Answer · Updated August 2026
What is a WISP, and does my law firm need one?
Direct answer
A WISP — Written Information Security Program — is the document that defines how your firm protects client data: risk assessment, access controls, encryption, vendor management, incident response, and testing cadence. Cyber insurers, corporate clients' outside-counsel guidelines, and the FTC Safeguards Rule all expect one, and it is usually the first document requested in a security review. If your firm lacks one, that gap surfaces at the worst possible time.
What goes into a WISP
A defensible WISP for a law firm typically covers fourteen sections — from governance and risk assessment through access control, encryption, vendor management, incident response, and the testing and review cadence. It should name owners, set review dates, and describe evidence: not just 'we test,' but when, how often, by whom, and where the reports live.
Who asks for it
Three audiences, same document:
- Cyber insurers: the WISP answers half the renewal questionnaire before the call starts
- Corporate clients: outside-counsel guidelines routinely require a written program and ask for it during onboarding or audits
- Regulators: for firms under the FTC Safeguards Rule, a written program is explicitly mandated, not implied
Keeping it alive
A WISP written once and never touched is worse than none at all in a dispute — it documents a promise you stopped keeping. Set an annual review, tie the testing cadence to real reports (continuous assessment produces dated evidence automatically), and update it when the firm changes systems, offices, or practice mix. Our law-firm WISP template maps each section to ABA Rule 1.6(c), the Safeguards Rule, and common client-audit language.
Related questions
Is a WISP the same as an information-security policy?
A WISP is the broader program document; policies (acceptable use, access control, incident response) live inside it. In practice, people use the terms loosely — what matters is that the written program exists, is current, and matches what the firm actually does.
How long should it be?
Long enough to be real, short enough to be followed. Ten to twenty pages covers most small and midsize firms; the 14-section template gives you the structure.
Who should own it?
A named individual — the Safeguards Rule calls this the qualified individual. In a small firm that is usually the managing partner or operations lead with outside support; what matters is that accountability is written down.
