If your business prepares taxes, arranges loans, finances vehicles or otherwise handles consumer financial information and isn't a bank, the FTC Safeguards Rule (16 CFR Part 314) expects you to run a Written Information Security Program (WISP). That means a named person in charge, a written risk assessment, specific technical controls, staff training, vendor oversight, testing, an incident response plan and a yearly written report.
The rule comes from the Gramm-Leach-Bliley Act (GLBA), and the Federal Trade Commission amended it substantially in 2021, with most of the new requirements taking effect in June 2023. Plenty of small firms still have a WISP that is a template nobody has opened since it was downloaded. This article walks through what the rule actually asks for, how to build a WISP that reflects how your office really works, and where an IT partner fits in.
NerdSquad is not a law firm. Confirm your firm's obligations with your compliance counsel.
The FTC rule covers "financial institutions" under its jurisdiction, which is a much wider group than the name suggests. Common examples in Southwest Florida include:
SEC-registered investment advisers and broker-dealers are not covered by this rule. They fall under the SEC's Regulation S-P, which was amended in 2024 with its own incident response and customer notification requirements. If that's you, start with our overview of the SEC and FINRA and what they regulate. For the broader law behind both, see GLBA: the Gramm-Leach-Bliley Act explained.
You must designate one person to oversee and enforce the information security program. It can be an employee or someone at a service provider such as a Managed Service Provider (MSP). If you use an outside provider, your firm still keeps responsibility for compliance, and you must designate a senior person to direct and oversee that provider.
Identify the reasonably foreseeable internal and external risks to customer information, assess how well your current safeguards handle them, and write it down. The assessment must include criteria for evaluating and categorizing risks and must be repeated periodically. Our article on what a compliance risk assessment is explains the process in plain terms.
Based on that assessment, the rule lists specific controls:
You must regularly test or monitor whether your safeguards work. That means either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months, and whenever there's a material change to your operations. If the term is new, read what a penetration test is.
Provide security awareness training to your staff, use qualified security personnel (in-house or through a provider), and keep their knowledge current.
Select vendors that can protect customer information, require safeguards in your contracts, and periodically assess how they're doing. That includes your tax software host, document portal, cloud storage and your IT provider.
Document goals, internal roles and decision authority, communications, how weaknesses get fixed, how incidents are documented and reported, and how the plan is reviewed after an incident.
The qualified individual must report in writing, at least once a year, to your board of directors or equivalent governing body. If there's no board, the report goes to a senior officer, which in a small firm is usually the owner. It covers the overall status of the program and material matters such as risk decisions, test results, incidents and recommended changes.
If your firm maintains customer information on fewer than 5,000 consumers, 16 CFR 314.6 exempts you from four elements: the written risk assessment, the continuous monitoring or penetration testing and vulnerability scanning requirement, the written incident response plan, and the annual written report. Everything else still applies, including MFA, encryption, access controls, training and vendor oversight. Count carefully: past clients whose records you still hold usually count, and many firms are bigger on paper than they feel day to day.
A 2023 amendment added a notification duty. If unencrypted customer information about 500 or more consumers is acquired without authorization, you must notify the FTC as soon as possible and no later than 30 days after discovery, using the FTC's online form. Information counts as unencrypted if the encryption key was also taken. This is separate from any notice owed to affected individuals under state law, such as Florida's Information Protection Act (Florida Statutes s. 501.171).
The IRS treats the Safeguards Rule as applying to professional tax preparers and points them to IRS Publication 4557, Safeguarding Taxpayer Data, for practical guidance. The IRS also published a sample WISP template for tax and accounting practices (Publication 5708). A template is a starting point; the plan has to describe your actual systems, people and procedures to be worth anything.
A practical WISP for a small financial office usually includes these sections:
Keep the evidence alongside the plan: training records, scan reports, access reviews, vendor reviews and the signed annual reports. If someone asks "how do you know this is working?", those are your answers.
A WISP is part policy and part proof. NerdSquad focuses on the technical controls and the documentation that shows they're in place:
We help put controls, documentation and evidence in place; your firm and its counsel decide what your obligations are. If you're a smaller office weighing whether to bring in outside help, our page on managed IT for small businesses explains how we work, and our IT for financial services firms page covers the financial side in more depth.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.
Related: Managed IT for small businesses