
The IRS requires every professional tax preparer to have a Written Information Security Plan (WISP), but a document sitting in a drawer doesn't stop a data breach. This session focuses on turning regulatory requirements into a functional security posture. The firm needs to understand how IRS Publication 4557 translates to daily operations, from the way staff logs into software to how they vet third-party vendors. The discussion moves beyond the legal mandate to address the actual tools that protect client data, including the transition to passkeys and the necessity of encrypted communications. Finally, the session covers the critical steps a firm must take when a security incident occurs, ensuring the practice meets its reporting obligations while minimizing damage to its reputation.
Tax partners, solo practitioners, firm administrators, and IT managers responsible for tax data security.
No. Solo practitioners and small firm administrators will find the material particularly useful because it focuses on practical tools you can manage yourself. We focus on the specific steps any tax professional must take to stay compliant.
You don't. While the course is at an intermediate level, I explain concepts like passkeys and encryption standards in plain language that relates to your daily tax work. We're looking at how these tools fit into your office, not how to write the code behind them.
We identify all the mandatory components required by IRS Publication 4557 so you can build a plan that fits your specific practice. You'll learn what needs to be in the document to satisfy a regulatory audit.
Yes. The session specifically addresses access control strategies for remote and hybrid teams, including how to manage devices that aren't physically in your office. We'll look at keeping data safe regardless of where your staff is sitting.
You should have a general familiarity with how a tax firm operates and basic IRS compliance requirements. There's no advanced preparation needed, but you'll get the most out of this if you're already handling client data regularly.
I started this project because I noticed too many colleagues treating their security plans as a chore to be filed away rather than a shield for their business. I wrote this for the practitioners who feel overwhelmed by technical jargon but know they need to keep their clients safe. We're going to turn these cold IRS mandates into a set of practical habits that actually work for your firm.
Reach out for more information or to bring this training to your organization.
Interested in bringing this training to your team, or want more information? Send a note and we’ll get back to you.