Transcription
[Music] [Music] [Music] Happy Tuesday and good morning everybody. Listen, today we are a little bit behind, and that is on me. You all know how I am about working in the morning, talking to people before 1 a.m. So, I was a little behind getting on here, and I apologize to you all and to our guests for today.
But we have a really, really awesome topic, which is much needed. I am happy to be able to bring on a guest with me today because what we are talking about today is something that is absolutely needed now. It's required if you have a P10. So, what is happening though? Because it's not tax-specific, is there are a lot of taxpayers who are checking the box to say they've met this requirement, and they aren't. Which is not only problematic for you as a preparer lying to the IRS, but it's also problematic because we live in a world where most of our business is internet-based, and we have to take into consideration how we are protecting our data and our clients' data as well, right?
So, if you are new here, my name is Timlin Bowens. I am America's Favorite EA. I am also the owner of Bowens Tax Solutions, which is a virtual firm based in Lexington, Kentucky, and we specialize in helping people with their tax issues. This video on today, though, is for my fellow tax professionals. And in our video today, we are going to be talking about a Written Information Security Plan. And as I said before, this is out of my area of expertise. Do I have one? Yes. Can I tell everybody else how to do one? Uh, there are going to be some bumps along the road. So, what I did is I brought in an expert to help us learn what types of things should be in a WISP, but also to look at the broader picture outside of the IRS because a WISP isn't new. It's just a new requirement for the IRS.
So, before I bring our special guest on today, I am going to see who is in the virtual room. And you all know I need to make sure that I'm live on LinkedIn. If you're on LinkedIn right now, if you hear me, see me, let me know down in the comments because as of right now, you are not popping up. Um, if this is your first time checking this out, I promise I'm not crazy. StreamYard and LinkedIn don't always have the best relationship. So, I can't see my LinkedIn people over here. I have you pulled up on my second screen. If you were going to leave a comment, make sure that you give StreamYard permission to share your comment, and then that way it should pop over here. So, let me see if I can see myself going live yet.
But in the meantime, first person on today was Casey Williams. Good morning from Georgia. Ben Cooper is online today. Thank you for joining us. We have Erica. Good morning. See Jacob. Jacob, you all did not see myself live yet. Make sure I'm here. So, my YouTube people are good. Nobody's on Facebook yet. We got about 13 on YouTube. May, it's so good to see you from California. Thanks for joining me super early. You guys know I wouldn't have made it to an 8 o'clock meeting. I would have had to get the replay. Tena, good morning. Anisha Taylor's here. Good morning. We got Miss Dorothy. Good morning. Tanya Horton. Oh, great news for me. David Puit is here. David Puit, CPA, is here. He's on LinkedIn. Thank you so much, David, for commenting because I still don't see myself over here. So, I was getting a little worried. We've got Carlos Boyd. Okay, here I am. Perfect. And ASA Jane, she says she's on LinkedIn and YouTube. Well, thanks for joining me on both spots.
So, without any further ado, I do want to go ahead and introduce our guest. So, unlike the other guests that I've had on here, I haven't met this person in a tax group. I didn't meet this person at a tax conference. Um, we actually met via email, and I went and I looked up this person online. And you guys know me, I'll go find you on LinkedIn and go do a deep dive because I had this list of things that I wanted to be able to share and help you all with. But as I mentioned already, the WISP is not something that I felt comfortable teaching because it's out of my area of expertise, right? So, I had these different things like tax planning. You know, I had Angie T here last week. I had the WISP. I was like, who can I get on here to do this for me? And it was like, God just placed this person right in my lap via email, letting me know that this was their expertise and asking if they could share with my audience. So, before I got too excited, I had to go vet them, right? And go do all the research and things. But today, I am happy to introduce to you all the owner of Blue Sky Technology, and his name is Mike Nava.
Now, before I bring him up, I'll give you a little bit more information. I'm not going to tell you everything. I'll let him do that, right? But Mike is a seasoned IT and cybersecurity, cybersecurity expert with over 20 years of experience. All right. With Blue Sky Technologies, he helps small businesses enhance their technology infrastructures through services like Managed IT solutions, cybersecurity assessments, and security awareness [Music] training. One of the really cool things that he shared with me is a tool that he has related to the IRS WISP. But of course, he's going to be able to tell us about it better than I can. So, I will go ahead and bring him on. Good morning, Mike. Thank you so much for being here with me today.
