The WISP Book Written Information Security Plans for small financial practices

Common questions

Including the last one, which is the question anyone selling compliance material should have to answer in writing.

I'm a sole practitioner. Does this really apply to me?

Yes. The FTC Safeguards Rule sets no minimum headcount, and there is no small-office exemption from the rule itself. Florida's breach statute is explicit that a covered entity includes sole proprietorships. The obligation attaches to the data you hold, not to the size of the office holding it.

What does change with size is scope. A one-person practice holding fewer than 5,000 consumers' information is excepted from four specific requirements — not from the rule. The longer answer is here.

The IRS gives away a template for free. Why would I buy this?

Download Publication 5708. It is free, it is real, and it is the right starting point. Then notice what it consists of: the mandate, an outline, and six blank sample attachments.

A blank form does not tell you what to write in it. It does not tell you whether your situation is one the rule reaches, whether to rely on an exception, what “encrypted” has to mean for you to say it, what to do when your software vendor will not sign anything, or what order to build things in when you have nothing yet. It also cannot tell you that a standard it points to was withdrawn last September.

The book is the part in between the mandate and the blank form. And the free pages on this site are free precisely because facts should be.

Is this just another template?

No, and the distinction is worth being precise about, because it began as one. A template hands you provisions and leaves the choosing to you. This book is a manual with the complete plan in it — the plan takes positions and prints the reasoning for each, which is the line between the two categories.

Three concrete examples. The plan waives the under-5,000-consumer exception rather than claiming it. It adopts semiannual vulnerability scanning and an annual penetration test as firm policy even where § 314.6 would excuse them. It sets notification to the IRS at 24 hours, stricter than the next-business-day baseline. Each of those is a decision a template would have left blank, and each is marked in the book as a position rather than a requirement, with the argument for it and the case for choosing differently.

The formal description is an annotated model Written Information Security Plan — the same shape as a model rule published with its commentary. Eighteen sections and twenty appendices are the instrument; ten chapters are the commentary explaining what each provision commits you to; three considerations mark the questions the book deliberately leaves to you. What is inside, in full.

It still has blanks, and it is meant to. Firm name, named Qualified Individual, the products on your desks. What it does not have is a blank where a judgment should be.

I have fewer than 5,000 clients. Am I exempt?

Two problems with the question, and both matter.

First, the threshold counts consumers, not clients. Those numbers are not close. A practice filing 300 individual returns can be looking at roughly 1,200 consumers, and the 5,000 line tends to bite somewhere around 900 to 1,300 returns. If you do payroll, it arrives much faster: 130 clients at 40 employees each is 5,200 people.

Second, “exempt” is the wrong word. Under 5,000 consumers, four requirements are excepted — the written risk assessment, the testing regime, the written incident response plan, and the annual written report. Everything else still applies. And note what the first exception actually excuses: putting the risk assessment in writing. Not assessing risk.

There is also a question nobody has answered: whether dependents on a joint return, or the employees of a payroll client, count toward the threshold. The FTC has published no counting method. We list that as an open question rather than guessing.

Isn't a WISP a wireless internet provider?

It is, and that industry is much larger online than this one, which is why searching for the acronym is unhelpful. In this context WISP means Written Information Security Plan: the documented security program the FTC Safeguards Rule requires of financial institutions, a category that explicitly includes tax preparation firms.

Where does the requirement actually come from — the IRS?

No, and this is worth getting right because it points you at the correct rulebook. The Gramm‑Leach‑Bliley Act creates the obligation; the FTC Safeguards Rule specifies it. The IRS restates the duty, publishes a template, and enforces through the e‑file program — where the consequences are real, including office visits and suspension.

Related: Form W‑12 line 11 asks whether you are aware of your data security responsibilities. It does not certify that you have a plan. More here.

How much work is this to maintain, once it exists?

Less than building it, and more than nothing. The recurring obligations are a quarterly regulatory check, an annual revisit of the whole plan, annual training with a record of it, an annual written report if you are not excepted from that one, and log entries whenever something happens — a device destroyed, a person given or removed access, an incident.

The realistic failure mode is not that it is too much work. It is that the plan gets built once, filed, and never dated again. A plan whose last date is three years old is worse than useless as evidence: it documents the neglect.

If I buy this book, am I compliant?

No.

Compliance is not a document you own. It is a set of things your firm actually does — and, when someone asks, can show it did. You could adopt every word of the plan in this book, sign every appendix, and still not be compliant, because the appendices would be describing controls you had not implemented.

What the book can do is tell you accurately what the requirements say, help you build a plan that fits a practice your size, show you what evidence to keep, and — through the status page — tell you when something it relies on has changed. It cannot do the work, and it cannot certify the work.

Nobody can sell you compliance. If someone offers to, that is the most useful thing you will learn about them.

Does this cover my state?

The federal layer — GLBA, the FTC Safeguards Rule, and the IRS e‑file requirements — applies wherever you practice. The state layer does not: every state has its own breach notification law, with its own thresholds and clocks.

The book works through Florida in full, as a worked example of how a state layer sits on top of the federal one, and shows you what to look for in yours. It does not contain fifty state chapters, and any book claiming to would be out of date before it shipped.

Something in the book is wrong. What do you do about it?

Tell us, and it goes on the corrections list with what it said, what it should say, which printings are affected, and the date. That list is public and it stays public, including when it is embarrassing.

The book already carries a full record of the corrections applied before publication, for the same reason. That record is here.

Check where you stand Ask something else