ATL271: Why Your WISP Is Essential in 2026
Impossibile aggiungere al carrello
Rimozione dalla Lista desideri non riuscita.
Non è stato possibile aggiungere il titolo alla Libreria
Non è stato possibile seguire il Podcast
Esecuzione del comando Non seguire più non riuscita
-
Letto da:
-
Di:
Episode Summary: ATL271 - Why Your WISP Is Essential in 2026
Podcast Page/Subscription Links: https://podcast.cpate.ch
Wiki Page: ATL271 - CPA Tech Wiki
In ATL271, “Why Your WISP Is Essential in 2026,” Randy Johnston and Brian Tankersley explain why a written information security plan is no longer a compliance document that can sit on a shelf. Accounting firms hold concentrated stores of tax, financial, identity, and sometimes health information, making them attractive targets for phishing, credential theft, ransomware, fraudulent wire instructions, and AI-enhanced attacks. The hosts walk through the overlapping expectations of the IRS, FTC Safeguards Rule, and HIPAA, including written policies, multi-factor authentication, encryption, logging, incident response, training, governance, vendor oversight, and regular risk assessment. They emphasize that penalties can be severe, but the larger business risk may be client loss, reputational damage, litigation, and disruption during tax season. The episode also highlights practical governance: assign accountability, review the WISP regularly, connect security spending to risk, and report results to leadership. Randy and Brian close with five high-impact controls—MFA, full-disk encryption, tested backups, a written incident response plan, and vendor security questionnaires—plus a recurring calendar for log reviews, backup restores, phishing simulations, vulnerability scans, training, patching, and annual WISP updates. Their message: security is an operating discipline, not paperwork. For firms of every size, preparation now is cheaper than recovery.
Key Takeaways
- A WISP should be an operating system for security—not shelfware. It needs ownership, periodic review, documented changes, and executive oversight.
- Accounting firms are unusually attractive targets because they aggregate tax, financial, identity, payroll, and other confidential information.
- Credential theft and phishing remain central risks, while AI is making fraudulent messages and attacks more convincing.
- Vendor management belongs inside the security program. Cloud applications, hosting companies, MSPs, AI services, and other third parties expand the firm's attack surface.
- Incident response must be planned before the incident. Firms should understand regulatory notification obligations, internal responsibilities, legal resources, and PR response.
- Security has a recurring calendar. Log reviews, backup restores, phishing tests, vulnerability scanning, access reviews, training, patching, and WISP updates need assigned frequencies and owners.
Catchy Quotes
Approx. TimeSpeakerQuote
02:04 | Brian Tankersley | “The firms get hit because you and I are the Fort Knox of confidential data.”
03:33 | Brian Tankersley | “The bad guys are getting better faster than the good guys are getting better.”
07:40 | Brian Tankersley | “Anything that touches client data is a death sentence for a hard drive in my office.”
12:10 | Brian Tankersley | “If you don't have an adequate WISP, you're in violation of the FTC safeguards rule.”
18:20 | Randy Johnston | “You've got risk on any provider.”
18:42 | Brian Tankersley | “As soon as you know something's happened, the clock is ticking.”
23:11 | Brian Tankersley | “Multi-factor authentication, full disk encryption, tested backup strategies, written incident response plans, vendor security questionnaires.”
24:55 | Randy Johnston | “Make sure that you've got your WISP … pulled out, dusted off, and updated for this year's regulations.”
Note: Timestamps are approximate where the quote occurs inside a longer timestamped speaker segment in the transcript.
Social Media Posts