Team assembling puzzle blocks representing data security, collaboration, and communication in a busy office setting.

How Can a CPA Firm Create a Written Information Security Plan That Actually Works?

August 06, 2026

A CPA Firm’s Written Information Security Plan Should Cover 10 Core Security Areas

A practical Written Information Security Plan, or WISP, should document 10 core areas: assigned responsibility, risk assessment, access control, employee security, device protection, encryption, vendor oversight, incident response, backup and recovery, and regular testing.

For a CPA firm with 25–50 employees, the plan should usually be detailed enough to explain who is responsible for each safeguard, how the safeguard works, how often it is reviewed, and what evidence confirms that the process is being followed.

A WISP should not be a generic policy downloaded once and stored in a folder. It should match the firm’s actual users, applications, vendors, offices, devices, remote-work practices, and security controls. At minimum, the plan should be reviewed annually and after material changes such as a merger, office move, major application migration, security incident, or change in IT provider.

What Is a Written Information Security Plan?

A Written Information Security Plan is a documented program describing how an organization protects sensitive information from unauthorized access, use, alteration, disclosure, or destruction.

For a CPA firm, protected information may include:

  • Social Security numbers
  • Tax returns
  • Bank-account information
  • Payroll records
  • Financial statements
  • Employee records
  • Client portal data
  • Authentication credentials
  • Business ownership records
  • Copies of identification documents

The WISP should connect policies with actual controls. For example, it is not enough to state that the firm uses secure access. The plan should identify where multi-factor authentication is required, who reviews administrator permissions, how former employees are removed, and how access changes are documented.

Review this overview of what a Written Information Security Plan should include.

Why CPA Firms Need a WISP

CPA firms store information that can be used for identity theft, tax fraud, payment fraud, and business impersonation. A WISP creates a repeatable structure for protecting that information and demonstrates that the firm has considered its risks instead of relying on informal practices.

A useful WISP can help the firm:

  • Assign clear security responsibilities.
  • Identify where sensitive information is stored.
  • Standardize employee onboarding and offboarding.
  • Document technical safeguards.
  • Prepare for client security questions.
  • Support cyber insurance applications.
  • Coordinate vendors and service providers.
  • Respond more quickly to security incidents.
  • Track corrective actions.
  • Prepare for regulatory or contractual reviews.

The document itself does not create security. Its value comes from translating requirements and risks into specific actions that employees and providers consistently perform.

The 911 IT 10-Part CPA WISP Framework

Use the following 10-part framework to create or update a WISP that reflects the firm’s actual operations.

1. Assign a Qualified Security Coordinator

The WISP should identify the person or role responsible for coordinating the information security program.

Responsibilities may include:

  • Maintaining the WISP
  • Coordinating risk assessments
  • Reviewing security findings
  • Tracking remediation
  • Overseeing employee training
  • Reviewing service providers
  • Coordinating incident response
  • Reporting material risks to leadership

The coordinator does not need to perform every technical task personally. A partner, administrator, compliance leader, or operations manager may coordinate the program while an MSP, cybersecurity provider, attorney, or other advisor supports specific areas.

The plan should also name a backup contact so the program does not depend on one person being available.

2. Complete and Document a Risk Assessment

The firm should identify the sensitive information it stores, where that information is located, who can access it, and what threats could affect it.

The assessment should review:

  • Employees and contractors
  • Workstations and laptops
  • Servers
  • Microsoft 365
  • Tax and accounting applications
  • Document-management systems
  • Client portals
  • Remote access
  • Mobile devices
  • Paper records
  • Cloud services
  • Third-party vendors
  • Backup systems
  • Office and physical security

Each material risk should be evaluated according to likelihood and potential impact. The firm should then document the existing safeguard, remaining gap, responsible owner, target completion date, and method for verifying remediation.

A simple risk register may use the following structure:

Risk Likelihood Impact Current safeguard Required action
Microsoft 365 account compromise High High MFA and email filtering Review legacy authentication and admin roles
Lost employee laptop Medium High Password protection Confirm encryption and remote management
Backup deletion during ransomware Medium High Cloud backup Add immutable storage and separate credentials

3. Document Access-Control Procedures

The WISP should explain how the firm grants, changes, reviews, and removes access.

