← Notes
July 25, 2026 · 6 min read

What is a WISP, and does your firm actually need one?

A Written Information Security Program is the document your insurer, your biggest client, and the FTC all ask for under three different names. What it is, who is expected to have one, and what has to be in it.

If you run a small firm, you have probably been asked for a “WISP” by someone who assumed you knew what that meant. It stands for Written Information Security Program, and the confusing part is that it is not a special kind of document you have never seen. It is the same thing a cyber insurance application calls an information security policy, and a client’s vendor questionnaire calls a security policy. Three names, one document.

The reason the acronym exists at all is that a few US rules ask for the program to be written down, specifically, as opposed to simply expecting a business to be careful. Once a rule uses the phrase “written information security program”, vendors and advisers start using the acronym, and small business owners inherit a piece of jargon nobody has explained to them.

Who is expected to have one

Three separate pressures push a small business toward a WISP, and most firms feel at least one of them:

  • A cyber insurance application. Carriers now ask whether you hold a written security policy, and increasingly ask you to attach it. An application is a set of representations — what you write there matters at claim time.
  • A client security review. Once you serve customers larger than you, their procurement process pushes their own security requirements down to their vendors, and asks for your policy as evidence.
  • A rule that applies to your line of work. The FTC’s Safeguards Rule asks a broad class of firms — including many tax preparers, bookkeepers and financial advisers — to maintain a written information security program. A handful of states go further and require a written program of any business holding their residents’ personal information, regardless of where the business itself sits.

Whether any of these actually reaches your business is a determination for you and your counsel. This article describes what the requirements say; it is not advice about your situation, and holding any document is not the same as being compliant with a rule.

What has to be in it

Strip away the jargon and a WISP answers a short list of questions about how your business actually operates. A reviewer is looking for specifics, not aspiration:

  • Who is accountable for security, by name or by role — most rules that ask for a written program also ask you to name someone.
  • How accounts are protected: multi-factor authentication, password practice, who holds administrator access, and what happens when someone leaves.
  • What happens on the devices people actually work on, including personal ones if you allow them.
  • Where business data lives, who can reach it, and how it is disposed of.
  • How you back up, and whether you have ever tested a restore.
  • Which vendors you depend on, and who secures what between you and them.
  • What you do when something goes wrong — which is usually a separate incident response plan the WISP points to.
  • When the program gets reviewed. Annually, timed to something you will actually remember, is the usual answer.

The mistake that costs the most

The strong temptation, faced with a template full of controls, is to tick everything. Do not. A security policy is a set of statements about your business, and the two audiences who read it most carefully — an underwriter assessing risk and a forensic investigator after an incident — are both in a position to find out whether the statements were true.

A policy that claims multi-factor authentication is enabled everywhere, at a firm where it covers email only, is worse than no policy. If an incident happens through one of the accounts it did not cover, that sentence is now a written misrepresentation attached to your insurance application. Claims have been contested over less.

The honest version is not weaker, and reviewers do not read it as weaker. A policy that says “multi-factor authentication is enabled on email today; extending it to banking and administrator accounts is the business’s next security action, owned by the owner, targeted within 30 days” tells an underwriter two useful things: what the risk is right now, and that someone is actually managing it. That reads as competence. A page of unqualified claims reads as a template someone downloaded.

Template, consultant, or generated

A free template gets you the structure and none of the specifics — it will say [COMPANY NAME] and list controls you may not have, and turning it into something true about your business is most of the work. A consultant or virtual CISO will do that work properly, and typically charges a monthly retainer in the thousands, which is hard to justify for a document you need once a year.

The middle option is to answer a structured set of questions about your business and have the document assembled from those answers — including honest remediation language where a control is not in place yet. That is what Coverwright does, deterministically: same answers in, same documents out, with every paragraph traceable to the answer that put it there.