FTC Safeguards Rule: How to Build a WISP

FTC Safeguards Rule: Building a Written Information Security Program (WISP)

If your business prepares taxes, arranges loans, finances vehicles or otherwise handles consumer financial information and isn't a bank, the FTC Safeguards Rule (16 CFR Part 314) expects you to run a Written Information Security Program (WISP). That means a named person in charge, a written risk assessment, specific technical controls, staff training, vendor oversight, testing, an incident response plan and a yearly written report.

The rule comes from the Gramm-Leach-Bliley Act (GLBA), and the Federal Trade Commission amended it substantially in 2021, with most of the new requirements taking effect in June 2023. Plenty of small firms still have a WISP that is a template nobody has opened since it was downloaded. This article walks through what the rule actually asks for, how to build a WISP that reflects how your office really works, and where an IT partner fits in.

NerdSquad is not a law firm. Confirm your firm's obligations with your compliance counsel.

Who the Safeguards Rule applies to

The FTC rule covers "financial institutions" under its jurisdiction, which is a much wider group than the name suggests. Common examples in Southwest Florida include:

  • CPA firms and tax preparers
  • Mortgage brokers and non-bank lenders
  • Auto dealers that finance or lease vehicles
  • Financial planners and advisers who are not registered with the SEC
  • Collection agencies, check cashers and similar non-bank financial businesses

SEC-registered investment advisers and broker-dealers are not covered by this rule. They fall under the SEC's Regulation S-P, which was amended in 2024 with its own incident response and customer notification requirements. If that's you, start with our overview of the SEC and FINRA and what they regulate. For the broader law behind both, see GLBA: the Gramm-Leach-Bliley Act explained.

What the rule requires (16 CFR 314.4)

1. A qualified individual

You must designate one person to oversee and enforce the information security program. It can be an employee or someone at a service provider such as a Managed Service Provider (MSP). If you use an outside provider, your firm still keeps responsibility for compliance, and you must designate a senior person to direct and oversee that provider.

2. A written risk assessment

Identify the reasonably foreseeable internal and external risks to customer information, assess how well your current safeguards handle them, and write it down. The assessment must include criteria for evaluating and categorizing risks and must be repeated periodically. Our article on what a compliance risk assessment is explains the process in plain terms.

3. Required safeguards

Based on that assessment, the rule lists specific controls:

  • Access controls: only authorized users get access to customer information, and only to what they need for their job.
  • Data and systems inventory: know what data you hold, where it lives and which devices, systems and people touch it.
  • Encryption: encrypt customer information in transit over external networks and at rest. If encryption isn't feasible, the qualified individual must approve effective alternative controls.
  • Secure development: if you build or customize applications that handle customer information, use secure development practices and evaluate the security of outside applications you rely on.
  • Multi-factor authentication (MFA): required for anyone accessing any information system, unless the qualified individual approves an equivalent control in writing. See MFA explained.
  • Secure disposal: dispose of customer information no later than two years after it was last used to serve that customer, unless you need it for a business or legal reason or targeted disposal isn't reasonably feasible. Review your retention policy periodically.
  • Change management: a documented process for changes to your network and systems.
  • Monitoring and logging: monitor and log the activity of authorized users and detect unauthorized access or use of customer information.

4. Testing

You must regularly test or monitor whether your safeguards work. That means either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months, and whenever there's a material change to your operations. If the term is new, read what a penetration test is.

5. Staff training

Provide security awareness training to your staff, use qualified security personnel (in-house or through a provider), and keep their knowledge current.

6. Service-provider oversight

Select vendors that can protect customer information, require safeguards in your contracts, and periodically assess how they're doing. That includes your tax software host, document portal, cloud storage and your IT provider.

7. A written incident response plan

Document goals, internal roles and decision authority, communications, how weaknesses get fixed, how incidents are documented and reported, and how the plan is reviewed after an incident.

8. An annual written report

The qualified individual must report in writing, at least once a year, to your board of directors or equivalent governing body. If there's no board, the report goes to a senior officer, which in a small firm is usually the owner. It covers the overall status of the program and material matters such as risk decisions, test results, incidents and recommended changes.

The small-business exemption

If your firm maintains customer information on fewer than 5,000 consumers, 16 CFR 314.6 exempts you from four elements: the written risk assessment, the continuous monitoring or penetration testing and vulnerability scanning requirement, the written incident response plan, and the annual written report. Everything else still applies, including MFA, encryption, access controls, training and vendor oversight. Count carefully: past clients whose records you still hold usually count, and many firms are bigger on paper than they feel day to day.

The breach notice amendment (effective May 13, 2024)

A 2023 amendment added a notification duty. If unencrypted customer information about 500 or more consumers is acquired without authorization, you must notify the FTC as soon as possible and no later than 30 days after discovery, using the FTC's online form. Information counts as unencrypted if the encryption key was also taken. This is separate from any notice owed to affected individuals under state law, such as Florida's Information Protection Act (Florida Statutes s. 501.171).

Tax preparers: IRS expectations

The IRS treats the Safeguards Rule as applying to professional tax preparers and points them to IRS Publication 4557, Safeguarding Taxpayer Data, for practical guidance. The IRS also published a sample WISP template for tax and accounting practices (Publication 5708). A template is a starting point; the plan has to describe your actual systems, people and procedures to be worth anything.

WISP outline checklist

A practical WISP for a small financial office usually includes these sections:

  1. Purpose, scope and the customer information covered
  2. Qualified individual (name, role, authority) and the senior person overseeing any provider
  3. Data and systems inventory: where customer information lives, including cloud apps and paper
  4. Written risk assessment and how often it's repeated
  5. Access control policy: user accounts, least privilege, onboarding and offboarding steps
  6. MFA policy and any approved exceptions
  7. Encryption standards for laptops, servers, email, file transfer and backups
  8. Retention and secure disposal schedule (including the two-year rule)
  9. Change management procedure
  10. Logging and monitoring: what's logged, who reviews it, how long it's kept
  11. Testing schedule: penetration testing and vulnerability scans, or continuous monitoring
  12. Security awareness training plan and attendance records
  13. Service-provider list, contract requirements and review schedule
  14. Incident response plan, including the FTC notice and state breach notices
  15. Annual report template and the date it's due
  16. Revision history

Keep the evidence alongside the plan: training records, scan reports, access reviews, vendor reviews and the signed annual reports. If someone asks "how do you know this is working?", those are your answers.

How NerdSquad helps

A WISP is part policy and part proof. NerdSquad focuses on the technical controls and the documentation that shows they're in place:

  • Implementing and managing MFA, encryption, access controls, endpoint protection and backups
  • Building and maintaining your data and systems inventory
  • Monitoring and logging across your systems, including automated monitoring around the clock
  • Security awareness training, which is a standard part of our cybersecurity plans
  • Penetration testing delivered with our penetration-testing partner: we scope it, coordinate it and handle the fixes
  • Producing evidence and technical input for your risk assessment, incident response plan and annual report

We help put controls, documentation and evidence in place; your firm and its counsel decide what your obligations are. If you're a smaller office weighing whether to bring in outside help, our page on managed IT for small businesses explains how we work, and our IT for financial services firms page covers the financial side in more depth.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Managed IT for small businesses