Access-control procedures should cover:

  • New employee onboarding
  • Role changes
  • Seasonal staff
  • Contractors and vendors
  • Departing employees
  • Administrator privileges
  • Remote access
  • Client portal permissions
  • File and application access
  • Periodic access reviews

Users should receive only the access required for their responsibilities. Administrator privileges should be limited and reviewed separately from ordinary employee access.

A 25–50 employee CPA firm should review high-risk and administrator access at least quarterly. Full user-access reviews should also occur after staffing changes, mergers, application migrations, or security incidents.

4. Establish Employee Security Requirements

Employees are involved in email, client communication, document handling, remote work, and financial workflows. The WISP should define the security practices employees are expected to follow.

Employee requirements may include:

  • Completing security awareness training
  • Using multi-factor authentication
  • Reporting suspicious messages
  • Protecting passwords and authentication codes
  • Using approved file-sharing methods
  • Securing paper records
  • Protecting devices outside the office
  • Verifying payment and bank-account changes
  • Reporting lost devices immediately
  • Avoiding unapproved software and storage services

Training should occur during onboarding and continue throughout the year. Short, recurring lessons and phishing simulations are generally more effective than relying only on one annual presentation.

The firm should document training dates, participants, topics, and any required follow-up.

5. Protect Workstations, Laptops, Servers, and Mobile Devices

The WISP should identify the safeguards used to protect devices that store or access sensitive information.

Device protections may include:

  • Managed endpoint detection and response
  • Operating system and application patching
  • Full-disk encryption
  • Screen-lock policies
  • Restricted administrator rights
  • Remote monitoring
  • Device inventory
  • USB and removable-media controls
  • Mobile-device management
  • Secure disposal procedures

The firm should know which devices are approved, who uses them, whether security tools are active, and when the devices must be replaced.

Unsupported systems should have documented remediation plans. If a device cannot receive security updates, the firm should replace, isolate, or otherwise address the risk.

6. Use Encryption and Secure Transmission Methods

The WISP should explain how sensitive information is protected while stored and transmitted.

Encryption and secure communication controls may include:

  • Full-disk encryption on laptops
  • Encrypted backup storage
  • Secure client portals
  • Encrypted email when appropriate
  • Protected file-transfer services
  • Secure remote access
  • Transport encryption for websites and cloud services
  • Restrictions on personal email and consumer file-sharing platforms

The plan should define which methods employees may use to exchange taxpayer information. It should also state that sensitive client data should not be transferred through unapproved personal accounts, ordinary text messages, or unmanaged storage services.

7. Manage Vendors and Service Providers

CPA firms often rely on cloud applications, tax-software providers, payroll platforms, hosting companies, shredding vendors, managed IT providers, and other service providers that may access or store sensitive information.

The WISP should define how vendors are selected, reviewed, approved, and monitored.

Vendor documentation may include:

  • Service provided
  • Type of information accessed
  • Primary business and security contacts
  • Contract and renewal dates
  • Security documentation
  • Incident-notification requirements
  • Data-retention and deletion terms
  • Backup and recovery responsibilities
  • Subcontractor use
  • Termination procedures

Higher-risk vendors should receive more detailed review. The firm should understand which security responsibilities belong to the vendor and which remain with the CPA firm.

An MSP should assist with technical vendor evaluation and coordination but should not claim that one security certification automatically resolves every risk.

8. Create an Incident Response Plan

The WISP should describe how employees report suspected incidents and how the firm coordinates containment, investigation, recovery, and communication.