Good morning. Thank you for inviting me. Yes, absolutely. Um, like I just mentioned to our audience, I definitely had to do my background check because I feel an obligation to take care of them to certain extent, almost like a parent, if you will. Um, but from what the research I was able to do, everything checked out, and I feel honored to have you here. Um, sometimes we can get lost in the tax language. So, for you to have that other area of expertise to help keep us safe the way we keep our tax clients safe is awesome.
Well, you worry about the uh uh the accounting language, and I'll handle the uh the cybersecurity language. That's my expertise. So, as I mentioned before, there, the IRS has made it, well, you've tried to make it, I'll say, a requirement. There's nothing that's going to kick you off the system right now if you don't have a WISP in place. But something that I found very dangerous is I did an article sharing 10 different foundational things to have success with starting an enrolled agent firm. I've had people respond to me in email, on the phone, in DMs with, "Well, what about the WISP? I saw that when I renewed my P10, but I don't even know what it is." So, I'm like, "Oh my goodness, hope the IRS doesn't call me in as a witness." Right? For the tax professionals who may not even know what a WISP is, can you share with us, what is a WISP?
Sure. Well, a WISP is, it stands for Written Information Security Plan. And there's a reason it has to be written because if you come into your office or uh workplace, and let's just say all the computers are gone, maybe there was a theft at night. Well, there's a lot of taxpayer information that was gone as well. So, the IRS basically is saying, well, some, some accounting firms are safeguarding, and some are not. So, why don't we just create kind of a set of policies, do's and don'ts, if you will, uh, for for safeguarding taxpayer data? And uh, that's what, that's what they call a WISP. So, it's, it's a written information security plan that you have to maintain on site, physically, in case there's a disaster. And there's many different types of disasters. You can go to it, you have all the phone numbers, you have all the instructions, and the, uh, basically the procedures and policies on what to do next.
Well, so you brought up a great point. Um, I remember my first busy season in 2011, there was a huge file room, right? Because people would bring things in, we'd scan, make copies, and everything was stored there. But now, for the most part, a lot of offices are paperless. I say most, not all. But when we're thinking about the Written Information Security Plan, a lot of people don't think about theft of their computer. So, it doesn't even necessarily have to be a hack. Like, what are you doing to protect that data? So, I'm glad that you use that as an example. But from a cybersecurity point of view, why is this important? Because I think some people are like, "Well, the IRS is just requiring us to do more things. Why are they adding another thing for us to do?"
Well, that little checkbox that you checked, you know, like you said, is very important. So, there's a couple of reasons they, they do this. First, it's a regulatory issue. So, you have the GLBA, the Gramm-Leach-Bliley Act, that you have to do it. So, not only is it a good practice, it's required, and it's required by that act. And there's three forms that I'll give you that your your viewers could look at. The WISP was basically comprised of three IRS forms, and that's Forms 578, 4557, and 13345. So, if they, if they just Google those, it'll probably be the first result. Uh, but if you look at those, that's basically what is comprised in the WISP. All the guidelines, all the, the technical requirements, and the reasoning why is all in those three, those three documents. But basically, it's, you have very sensitive information, driver's licenses, sometimes HR payroll records, and you have, you know, Social Security, and all this. They want to make sure that that's protected from various forms of problems or, uh, for example, theft. We already covered that. Ransomware is probably the number one. And ransomware is where all of your files get encrypted, uh, and you can't open anything. You can't open a picture, you can't open a PDF file, uh, and usually those are indicated by white icons with a ransom note, usually a notepad on the front of your desktop saying, "Open me" or "Read me." And that's basically telling you, "We own all your files, and pay us this much money in this fashion, and we will release them to you." That is ransomware, and that is probably the number one pervasive problem that accountants are facing, because it takes seconds to encrypt every file on your computer. Um, but you also have to worry about theft, and water damage, and some of the other things that, uh, will put your taxpayer data at risk.
So, with the ransomware, this is another thing that, so, is mind-boggling to me. I'll have people on, I lost your audio a second, uh, oh, can you hear me now? Can you hear me? I lost the...
Give you just a [Music] second. I think I got you back.
You got me back? Can you hear me?
