Whatβs a WISP, and Why You Need One.
A WISP — short for Written Information Security Plan — is a formal document that explains how your business protects sensitive data. It covers things like who has access to client information, how your systems are secured, what happens in the event of a breach, and how you train your staff.
In New York, if you collect or store personal, financial, health, or other sensitive information, you're legally required to have a WISP. That includes law firms, accounting firms, nonprofits, healthcare providers — even small companies that store names and email addresses for clients.
Here’s the catch: most small businesses don’t have one. And most IT companies never bring it up — either because they’re not paying attention, or they don’t understand today’s compliance landscape. But cyber insurers and regulators are paying attention. More and more insurance policies now require a WISP to be in place — and if you don’t have one, your claim could be denied after a breach.
The good news? We’ll help you get compliant in less than an hour.
It’s also required by many cyber insurance providers. Without it, your claim could be denied.