A ransomware event, a lost laptop, or an employee who falls for a phishing email can quickly become more than an IT problem. If your business handles customer financial information, personal data, or regulated records, the question is not simply whether your network is protected. It is who needs a WISP policy, and whether your company can prove it has taken reasonable steps to protect sensitive information.

A WISP, or Written Information Security Plan, documents how your organization protects confidential data. It assigns responsibility, identifies risks, defines safeguards, and establishes what happens when something goes wrong. For many businesses, it is a regulatory requirement. For others, it is a practical way to reduce preventable security and operational risk.

Who Needs a WISP Policy?

Businesses covered by the Federal Trade Commission’s Safeguards Rule generally need a WISP. The rule applies to many organizations classified as financial institutions under the Gramm-Leach-Bliley Act. That definition is broader than many owners expect. It can include companies that are significantly involved in activities related to financial products or services, even if banking is not their primary business.

Tax preparation firms, CPA practices, bookkeeping companies, mortgage brokers, financial advisors, insurance agencies, auto dealerships that arrange financing, and certain lenders are common examples. These businesses routinely receive Social Security numbers, tax returns, bank details, credit information, and other nonpublic personal information. A written plan is not optional when the Safeguards Rule applies.

A WISP may also be necessary because of a client contract, cyber liability insurance application, industry requirement, or audit request. Even when a business is not directly regulated by the FTC Safeguards Rule, customers and business partners increasingly expect written security policies before sharing sensitive records.

Tax and Accounting Firms Have a Clear Obligation

For tax professionals, the expectation is especially clear. Tax returns contain some of the most valuable data available to criminals: names, addresses, dates of birth, income details, account information, and Social Security numbers. A single compromised mailbox or workstation can expose hundreds or thousands of records.

The FTC considers professional tax preparers financial institutions for purposes of the Safeguards Rule. That means many tax preparation businesses need a written security program appropriate to their size, operations, and the sensitivity of the information they maintain.

A small accounting office does not get a pass because it has fewer employees. The plan can be scaled to the business, but it still needs to be real. A generic document downloaded from the internet will not protect the firm if its actual systems, email processes, remote access, backups, and vendors are not addressed.

Other Businesses That Should Take a WISP Seriously

Not every organization needs a document labeled “WISP” under federal law. However, a written information security plan is still a smart operational requirement for many small and midsize businesses.

Medical and dental offices must comply with HIPAA security requirements for protected health information. HIPAA does not always use the term WISP, but it requires documented policies, risk analysis, safeguards, workforce training, and incident response processes. In practice, a well-designed WISP can support those requirements when it is tailored to the practice and coordinated with its HIPAA compliance program.

Law firms, municipal organizations, human resources departments, and hospitality businesses also handle sensitive information that can create serious exposure if lost or stolen. Employee records, payment card data, legal documents, resident information, and customer identity details all deserve documented protection. State privacy and breach-notification laws may create additional responsibilities depending on the data involved and where affected individuals live.

If your business stores sensitive data in Microsoft 365, on a server, in a line-of-business application, or with a cloud vendor, a written plan helps answer the questions that matter after an incident: What information was involved? Who had access? What controls were in place? Who was responsible for responding?

What a WISP Policy Should Cover

A useful WISP is not a single statement saying that the company takes cybersecurity seriously. It should describe the actual safeguards used by the business and the people responsible for carrying them out.

At a minimum, the plan should identify the employee or qualified provider responsible for the information security program. It should document how the company identifies and evaluates risks to sensitive data. This includes risks from phishing, ransomware, weak passwords, lost devices, unsecured remote access, outdated software, former employee accounts, and third-party vendors.

The policy should also describe the safeguards in place. For a typical small business, that may include multi-factor authentication, managed endpoint protection, firewall security, encrypted devices, secure VPN access, regular patching, limited user permissions, protected backups, and security awareness training. The right controls depend on the environment. A CPA firm with remote employees and tax software has different risks than a dental office with imaging systems and patient management software.

A WISP should also address how the company monitors its controls, reviews vendors, retains records, and responds to a security incident. If an employee reports a suspicious email or a server shows signs of ransomware, the team should not be deciding its process from scratch while systems are unavailable.

A Written Plan Must Match Your Actual Environment

One of the biggest mistakes businesses make is treating a WISP as a paperwork exercise. A policy that says multi-factor authentication is required is a problem if email, remote access, or administrator accounts do not actually use it. A policy that promises encrypted backups is not useful if backups have never been tested for recovery.

Auditors, insurers, regulators, and clients may ask for documentation, but they can also ask follow-up questions. Can you show that employees receive security training? Are former employees removed promptly? Are security updates applied? Do you know which vendor has access to customer information? Can your business restore critical data after a ransomware incident?

The plan should be reviewed periodically and updated when operations change. New cloud software, a move to remote work, an office relocation, a merger, a new payment system, or a change in IT providers can all affect the security controls your company needs.

WISP Policy Requirements Depend on Risk

There is no responsible one-size-fits-all answer to WISP policy requirements. A two-person bookkeeping practice does not need the same systems or documentation depth as a regional financial services firm. But both may need to protect the same types of highly sensitive client records.

The standard is usually reasonableness: safeguards should fit the size and complexity of the organization, the nature of its activities, and the sensitivity of the information it handles. That does not mean basic security can be ignored. Smaller companies are frequent targets because attackers know they may lack dedicated internal IT and security staff.

A practical risk assessment is the starting point. It identifies where data lives, how it moves, who can access it, and where the weaknesses are. From there, the business can prioritize corrections that make a meaningful difference, such as securing email, closing exposed remote access, implementing backup protection, and documenting incident response contacts.

Do Not Confuse a WISP With a Security Checklist

Security tools matter, but tools alone do not create a security program. Buying antivirus software does not establish who reviews alerts. Turning on backups does not prove the business can recover. Issuing a policy does not mean employees understand how to handle suspicious requests for payroll changes, wire transfers, or passwords.

The strongest approach connects policy, technology, and day-to-day behavior. Staff need clear expectations. Management needs visibility into risks. IT systems need ongoing maintenance. When those elements work together, the WISP becomes a living business document rather than something filed away until an audit or breach occurs.

For businesses in Lombard and the Chicago suburbs, this is where an experienced IT partner can help. Tomorrow’s Solutions can assess your environment, identify practical gaps in your security controls, and help align your systems with the written policies your business is expected to follow.

A WISP is most valuable before someone asks to see it. Build it around the way your business actually operates, keep it current, and use it to make better security decisions before a lost device, compromised account, or ransomware attack forces the issue.