Really? They should have fired the webmaster...
I agree, that's totally a good idea. But I think it'd be interesting if you FINED the IRS like you would fine a publicly traded company if they had a serious deficiency in their IT control environment. A few years back, we had that whole craaazy "Enron" thing, and one of our responses was SOX regulation. Many companies who handle credit cards have to comply to PCI standards, which are even more strict. Now all publicly traded companies have to bend over backwards, paying for and receiving audits that they sometimes really don't need. A full-scale internal IT Audit department for a candle making company? It's payback time
"Just the facts, Ma'am" -- Joe Friday