security behavior errors | Whether corrective coaching transfers |
| WISP / training update cycle | Whether the program changes as systems and threats change |
Common WISP Training Mistakes
Mistake 1: Email the WISP and collect signatures
Acknowledgement is useful evidence that employees received the policy. It is not proof they can apply it.
Mistake 2: Train cybersecurity generically
Tax firms need scenarios involving portals, source documents, EFIN/PTIN/CAF information, tax software, new-client attachments, client impersonation, e-file anomalies, and tax-season pressure.
Mistake 3: Treat small firms as exempt
The under-5,000-consumer provision is a limited exception to specified Safeguards Rule requirements, not a blanket exemption.
Mistake 4: Make reporting feel punitive
Employees hide mistakes when the culture rewards silence. Speed matters more than embarrassment in the first minutes of a potential event.
Mistake 5: Train phishing once a year
Attack methods change and employee vigilance decays. The FTC calls for security awareness training and regular refreshers.
Mistake 6: Ignore physical information
Paper tax documents remain customer information.
Mistake 7: Ignore app and AI sprawl
A modern security program must account for tools that store, access, transmit, or process customer information.
Mistake 8: Train staff but not partners
A partner who requests an unsafe workaround teaches employees that deadlines outrank the WISP.
Mistake 9: Focus only on prevention
Employees also need to know what to do when a click, loss, misdirected file, or suspicious login has already occurred.
Mistake 10: Never test transfer
Training should be judged by whether behavior changes under real work conditions.
How SkillAbility Fits WISP Behavior Training
Security awareness should not live only inside annual compliance content.
It belongs inside the employee’s workflow development.
BASE — Secure execution
Practice:
- Approved systems
- Client-data intake
- MFA
- Secure file handling
- Remote work
- Incident reporting
MAPS — Security judgment
Practice:
- New-client verification
- Phishing decisions
- Unusual client requests
- AI/tool boundaries
- Client communication when secure process creates friction
- Escalation
SUMMIT — Security leadership
Develop managers who can:
- Coach secure behavior
- Review exceptions
- Protect access discipline
- Escalate incidents
- Model policy-compliant behavior under deadline pressure
- Help leadership identify where the WISP and actual workflow diverge
The larger principle matches The CPA Firm Capability Map: technical execution is only one layer. Workflow fluency, documentation, judgment, escalation, and communication determine whether staff can operate independently without creating risk.
Frequently Asked Questions About WISP Training for Tax Professionals
Are tax preparers required to have a WISP?
Yes. The IRS states that tax professionals are required by law to create, implement, and maintain an information security plan to protect client data. IRS Publication 5708 explains that tax and accounting professionals are treated as financial institutions under the GLBA/FTC Safeguards Rule.
Does a one-person tax firm need a WISP?
IRS guidance says the requirement applies regardless of firm size. The plan should be appropriate to the firm’s size, complexity, activities, and sensitivity of customer information.
Are firms with fewer than 5,000 consumers exempt from the Safeguards Rule?
No. 16 CFR § 314.6 exempts those firms from specific provisions in § 314.4(b)(1), (d)(2), (h), and (i). It is not a blanket exemption from the Safeguards Rule.
Does the FTC Safeguards Rule require employee training?
Yes. The FTC requires security awareness training and regular refreshers. It also calls for specialized training for people responsible for implementing the information security program.
Is multi-factor authentication required for tax firms?
The FTC Safeguards Rule requires multi-factor authentication for anyone accessing customer information on covered systems, subject to the rule’s written equivalent-control provision. Firms should implement the requirement according to their environment and current legal/security advice.
Does client data need to be encrypted?
The FTC guidance requires covered firms to encrypt customer information on systems and when transmitted, unless encryption is infeasible and an effective alternative control is approved as permitted by the rule.
What should WISP training cover?
At minimum, training should translate the firm’s own WISP into the employee’s role: data locations, access, MFA, passwords, secure transmission, remote work, physical security, phishing and verification, approved apps, vendors, incident reporting, retention/disposal, and role-specific responsibilities.
How often should WISP training occur?
The FTC calls for security awareness training and regular refreshers. Firms should also train when employees start, roles or access change, systems/apps change, new threats emerge, incidents occur, or the WISP changes materially.
What is the best way to train staff on phishing?
Use realistic tax-firm scenarios, verification protocols, phishing simulations, and immediate coaching. Train employees to pause and independently verify unusual requests rather than relying only on visual clues in an email.
What should an employee do after clicking a phishing link?
Follow the firm’s incident procedure immediately. The employee should not wait to see whether something bad happens or attempt to investigate alone. Fast internal reporting allows the firm’s response team to determine containment, evidence preservation, notifications, and external reporting.
Who should tax professionals contact after a data theft?
The IRS instructs tax professionals to report client data theft to their local IRS Stakeholder Liaison immediately and directs them to state tax-agency reporting resources. Other reporting duties—including FTC notification for qualifying events and state breach notices—depend on the event and applicable law.
