{"id":68950,"date":"2024-12-06T10:00:08","date_gmt":"2024-12-06T18:00:08","guid":{"rendered":"https:\/\/lapost.us\/?p=68950"},"modified":"2024-12-06T10:00:08","modified_gmt":"2024-12-06T18:00:08","slug":"national-tax-security-awareness-week-day-5-tax-pros-urged-to-guard-against-identity-theft-with-updated-written-information-security-plan","status":"publish","type":"post","link":"https:\/\/lapost.us\/?p=68950","title":{"rendered":"National Tax Security Awareness Week, Day 5: Tax pros urged to guard against identity theft with updated Written Information Security Plan"},"content":{"rendered":"<p>IR-2024-308, <strong>Dec. 6, 2024,\u00a0WASHINGTON<\/strong> \u2013 On the\u00a0final day of National Tax Security Awareness Week,\u00a0the Internal Revenue Service and its Security Summit partners urged tax professionals to reassess their plans for protecting themselves and their clients\u2019 sensitive information amid increasing attempts by\u00a0identity thieves to steal tax data.<\/p>\n<p>Identity thieves on the hunt for taxpayer data aren\u2019t just targeting taxpayers, they\u2019re going after the tax professionals, who hold enormous amounts of sensitive taxpayer data, in hopes of filing fraudulent tax returns. This year, the IRS has already received more than 250 reports of data breach incidents from tax professionals affecting approximately 200,000 clients.<\/p>\n<p>Amid these continuing reports of tax professionals encountering data breaches, the Security Summit partners urged practitioners to review the newly updated\u00a0<a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p5708.pdf\">Written Information Security Plan (WISP)<\/a>.<\/p>\n<p>Tax professionals are required by federal law to have written plans identifying foreseeable data security risks and safeguards, and a plan of action to take in the event of a security breach. To simplify this complex task, a special team of Security Summit members from the tax community released an updated WISP that tax professionals can use as a roadmap to apply to their own practice.<\/p>\n<p>The IRS also reminds taxpayers that additional safeguards, like multi-factor authentication (MFA), are required by federal law to better protect themselves and their clients. MFA provides an extra layer of security to ensure the proper people are accessing sensitive accounts and systems.<\/p>\n<p>\u201cCountering identity theft is a collective effort, and tax pros are the first line of defense when it comes to protecting taxpayer information,\u201d said IRS Commissioner Danny Werfel. \u201cMillions of taxpayers entrust their personal data to tax professionals, and we want to make it as easy as possible for tax pros to know what they need to do to keep themselves and their clients\u2019 information safe. The Written Information Security Plan forms an essential part of the tax professionals\u2019 defense against data breaches and identity thieves, helping protect their clients and protect themselves.\u201d<\/p>\n<p>The WISP, available in IRS\u00a0<a href=\"https:\/\/www.google.com\/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=&amp;ved=2ahUKEwjo3I7pjbSJAxXjElkFHS4kIfQQFnoECBwQAQ&amp;url=https%3A%2F%2Fwww.irs.gov%2Fpub%2Firs-pdf%2Fp5708.pdf&amp;usg=AOvVaw25JsUo-MphkMKw_s2ZG6bf&amp;opi=89978449\">Publication 5708, Creating a Written Information Security Plan for your Tax &amp; Accounting Practice<\/a>, walks tax professionals through the steps of assembling a plan, including understanding security compliance requirements and professional responsibilities. It also provides a sample template that tax professionals can use as they draft a plan for their business.<\/p>\n<p>The new version of the WISP, the result of a year-long collaborative effort between the IRS and its Security Summit partners, includes several updates, like highlighting best practices for implementing multi-factor authentication.<\/p>\n<p>During <a href=\"https:\/\/www.irs.gov\/newsroom\/national-tax-security-awareness-week-2024\">National Tax Security Awareness Week<\/a>, now in its ninth year and concluding today, the Security Summit partnership of the IRS, tax professionals, tax software and financial companies as well as state tax agencies work to raise awareness among taxpayers and tax professionals about the importance of safeguarding information to protect against identity theft. The Security Summit formed in 2015 to combat tax-related identity theft through better public-private sector coordination as well as strengthening internal protections in the tax community and raising public awareness about security threats.<\/p>\n<p>Tax pros are on the front lines of defense in protecting taxpayer information. The Summit partners highlighted several key steps that tax pros \u2013 regardless of the size of their practice \u2013 should take to protect their systems and comply with federal standards.