DOUBLE RULEA Black Lantern Labs practice
Learn

Security requirements, translated for accounting-firm leadership.

Security regulations are written for legal precision, not operational clarity.

These briefings explain what the requirements mean, where firms commonly fall short, and what practical action looks like.

WISP

A WISP is not the program. It is the written record of the program.

A Written Information Security Plan describes how the firm protects customer information.

It should identify responsible individuals, relevant systems and information, risks, safeguards, service-provider oversight, incident procedures, and how the program is reviewed.

The IRS states that tax professionals are required by law to maintain a WISP.

But downloading a template does not create the controls the template describes.

A useful WISP must correspond to the firm's real:

  • Systems
  • Personnel
  • Vendors
  • Access controls
  • Security tools
  • Data flows
  • Response procedures
  • Decision-making structure

When the document and the environment disagree, the document does not solve the underlying problem.

Safeguards Rule

Why the Safeguards Rule matters to tax and accounting practices

The FTC Safeguards Rule applies to covered financial institutions under the Gramm-Leach-Bliley Act.

Official IRS guidance states that federal regulations require professional tax preparers to create and enact security plans protecting client data.

The required program may include, depending on applicability and circumstances:

  • A qualified individual responsible for the program
  • A written risk assessment
  • Administrative, technical, and physical safeguards
  • Access controls
  • Encryption
  • Multi-factor authentication
  • Secure disposal
  • Monitoring or testing
  • Employee training
  • Service-provider oversight
  • An incident response plan
  • Periodic reporting to the governing body

The key question is not whether the firm owns a document called a WISP.

The key question is whether the firm can show that an information-security program exists, reflects its actual environment, and is being maintained.

IT support

Why IT support is not automatically a security program

A capable IT provider may be essential to the firm.

They may manage:

  • Devices
  • Microsoft 365 or Google Workspace
  • Software deployment
  • Backups
  • Networking
  • User support
  • Infrastructure
  • Account administration

But those services do not automatically establish:

  • A written risk-assessment process
  • Security-program governance
  • A complete vendor register
  • Executive reporting
  • A maintained WISP
  • Formal incident planning
  • Remediation prioritization
  • Independent control validation
  • Clear accountability to the partners

Double Rule does not argue that IT support is unimportant.

We make sure the security program exists around it.

Incidents

What happens when the firm suspects an incident

A suspected compromise creates several simultaneous questions:

  • Is the activity real?
  • Which systems or accounts are affected?
  • Is client information involved?
  • Should access be disabled?
  • Who preserves evidence?
  • Which technology providers must respond?
  • Does the insurance carrier need notice?
  • Is legal counsel required?
  • Do clients, regulators, law enforcement, or other parties require notification?
  • How does the firm continue operating safely?

An incident response plan establishes contacts, authority, decision paths, documentation expectations, and initial actions before those questions must be answered under pressure.

The exact legal and notification obligations depend on the incident, the information involved, applicable jurisdictions, contracts, and professional advice.

Partner questions

The security questions every managing partner should be able to answer

  • Who is responsible for the security program?
  • Where is sensitive client information stored?
  • Which vendors can access it?
  • Is multi-factor authentication consistently enforced?
  • Are devices encrypted and protected?
  • How quickly is access removed when someone leaves?
  • Can the firm recover from a destructive incident?
  • When was the last written risk assessment?
  • What are the three largest unresolved security risks?
  • What happens during a suspected breach?
  • What evidence would the firm provide to an insurer, regulator, client, or acquirer?
  • When did the partners last receive a security report?

Not knowing every technical detail is normal.

Not assigning anyone to obtain and maintain the answers is the real exposure.