When must a Safeguards Rule event be reported to the FTC?
The current rule generally requires notification as soon as possible and no later than 30 days after discovery of a notification event involving unauthorized acquisition of unencrypted customer information of at least 500 consumers, as defined in the rule.
Can tax staff use AI tools with client information?
Only according to the firm’s approved security, confidentiality, vendor, and technology policies. Employees should never assume a public or consumer AI tool is approved for taxpayer information merely because it is convenient or useful.
Does a signed WISP acknowledgement count as training?
It can document that the employee received or acknowledged the policy, but it does not by itself demonstrate security awareness or the ability to apply the policy. Role-based instruction, realistic scenarios, refreshers, and observed behavior provide stronger training evidence.
What is WISP READY?
WISP READY is SkillAbility’s behavior-training framework: Where customer information is allowed, Identity/access, Secure handling, Phishing/verification, Report incidents, Evaluate apps/vendors, Apply retention/disposal, Drill decisions, and Year-round evidence/updates.
Current Research and Authority Resources
- IRS Tax Tip 2026-49 — Written Information Security Plans Are Essential for Tax Pros
- IRS Publication 5708 — Creating a Written Information Security Plan for Your Tax & Accounting Practice
- IRS Publication 4557 — Safeguarding Taxpayer Data
- IRS — Identity Theft Information for Tax Professionals
- IRS / Security Summit — Protect Your Clients; Protect Yourself, Summer 2026
- IRS IR-2026-85 — Phishing and Other Attacks Against Tax Professionals
- FTC — Safeguards Rule: What Your Business Needs to Know
- 16 CFR Part 314 — Standards for Safeguarding Customer Information
- 16 CFR § 314.6 — Exceptions
- Google Search Central — Optimizing for Generative AI Features
Cybersecurity and breach duties are fact-specific and change over time. Firms should coordinate WISP design and incident response with qualified cybersecurity professionals, legal counsel, insurers, software providers, and relevant federal/state authorities as appropriate.
The Bottom Line
A WISP cannot protect taxpayer data from inside a filing cabinet.
It has to appear in daily behavior.
Train where customer information is allowed.
Train identity, MFA, and access.
Train secure storage and transmission.
Train employees to verify unusual requests.
Train immediate incident reporting.
Train approved app and vendor behavior.
Train retention and secure disposal.
Practice realistic tax-firm security decisions.
Keep evidence and refresh the behavior as systems and threats change.
That is WISP READY.
The strongest security plan is not the longest PDF.
It is the plan employees can execute when a new client sends an attachment at 4:45 p.m. on April 14.
It is the employee who denies an unexpected MFA prompt.
It is the senior who stops an unapproved upload.
It is the manager who refuses to bypass the portal because a client is impatient.
It is the staff member who reports a mistaken click immediately instead of hoping nothing happened.
And it is the firm that can show those behaviors are trained, practiced, measured, corrected, and updated.
Write the plan.
Translate the procedure.
Practice the decision.
Prove the behavior.
Protect Knowledge. Develop People. Scale the Firm.
Would Your Staff Know What to Do Before—or After—the Security Incident?
SkillAbility helps accounting firms convert firm policies and expert knowledge into structured, scenario-based practice that builds workflow discipline, professional skepticism, escalation judgment, review readiness, and measurable staff behavior before live client work exposes the gap.
Book Your Free 10-Minute Structural Alignment Review →
Includes our 45-Day Out-of-Pocket Performance Guarantee.
To firms that turn written standards into everyday capability,
Vincent Howard, CPA
Managing Partner, Howard, Howard and Hodges
SkillAbility for Accounting Firms
About the Author
Vincent Howard, CPA has practiced public accounting since 1990. He earned a Bachelor of Science in Accounting and a Master’s in Taxation from the University of Central Florida, founded his accounting firm in 1993, and serves as Managing Partner of Howard, Howard and Hodges. He helped grow the organization from three people to approximately 50 staff across multiple Florida locations and states. He has participated in PASBA since 1997, and the firm was named PASBA Firm of the Year in 2015. Since 2020, he has built and run the SkillAbility accounting workforce development platform, used by more than 1,000 accounting professionals across dozens of PASBA firms.
How This Guide Was Developed
This guide combines Vincent Howard’s public-accounting and workforce-development experience with the current FTC Safeguards Rule and small-entity exceptions, IRS Publications 5708 and 4557, the IRS/Security Summit 2026 Protect Your Clients; Protect Yourself campaign, current IRS incident-reporting guidance for tax professionals, and SkillAbility’s scenario-based development methodology. The WISP READY framework and behavior-readiness scorecard are SkillAbility training frameworks designed to translate written security requirements into observable employee actions.
© 2026 SkillAbility for Accounting Firms. This article provides general educational information and does not replace cybersecurity, information-security, privacy, legal, incident-response, insurance, regulatory, state-law, professional-standards, or other qualified advice.
