Written Information Security Plan
Your WISP, built around how the firm really works: what client data you hold, who touches it, and what protects it. Reviewed and updated as the firm changes, not filed away and forgotten.

Based in Winter Haven · Serving Polk County & the I-4 corridor
I am Kevin Woolf, the owner of Woolf IT Solutions. The IRS and the FTC require paid tax return preparers to keep a written information security plan. I build yours around how your firm actually works, put real security controls behind it, and keep both current.
Winter Haven chain of lakes, Central Florida
The problems
Your firm holds other people's financial records and works against deadlines that do not move. These are the problems I hear about most.
Filing season is the worst possible time for downtime. Returns are queued, clients are calling, and a deadline is already on the calendar. I set systems up so those mornings stay rare, and I put the upgrades and replacements in the quiet months instead of the busy ones.
Plenty of firms have a written plan in a folder somewhere, filled in once and never opened again. A plan that describes safeguards the firm does not actually run is worse than no plan, because it is a written record of the gap. I keep the document and the reality pointed at each other.
Client files carry Social Security numbers, bank details, and a complete picture of someone's finances. That is what makes a small firm worth attacking. Most attempts arrive as ordinary-looking email, and the defenses are multi-factor authentication, email security, and habits your team can actually keep during season.
A client's security questionnaire, an insurance renewal, or a professional review asks what safeguards you have in place. I hand you documentation written in language a reviewer already understands, so answering means sending a file instead of writing one under pressure.
What I do
One local person for the written plan, the controls behind it, the day-to-day support, and the planning. No juggling vendors.
Your WISP, built around how the firm really works: what client data you hold, who touches it, and what protects it. Reviewed and updated as the firm changes, not filed away and forgotten.
Endpoint protection, multi-factor authentication, and email filtering, sized for a small firm and tuned so it does not slow anyone down in the middle of season.
Automated backups of the client records and working files your firm cannot lose, tested so they actually restore, with a written recovery plan for the bad day.
I watch over your computers, network, and updates, and I am the person you call when something is wrong. You deal with the owner, not a ticket queue.
A Microsoft 365 move, a server replacement, an office move, or cleaning up years of IT drift. Scoped in plain English and scheduled around your calendar.
Technology budgets, roadmaps, and vendor decisions planned in the off season, so spending on IT stops being a surprise in the middle of one.

When the document and the reality drift apart, the document is the part that hurts you.
Great blue heron, Lake Howard, Winter Haven
The WISP
If your firm prepares tax returns for pay, the IRS and the FTC require you to keep a written information security plan. The FTC Safeguards Rule applies to "financial institutions" under the Gramm-Leach-Bliley Act, and that definition is broad enough to cover tax preparers and many accounting practices. Law firms that do not prepare returns get asked for the same thing anyway, by clients, by carriers, and by their own duty to protect what clients tell them.
IRS Publication 4557, "Safeguarding Taxpayer Data", is the plain-language reference, and the IRS has published a sample WISP template with the Security Summit. Both are a good place to start reading. Neither one is your plan, because a plan has to describe your firm: the data you hold, the people who touch it, and the controls that are actually running.
That is the work. I build the plan around how your firm really operates, put real security controls behind every line of it, and keep both current as the firm changes. When the document and the reality drift apart, the document is the part that hurts you.
I will not tell you I can make your firm compliant. Nobody outside your office can. Compliance includes how your team works every single day, and no vendor controls that. What I can do is keep the written plan honest, keep the safeguards real, and hand you documentation you can give a client, an insurer, or a reviewer without translating it first.
Chances are your firm runs on tax preparation software, a document management system, and the Microsoft 365 stack. I support the machines, the network, and the accounts all of that depends on, and I work with your software vendors when something breaks. I do not resell any of them, so my advice is not a sales pitch.
What you end up holding
Why Woolf IT
Woolf IT Solutions is owner-operated. There is no call center and no ticket roulette. The person who built your plan is the person who answers when something is wrong.
I live and work here, and I serve small offices across Polk County and the I-4 corridor. You are hiring a neighbor, not a national franchise.
The heavy work belongs in the quiet months. I set up monitoring that runs around the clock so problems get caught early, and I schedule upgrades and migrations well away from a deadline.
Questions
The questions partners and office managers ask me most. If yours is not here, just ask.
If your firm prepares tax returns for pay, yes. The IRS and the FTC both require it. The FTC Safeguards Rule reaches "financial institutions" under the Gramm-Leach-Bliley Act, and that definition covers tax preparers and many accounting practices. IRS Publication 4557, "Safeguarding Taxpayer Data", is the plain-language reference if you want to read the source yourself.
It is a genuinely useful starting point, and the IRS published it with the Security Summit for exactly that reason. The catch is that the template asks questions only your firm can answer, and a plan describing safeguards you do not actually run is a written record of the gap. Fill it in if you like, then let me make every line of it true.
No, and I would be careful with anyone who says otherwise. Compliance includes how your team works every day, which no outside vendor controls. What I do is build the plan around your firm, run the security controls behind it, keep both current, and give you documentation that shows the safeguards are real.
You do not have to wait, and you should not stop working to do this. We start with the pieces that would hurt most if they failed, usually backups, multi-factor authentication, and email security, then save the bigger changes for after the deadline. The written plan gets built alongside the work, not instead of it.
I support the computers, servers, network, and Microsoft 365 accounts that your tax preparation software and document management system run on. When the software itself misbehaves, I work with that vendor on your behalf, so you are not refereeing your own vendors in the middle of season.
They were always yours. Your accounts, domain, and data stay in your name, so nothing ends up parked under a master account of mine. If you ever leave, you leave with everything, and I help with the handoff.
It starts with a free IT assessment: a relaxed 30-minute conversation about your firm, your systems, and whatever you already have written down. You get a plain-English picture of where you stand and what the WISP would take, with no obligation.

The first step
Book a free IT assessment. We will start with your written information security plan: what it has to say, what has to be true behind it, and where your firm stands today. No pressure, no obligation. If you would rather talk first, call me.
Sunset on the dock, Winter Haven