Skip to main content

Compliance-focused cybersecurity

FTC Safeguards Rule and WISP compliance for CPA and accounting firms

Firms that prepare tax returns fall under the FTC Safeguards Rule. KairosIT helps CPA and accounting firms build a WISP that matches how the firm really works, then run and document the controls behind it.

WISP Gap Assessment

Request a readiness review

Book a WISP Gap Assessment and get a practical FTC Safeguards readiness check of your written plan, MFA, encryption, vendors, and incident response.

  • Managed IT
  • Cybersecurity
  • Microsoft 365
  • Backup & recovery
  • Compliance readiness

Who this helps

CPA firms, tax practices, enrolled agents, and accounting firms that handle client tax and financial data

Most firms know they need a WISP. The gaps are usually behind it:

  • A template filed once and never updated
  • MFA and encryption that stop short
  • No security review of software and portal vendors
  • No written incident response plan
  • Hard questions from PTIN renewal, insurers, or clients

Common roadblocks

Are compliance gaps creating business risk?

Most regulated organizations do not fail because one tool is missing. They struggle because identity, documentation, support, security, backup, and day-to-day process are not working together.

01

Unclear ownership

Teams know the requirement matters, but no one owns the technical roadmap from gap review to remediation.

02

Weak access control

Microsoft 365, devices, shared mailboxes, admin accounts, and vendor access need tighter review.

03

Missing evidence

Policies may exist, but leadership still needs usable proof of backups, monitoring, patching, and response.

04

No practical plan

Audit pressure, client requirements, or cyber insurance requests create urgency without clear next steps.

What matters

Compliance pressure usually exposes operational IT gaps

01

Controls

What the FTC Safeguards Rule requires:

  • A written security program (your WISP)
  • A designated Qualified Individual
  • A written risk assessment
  • Access controls, encryption, and MFA
  • Secure disposal and change management
  • Continuous monitoring or periodic testing
  • Staff security training
  • Service provider oversight
  • A written incident response plan
  • A yearly written report to leadership
  • FTC notice for breaches of 500+ consumers

Based on 16 CFR Part 314 and IRS Publications 5708 and 4557.

02

Operations

How KairosIT helps:

  • Support for your Qualified Individual
  • Written risk assessment and updates
  • WISP writing and annual review
  • MFA, encryption, EDR, and patching
  • Microsoft 365 and email security
  • Vendor security reviews
  • Incident response planning
  • Help preparing the annual report to firm leadership
  • Security awareness training

What we manage

Managed IT services that support FTC Safeguards & WISP readiness

KairosIT connects compliance pressure to the real systems your team uses every day, so the work becomes operational instead of theoretical.

Identity & access

User access, admin accounts, MFA, conditional access, onboarding, offboarding, and permission reviews.

Microsoft 365 security

Email security, SharePoint, Teams, OneDrive, retention, auditability, and configuration hardening.

Endpoint protection

Device management, patching, antivirus, endpoint detection, encryption, and security baselines.

Backup & recovery

Backup monitoring, restore testing, business continuity planning, and recovery expectations.

Monitoring & response

Alerting, escalation, incident readiness, documentation, and recurring security visibility.

Roadmap planning

Prioritized remediation, leadership reporting, budget planning, and practical next steps.

< 30 min Avg. response target
24/7 Monitoring & alerting
M365 + Azure Cloud security work
Security-first Built into every plan

How KairosIT helps

Practical readiness, not checkbox theater

  • WISP Gap Assessment: review your plan, systems, users, and vendors.
  • Map gaps in MFA, encryption, access, vendors, and incident response.
  • Prioritize fixes around filing-season deadlines.
  • Write or update your WISP to match what you actually run.
  • Keep it current with monitoring, training, and annual review.

Book a Discovery Call to schedule your WISP Gap Assessment.

Our process

A simple step-by-step path from pressure to plan

We help you move from “we need to deal with this” to a clear roadmap your leadership team can understand, fund, and execute.

1

Discover

We review your business context, current technology, risk, and what triggered the requirement.

2

Map

We connect the requirement to your identity, endpoint, Microsoft 365, backup, and support environment.

3

Prioritize

We separate urgent gaps from nice-to-have work so the roadmap is realistic.

4

Execute

We help remediate, document, monitor, and improve the environment over time.

FAQ

Questions about FTC Safeguards & WISP

Does my CPA or tax firm need a WISP?

If your firm prepares tax returns, almost certainly. The FTC Safeguards Rule treats tax preparers as financial institutions and requires a written security program. The IRS calls it a WISP, and Form W-12 asks you to acknowledge the requirement at every PTIN renewal.

We have fewer than 5,000 clients. Are we exempt?

Only partly. Below 5,000 consumers, four items drop off: the written risk assessment, periodic testing, the written incident response plan, and the annual report. Your WISP, Qualified Individual, MFA, encryption, access controls, training, and vendor oversight still apply.

Is the IRS WISP template in Publication 5708 enough?

It is a solid starting point. Publication 5708 is a sample you must tailor to your people, systems, and vendors, and the controls it describes have to actually run. KairosIT helps turn the template into a WISP that matches your firm.

Can KairosIT help us understand where to start?

Yes. The first step is a focused readiness conversation: current systems, security posture, documentation, risk, and the business reason behind the requirement.

Ready to talk?

Let us review where your IT environment stands.

Book a WISP Gap Assessment and get a practical FTC Safeguards readiness check of your written plan, MFA, encryption, vendors, and incident response.

Request a WISP Gap Assessment