I can hear you. Okay, awesome. I was like, "Oh no, the whole reason you're here is me, the expert." I was feeling butterflies over here. Um, with the ransomware, when I was saying is, there are a lot of people who, they don't realize that they shouldn't click on links or open attachments from people that they don't recognize. Do you know, and if you don't know an exact number, that's okay, how often it is that people are victims of, uh, being hacked like with ransomware where everything is getting encrypted like that?
I, I don't have the numbers currently with me, um, but it's increasing. It's increasing a lot. In fact, the IRS, I believe, this earlier this year, came out with a reminder for that WISP, uh, with a, um, a fine schedule as well. Uh, so, basically, nobody's doing it. I know an IRS agent who does audits. Fact, he's a family member. Um, and we unofficially talked about this, and he said, "Yes, no, very few people are doing it." They're checking the box, they're paying their $30 for the P10, but nobody is really doing the WISP. They might have an antivirus, they might have some protections in there, in their, in the workplace, but nobody is really doing it, which is what, why the IRS was prompted to remind everybody of the fine schedule.
Gotta. So, we have all these different areas that the client data at risk. What are some of the most important things to consider when creating the WISP? And of course, you gave the publications where the IRS does have a template, right? But for somebody who's not in IT world, that's the equivalent to me telling you, "Well, Mike, you can do your 1040. The IRS gave you instructions. The form is right there online."
That's a really, it's a really, really good point. So, let me hit some high points on kind of the big ones. You know, just maybe the, the top maybe three or four big things that they want you to worry, not worry about, but but to have in place. First, of course, it's protect. It's all about protecting the taxpayer data. So, encryption is one of the kind of the technical things that, that is kind of a big deal. So, I used earlier that scenario where you come in and all your computers are gone. Okay, all your taxpayer data is basically gone. Um, I can take your computer out of your office, bring it to my workshop, open it up, take the hard drive out, mount it to my computer, and just drag and drop all the files. Okay? If your computer is encrypted, when I try to do that, I see a bunch of scrambled data. I don't see anything. That is what's called encryption. And and they want you to have that encrypted hard drive so that if you do have a physical problem where somebody gains access to your computer, they can't just open the hard drive, rip out your data, and copy it and get to it. It's impossible to do that. So, encryption is one of those kind of big, big words that you'll hear. And there's different types of encryption. Uh, there's encryption, uh, according to the IRS, and and and what they require is protection with, uh, encryption at rest, which is encrypting your hard drive. And if they look, BitLocker, you could easily encrypt your own hard drive. It, it doesn't take long, and the instructions are online. It's called BitLocker. That's a Microsoft way to encrypt the drive. Uh, it's free, and you can, anybody can do that. Then there is encryption in transit. So, there's encryption while that, that PDF file, let's just say a PDF file, uh, is sitting on your computer. That computer has to be encrypted. But what about in transit? As you're doing your day-to-day work, let's use QuickBooks as a great example. Uh, if you're using QuickBooks Online, your data is basically on a secure server at all times. And as you move it around, as you maybe email the client through QuickBooks Online, all that data is scrambled. It's encrypted. If, if I were to somehow get in between you and, uh, your server provider and, and, and grab that data to try to manipulate it or look at it, I can't. It's encrypted. Encrypted is just scrambled. So, there's two requirements: encryption at rest and encryption in transit. So, now let's look, we, the online services, if you use online services, TaxSlayer, and QuickBooks, and I'm sure all the other ones, they're handling the encryption in transit. But it's that encryption at rest, as it sits on your computer, that the problem.
One scenario that I get a lot, "Well, Mike, we don't have our drives encrypted, but everybody has a password. You know, if we use QuickBooks local on the computer, the desktop version, well, everybody has a login, you know, before they can access the data." So, is that okay?
