The WISP Book Written Information Security Plans for small financial practices

Start here

Twelve questions. About four minutes. At the end you will know where the gaps in your security program are — which is a different thing from knowing how to close them, and a useful thing to know first.

Nothing you enter here is sent anywhere. This runs entirely in your browser. There is no form submission, no account, no cookie, no analytics on your answers, and no “enter your email to see your results.” When you close the tab your answers are gone. It would be a strange thing to write a book about protecting client data and then harvest yours in exchange for a quiz score.

Answer honestly, and answer from memory. If you have to go and look something up, the answer is “not sure” — that is a real finding, not a failure of the quiz. A plan nobody can recall under pressure is not doing its job on the day it matters.

1Is there one named person responsible for your security program — a specific human being, named in writing, not “the office” or “whoever set up the computers”?
2Does your written plan carry a date, and is that date within the last twelve months?
3Have you written down what client data you hold and where it lives — every computer, phone, backup drive, and cloud service?
4Have you worked through what could go wrong with that data — theft, loss, a compromised email account — and recorded what you concluded?
5Is client data encrypted both on your devices and when you send it? Full-disk encryption turned on, and no client documents going out as plain email attachments.
6Does every account that can reach client data require something more than a password — tax software, email, cloud storage, remote access, all of them?
7Has every person with access to client data — employees, contractors, the part-time seasonal help, family members who answer the phone — signed something saying they understand the rules?
8Has everyone had security training in the past year, with a record showing who and when?
9Can you list every outside service that can reach your client data, and show what each one is required to do to protect it?
10When a computer, drive, or box of paper is destroyed, is there a log recording what it was, the date, the method, and who did it?
11If you discovered a breach tomorrow morning, could you say who to call first and by when — right now, without looking it up?
12Do you check your EFIN and PTIN filing counts on a regular schedule, so you would notice returns filed under your numbers that you did not file?
0 of 12 answered