Cybersecurity · Compliance
What a WISP is, who is required to have one, what goes in it and how to write one that matches how your office really works.
Who is required to have one
What goes in a WISP
How to write and maintain it
30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.
A written information security plan (WISP) is a document that describes how your business protects the sensitive information it holds: who is in charge, what data you have, the risks you face, the safeguards you use and what you do when something goes wrong. Tax preparers, CPAs, mortgage brokers, auto dealers that arrange financing and other businesses covered by the FTC Safeguards Rule must have a written information security program. The IRS tells tax professionals they are legally required to have a written plan. Massachusetts requires a WISP from any business that holds personal information about its residents.
Even when no law names you, insurers and larger clients increasingly ask for one. A good WISP is specific to your office and reviewed every year.
This is general information, not legal advice. Confirm your obligations with counsel.
The sections below follow the elements the FTC Safeguards Rule and IRS Publication 5708 expect. Use your own headings if you prefer, but cover each one.
Want to see which parts of your plan are missing? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report rating your IT operations, cybersecurity, backups and business continuity as controlled, needs attention, significant exposure or unknown, with a short list of next steps in order. It is yours to keep, with no obligation. Book your assessment.
The owner or office manager should own the plan, because it describes how the business runs. Your IT provider should write or review the technical sections, since they know which controls are really in place. A lawyer is worth involving if you are regulated, hold data from several states or have had an incident. For a 10 to 50 person office with decent records, a first draft usually takes a few working sessions; most of the time goes into the data inventory and the walk-through, not the writing.
Keep a short evidence folder next to the plan: training sign-in sheets, the latest restore test, MFA reports and vendor contracts. If an insurer, auditor or regulator asks, the evidence matters as much as the document.
The hardest part is usually not writing but making the plan true: turning on MFA everywhere, encrypting laptops, removing leavers the same day and testing backups. That is the day-to-day work our cybersecurity services handle, along with help on cyber-insurance questionnaires that ask about your plan. If people leaving is your weak spot, start with our employee offboarding IT checklist.
People use these terms loosely. The WISP is the umbrella document. Individual policies, such as acceptable use or password rules, sit underneath it for staff to read and sign. The incident response plan is one required section, often kept as a separate short document so it can be printed and used under pressure. Keep all three consistent, and when one changes, update the others.
Book it now
Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.
Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.
A WISP is a document describing how a business protects sensitive data: who is responsible, what data it holds, the risks, the safeguards in place, how staff are trained, how vendors are overseen and how incidents are handled.
The IRS says tax professionals are legally required to have a written information security plan, because federal law treats them as financial institutions for data security. IRS Publication 5708 provides a free template.
Yes. IRS Publication 5708 is a free template aimed at small tax and accounting practices, and other small businesses can adapt its structure. Customize it to your actual systems and vendors.
Review it at least once a year and after significant changes such as new software, a new office, a new IT provider or a security incident.
Possibly. Massachusetts requires one from any business holding its residents’ personal information, and clients and insurers often ask. This is general information; confirm with counsel.