That's good. That satisfies the access, you know, uh, everybody has to have their own access to data that you can control. Um, but, uh, it doesn't mean that that data is encrypted just because you have a password to get into QuickBooks. So, that data is still there unencrypted, and I can rip that off if I gained access to that hard drive. So, encryption is probably one of the big ones. And then the other one is just access. You have a lock on your computer. Uh, can I walk by your computer? What if I walk by your computer and take a quick picture of your screen as you're filling out some taxpayer data? I can take that screenshot, put that in the ChatGPT, and read everything in about three seconds. Um, so, you got to make sure, uh, you also have safeguards for physical access. You know, a screen protector. So, I cannot just walk by your computer and videotape everybody's screen on the way to the bathroom and then ChatGPT the heck out of that thing and get everything I, I can. So, so they want to make sure that that doesn't happen. If you get up and walk away from your computer, that you have a lock, you know, a screen, a screen protector, or a screen lock that locks that device. So, little simple, little things that you can easily do. Most of these things, everybody can do without any, any cybersecurity help. But those are kind of the foundations: is access to the data, password, make sure that you're protected physically, you know, that, that you can't just, I can't walk up to your computer and, and, and have access to everything. And then also, uh, make sure the drive is encrypted.
Yeah, and like you said, thank you for sharing at that high level because if anybody's ever read the publication, they can definitely get into the weeds. And if you don't mind sharing, because you shared three different IRS forms, and I'm going to get the messages, "What were the forms that Mike said again?" If you don't mind sharing those forms again.
Sure. IRS 578, IRS 4557, and IRS 1345.
Okay, the 50, yeah, they have templates, and they have, you know, it's meant really to do it yourself. Uh, some people can, some people don't. Uh, but they give you a fairly easy template, and it's, and it's pretty well written. It's, it's kind of toned down so it's not so highly technical. Uh, I think it's a pretty easy read, and I think it's 15 pages or so. And again, I will say this and use the example because when working with taxpayers, we have the ones who they are willing to pay for convenience and the service and just not get their hands dirty with the taxes and do all the research and everything. And then we have the DIY people that will call the expert just to ask questions. They can do it themselves. So, I'm going to say this to my fellow tax professionals. As Mike is saying this, when you go look at the publication, look at the templates. If you feel overwhelmed, just think about when we see a tax return that is actually straightforward and we're like, "Oh, that's pretty easy, straightforward." All you have to do, just remember that this is Mike's area of expertise, and that's not to scare anybody. That's just to say, don't feel bad if you don't understand it and you do need help because thank God, that's why we have experts like Mike, right? So, getting ready for tax season, then need to get that P10 renewed, and you need to have that WISP in place. Don't get stuck in the weeds. If you can't get through it with a good understanding, that's just what I will leave with you there.
Um, Mike, you mentioned something, and correct me if I'm wrong, I believe it's called the clean desk policy, as far as leaving stuff on your virtual desktop and your actual desk. That is something that because we're in a virtual world, people work remotely, they take for granted, right, um, where they are working. Do you have any tips for somebody, um, maybe they're a solo practitioner, and they work remotely, at a coffee shop, or remote, uh, virtual office, virtual office space where they have the different people and they're working? Do you have any tips for some things that they can do to observe the clean desk policy?
Just, just mind the hygiene. Pretend if it's your driver's license that's on a desk, you want to make sure nothing is around. What if the housekeeping staff, some office buildings have, you know, staff that comes through everybody's desk and maybe cleans up or wipes down? They have eyes too, okay? You want to make sure that nothing is out there, out in the open. You know, the, the Social Security numbers on your Post-it note with the customer's name on it, okay? Don't do that. Don't do that. Now, yeah, watch what's on the printer. You know, a lot of people print and they don't take off the printer. Okay, look at the printer. Make sure there's not a whole bunch of, of, of things that were printed that has taxpayer data on it. And basically, the magic thing is two pieces of identifiable information. If you just have a Social Security number with no name or no anything attached to it, that's not really identifiable to anybody. But if you have names and addresses and that kind of personal information, a lot of people print out, you know, these things from QuickBooks, they'll print them out, they'll put them on their desk, under the keyboard, you'll see passwords around a computer. Um, that's, that's quite dangerous, and it's not, it's not very good cyber hygiene anyway, whether you're under a WISP or not, whether you're either doing taxpayer data or not. It's very good practice to keep that stuff hidden, preferably in a locked door or in a locked computer.
Thank you. And nothing that you have shared so far has been over complicated. But again, going back to the template, and like you said, it has to be written out, these are some of the things that the IRS is wanting you to map out how you'll handle, right? So, even in a home office, you still are supposed to be in an area that everybody doesn't have access to. Why? Because you have that personal identifying information. So, with that as well, even if you don't have a house cleaner, right? Maybe, I know in my situation, I have a 10-year-old. So, something to take into consideration. And of course, I'll let you talk to this more, is are we on the same internet connection? Because now, since Niti, with a non-traditional instruction, a lot of different students have Chromebooks. So, yeah, she's supposed to be doing homework, right? Homework only. Um, but what if she is streaming or looking at something, clicks on something that attaches to my home internet? So, now I'm potentially at risk, as well as all of my client data, connecting at an airport or coffee shop. These are the...
