Howell & Gibbs

A defensible WISP
in 30 minutes.

The Written Information Security Plan the IRS and your cyber insurer require — built from how your practice actually works, not a template you fill in and never look at again.

Start the form free

$299 once · no subscription · you keep it

Every other WISP tool hands you a document. This one tells you what is wrong with your practice.

As you answer, it scores eight standard threats against the safeguards you actually have, and names the specific control each gap needs — not “partial”, but still needs a tested restore. Those gaps become a remediation plan at the back of your WISP, each with your name against it and a date.

That is the section an examiner turns to, and the one a cyber underwriter asks for. A plan that names its gaps is defensible. One that quietly omits them is not.

Remediation plan — extract

Multi-factor authentication on every system · target 14 Feb 2027
A secure client portal · target 16 Nov 2026
A tested restore · target 14 Feb 2027

How it works

  1. 01

    Answer

    Fifteen short sections of plain questions about your firm. Every one explains why the IRS or the FTC asks for it. Saves as you type — stop and come back.

  2. 02

    See your gaps

    Open items appear as you go, each linked to the question that closes it. Fix them now or record them with a date.

  3. 03

    Download

    A formatted, page-numbered PDF with a contents page, ready to hand to an examiner, an insurer, or your PTIN renewal.

What the document covers

  • Scope and firm details
  • Qualified Individual
  • Workforce
  • Data inventory
  • Risk assessment
  • Tools in use
  • Physical safeguards
  • Authentication and passwords
  • Access control
  • Encryption
  • Backups and recovery
  • Monitoring, testing, and change management
  • Service providers
  • Incident response
  • Training
  • Program review and maintenance
  • Remediation plan

Written against IRS Publication 4557, Publication 5708, and the FTC Safeguards Rule (16 CFR Part 314).

$299, once.

Includes twelve months of regulatory updates: come back and regenerate against the current rules at no charge. After that, updates and the remediation tracker are $99/year if you choose to buy them — optional, never automatic — and if you do not, the document you generated stays yours.

 ThisWISP BuilderA consultantFree template
Price$299 once$249 / year$577–999$0
Time to a finished plan30 minutesSelf-serve7–10 daysYour weekend
Names the safeguards you lackYesNoSometimesNo
Dated remediation planYesNoNoNo
Keep it if you stop payingYesNoYesYes
Staff sign-off, multi-userNot yetYesVariesNo

Built for solo and small practices. If you have staff who each need to sign off on the plan, WISP Builder does that today and we do not — we would rather say so than sell you the wrong thing.

Competitor prices and features are as published on their own sites, last checked September 2026, and may have changed since.

Common questions

Do I actually need one?
If you are a paid preparer handling taxpayer data, yes. The FTC Safeguards Rule treats tax practices as financial institutions and requires a written program, Form W-12 makes you confirm you know that obligation every time you renew your PTIN, and cyber insurers increasingly will not quote without one — and will look for it before paying a claim.
Does my data leave my browser?
Your answers are stored in your browser, not on our servers. They are sent to us once, at the moment you download, so the PDF can be rendered — and are not kept afterwards. There is no account and no database holding your firm’s details.
What if my practice changes mid-year?
Come back, change the answers, and generate again. Taking on a first employee or having an incident are both reasons the plan should be revised, and the document says so in its own review section.
Is this legally sufficient?
It is written against IRS Publication 4557, Publication 5708, and 16 CFR Part 314, by security engineers who maintain a WISP for a tax platform of their own. It is not legal advice, and no document makes a practice compliant on its own — the safeguards it records have to be real.
What if it is not what I expected?
Email us within 14 days and we will refund you.