Skip to content
Bellator Cyber Guard
IRS • FTC • State Enforcement

WISP penalties: the real cost of non-compliance

Many tax professionals assume that cybersecurity compliance is optional or that the IRS will not enforce the rules against small practices. They are wrong. The consequences of non-compliance are severe, immediate, and increasingly common.

The numbers speak for themselves

$250
Base §6713 penalty per improper disclosure or use
$10K
Standard §6713 annual cap
$1K
Identity-theft-related amount per disclosure or use
$50K
Separate annual cap for identity-theft-related conduct

What happens when you do not comply

Non-compliance exposes you to overlapping penalties from federal agencies, state regulators, and private lawsuits. Here is what you are risking.

Potentially unlimited liability

Client Lawsuits and Class Actions

A breach can create contractual, insurance, notification, investigation, and customer-response obligations. The actual exposure depends on the incident and governing agreements; review those documents before making a cost estimate.

Don’t wait for an audit to find out you’re not compliant

The IRS, FTC, and state attorneys general are actively enforcing WISP requirements. Getting compliant now costs a fraction of what a single penalty or breach would cost your practice.

The hidden costs of a data breach

Regulatory fines are just the beginning. The true cost of a breach extends far beyond the penalties and can threaten the survival of your entire practice.

Incident scoping and forensic investigation

Legal and regulatory response

Customer notification and support

Business interruption and lost revenue during recovery (weeks to months)

Client attrition as affected individuals take their business elsewhere (30-50% typical)

Increased insurance premiums or inability to obtain cyber insurance

Reputational damage in your community that persists for years

Personal stress, anxiety, and time spent on recovery instead of serving clients

WISP penalties — frequently asked questions

There is no single automatic fine for “not having a WISP.” Depending on the conduct, enforcement can involve the FTC Safeguards Rule, 26 U.S.C. §§6713 and 7216, state law, contracts, or other authorities. The facts and applicable law determine the remedy.

Current Form W-12 instructions say Line 11 acknowledges awareness that paid preparers are required by law to create and maintain a WISP. The instructions do not describe Line 11 as an IRS approval of the plan or state that missing a WISP automatically revokes a PTIN.

The FTC publishes Safeguards Rule compliance guidance, and the IRS directs tax professionals to Publications 4557 and 5708. This page does not claim a specific future audit frequency or enforcement quota. Keep the plan current and retain evidence that safeguards are operating.

A breach can require investigation, legal analysis, notifications, customer support, restoration, and business-continuity work. The actual cost depends on the records, systems, contracts, insurance, jurisdictions, and response; use a scoped incident assessment instead of a generic average.

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

  • Know what applies
  • Document the evidence
  • Make the safeguard operational

A defensible path

  1. 01

    Confirm the requirement

    Separate what is required from recommendations and vendor language.

  2. 02

    Map it to your environment

    Connect the rule to people, devices, data, vendors, and current procedures.

  3. 03

    Close and document the gaps

    Prioritize changes and keep evidence that the process is being followed.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.