Client Story
A regional accounting and tax firm with more than 50 employees
Building a WISP That Would Hold Up
The firm had an internal IT department that knew its environment. What it needed was a Written Information Security Plan, risk assessment, and breach procedure that could stand up when a regulator, insurer, or client asked to see them.
Why this story is anonymous
We do not publish the firm's safeguards, access controls, remote access rules, network configuration, or breach procedures. Those details would give an attacker useful reconnaissance. This story describes the engagement and regulatory frame without exposing how the client is protected. This is part of the same security standard we ask clients to follow.
The regulatory frame
A template with the firm's name added is not a WISP that holds up.
Tax and accounting firms fall under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, which require a Written Information Security Plan. The requirement is not new. What has changed is how often firms are asked to produce the plan.
The request may come from the IRS, a cyber insurance carrier at renewal, or a client conducting vendor due diligence. In each case, the question is not whether a document exists. It is whether the document reflects a real program, assigns responsibility, and stays current.
A generic template with the firm's name dropped in does not survive that scrutiny. Our FTC Safeguards Rule guide explains the obligation, and the free FTC Safeguards checklist gives firms a practical place to start.
The situation
The technical knowledge existed. The regulatory proof did not.
The firm had an internal IT department that knew its environment well. The gap was not technical capability. Nobody had translated what the firm already did into what the Safeguards Rule expects it to show.
That meant the firm did not have a written plan built around its actual program, a documented risk assessment, or a breach notification procedure ready before an incident rather than written during one.
This is a common gap. The people who understand the systems are also the people keeping them running. Documentation that requires regulatory interpretation keeps losing to the operational work that has to happen today.
What we did
We translated what the team knew into what the firm had to demonstrate.
We worked alongside the internal IT department rather than around it. They knew the environment. We knew the regulatory frame and what a WISP has to demonstrate to hold up under examination.
Together, we produced three working documents. The standard throughout was meeting or exceeding the requirement, not clearing the minimum bar.
Written Information Security Plan
A plan covering the program's administrative, technical, and physical safeguards, with responsible officials, a defined scope, and an annual review cycle.
Risk assessment
A documented assessment of foreseeable internal and external risks, their potential impact, and whether the firm's safeguards were sufficient.
Breach notification plan
A procedure defining who notifies whom, in what order, and on what timeline. A firm discovering a breach on a Friday afternoon should not be deciding then who to call first.
Why this is co-managed work
The internal team had the depth. We added capacity and specialization.
An internal IT department has depth on its own environment that no outside provider starts with. What it usually lacks is time and regulatory specialization, because the people who understand the systems are the same people keeping them running.
That is the case for co-managed IT. It is not about replacing an internal team. It adds the capacity and specialization the team does not have room to build, while keeping operational knowledge and ownership where they belong.
The same partnership applies to broader governance, risk, and compliance work. The outside team brings the regulatory frame. The internal team brings the environmental truth. The documentation has to reconcile both.
The outcome
Documentation the firm can produce, follow, and keep current.
The firm now has documentation that satisfies its GLBA and Safeguards Rule obligations, a risk assessment it can point to, and a breach procedure it can follow rather than improvise.
The internal team retains ownership of the environment. The annual review cycle is defined, so the plan stays current instead of aging into a file nobody opens.
That same evidence also matters at cyber insurance renewal, when a carrier asks the firm to support its answers instead of checking boxes from memory. Firms that need a starting structure can use our Written Information Security Plan template.
The result
What changed.
The firm can produce a defensible WISP, point to a documented risk assessment, and follow a breach procedure instead of improvising one. Its internal team retains ownership, and an annual review cycle keeps the work current.
Related work
The standards behind the outcome.
IT for Accounting & Financial Firms
Technology, documentation, and security held to the standard expected of firms handling client financial data.
Read moreCo-Managed IT Services
Regulatory specialization and added capacity without replacing the internal team that knows the environment.
Read moreGovernance, Risk & Compliance
WISPs, risk assessments, and incident documentation that reflect reality and hold up under review.
Read moreFTC Safeguards Rule Resources
Plain-language guidance, a free compliance checklist, and a WISP template for accounting and financial firms.
Read moreCyber Insurance Readiness
Documentation and evidence that support the answers a carrier expects at renewal.
Read moreNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
