Skip to content
Bellator Cyber Guard
Small Business5 min readStandard

What Is a WISP for Small and Medium Businesses?

By Bellator Cyber Guard Security Team
What Is a WISP for Small and Medium Businesses? - wisp for small and medium

A WISP Is Required, Not Optional, for Most Small Businesses

A written information security plan, or WISP, is a documented set of administrative, technical, and physical safeguards that spells out exactly how your business protects customers' and employees' sensitive personal data. For most small and medium businesses that touch financial or tax information, a WISP is not a best practice you can skip. It is required under the FTC Safeguards Rule (16 CFR Part 314), and the IRS directs tax preparers to maintain one under Publication 4557. Healthcare practices covered by HIPAA need an equivalent documented security program under the HIPAA Security Rule, even though HIPAA does not use the term WISP.

This guide explains who the requirement actually covers in 2026, what the plan has to contain, and how small and medium businesses typically get one in place without spending weeks writing it from scratch.

Quick Answer

A WISP is a written document describing the safeguards a business uses to protect sensitive customer and employee data. Under the FTC Safeguards Rule, any business classified as a financial institution under the Gramm-Leach-Bliley Act (GLBA), including tax preparers and accounting firms, must have one in writing. The plan has to name a qualified individual, document a risk assessment, and describe access controls, encryption, monitoring, incident response, and vendor oversight. Free templates like IRS Publication 5708 are a starting point, but they need to be customized to match your actual systems and vendors.

Who Needs a WISP in 2026

The FTC Safeguards Rule applies to any business the FTC classifies as a financial institution under GLBA, a federal law that gave the FTC authority to regulate how nonbank financial businesses protect customer data. That definition is broader than most owners expect. It covers tax preparation firms, accounting and bookkeeping firms, mortgage brokers, payday lenders, auto dealers that arrange financing, and check-cashing businesses, among others.

If your firm prepares tax returns, the IRS reinforces the same requirement. IRS Publication 4557, Safeguarding Taxpayer Data, directs every paid tax preparer to have a written plan, and the IRS publishes a template in Publication 5708 to help smaller firms get started. Healthcare offices fall under a separate but similar obligation: the HIPAA Security Rule requires a documented risk analysis and written security policies, which function the same way a WISP does for financial data. Review the written information security plan requirements for tax and accounting firms specifically, and see how a missing plan factors into a broader small business data breach response plan if an incident happens.

FTC Deadline Already Passed

According to the FTC, amended Safeguards Rule provisions took effect June 9, 2023, adding requirements such as a written incident response plan, encryption of customer data, and multi-factor authentication for anyone accessing customer information. If your business has not updated its plan since before that date, it is very likely out of date.

What a WISP Must Include

A WISP that meets the FTC Safeguards Rule's requirements has to name a specific person who owns the program, document a risk assessment of where customer data lives and what threatens it, and describe the controls your business actually runs, not generic language copied from a template. The checklist below reflects the elements the rule requires.

What a WISP Must Cover

  • A designated qualified individual who owns the security program
  • A written risk assessment identifying threats to customer and employee data
  • Access controls, including multi-factor authentication for sensitive systems
  • Encryption of customer information at rest and in transit
  • Monitoring and logging to detect unauthorized access
  • A written incident response plan
  • Annual employee security awareness training
  • Written oversight of service providers and vendors who touch client data
  • At least an annual review and update of the plan

A Free Template Is a Starting Point, Not a Finished Plan

The IRS Publication 5708 template and similar free WISP templates are a reasonable starting point because they lay out the required sections. The problem shows up later: if your plan still describes systems you don't use, vendors you've replaced, or safeguards you never actually implemented, it can create a documentation gap during a data breach investigation or an FTC inquiry, since the written plan is supposed to match what your business actually does.

Building a plan that genuinely matches your systems, vendor list, and risk profile typically takes an owner or office manager somewhere in the range of 20 to 40 billable hours when done from scratch, time spent researching requirements, inventorying data, and drafting language instead of serving clients. Pairing a written plan with real controls, like the password security and multi-factor authentication practices it documents, and a tested incident response process, closes the gap between what the plan says and what your business actually does. Because cyber attacks on small businesses increasingly target firms with outdated or paper-only security plans, keeping the WISP current is part of reducing that exposure, not just a compliance exercise.

Get a Custom WISP Built for Your Business

Bellator Cyber Guard builds a custom written information security plan starting at $749 for businesses with up to 5 users, with larger practices quoted separately. It's built around your actual systems, vendors, and risk assessment, not a generic template.

Frequently Asked Questions

Yes. If you are classified as a financial institution under GLBA or you prepare tax returns for compensation, the requirement applies regardless of your business size or whether you have employees.

At minimum annually, and whenever you change vendors, add new systems, or have a security incident, since the FTC Safeguards Rule requires the plan to reflect your current risk assessment.

You can start with it, but every section needs to be customized to match your actual systems, vendors, and safeguards. A template that describes practices you don't follow does not satisfy the rule's intent.

The FTC can investigate and pursue enforcement action for Safeguards Rule violations, and in a breach, the absence of a documented plan can complicate your legal and insurance position. Specific legal consequences depend on your situation, so questions about liability belong with an attorney.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn the requirement into a security plan people can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Incident response & NIST

Build a response process that helps people detect, contain, recover, and improve when something goes wrong.