The incident response section should identify:

  • Internal leadership contacts
  • IT and cybersecurity contacts
  • Legal counsel
  • Cyber insurance contacts
  • Communication responsibilities
  • Evidence-preservation procedures
  • System recovery priorities
  • Vendor escalation contacts
  • After-hours reporting methods

The plan should address common scenarios such as:

  • Phishing and credential theft
  • Business email compromise
  • Ransomware
  • Lost or stolen devices
  • Accidental disclosure
  • Unauthorized account access
  • Vendor security incidents
  • Unavailable tax or document systems

Conduct an incident-response tabletop exercise at least annually. A 60–90 minute exercise can reveal outdated contacts, unclear authority, missing insurance information, and untested assumptions.

9. Document Backup, Recovery, and Business Continuity

The WISP should explain how the firm protects information and continues operating after deletion, corruption, equipment failure, ransomware, or a broader disruption.

The plan should document:

  • Protected systems and data
  • Backup frequency
  • Retention periods
  • Encryption
  • Immutable or isolated copies
  • Recovery testing
  • Recovery point objectives
  • Recovery time objectives
  • System recovery priorities
  • Remote-work procedures
  • Emergency communication methods

Critical backup jobs should be reviewed daily, representative files should be restored monthly, important applications should be recovery-tested quarterly, and the complete recovery process should be exercised at least annually.

Explore business continuity services for backup monitoring, disaster recovery, ransomware-resistant protection, and continuity planning.

10. Test, Review, and Improve the Security Program

A WISP should include a schedule for reviewing whether safeguards remain effective.

Testing may include:

  • Vulnerability scans
  • Patch compliance reviews
  • Phishing simulations
  • Backup restoration tests
  • User-access reviews
  • Incident-response exercises
  • Vendor reviews
  • Security-alert reviews
  • Penetration testing when appropriate
  • Policy and documentation reviews

The WISP should be reviewed at least annually and after material changes.

Examples of changes requiring review include:

  • A new office or remote-work model
  • A merger or acquisition
  • A new IT provider
  • A major software migration
  • A security incident
  • A new cloud platform
  • A significant increase in employees
  • A change in legal or contractual obligations

What Sections Should a CPA Firm WISP Contain?

A production-ready WISP may include the following sections:

  1. Purpose and scope
  2. Definitions
  3. Security-program responsibility
  4. Information and system inventory
  5. Risk-assessment process
  6. Access-control procedures
  7. Employee security and training
  8. Device and network safeguards
  9. Encryption and secure transmission
  10. Vendor-management procedures
  11. Incident-response procedures
  12. Backup and business-continuity procedures
  13. Physical security
  14. Secure disposal
  15. Testing and monitoring
  16. Review and approval process
  17. Appendices, contacts, and supporting records

The document should be written so firm leadership, employees, and service providers can understand their responsibilities. Excessive technical language can make the plan difficult to use during onboarding, audits, or emergencies.

What Evidence Should Support the WISP?

The WISP states what the firm intends to do. Supporting evidence demonstrates that the activities actually occur.

Evidence may include:

  • Current user and device inventories
  • Risk-assessment reports
  • Training completion records
  • Phishing simulation results
  • Backup test reports
  • Access-review records
  • Patch and vulnerability reports
  • Incident-response exercise notes
  • Vendor-review documentation
  • Encryption reports
  • Employee onboarding and offboarding checklists
  • Remediation plans
  • Meeting minutes and approvals

The firm does not need to place every supporting record inside the WISP. The document can identify where records are maintained, who owns them, and how long they are retained.

How Often Should the WISP Be Reviewed?

A CPA firm should complete a formal WISP review at least once every 12 months. High-risk sections may require more frequent review.

WISP component Recommended review frequency
User and administrator access Quarterly and after staffing changes
Employee training During onboarding and throughout the year
Vendor inventory At least annually and before major renewals
Backup and recovery Daily monitoring, monthly and quarterly testing
Incident response At least annually and after an incident
Risk assessment At least annually and after material changes
Complete WISP At least annually

Every review should record the date, participants, changes made, open actions, and approval by appropriate leadership.

Who Should Participate in the WISP Process?

The WISP should not be created by the IT provider in isolation. It affects people, operations, legal responsibilities, physical records, vendors, and business continuity.