<\/p>\n<p><strong>WISPs and MFA are crucial \u2013 and necessary <\/strong><\/p>\n<p>Members of the Summit&#8217;s tax professional team developed a helpful guide that allows practitioners to quickly develop their own WISP to provide a blueprint for information security.<\/p>\n<p>\u201cThis helpful guide with sample templates provides a starting point for businesses large or small, and can be scaled for a company&#8217;s size, scope of activities, complexity and customer data sensitivity,\u201d said Kimberly Rogers, the IRS Return Preparer Office director and co-chair of the Summit\u2019s tax pro group. \u201cThere&#8217;s not a one-size-fits-all WISP. A sole practitioner can use a more abbreviated and simplified plan than a 10-partner accounting firm. This flexibility is reflected in the sample policies and pre-populated templates included in the publication.\u201d<\/p>\n<p>Addressing security issues for a tax professional can be difficult and expensive. A WISP addresses risk considerations for inclusion in an effective plan and provides a blueprint of applicable actions in the event of a security incident, data loss or theft.<\/p>\n<p>Tax pros can also review\u00a0<a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p5709.pdf\">IRS Publication 5709, How to Create a Written Information Security Plan for Data Safety<\/a>, for more information on WISPs.<\/p>\n<p>In addition to requirements to have a WISP, the IRS also reminds the tax community that the Federal Trade Commission last year updated its safeguards standards and now require tax professionals to use MFA to protect client information. MFA, which can include sending text\/SMS verification codes to a user or asking additional questions to confirm the identity of a person logging into a system, provides an extra layer of security to ensure the proper people are accessing sensitive accounts and systems.<\/p>\n<p>&#8220;Building and maintaining a resilient security plan is more than just a requirement \u2014 it&#8217;s a safeguard for both tax professionals and their clients,&#8221; said Jared Ballew, president of the National Association of Computerized Tax Processors and one of the Summit members who helped develop the WISP.<\/p>\n<p>&#8220;There\u2019s no single silver bullet for security; effective protection requires multiple layers of defense,\u201d Ballew continued. \u201cOur goal with these resources is to help tax pros create and reinforce those layers, with the WISP providing a solid foundation to start or enhance that process. The Security Summit partners remain committed to helping every tax professional stay proactive and protected in today\u2019s digital landscape.&#8221;<\/p>\n<p><strong>IRS Tax Pro Account: Protects pros and their clients\u2019 data and saves time, too<\/strong><\/p>\n<p>The IRS and Summit partners also emphasize another way to help protect sensitive information from identity thieves is through secure online tools such as the\u00a0<a href=\"https:\/\/www.irs.gov\/tax-professionals\/tax-pro-account\">Tax Pro Account<\/a>. These tools can help manage client information to safeguard sensitive taxpayer and financial data from cyberthreats.<\/p>\n<p>The Tax Pro Account is a secure, mobile-friendly, digital, self-service application that enables tax professionals to act on a taxpayers&#8217; behalf, view the taxpayers&#8217; information and manage their authorization relationships more efficiently.<\/p>\n<p>As part of IRS transformation efforts, the IRS will continue adding new features to the Tax Pro Account in the future to help tax professionals securely and efficiently serve their clients.<\/p>\n<p>Currently, tax professionals can use Tax Pro Account to send Power of Attorney and Tax Information Authorization requests directly to a taxpayer&#8217;s individual\u00a0<a href=\"https:\/\/www.irs.gov\/payments\/online-account-for-individuals\">IRS Online Account<\/a>. Once the taxpayer approves the request, it&#8217;s processed in real time \u2014 no faxing, mailing, uploading or long waits.<\/p>\n<p>Visit the\u00a0<a href=\"https:\/\/www.irs.gov\/tax-professionals\">Tax Professionals<\/a>\u00a0page on IRS.gov to learn more about E-Services, Tax Pro Account, Employer Identification Numbers, filing, forms, third-party authorizations as well as other safe and secure online tools to serve clients.<\/p>\n<p><strong>Data breaches: What to do when the worst happens<\/strong><\/p>\n<p>The IRS also recommends tax professionals create an action plan to outline the steps to take in the event of a breach or data theft, in addition to the required Written Information Security Plan. Tax pros now need to report a security event affecting 500 or more people to the Federal Trade Commission as soon as possible, but no later than 30 days from the date of discovery.