What Is a WISP and Does My Houston CPA Firm Need One?

Yes — if your Houston CPA firm handles client tax returns, bank account numbers, or Social Security numbers, the FTC already requires you to have a written information security program, commonly called a WISP. This has been enforced since June 2023 under the FTC Safeguards Rule, and civil penalties can reach up to $51,744 per violation. A WISP isn't optional paperwork you can draft once and forget — it's a living document that has to match what your firm actually does to protect client data, and most small and mid-size firms don't have one that would survive an audit.

What Is a WISP, and Why Does the FTC Require One?

A WISP is a written document that describes, in specific terms, how your firm identifies risks to client financial data and what safeguards you have in place to address them. The requirement comes from the Gramm-Leach-Bliley Act (GLBA), which the FTC has interpreted to cover any business that provides financial services — including tax preparers, bookkeepers, and CPA firms, not just banks. If your firm files tax returns, processes payroll, or advises on financial accounts, you meet the FTC's definition of a "financial institution" for Safeguards Rule purposes, whether or not you think of yourself that way.

The rule doesn't just ask you to have good security habits. It requires a designated person, a documented risk assessment, and specific technical controls, all written down in a way an examiner or insurer could review. Firms that get flagged in an FTC investigation or a data breach lawsuit are almost always firms that either never wrote a WISP or wrote one years ago and never updated it to match their actual systems.

What Must Be Included in a Compliant WISP?

 

Compliant WISP

The FTC Safeguards Rule lays out specific elements every WISP must address. At minimum, your document needs to cover:

  • A designated Qualified Individual — who is designated to oversee your information security program and hold them accountable for its upkeep.
  • A written risk assessment — a documented process for identifying where client financial data lives, how it flows through your systems, and what could go wrong.
  • Documented safeguards — access controls, encryption, monitoring, and incident response procedures that map directly to the risks you identified.
  • Vendor and service provider oversight — a requirement that any vendor touching client data (including your IT provider) is contractually obligated to maintain equivalent safeguards.
  • An incident response plan — a documented process for how the firm identifies, contains, and reports a security incident, including who gets notified and when.

Notice that almost every one of these elements depends on having the underlying technical controls in place first. You can't write an honest risk assessment if you don't know what's actually monitoring your network, and you can't document an incident response plan if nothing is watching for incidents in the first place.

Who at Your Firm Is Responsible for the WISP?

The FTC requires firms to name a single Qualified Individual responsible for the program — usually a partner, the firm's IT lead, or (for firms without in-house IT staff) a managed IT provider acting in that capacity. That person doesn't need to write every technical control themselves, but they do need to be able to answer for the program in front of an examiner, an insurer, or a client's due diligence questionnaire.

In practice, most Houston CPA firms in the 5–75 employee range don't have a dedicated security officer. The Qualified Individual role typically falls to a managing partner who then leans on their managed IT provider to supply the documentation, monitoring, and technical evidence the WISP requires. That division of labor works, but only if the IT provider is actually producing WISP-grade documentation — regular reports, tested backups, and a paper trail — rather than just fixing tickets.

How the Assured Plan Provides the Technical Controls Your WISP Requires

A WISP is a document, but it has to be backed by real controls or it won't hold up to scrutiny. Scorpion Technology's Assured plan — our recommended minimum for CPA and accounting firms — includes the specific safeguards examiners and cyber insurers expect to see referenced in a WISP:

  • Dark Web Monitoring — continuous alerts if employee or firm credentials appear in a data breach, so compromised passwords get changed before they're used against you.
  • Phishing Simulation & Security Awareness Training — ongoing simulated phishing tests and staff training, directly satisfying the WISP requirement for an employee security awareness program.
  • Managed EDR with 24x7 SOC Response — behavior-based threat detection with a 24x7 Security Operations Center response team, the technical control examiners most often ask about first.
  • Cloud Account Security Monitoring — continuous alerts on suspicious sign-ins and configuration changes across your cloud accounts.
  • Microsoft 365 / Google Workspace Backup — one full year of retained, restorable backups for Microsoft 365 or Google Workspace, satisfying data recovery and business continuity requirements.
  • Managed DMARC, SPF & DKIM — email authentication controls that prevent your domain from being spoofed in phishing attacks against your own clients.

Beyond the technical safeguards, Assured plan clients receive a Quarterly Technology Business Review — a standing meeting where we walk through what's been monitored, what's changed, and what still needs attention. That review becomes part of the documentation trail your WISP depends on.

How One Houston CPA Firm Closed Its WISP Gap

When a 12 person Houston CPA Firm came to Scorpion, the firm had a WISP template downloaded from a professional association website — it referenced software they no longer used and named an IT contact who had left the firm two years earlier. After a technology assessment, we moved the firm onto the Assured plan and rebuilt their WISP to match their actual environment: real risk assessment, real vendor oversight language, and monitoring data the firm's Qualified Individual could point to directly. Within 3 weeks the firm passed its cyber insurance renewal without the premium increase 50% their broker had originally quoted, and had documentation ready when a client's due diligence team asked for proof of a security program during a merger review.

Why Houston CPA Firms Trust Scorpion Technology for WISP Compliance

A WISP that only exists on paper won't protect your firm in an FTC investigation, a breach, or a cyber insurance renewal. It has to be backed by monitoring, documentation, and a provider who understands what examiners and insurers are actually looking for.

Scorpion Technology has served small businesses and healthcare practices across Houston, Dallas, Austin, and San Antonio for over 19 years. We specialize in HIPAA-compliant IT for medical practices and professional services firms, with a 15-minute guaranteed response time for all managed clients. Our team is local, responsive, and built around keeping your practice running — not just fixing problems when they break. Learn more at ScorpionITSupport.com or call 713-623-1266.