Participants may include:

  • Firm ownership or executive leadership
  • The designated security coordinator
  • Operations or office management
  • Human resources
  • The managed IT provider
  • Cybersecurity specialists
  • Legal counsel
  • Cyber insurance advisors
  • Department leaders

Each participant should review the sections relevant to their responsibilities. For example, the MSP may document endpoint security and backups, while firm leadership approves risk priorities and human resources supports employee procedures.

How Should the WISP Address Remote Work?

Remote-work procedures should define how employees access, store, display, print, and dispose of sensitive information outside the office.

The WISP should address:

  • Approved devices
  • Multi-factor authentication
  • Secure remote access
  • Device encryption
  • Home wireless security
  • Printing and paper records
  • Use of personal email and storage
  • Lost-device reporting
  • Privacy in shared workspaces
  • Remote technical support

Employees should use firm-managed devices whenever possible. Taxpayer information should not be stored on personal computers or moved into unapproved applications for convenience.

How Should the WISP Address Seasonal Employees?

Seasonal staffing introduces a predictable increase in accounts, devices, software licenses, and client-data access.

The WISP should require:

  • Authorized onboarding requests
  • Role-based access
  • Defined account start and expiration dates
  • Multi-factor authentication
  • Security training
  • Approved devices
  • Monitoring and endpoint protection
  • Prompt offboarding
  • Device return
  • Access verification after departure

Seasonal access should not remain active until the next filing period. The firm should use an offboarding checklist to remove access as soon as work ends.

How Should Physical Records Be Covered?

A WISP should not focus only on digital systems. CPA firms may also store printed tax returns, source documents, payroll records, and identification information.

Physical safeguards may include:

  • Locked offices and file storage
  • Visitor controls
  • Clear-desk procedures
  • Secure printing
  • Document checkout procedures
  • Locked disposal containers
  • Approved shredding services
  • Records retention schedules
  • Restrictions on removing documents from the office

The firm should document how physical information is transported, stored, and destroyed.

Common WISP Mistakes CPA Firms Should Avoid

Using a Generic Template Without Customization

A template may provide structure, but the final plan should identify the firm’s actual applications, vendors, systems, and procedures.

Listing Security Tools Without Explaining the Process

The WISP should explain who manages each control, how it is monitored, and what happens when the control fails.

Ignoring Cloud Services

Microsoft 365, tax applications, document platforms, and client portals should be included in inventories, risk assessments, and recovery plans.

Failing to Assign Owners and Deadlines

Security findings without a responsible owner and target date often remain unresolved.

Assuming the IT Provider Owns the Entire Program

The MSP supports technical safeguards, but firm leadership remains involved in risk decisions, employee procedures, vendor approval, and program oversight.

Not Testing Incident Response or Recovery

A policy that has never been exercised may contain outdated contacts, inaccessible credentials, or unrealistic assumptions.

Updating the WISP Only After an Incident

Review the document at least annually and after significant changes.

The 911 IT CPA WISP Checklist

Program Management

  • A security coordinator and backup contact are named.
  • The WISP has a current approval date.
  • Leadership reviews material security risks.
  • Security actions have assigned owners and deadlines.

Risk and Inventory

  • Sensitive information has been identified.
  • Users, devices, applications, and vendors are inventoried.
  • A risk assessment has been completed within the last 12 months.
  • High-risk findings have documented remediation plans.

Identity and Access

  • Multi-factor authentication is required where appropriate.
  • Administrator privileges are limited.
  • User access is reviewed regularly.
  • Onboarding and offboarding procedures are documented.
  • Seasonal accounts have expiration dates.

Technology Safeguards

  • Approved devices have managed endpoint protection.
  • Operating systems and applications are patched.
  • Portable devices are encrypted.
  • Email and cloud security settings are reviewed.
  • Remote access is secured and monitored.

People and Vendors

  • Employees complete recurring security training.
  • Phishing and financial-change verification procedures are documented.
  • High-risk service providers are reviewed.
  • Vendor incident-notification contacts are current.

