954-539-5678Free audit
Menu

Cybersecurity · Compliance

Your written information security plan, explained in plain English

What a WISP is, who is required to have one, what goes in it and how to write one that matches how your office really works.

Who is required to have one

What goes in a WISP

How to write and maintain it

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The short answer

A written information security plan (WISP) is a document that describes how your business protects the sensitive information it holds: who is in charge, what data you have, the risks you face, the safeguards you use and what you do when something goes wrong. Tax preparers, CPAs, mortgage brokers, auto dealers that arrange financing and other businesses covered by the FTC Safeguards Rule must have a written information security program. The IRS tells tax professionals they are legally required to have a written plan. Massachusetts requires a WISP from any business that holds personal information about its residents.

Even when no law names you, insurers and larger clients increasingly ask for one. A good WISP is specific to your office and reviewed every year.

Who is required to have a WISP

This is general information, not legal advice. Confirm your obligations with counsel.

  • Businesses covered by the FTC Safeguards Rule. The rule applies to non-bank financial institutions under FTC jurisdiction. The FTC’s guidance lists mortgage brokers and lenders, tax preparation firms, finance companies, collection agencies, investment advisors not registered with the SEC and others. The rule requires a written information security program with specific elements.
  • Tax professionals. The IRS and its Security Summit partners state that tax pros are required to have a written information security plan, because federal law treats them as financial institutions for data security purposes. IRS Publication 5708, updated in August 2024, is a free template built for small practices.
  • Businesses holding Massachusetts residents’ data. Massachusetts regulation 201 CMR 17.00 requires a comprehensive written information security program from anyone who owns or licenses personal information about a Massachusetts resident, wherever the business is located.
  • Healthcare and others. HIPAA does not use the term WISP, but it requires written security policies, procedures and a risk analysis, which overlap heavily.

What goes in a WISP

The sections below follow the elements the FTC Safeguards Rule and IRS Publication 5708 expect. Use your own headings if you prefer, but cover each one.

  1. Qualified individual. Name the person responsible for the program. It can be an employee or an outside provider, but the business stays responsible.
  2. Data inventory. What sensitive data you hold (Social Security numbers, tax returns, bank details, driver’s licenses), where it lives and who can reach it. Include paper files, email, laptops, phones, cloud apps and backups.
  3. Risk assessment. The realistic threats to that data, such as phishing, stolen laptops, a careless vendor or a departing employee, and how likely and damaging each is. The FTC rule requires a written risk assessment for most covered firms.
  4. Safeguards. The specific controls you use: multi-factor authentication, encryption of data at rest and in transit, access limited by role, endpoint protection, updates, secure disposal and activity logging.
  5. Employee policies and training. Acceptable use, password and MFA rules, clean desk, how to spot phishing, and annual training with records of who attended.
  6. Vendor oversight. Which service providers touch your data, the security terms in their contracts and how you check them.
  7. Monitoring and testing. How you check that safeguards work: log reviews, vulnerability scans, restore tests.
  8. Incident response. Who to call and what to do if data is exposed, including notification duties.
  9. Review and reporting. When the plan is reviewed, who signs off and, under the FTC rule, an annual written report to the owner or board.

Want to see which parts of your plan are missing? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report rating your IT operations, cybersecurity, backups and business continuity as controlled, needs attention, significant exposure or unknown, with a short list of next steps in order. It is yours to keep, with no obligation. Book your assessment.

How to write a WISP in six steps

  1. Start from a template, then make it yours. IRS Publication 5708 works well for tax and accounting offices. Other businesses can borrow its structure. A template with the wrong names, systems and vendors is worse than none, because it shows you have not looked.
  2. Walk the office. Follow a client file from the moment it arrives to the moment it is destroyed. Note every place it is stored or sent: scanners, email, shared drives, tax software, personal phones.
  3. Describe what you actually do. Write “all staff use an authenticator app for Microsoft 365” only if it is true. If it is not true yet, put it in a dated action list.
  4. Assign owners. Every control needs a person. For outsourced IT, name the provider and what they handle.
  5. Get it signed. The owner or managing partner signs and dates it. Staff acknowledge they have read the policies that apply to them.
  6. Put the review on the calendar. Review yearly and after changes such as a new office, new software or a security incident.

Who should write it

The owner or office manager should own the plan, because it describes how the business runs. Your IT provider should write or review the technical sections, since they know which controls are really in place. A lawyer is worth involving if you are regulated, hold data from several states or have had an incident. For a 10 to 50 person office with decent records, a first draft usually takes a few working sessions; most of the time goes into the data inventory and the walk-through, not the writing.

Keep a short evidence folder next to the plan: training sign-in sheets, the latest restore test, MFA reports and vendor contracts. If an insurer, auditor or regulator asks, the evidence matters as much as the document.

Common WISP mistakes

  • A downloaded template with blanks still in it
  • No data inventory, so the plan protects systems nobody uses and misses the ones that matter
  • Claims of controls that are not in place, which can hurt you after a breach or with an insurer
  • No named qualified individual, or a name with no authority or time
  • Vendors left out, even though most data now lives in cloud software
  • Written once and never reviewed

The hardest part is usually not writing but making the plan true: turning on MFA everywhere, encrypting laptops, removing leavers the same day and testing backups. That is the day-to-day work our cybersecurity services handle, along with help on cyber-insurance questionnaires that ask about your plan. If people leaving is your weak spot, start with our employee offboarding IT checklist.

WISP, security policy and incident response plan: how they fit

People use these terms loosely. The WISP is the umbrella document. Individual policies, such as acceptable use or password rules, sit underneath it for staff to read and sign. The incident response plan is one required section, often kept as a separate short document so it can be printed and used under pressure. Keep all three consistent, and when one changes, update the others.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

What is a written information security plan?

A WISP is a document describing how a business protects sensitive data: who is responsible, what data it holds, the risks, the safeguards in place, how staff are trained, how vendors are overseen and how incidents are handled.

Do tax preparers need a WISP?

The IRS says tax professionals are legally required to have a written information security plan, because federal law treats them as financial institutions for data security. IRS Publication 5708 provides a free template.

Is there a free WISP template?

Yes. IRS Publication 5708 is a free template aimed at small tax and accounting practices, and other small businesses can adapt its structure. Customize it to your actual systems and vendors.

How often should a WISP be updated?

Review it at least once a year and after significant changes such as new software, a new office, a new IT provider or a security incident.

Does a small business outside finance need a WISP?

Possibly. Massachusetts requires one from any business holding its residents’ personal information, and clients and insurers often ask. This is general information; confirm with counsel.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678