yossio Stephen M. Yoss, CPA
Home Articles
Securing the Tax Practice: WISP, IRS Pub 4557, and Practical Controls — course hero graphic

Securing the Tax Practice: WISP, IRS Pub 4557, and Practical Controls

📋 Overview

The IRS requires every professional tax preparer to have a Written Information Security Plan (WISP), but a document sitting in a drawer doesn't stop a data breach. This session focuses on turning regulatory requirements into a functional security posture. The firm needs to understand how IRS Publication 4557 translates to daily operations, from the way staff logs into software to how they vet third-party vendors. The discussion moves beyond the legal mandate to address the actual tools that protect client data, including the transition to passkeys and the necessity of encrypted communications. Finally, the session covers the critical steps a firm must take when a security incident occurs, ensuring the practice meets its reporting obligations while minimizing damage to its reputation.

👥 Who Should Attend

Tax partners, solo practitioners, firm administrators, and IT managers responsible for tax data security.

Prerequisites
General familiarity with tax firm operations and IRS compliance requirements.
Advanced Prep
None

🎯 Learning Objectives

🚀 What You'll Walk Away With

📚 Major Topics

  1. IRS Publication 4557 and the WISP mandate
  2. Access control strategies for remote and hybrid teams
  3. Transitioning from passwords to MFA and passkeys
  4. Vendor risk management and data processing agreements
  5. Hardware security and device management for tax staff
  6. Client data encryption in transit and at rest
  7. Incident response planning and reporting requirements

🏷️ Topics

cybersecurityirs compliancewispdata privacytax technology

Questions

Is this course only for large firms with dedicated IT departments?

No. Solo practitioners and small firm administrators will find the material particularly useful because it focuses on practical tools you can manage yourself. We focus on the specific steps any tax professional must take to stay compliant.

Do I need to be a security expert to understand the technical sections?

You don't. While the course is at an intermediate level, I explain concepts like passkeys and encryption standards in plain language that relates to your daily tax work. We're looking at how these tools fit into your office, not how to write the code behind them.

Does this course provide a template for the WISP?

We identify all the mandatory components required by IRS Publication 4557 so you can build a plan that fits your specific practice. You'll learn what needs to be in the document to satisfy a regulatory audit.

Will we cover hardware security for employees who work from home?

Yes. The session specifically addresses access control strategies for remote and hybrid teams, including how to manage devices that aren't physically in your office. We'll look at keeping data safe regardless of where your staff is sitting.

What kind of prior knowledge should I have before starting?

You should have a general familiarity with how a tax firm operates and basic IRS compliance requirements. There's no advanced preparation needed, but you'll get the most out of this if you're already handling client data regularly.

🗂️ Course Details
Course ID
2200
Short Name
Securing the Tax Practice: WISP, IRS Pub 4557, and Practical Controls
Created
2026-09-17
Last Updated
2026-09-18

✍️ A Note from the Author

I started this project because I noticed too many colleagues treating their security plans as a chore to be filed away rather than a shield for their business. I wrote this for the practitioners who feel overwhelmed by technical jargon but know they need to keep their clients safe. We're going to turn these cold IRS mandates into a set of practical habits that actually work for your firm.

🎤 About the author

Stephen M. Yoss, CPA

Stephen is a certified public accountant, the CEO and partner of Devmatics, LLC, a continuing education instructor for financial professionals, a professional speaker at live events, and a licensed pyrotechnician. While his interests and skills are varied, they all share a common thread—his love for and skill in finding technology-based solutions. Whether it’s teaching in the classroom, consulting clients in a boardroom, or shooting a fireworks display, Steve brings passion, hard work, value—and above all else—technological expertise to each of his clients. With an open, honest approach, he creates a unique strategy for each client specifically designed to benefit their needs and streamline their operations in order to create efficiency and maximize their financial potential.

Share

Interested in this course?

Reach out for more information or to bring this training to your organization.