August 28, 2026

What Boise CPA Firms Need in a Written Information Security Plan

The FTC Safeguards Rule requires firms handling customer financial information to maintain a written information security plan, commonly called a WISP. For most Boise CPA and accounting firms this is not optional and it is not satisfied by having good IT. It has to exist as a document, name a responsible individual, and be reviewed on a schedule.

Requirements change. Confirm current obligations with the FTC or your professional association before relying on any summary, including this one.

A WISP is a document, not a posture

The most common misunderstanding we see is a firm with genuinely solid security and no plan. Strong controls do not satisfy a documentation requirement. The plan has to be written down, and it has to describe what you actually do rather than what a template says.

What generally belongs in it

  • A named qualified individual responsible for the program. One person, named, not a committee.
  • A risk assessment identifying where customer information lives and what threatens it.
  • The safeguards you have implemented, mapped to the risks you identified.
  • Access controls describing who can reach client data and how that is reviewed.
  • Encryption of customer information in transit and at rest.
  • Multifactor authentication for anyone accessing customer information.
  • A service provider oversight process covering vendors who touch client data.
  • An incident response plan with named roles.
  • Staff security awareness training with records.
  • A schedule for testing and for reviewing the plan itself.

Where Boise firms commonly fall short

Three gaps come up repeatedly.

The first is the qualified individual left unnamed. A plan that says the firm is responsible does not meet the requirement. A person has to own it, and that person needs enough authority to act.

The second is vendor oversight. Tax software, cloud hosting, document management, and portals all touch client data. Firms rarely have a list, and almost never have documentation of having assessed them.

The third is the plan that was written once and filed. Review is part of the requirement. An unreviewed plan from three seasons ago describes a firm that no longer exists.

Tax season is the wrong time to discover a gap

Between January and April, a firm's tolerance for disruption is near zero, staff are working long hours on unfamiliar devices, and phishing volume aimed at tax professionals rises sharply.

The right window for this work is now. Reviewing the plan, testing a restore, and confirming multifactor coverage in the fall costs a fraction of what it costs in March.

Who writes it

The firm owns the plan. An IT provider supplies the technical detail, evidence that controls are running, and documentation of the environment. A provider who offers to hand you a finished WISP with your name inserted is selling you a template, and a template that does not describe your actual practice is worse than useful.

Supporting CPA firms in the Treasure Valley

IDACOMP has supported Idaho businesses since 2002 as part of Bytagig, founded 2009. We work with Boise CPA and accounting firms on tax-season continuity, financial data security, and the technical controls that support Safeguards obligations. Managed clients see a 15-minute average first response, measured from ticket data rather than offered as a contractual promise.

If your plan has not been reviewed since last season, now is the window. Reach out and we will walk your current controls against what the rule expects.

An attorney reviewing documents at a desk in a bright office with bookshelves behind them.
By John Jackson August 28, 2026
Practical questions Boise law firms should ask any IT provider about protecting client data: encryption, access control, retention, breach response, and vendor risk.
A business owner reviewing insurance paperwork at a desk in a bright modern office.
By John Jackson August 28, 2026
Cyber insurance carriers verify controls, not just attestations. What Boise businesses should have in place before an audit or renewal, and where gaps usually appear.
Two IT colleagues working together at a desk with laptops in a bright modern office.
By John Jackson August 28, 2026
Co-managed IT keeps your internal IT person in charge while an outside team adds depth, after-hours coverage, and security. How the split works in the Treasure Valley.
A desk phone and open laptop on a tidy office desk in warm natural light.
By John Jackson July 28, 2026
Why Boise businesses get Microsoft 365 and hosted VoIP from one provider, what breaks when vendors are split, and how to choose between Teams Phone and hosted VoIP.
Two business people reviewing printed insurance documents across a desk in a bright office.
By John Jackson July 28, 2026
What cyber insurance carriers ask Idaho small businesses about MFA, backups, EDR and incident response, what each control means, and how to close gaps before renewal.
A manufacturing worker in a hard hat inspecting equipment on a factory production floor.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise manufacturers. Keep production running, secure office IT and the shop floor, and protect designs from ransomware and theft.
A diverse group of nonprofit team members and volunteers collaborating around a table.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise nonprofits. Stretch limited budgets, protect donor data, and keep your team running so you can focus on your mission.
An architect reviewing building blueprints and a scale model at a desk in a modern studio.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise architecture and engineering firms. Support demanding CAD and BIM workloads, protect design data, and keep teams in sync.
A financial advisor meeting with a client across a desk in a bright modern office.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise financial advisors. Protect client data, align with GLBA and SEC expectations, and keep systems running for clients.
An attorney reviewing documents at a desk with shelves of legal volumes behind them.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise law firms. Protect privileged client data, meet cyber insurance requirements, and keep systems running for every deadline.