Unclear ownership
Teams know the requirement matters, but no one owns the technical roadmap from gap review to remediation.
Compliance-focused cybersecurity
Firms that prepare tax returns fall under the FTC Safeguards Rule. KairosIT helps CPA and accounting firms build a WISP that matches how the firm really works, then run and document the controls behind it.
WISP Gap Assessment
Book a WISP Gap Assessment and get a practical FTC Safeguards readiness check of your written plan, MFA, encryption, vendors, and incident response.
Who this helps
Most firms know they need a WISP. The gaps are usually behind it:
Common roadblocks
Most regulated organizations do not fail because one tool is missing. They struggle because identity, documentation, support, security, backup, and day-to-day process are not working together.
Teams know the requirement matters, but no one owns the technical roadmap from gap review to remediation.
Microsoft 365, devices, shared mailboxes, admin accounts, and vendor access need tighter review.
Policies may exist, but leadership still needs usable proof of backups, monitoring, patching, and response.
Audit pressure, client requirements, or cyber insurance requests create urgency without clear next steps.
What matters
What the FTC Safeguards Rule requires:
Based on 16 CFR Part 314 and IRS Publications 5708 and 4557.
How KairosIT helps:
A WISP your team can actually run, with clear owners and evidence.
Related: IT services for accounting and CPA firms, finance and banking IT, and regulated IT compliance services.
What we manage
KairosIT connects compliance pressure to the real systems your team uses every day, so the work becomes operational instead of theoretical.
User access, admin accounts, MFA, conditional access, onboarding, offboarding, and permission reviews.
Email security, SharePoint, Teams, OneDrive, retention, auditability, and configuration hardening.
Device management, patching, antivirus, endpoint detection, encryption, and security baselines.
Backup monitoring, restore testing, business continuity planning, and recovery expectations.
Alerting, escalation, incident readiness, documentation, and recurring security visibility.
Prioritized remediation, leadership reporting, budget planning, and practical next steps.
How KairosIT helps
Book a Discovery Call to schedule your WISP Gap Assessment.
Our process
We help you move from “we need to deal with this” to a clear roadmap your leadership team can understand, fund, and execute.
We review your business context, current technology, risk, and what triggered the requirement.
We connect the requirement to your identity, endpoint, Microsoft 365, backup, and support environment.
We separate urgent gaps from nice-to-have work so the roadmap is realistic.
We help remediate, document, monitor, and improve the environment over time.
FAQ
If your firm prepares tax returns, almost certainly. The FTC Safeguards Rule treats tax preparers as financial institutions and requires a written security program. The IRS calls it a WISP, and Form W-12 asks you to acknowledge the requirement at every PTIN renewal.
Only partly. Below 5,000 consumers, four items drop off: the written risk assessment, periodic testing, the written incident response plan, and the annual report. Your WISP, Qualified Individual, MFA, encryption, access controls, training, and vendor oversight still apply.
It is a solid starting point. Publication 5708 is a sample you must tailor to your people, systems, and vendors, and the controls it describes have to actually run. KairosIT helps turn the template into a WISP that matches your firm.
Yes. The first step is a focused readiness conversation: current systems, security posture, documentation, risk, and the business reason behind the requirement.
Related specialty services
Related KairosIT services
Compliance work is strongest when it is tied to managed IT, cybersecurity, Microsoft 365, backup, and the industry context behind the requirement. If you are planning budget, start with our managed IT pricing guide.
Ready to talk?
Book a WISP Gap Assessment and get a practical FTC Safeguards readiness check of your written plan, MFA, encryption, vendors, and incident response.