Oh, go ahead. You're, you're absolutely right. So, there's two considerations for that. I'm glad you mentioned the airport coffee shop. So, there's two pro, two more protections, and these are free. You know, you don't pay anybody to do this. But I, I love the, the point you brought up because we addressed the encryption, the data as it sits, and as it's moving. But what about, if you go out a little bit on that ring, what about your network? So, there's two requirements that, that they would like to see: is a guest Wi-Fi. That's one of them, or a separate network. A guest Wi-Fi counts as a separate network. So, if I'm a vendor and if I come in, uh, for a meeting, and I say, "Hey, can I jump on your Wi-Fi? My, my signal is very bad." You want to make sure you give them that guest Wi-Fi or that separate Wi-Fi because those are built in, isolated from, say, your computer or your daughter's computer. They basically have a pipe to the internet, and that's it. I have my NAS, my Network Attached Drive, and I have some network shares in my local network that you could easily access with our main Wi-Fi password. Uh, so I don't want to give that to anybody in the house. If you're having a party, or if you're having guests over, give them the guest Wi-Fi. Or stand up another Wi-Fi. If you know how to do a guest Wi-Fi, then you'll stand up another Wi-Fi. Maybe a work network, a family network, and maybe a guest network would be ideal. I have IoT devices, my thermostat, and all that other stuff that connects to the internet. I have all that stuff on a separate network, just because those are more hackable devices than my computer. The other area. So, one area was a separate network, separate that network with a password. And the second is is firewall. So, if you were to take that laptop, say, to Starbucks or somewhere else, you don't know who you're connecting to. You just because it says, "Hey, free, free Wi-Fi." Well, I can set up a fake Wi-Fi too and call it, you know, Hilton Free Wi-Fi and suck everybody's data being in the room next to you. I can easily do that. So, you want to make sure if that does happen, that's absolutely crazy worst-case, that you have what's called a firewall on your computer. Firewall will protect, well, at least make your data invisible to people on a basically a, a public network. Without the firewall, if you're sharing any of your files, it's going to be visible to everybody on that network as well. So, make sure you have a firewall. And every Windows computer comes with a firewall. It's free. You just got to make sure that you turn it on. And if you hit the Windows key and type the word firewall, uh, you'll, you'll see your options there.
Cool. So, with that, you have given us, you know, options that are free, DIY, that we can do ourselves. Um, I'm already thinking about the WISP template because I've seen it. Of course, creating mine. You all, it is a lot that adds up. And then there are certain, um, not thresholds, but certain requirements for what is needed. With that, though, Mike, I feel like into today's world, it's inevitable. Not everybody, but a lot of people are going to be the victims of having their system hacked, whether it is their personal system or their work system. Now, one of the things that we as tax professionals have to do if that happens to us is contact our IRS stakeholder liaison, right? And be able to show our WISP and talk about what we did after that breach happened. For you, from an IT point of view, and of course, you all, there's the template. So, still look at the template and see what the IRS requires. But with an expert here, if that were to happen to us, what are some of the things that you recommend that we do after that type of breach has happened?
Well, you have the reporting requirement. So, you, you should be reporting this to the regulatory bodies. IRS, depends on how, how big you are. I think you're 500 or more clients affected, you have to report that to the FTC. Um, so, there's some reporting requirements. But it really just depends. First, backups are critical. So, if you, let's just say, worst case is ransomware. Worst case is you walk in and all your computers are stolen out. Well, let's say it's ransomware. Okay, you, you turn it on, and something happened overnight, or somebody clicked on something and just created havoc. And sometimes these ransomware infections will spread through the network. So, it's not just one machine that's affected. The entire network could be affected. So, um, you got to make sure that, uh, you have a plan in place for that. So, backups are, are really critical. Do the reporting requirements. This is where the online stuff is really helpful. If you use online QuickBooks or TaxSlayer or one of these other online services, that's a big help because you could at least go to, go to a working computer and log in and verify that, okay, the data is good. We have everything on, you know, on our, our servers. Um, but backups are really critical. You got to get back up and running as fast as possible. But having those cloud services is really, really important as well, and they, they take care of your encryption for you, and they have a lot of safeguards that might not be on your local computer.
