If you handle customer financial information—including tax and accounting firms—the FTC Safeguards Rule makes you a 'financial institution' with a written security program to maintain. We monitor continuously and produce the evidence that shows your WISP is real and operating.
Book a 15-minute review →The FTC Safeguards Rule (16 CFR Part 314), under the Gramm-Leach-Bliley Act, requires covered businesses to maintain a written information security program with specific elements—a qualified individual, a risk assessment, access controls, monitoring, and encryption. For tax professionals, the IRS reinforces this through Publication 4557 and expects a written data security plan as a condition of holding a PTIN.
MDRwatchdog maps continuous monitoring to the Safeguards Rule's requirements and produces the evidence that your written plan isn't just a document in a drawer. You get safeguard evidence, risk-assessment support, and a gap report—so the plan reflects what your systems are actually doing.
MDRwatchdog supplies the monitoring and evidence to support your program; your specific obligations under the Safeguards Rule and IRS guidance should be confirmed with your own advisors. This is not legal or tax advice.
Yes. Firms that handle customer financial information are 'financial institutions' under the Rule and must maintain a written information security program. The IRS reinforces this for tax preparers through Publication 4557 and the WISP requirement.
A Written Information Security Plan documents how your firm protects client data—the safeguards, the responsible person, the risk assessment, and the incident response. The IRS expects every tax professional to have one; MDRwatchdog produces evidence that it's operating.
Key elements include a qualified individual to oversee the program, a written risk assessment, access controls, encryption, monitoring, and an incident response plan. MDRwatchdog maps continuous monitoring to these and flags gaps.
No. MDRwatchdog provides security monitoring and evidence to support your compliance program. Confirm your specific obligations with your own legal and tax advisors.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).