How ready is your firm? Score yourself in two minutes.
Ten plain-language questions mapped to the FTC Safeguards Rule and IRS Publication 4557, Safeguarding Taxpayer Data. Instant grade, no jargon, clear next steps.
-
1Does your firm have a written information security plan (WISP) that was reviewed or updated in the last 12 months?
-
2Is one specific person accountable for your firm’s security program?
-
3Is multi-factor authentication enforced on every account that touches client data, email included?
-
4Does every computer used for client work run managed, monitored threat protection (not just store-bought antivirus)?
-
5Does everyone work from a dedicated, firm-managed computer? No personal or family-shared devices touching client data?
-
6Are the hard drives on all firm laptops and computers encrypted?
-
7Does every person in the firm complete security awareness training at least annually?
-
8Are your backups automatic, stored offsite, and actually tested with a restore?
-
9Do you know every vendor and cloud service that holds your client data, and have you assessed them?
-
10Do you have a written incident response plan your team could follow at 7 a.m. on April 10th?
Answer every question to see your score.
Solid foundations, real gaps.
Your breakdown, worst gaps first
This self-assessment is educational, based on the FTC Safeguards Rule's required elements and IRS Publication 4557 guidance. It is not a compliance certification or legal advice. For a real assessment of your firm, talk to us or your counsel.
Whatever you scored, we can get you to an A.
A 30-minute discovery call. We will look at your gaps together and show you exactly what closing them takes.
Talk to a guru nowNot ready to talk? Score your firm's security in two minutes.
No long-term contract. No hour caps. No minimums. 60-day cancellation any time. We earn it every month. · (800) 692-6096