Gotcha. So, you shared a very kind of flooring statistic with me. You told me that, of course, like I said, I went and did my homework. I had a teacher in college that said, "Don't even trust your mother without fact-checking it." So, being a person who likes numbers, data, statistics, I did go look at this, and like I said, my jaw about hit the floor. You shared with me that 70% of breaches happen because of user behavior, which is wild because that means that some type of negligence on our part. Um, first, that's a huge risk just because of cybersecurity. And I don't know if you want to speak to that, the cybersecurity insurance potentially not covering a claim if you made one because you didn't even follow the outline of your WISP or you don't have one in place. But what is something that tax professionals specifically can do, just to make sure that they're up to date on best practices and things that they can do as to not have behavior that's going to put them at risk of a breach?
Well, another requirement is education. So, uh, part of that WISP is, you are going to educate your, your staff, or you, if you're a sole operator, on, and I think it's once a year minimum, you know, you, you got to educate them. You got to, you got to train them, or run them through even a couple of YouTube videos. But you have to document that. Have to document, uh, uh, who finished it, what, you know, whether they passed or not. So, you have to document. Make sure that if the IRS walks into your office and says, "Show me your WISP," or "Show me your, your education plan and who, you know, who is valid under, who's, who's been educated and who's run through your program," you have to be able to provide that. So, proof of of education is important. Not just that, "Yeah, we, you know, we watch, you know, we watch videos every month as a team, and, you know, we have a great process." It's got to be written down. You've got to have a practice in place. So, one of the things that we all offer is, is, uh, education and training for cybersecurity professionals that have all the reporting, the reporting, and the recording requirements that's necessary.
Cool. And so, I don't know how much you know about tax world, but as an enrolled agent, within my renewal cycle, I have to have 72 hours. For as a CPA, there's a certain amount of continuing education they have to have, and tax attorneys as well. So, for my viewers, I want you to think of this in terms of the CE that you have to get already. With the continuing education, I could see the IRS moving to cybersecurity being a category soon. So, right now, every year, we have to have at least two years of ethics, which is a low amount compared to the other stuff we have to have, but that's a different conversation. But also with different tax updates. So, for you, make that mental note, write it down now, to stay in compliance with your WISP requirements, you need to be taking some type of training. And like Mike said, that is something that his company does actually offer. And I am going to drop this in the chat so that you all have it available. So, I just went to YouTube and Facebook. I'm going to add this over here on LinkedIn as well, because again, I'm doing the best I can right here, introducing you to Mike, but this isn't my area of expertise where I can make sure that you have everything covered, right? So, I want you all to go and check that out. Um, and just keep in mind that you don't want that to be on your head if you were to get, uh, hacked by somebody because of your negligent behavior. Like I said, for some, it's going to be inevitable. Scammers and things are getting more creative and the things that they do. But you don't want your client's data to be at risk because you didn't follow the clean desk policy, because you decided to go work at Panera Bread and went to the bathroom and left your computer there, right?
So, Mike, thank you for that information about the training. If somebody does decide, "Okay, I'm not sure if I want to try to DIY this, or if I want to work with somebody, and I think that Mike guy that Tim was talking to is kind of cool." Where can they go to find your information?
Well, they can go to our website, which is Blue, uh, Blue Sky Technologies. I'll spell that out: blue-sky.it. I love that, that .it domain name. Uh, so, they can go there, and we have a couple of things there. So, we have a bunch of WISP information there. And also, we do voice AI assistants. So, I spun up a voice AI assistant specifically for a WISP. It will basically give you a risk score after asking you a couple of questions. So, if it's an AI voice, but I trained this to be in, uh, engaging and a little funny and a little humorous. Um, but she will ask you, it's a she now. She will ask you, uh, some questions. And if you have any cybersecurity, she is trained on everything cybersecurity. So, if you have questions, "What's encryption?" "I have QuickBooks," or "How do I do this or that?" Just ask her. She'll totally help you out. Um, so, the 800 number is, is something I sent you, and that, that's good. And if you wanted to get information or have us call you back, just ask her, and she'll, she'll relay that to us, and we'll give you a call back.