<\/p>\n<p>A key component to an effective action plan is knowing who to contact. In addition to reporting data loss to the IRS, tax professionals should contact law enforcement, the appropriate states, clients and security professionals.<\/p>\n<p><strong>Places to get help in case of a data breach:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/www.irs.gov\/businesses\/small-businesses-self-employed\/stakeholder-liaison-local-contacts\">IRS Stakeholder Liaison<\/a>\u2013 The IRS recommends reporting data theft to the local Stakeholder Liaison first. Liaisons will notify IRS Criminal Investigation and others within the agency on the tax professional&#8217;s behalf. Speed is critical. If reported quickly, the IRS can take steps to block fraudulent returns in clients&#8217; names.<\/li>\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/privacy-security\/gramm-leach-bliley-act\/safeguards-rule-form\">Federal Trade Commission<\/a> \u2013 Data breaches involving 500 or more people are now required to be reported to the FTC as soon as possible, but no later than 30 days from the date of discovery.<\/li>\n<li><a href=\"https:\/\/www.fbi.gov\/contact-us\/field-offices\">Federal Bureau of Investigation<\/a>\u2013 the local office.<\/li>\n<li><a href=\"http:\/\/www.secretservice.gov\/contact\/field-offices\/\">Secret Service<\/a>\u2013 the local office (if directed).<\/li>\n<li>Local police \u2013 to file a police report on the data breach.<\/li>\n<\/ul>\n<p><strong>Contacting states in which tax pros prepare state returns:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/taxadmin.org\/report-a-data-breach\/\">Federation of Tax Administrators<\/a>\u2013 Tax professionals can reach this special &#8220;report a data breach&#8221; web page for victim reporting guidance to the states.<\/li>\n<li><a href=\"http:\/\/www.naag.org\/naag\/attorneys-general\/whos-my-ag.php\">State Attorneys General<\/a>\u2013<strong>\u00a0<\/strong>most states require that the state attorney general be notified of data breaches.<\/li>\n<\/ul>\n<p><strong>Additional resources<\/strong><\/p>\n<ul>\n<li>Go to <a href=\"https:\/\/www.irs.gov\/newsroom\/national-tax-security-awareness-week-2024\">National Tax Security Awareness Week 2024<\/a> for additional information.<\/li>\n<li>For more information on preventing tax information theft, visit <a href=\"https:\/\/www.irs.gov\/newsroom\/security-summit\">Security Summit<\/a>.<\/li>\n<li>Victims of identity theft, or a client that is, can visit <a href=\"https:\/\/www.irs.gov\/identity-theft-central\">Identity Theft Central<\/a>.<\/li>\n<li><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\">Publication 4557, Safeguarding Taxpayer Data<\/a>.<\/li>\n<li><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p5293.pdf\">Publication 5293, Data Security Resource Guide for Tax Professionals<\/a>.<\/li>\n<li><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4524.pdf\">Publication 4524, Security Awareness for Taxpayers<\/a>.<\/li>\n<li>National Institute of Standards and Technology\u00a0\u2014\u00a0<a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2016\/NIST.IR.7621r1.pdf\">Small Business Information Security: The Fundamentals<\/a>.<\/li>\n<li>Federal Trade Commission&#8217;s\u00a0<a href=\"https:\/\/www.ftc.gov\/business-guidance\/small-businesses\/cybersecurity\">Cybersecurity for Small Businesses<\/a>.<\/li>\n<\/ul>\n<p>Tax professionals should also stay connected to the IRS through subscriptions to\u00a0<a href=\"https:\/\/www.irs.gov\/newsroom\/e-news-subscriptions#taxpros\">e-News for tax professionals<\/a>\u00a0and its\u00a0<a href=\"https:\/\/www.irs.gov\/newsroom\/irs-social-media\">social media sites<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IR-2024-308, Dec. 6, 2024,\u00a0WASHINGTON \u2013 On&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,7],"tags":[],"class_list":["post-68950","post","type-post","status-publish","format-standard","hentry","category-business","category-u-s-a"],"_links":{"self":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/68950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=68950"}],"version-history":[{"count":1,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/68950\/revisions"}],"predecessor-version":[{"id":68951,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/68950\/revisions\/68951"}],"wp:attachment":[{"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=68950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=68950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=68950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}