Response and Recovery

  • An incident-response plan is documented.
  • Emergency contacts are available outside normal systems.
  • Critical backups are reviewed daily.
  • Recovery tests are completed and documented.
  • Business-continuity procedures are current.

Testing and Review

  • The WISP is reviewed at least annually.
  • Access reviews occur at defined intervals.
  • Incident-response exercises occur at least annually.
  • Vulnerability and patch reports are reviewed.
  • Material changes trigger an additional review.

Real Client Scenario: Security Planning That Supports the Business

911 IT clients frequently describe the value of working with a provider that learns the organization before recommending technology. One client explained that the team invested time in understanding the company and its industry, then developed solutions that supported the business rather than applying generic technical recommendations.

“911 IT really took the time and put in the effort to learn about our business and industry to help our company succeed.”

A useful WISP follows the same principle. The plan should be designed around the firm’s actual client services, employees, deadlines, applications, risks, and operational needs.

The result is not only a better document. It is a security program employees can follow, leadership can oversee, and service providers can support.

How 911 IT Helps CPA Firms Build and Maintain a Practical WISP

911 IT provides managed IT services and cybersecurity support for CPA and financial firms that need documented safeguards, responsive support, and ongoing risk management.

WISP-related services may include:

  • Technology and cybersecurity risk assessments
  • User, device, software, and vendor inventories
  • Multi-factor authentication implementation
  • Endpoint and email security
  • Microsoft 365 security reviews
  • Employee onboarding and offboarding procedures
  • Security awareness training
  • Backup and recovery documentation
  • Incident-response planning
  • Tabletop exercises
  • Remediation tracking
  • Recurring security reviews

911 IT combines CPA-industry familiarity with cybersecurity-first technology management, 24/7 access to live technicians, local Salt Lake City-area support, strategic vCIO guidance, and a 100% satisfaction guarantee.

Explore cybersecurity services, learn more about IT support for CPA and financial firms, or read experiences from 911 IT clients.

Frequently Asked Questions

Does every CPA firm need a WISP?

CPA firms handling sensitive taxpayer and financial information should maintain a documented information security program. The exact content and complexity should reflect the firm’s size, systems, risks, services, and applicable responsibilities.

Can a CPA firm use a WISP template?

A template can provide a useful starting point, but it should be customized to the firm’s actual users, applications, vendors, offices, safeguards, and procedures.

Who should write the WISP?

The document should be developed collaboratively by firm leadership, the designated security coordinator, IT and cybersecurity providers, and appropriate legal, insurance, or compliance advisors.

How long should a WISP be?

There is no universal page count. It should be long enough to define responsibilities and procedures clearly without becoming so complex that employees and leaders cannot use it.

How often should the WISP be updated?

Review it at least annually and after material operational, technology, vendor, staffing, legal, or security changes.

Does having a WISP make a firm compliant?

No. The document must be supported by implemented safeguards, evidence, monitoring, training, testing, and corrective action.

Should employees receive the entire WISP?

Employees should receive the policies and procedures relevant to their work. Sensitive administrative, security, and incident-response details may require limited distribution.

Should the WISP include vendor names?

The plan may identify important providers or refer to a separate vendor inventory. Contacts, services, responsibilities, and security-review records should remain current.

What happens when the firm changes IT providers?

Review system ownership, administrative access, security tools, backup procedures, incident contacts, vendor records, and every WISP section affected by the transition.

How should the firm prove that the WISP is active?

Maintain supporting records such as risk assessments, access reviews, training reports, backup tests, incident exercises, vendor reviews, and remediation tracking.

Turn the WISP Into an Active Security Program

A useful Written Information Security Plan should tell employees, leadership, and service providers what must happen, who is responsible, how often it occurs, and how the firm verifies completion.

Start with the firm’s actual risks. Add specific safeguards, owners, review schedules, examples, and evidence. Then test the plan and update it when the business changes.

Schedule a discovery call with 911 IT to discuss a WISP risk assessment, cybersecurity controls, employee procedures, and ongoing security planning for your CPA firm.