That is really cool and like mind-blowing to me that technology is that advanced now. But I am going to say the number just because I know sometimes people will go back, and I want it to be in the closed captions. But also, after we're done, I will add the phone number to the description. I'm going to add it to the chat now, but sometimes that's hard to find in the live chat. But the number, if you wanted to check out the WISP hotline with the AI assistant, and I believe, like you said, this is a free resource to use, right? So, Mike is wanting you to go call the number. It is 1-877-560-6489. Again, it's 1-877-560-6489. So, you all should have that on LinkedIn. You should have it here on YouTube, Facebook as well.
Now, Mike, this is interesting because I don't know if people are feeling overwhelmed or they're looking at the template or not. Usually, I have a lot more questions. So, I'm going to remind you all, um, as we're going, because we're going to wrap up soon, if you have any questions, to go ahead and put those in the chat. LinkedIn is freezing up a little bit on me, but it looks like we have about seven over here, and we are her, my phone, 18 with the 17 on YouTube. So, you guys, if you have any questions about the WISP at all, as far as creating it, um, make sure you drop those in the comments. If you don't have any questions, and this has been good, just drop me a thumbs up in the comments. Um, again, Mike, I appreciate you being here with me and sharing your expertise. Um, I always call our language is tax professionals, tax and needs. But kind of breaking down some of that, because as you shared it, it didn't seem difficult or hard to do. But having it all together in a template, because you all, when you look at Publication 5708, that template is huge, and it looks like a lot. So, if you haven't looked at it yet, you might look at it and go back to this conversation and be like, "But Mike made it seem so easy." Right? So, Mike, one of the things that we talked about that you offer, I believe, is a WISP assessment. Would you speak to that a little bit, and what that actually is?
Sure. So, um, that 800 number is stood up to answer any question you have. Even if it's a highly technical question, she knows everything. Okay? So, what the WISP assessment is [Music] is, but we also give you your policies. You have to give you like 11 cybersecurity policies that you, you can have policies on encryption, policies on access, safe access to data, stuff that they want you to have in place. And then you also get the forms for employees to acknowledge that they understand all of these policies and they're going to abide by them. They have to sign those forms. And also vendors. You know, on that 70% statistic that, that you read out, uh, earlier, said 70% of, of breaches are basically done from a user. Even the big ones, the biggest hacks in the world, the Sony hack, you know, that movie that North Korea years ago, that was done by somebody clicking on a link. The DNC hack years ago, the Democratic National, uh, committee, that was one of the biggest hacks in, in, in political history, that was done by somebody clicking on a link. So, as you see, um, a lot of these can be prevented by education. So, the education is another thing that we, uh, that we provide or that we offer for you guys. It's very cheap, and it's just, you know, a couple of fun videos that you watch for a couple of minutes, and then you answer your questions. Uh, but we could record that, and we could make sure that, uh, uh, any phishing, you know, we do phishing attempts as well. So, you can, with that program, um, make a, we have built-in templates, you know, "Your Netflix account is going to expire, click here," or "Hey, you know, uh, uh, whatever, you know, your bank is, uh, Wells Fargo, or whatever bank you use, needs you to validate your access." So, you can, you can send those out to your employees, um, and make sure that, that they're aware of some of these techniques and tactics, uh, that are being used. And one other thing is vendors. I don't know how much of that 30%, but a lot of that 30% is going to be vendor problems. Vendors that have access to your, uh, to your information, that may be logging into your systems, that come in once a month, or help you with your books once a month, or help you with something once a month. Any vendor that has access to your taxpayer data, they have to have a form that acknowledges that they have safeguards in place if their systems tie into your systems. So, it becomes a little bit more complicated when you have vendors and when you have other people tying into your network or access to your network. You got to make sure the vendors understand that you have very strict policies in place because you have to, and that they also have to abide by those, uh, those conditions.
Very good. Yeah, because that's one of the things too that you kind of, I'll say, for me, before looking at all this, didn't take into consideration. It's just like, "Oh, well, I only have to worry about me, what my preparer is doing." And not like, "Oh, wait a minute, I'm on a remote desktop. Oh, wait a minute, this person would also have access." I'll tell you, the first time I sat in on a training, um, after the GLBA, I was terrified. I was like, "I don't even know if I want to do taxes anymore," just because of all of the exposure. I don't know what the penalties are now, do you know? Because there is a monetary penalty along with this, you all. Um, and then potentially, if you were facing a lawsuit from being hacked, and I was like, "Yeah, no, this isn't for me anymore." Right?
