protesure · wisp_generator

Build your Written Information Security Plan. Free, in about ten minutes, based on IRS and FTC guidance.

Answer nine short sections about how your firm handles client data. We assemble a complete WISP you can download as a Word document, print, and sign.

9 sections

Business info through incident response, each mapped to a required safeguard.

Word & print output

Download a formatted .doc with signature blocks, or print straight from the browser.

Nothing is transmitted

The plan is assembled in your browser. No account, no upload, no copy kept.

Free to use

No signup and no charge. Implementation help is available if you want it.

Federal rules require a written plan. If your firm touches taxpayer or financial data, a documented WISP is not optional.

IRS Publication 4557

All tax preparers must create and maintain a written security plan documenting how they protect taxpayer data. Required for PTIN renewal.

FTC Safeguards Rule

The amended Safeguards Rule (16 CFR Part 314) requires financial institutions, including tax preparers, to implement comprehensive security programs.

Penalties for non-compliance

FTC penalties can reach $46,517 per violation per day. Non-compliance may also result in PTIN suspension, preventing you from filing federal returns.

Gramm-Leach-Bliley Act

The GLBA requires businesses handling financial information to establish safeguards protecting the security and confidentiality of customer records.

WISP BUILDER

Answer the sections below. Your responses assemble a customized plan you can download and sign.

Everything runs locally in your browser. Nothing you type is sent to ProteSure or stored anywhere.

Step 1 of 9

Business Information

Basic information about your organization that will appear throughout your WISP.

Designated Security Coordinator

Federal regulations require you to designate a qualified individual responsible for coordinating your information security program.

Data Inventory & Risk Assessment

Identify the types of sensitive information your business collects, stores, and processes.

Physical Security Controls

Physical safeguards prevent unauthorized access to your office, equipment, and paper records.

Network & System Security

Technical safeguards that protect your computers, network, and systems from unauthorized access and cyber threats.

Data Protection & Encryption

How your business protects sensitive data in storage (at rest) and during transmission (in transit).

Access Controls & Authentication

Controls that ensure only authorized individuals can access sensitive systems and data.

Employee Training & Security Awareness

Ongoing training ensures employees understand their role in protecting sensitive information.

Incident Response & Breach Notification

Your plan for detecting, responding to, and recovering from security incidents and data breaches.

A plan on paper is the starting line. We implement the safeguards it describes, train your staff, and keep the documentation current.

This generator produces a starting document based on IRS Publication 4557, IRS Publication 5708, and the FTC Safeguards Rule (16 CFR Part 314). Have it reviewed by a qualified professional to confirm it meets the requirements that apply to your firm.