No WISP on file
The FTC Safeguards Rule (via GLBA) requires tax preparers to maintain a written information security plan. Many firms have none — or a template nobody implemented.
The FTC Safeguards Rule makes a written information security plan mandatory for tax preparers — and April doesn't wait for a server. We implement the required technical controls, keep tax software fast, and make busy season boring.
Tax preparers handle SSNs, bank statements, and filing deadlines under the FTC Safeguards Rule and IRS Publication 4557 expectations. We implement and document the technical safeguards those frameworks call for; your firm retains responsibility for its overall compliance program. Busy season also means seasonal staff, database-heavy tax apps, and zero tolerance for untested backups.
The FTC Safeguards Rule (via GLBA) requires tax preparers to maintain a written information security plan. Many firms have none — or a template nobody implemented.
Database-heavy tax applications punished by old servers and flat networks exactly when filing volume peaks.
SSNs and bank statements moving through unencrypted email instead of a portal.
Multi-factor authentication is now baseline for tax pros; partial rollouts leave the gap an auditor finds.
Temporary preparers need accounts, access, and training in January, and clean removal in May.
A ransomware event during filing season with an unverified backup is a firm-ending scenario.
The services most relevant to CPA and accounting firms:
Safeguards technical controls: MFA, email security, access control, and phishing training.
View service →Continuous monitoring that supports Safeguards technical controls.
View service →Busy-season help desk, seasonal onboarding/offboarding, and workstation performance.
View service →Restore-tested backups for tax databases and client files before filing season.
View service →Encryption, secure sharing, and portal-friendly document workflows.
View service →Fast remote response when a preparer's workstation fails mid-return.
View service →A useful review connects written policy to evidence in the environment. RANGO maps the technical side of your WISP to identities, devices, email, tax-data storage, monitoring, vendors, and recovery. Your firm and its advisers retain responsibility for deciding which legal and regulatory requirements apply.
We identify which technical safeguards are implemented, where proof is stored, who owns each control, and which gaps need a dated remediation plan.
We review administrator roles, remote access, temporary preparer accounts, shared credentials, and the offboarding process after filing season.
We benchmark workstations, servers, storage, network paths, and vendor dependencies so busy-season performance work targets measured constraints.
We verify what is protected, how long it is retained, whether restores work, and how the firm will communicate and operate during a security incident.
Start with the regulators' own guidance, then use RANGO's implementation guides to turn written requirements into practical controls and recovery tests.
The FTC's explanation of the written information security program and administrative, technical, and physical safeguards covered entities need to address.
Read official source ↗Official IRS guidance for tax professionals on safeguarding taxpayer data and maintaining a security plan.
Read official source ↗How MFA, EDR, backups, and incident planning commonly show up in underwriting questionnaires.
Explore resource →A control-focused guide to reducing ransomware exposure and testing recovery.
Explore resource →Local support for professional firms in Coral Gables and nearby business districts.
Explore resource →Managed IT and cybersecurity support from RANGO's Miami Lakes headquarters.
Explore resource →We implement and document the technical controls the plan requires — access control, encryption, MFA, monitoring, backup — and provide the documentation for your plan.
We support the infrastructure, identity, and file-performance side your tax platforms run on and handle vendor escalations; the platforms remain yours.
15-minute remote acknowledgement for critical incidents, 24/7, for managed-service clients. On-site response typically under 4 hours in Miami-Dade during business hours.
We configure secure file exchange and email encryption around your existing tax and document workflow.
A designated security lead, risk assessment, access controls, encryption, MFA, monitoring, tested incident response, and vendor oversight — we map each to a concrete control in your environment.
A free CPA firm IT review maps Safeguards technical controls, tax-app performance, MFA gaps, and backup restore readiness. No obligation.