I, I don't have the numbers offhand, but it is per, uh, your penalized per record. How many records you have? So, if you have a hundred records, uh, and they get attacked, I, I don't want to quote the number offhand, but it's, they're going to, they're going to fine you per, per instance, and every record is an instance. So, it can get very costly.
Yeah, and I, I want to highlight with that too, because when I first heard it, it was scary enough. But when we're looking at records, it's not, if you're doing taxes, per tax return, it's per the person's identifying information, am I correct there? So, in my family, we have three people. If my tax returns were hacked, successfully, whatever, that's three different instances that you get penalized for. You have a family of seven, that's seven different instances, not just one, because now you have seven different people who were at risk because their information was exposed. Not to scare anybody else, but yes, that for me was the sealed deal. I don't want to write this WISP. I need to understand it to make sure that I'm following everything. But I wanted to make sure that I was doing everything best practice-wise, because again, the IRS has things in place, you know, to try to make us better, keep us safe, but they're not IT experts. We work with them. They're not IT experts. So, there is something to having, um, somebody from the outside, you, as an IT expert, help you. Now, I'm going to go back a little bit because I noticed it too, and I was hoping it was only me. So, Jacob said that you blanked out for a second. The part where you blanked out was the very beginning where you start talking about the WISP assessment.
Okay. So, the WISP, I'll try to remember what. But the WISP assessment, in addition to the, the basic assessment of, "Okay, we have, here's our access control, and here's our policies for that," or "Here's our, our, our records for that," are the policies you have to have. So, you have to have, we give you 11 policies, uh, which is like a clear desk policy. And that is something that you should have your employees sign and acknowledge that they understand. Having a policy in place does nothing unless the employees know about it and they acknowledge it and they understand, you know, you got to also make them understand why we're doing this stuff. So, uh, a little bit of hygiene, a little bit of education, and acknowledge from the employees and your vendors. If they're remoting in, well, their virus could easily go into, into your system as well through that remote system. So, uh, you want to make sure you have your policies, your acknowledgements, and the WISP, which is a basically a status report on your environment.
Cool. So, yes, you remembered exactly what you said because we didn't have all of that. Thank you. Okay. Um, and if, like, that is a service offered, I believe, a paid service. I do have the link here for that, which I'll also drop in the chat if anybody is interested. So, oops, I almost sent it to Mike. He doesn't need it. He already has that. So, Mike, I think you were just so good today. Nobody has any questions. They're still trying to get it all, take it all in. So, ASA Jane says, "Thanks for sharing the details, Mike." Jacob says, "Thanks." Miss Dorothy Smith in Memphis, Tennessee says, "Great information. I have my firewalls. I'll check my firewall." Thanks. Carol put a thumbs up. That's our code for all good. Let's see. Jacob says, "Thank you, Timlin." So, before people leave, um, if, like I mentioned, if you're new to me, you may not know I do have a community, Howy Sant Enrolled Agent Firm. You can access that by visiting AmericasFavoriteEA.com, and under Groups, there is, um, "How to Start an Enrolled Agent Firm." Within that group, I provide a community that I wish I would have had for laying out the good foundations for your firm. One of the key components at this time is the WISP. So, again, Mike, thank you so much for being here. You still got some more stuff coming in. I think all the fire means you're great. Not they want to burn your computers up. Good. So, you all, the information is there. I will update the YouTube, uh, description just so that it'll be easier for you all to click, and probably a follow-up email to my email list with Mike's information. We appreciate you. And of course, per usual, I'm getting some questions now. So, Paula's Pick says, "Great combo. Thank you so much, Paula." Jacob says, "Thanks." And we have Ike checking in that says, "Hello, fam." Hello to you, Ike. For those of you that are in the community, if you have any follow-up questions, share that in the community. Again, if it's above my pay grade, I will be sending those to Mike or making sure that you have the 1-800 number. Um, Mike, thank you so much. I'm going to let you go. I appreciate you spending time with me today. And for everyone else, I will see you all later. Enjoy the rest of your Tuesday.
Thank you. Appreciate it.