Intaxion
Operations

Backlog rebuild: 75-minute WISP incident-response drill

Published June 29, 2026
4 min read
By Intaxion Team
Illustration of a small bilingual tax office team gathered around a table running a timed incident-response tabletop exercise, with a countdown clock and role cards in front of them.

A vague warning sign, a confirmed security event, suspected data loss, and confirmed unauthorized access are four different things. Whether confirmed unauthorized access triggers a reporting or notification duty depends on the specific facts and the requirements that apply to your firm — that determination should be escalated to the right people, not assumed on the spot. Small bilingual tax offices that blur these categories tend to either freeze or overreact, and both mistakes cost time when time matters most. This drill tests whether your office can move through those distinctions using the incident-response plan you already have written — not whether you have one.

This is an editorial practice format, not a government-prescribed duration or a real-incident timeline. Use only synthetic names, systems, records, and identifiers — no client or taxpayer data should ever enter the exercise. If a real incident happens during or outside this drill, stop: follow your firm's approved plan and contact your designated cybersecurity provider, legal counsel, insurer, and any required government contacts right away. Don't wait for a drill schedule.

Diagram of five incident-response roles — incident lead, recorder, technical liaison, communications lead, and owner decision-maker — arranged on an assignment board with authority limits noted for each.

0–10 minutes — Roles and setup. Assign an incident lead, a recorder, a technical liaison, a communications lead, and an owner decision-maker. State each role's authority limits out loud. Open a live exercise log with columns for observation, source, known fact, assumption, unknown, decision, decision owner, timestamp, and follow-up owner. Every entry from this point goes in the log.

10–25 minutes — Ambiguous warning signs. Introduce two synthetic warning signs drawn from IRS-identified patterns: an unexpected e-file acknowledgement or rejection, and a client reporting an email the office never sent. Participants classify each log entry as fact, assumption, or unknown — not as a confirmed breach. The goal is disciplined triage, not a verdict.

Sample exercise log template with columns for observation, source, known fact, assumption, unknown, decision, decision owner, timestamp, and follow-up owner.

25–40 minutes — Containment decision authority. Test who is authorized to isolate affected systems, who contacts the cybersecurity provider, and what evidence-preservation questions must be escalated before action. This segment tests decision authority, not specific technical steps — no system is the same, and no single containment action is safe for every incident.

40–55 minutes — Reporting and notification paths. Build a decision matrix covering the IRS Stakeholder Liaison, state authorities, the FTC, law enforcement, your insurer, vendors bound by contractual notice duties, and affected clients. Treat these as parallel, fact-sensitive tracks: reporting to the IRS doesn't resolve FTC, state, insurer, or client notification questions, and not every warning sign triggers every path.

Decision matrix showing possible IRS Stakeholder Liaison, state authority, FTC, law-enforcement, insurer, vendor, and client paths branching from one warning-sign entry point, with each path marked for separate evaluation.

55–68 minutes — Recovery checks. Before anyone proposes resuming normal operations, this tabletop requires three checks: confirmed backup integrity, an established cause and scope, and a plan for monitoring continued suspicious activity. These are checks built into this exercise's design, not a universal list of what every real recovery requires — actual recovery steps depend on the incident. Recovery proposals that skip a tabletop check go back to the log as open items.

68–75 minutes — Bilingual holding notes and close. Draft internal-only, unsent holding notes in English and in independently composed es-US Spanish, limited strictly to verified facts, unknowns, and next internal steps. Nothing drafted in this window gets sent. Close by assigning concrete owners and dates for updates to your WISP, incident-response plan, contact list, staff training, service-provider arrangements, safeguards, and the next tabletop.

Sources

  • https://www.irs.gov/pub/irs-pdf/p4557.pdf
  • https://www.irs.gov/pub/irs-pdf/p5293.pdf
  • https://www.irs.gov/identity-theft-central/identity-theft-information-for-tax-professionals
  • https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
  • https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business
  • https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314

Get our free Tax Preparer Compliance Checklist

A practical checklist to ensure you're meeting all IRS due diligence requirements. Download instantly.

We respect your privacy. Unsubscribe at any time.