Deziel's Tax Service · Website and security plan

Meeting agenda — Tuesday, August 11, 2026

Mark Deziel · Mike Deziel · Joe Skelley

Three items. Tap a heading to open it.

1Privacy statement and security plan — and what the website needs for them

Two different documents, often confused

The privacy statement is the page on the website that tells your clients what you collect and what you do with it. Anyone can read it. It is a public promise.

The security plan — the WISP, or Written Information Security Plan — is an internal document. The IRS requires it of any paid preparer filing eleven or more federal returns a year, and the FTC Safeguards Rule requires it because a paid tax preparer counts as a financial institution under federal law. Nobody outside the office reads it unless something goes wrong or someone asks: an insurer, an auditor, or the IRS after an incident.

They have to agree with each other. The public page must not claim a protection the office doesn't actually perform.

Where the security plan stands

The plan is drafted in full. It covers all nine elements the FTC Safeguards Rule requires, it has a complete incident-response attachment with the reporting contacts already researched, and it has a risk worksheet with nine risks laid out.

Outstanding: the facts in the worksheet below, and three items to close — sign the data-handling agreement between Deziel's and Joe's Tech Support, name the security coordinator, and confirm the database platform's service tier.

What the website needs from this

  • The tax software is named on the privacy page. There is a section headed “Use of Drake tax software and service providers.” When the new preparation software replaces Drake, that section names the new company instead, and the security plan adds it as a service provider with the safeguards its contract requires.
  • The security claims on the privacy page. The page tells the public that access is restricted to staff who need it, that systems are password-protected, that paper files are stored securely, and that electronic filing and document exchange use secure transmission.
  • Multi-factor sign-in. The security plan requires it on every system that reaches client information. The office does not have it yet. The privacy page does not currently claim it.
  • How long records are kept. The privacy page says “as long as necessary.” The security plan needs a number of years.
  • Access to the website and the client login. The security plan lists the website as a place client information can live. That row needs its access list.

Resources

The security plan working draft — the file deziel-wisp.md in Joe's Deziel folder.

The current privacy statement — the Privacy Policy page on the rebuilt site
dts-rebuild.pages.dev/privacy


Security plan worksheet

1. Effective date of the plan

The date it is adopted, and today's date as the first review.

2. Security coordinator

One named person accountable for the plan. Name, title, phone and email.

3. Systems inventory — where client information lives and who can reach it

For each one: where it sits, and the list of people with access.

Tax preparation software (Drake today)

Installed on the office machines, or hosted?

Office computers and workstations

Email

Google Workspace Business Starter, one licensed mailbox. Other addresses are aliases or groups — which, and who reads each one.

File storage and document exchange

Website and client login

Paper files

4. Under five thousand client records?

Below that count, the annual written report to ownership eases. Every other control applies either way.

5. Anti-malware product

Which one, and on which machines.

6. Backups

Method, frequency, and where the copies live.

7. Physical security of the office

Locked storage for paper, the office secured when unattended, alarm, cameras, who holds keys.

8. How long records are kept

The retention period before paper is shredded and electronic files are deleted.

9. Training used

What staff get on phishing and handling client documents, at hiring and once a year after.

10. How acknowledgment is recorded

A signed sheet, an email, a line in a personnel file.

11. Cyber-insurance carrier

Carrier, policy number, claims phone line.

12. The risk worksheet ratings

Nine risks with a starting likelihood and impact — phishing, ransomware, a lost laptop, paper left out, a departing employee, and the rest. Each needs a confirmation or an adjustment.

2Design status

The current site — reference for what was there
dezielstaxservice.com

The new site — current status
dts-rebuild.pages.dev

Where does the new site need improving?

  • Typography
  • Logo
  • The banner across the top
  • The sections and how they are arranged
  • The tabbed block below the top of the home page
  • Home page in season and out of season
  • Google reviews
  • Fees
  • Deadlines and filing reminders
  • About page and the John Weinard history
  • The 1099 and W-2 pages
  • Directions and refund checking
  • Phones and tablets
  • Content on the current site that is not yet on the new one
3How do we link the website to the new tax preparation software's portal?
  • The address clients use to sign in.
  • A link out to it, or something inside the Deziel site.
  • Where it goes on the site, and what it says.

The site's buttons go to the office phone number today.