What is WISP (Written Information Security Program)?
A WISP is a single written document describing how your organization protects sensitive information - required by FTC Safeguards, often by security reviewers, and the foundational document SOC 2 + HIPAA audits expect to see first.
A WISP isn't a specific format mandated by law - it's a document that demonstrates the existence of your security program. Auditors and reviewers want to see administrative, physical, and technical controls; a designated security officer; an incident response plan; vendor risk management; and an annual review schedule.
Most security renewal questionnaires in 2026 ask whether you have a WISP and request a copy. A missing WISP makes every security review slower because the answers have to be rebuilt from scratch.
A small-office WISP typically runs 12-25 pages including policy snapshots and a control matrix.
Why it matters for Florida small business
Without a WISP your insurance review goes up; with one you can answer the standard renewal questionnaire in 10 minutes.
What to do
Adopt a WISP template, fill in your specifics, sign and date it, schedule annual reviews. Build one with your IT advisor, keep it current, and review it every year.