top of page
IronShield-Advisors-logo

What Should Be in a Dealership’s WISP?

Writer: Kenny Mollitor
Kenny Mollitor
Jul 17
3 min read

A real WISP turns dealership cybersecurity into a documented program with clear ownership, risk assessment, safeguards, and training—not just a generic policy on paper.
A real WISP turns dealership cybersecurity into a documented program with clear ownership, risk assessment, safeguards, and training—not just a generic policy on paper.

If your equipment dealership offers financing or leasing, you’re expected to have a Written Information Security Program (WISP). But what does that actually look like in practice?


A dealership WISP is a living document that spells out how you safeguard customer information—who owns the program, which risks you’ve identified, and what controls you’re using to manage them. If your “WISP” is a generic one-page policy or doesn’t exist at all, you’re exposed.


The Role of a WISP in Compliance

The WISP is the backbone of your Safeguards Rule compliance. It:

  • Defines your information security objectives.

  • Describes how you identify, manage, and monitor risk.

  • Connects your policies, procedures, and technical controls into a coherent program.

  • Gives auditors and lenders a way to see that you’re not just checking boxes—you’re managing risk on purpose.

Without a WISP, you have no defensible way to show that your safeguards are reasonable for your dealership’s size and complexity.


The 9 Core Elements Your WISP Should Cover

While wording can vary, a dealership-ready WISP should address at least these nine areas:

  1. Program Governance & Qualified Individual

    • Who is responsible for your security program?

    • How are decisions made and reported to ownership?

  2. Risk Assessment

    • Where does customer information live (systems, email, paper, vendor platforms)?

    • What internal and external risks have you identified?

  3. Access Controls & Authentication

    • Who can access which data, and based on what criteria?

    • How do you enforce unique logins, strong authentication, and least-privilege access?

  4. Data Encryption & Handling

    • How is customer information protected in transit and at rest?

    • How are backups handled and secured?

  5. Secure Development & Change Management

    • How do you evaluate changes to systems or processes that touch customer data?

    • How do you avoid introducing new vulnerabilities inadvertently?

  6. Vendor Management

    • Which service providers receive customer information?

    • How do you vet them and ensure they maintain appropriate safeguards?

  7. Monitoring, Testing & Logging

    • How do you monitor for suspicious activity or failures?

    • How often do you test your controls (e.g., periodic reviews, external tests)?

  8. Incident Response Plan

    • What happens if you experience a breach or serious security incident?

    • Who is involved, and how is communication handled with customers, lenders, OEMs, and regulators?

  9. Training & Continuous Improvement

    • How often are employees trained on cybersecurity and data handling?

    • How do you update the WISP when risks, systems, or regulations change?

If your current document doesn’t clearly address these areas, it’s time for a refresh.


Avoiding Common WISP Mistakes

Dealers often get into trouble by:

  • Using a generic template that doesn’t reflect their actual operations.

  • Failing to keep the WISP updated as they add locations, systems, or vendors.

  • Treating the WISP as a one-time project instead of an ongoing governance tool.

  • Keeping the WISP completely separate from day-to-day processes and training.

A realistic WISP should be something your leadership can understand and use—not a binder that collects dust on a shelf.


How IronShield Builds Dealership-Specific WISPs

IronShield Advisors helps dealerships:

  • Translate FTC requirements into practical, dealership-language policies.

  • Map controls to real systems (DMS, CRM, email, file shares, vendor portals).

  • Create an incident response plan that matches your staffing and resources.

  • Align training and vendor oversight with the commitments in your WISP.

You end up with a document you can show to lenders, OEMs, and insurers, and a program you can actually follow.


If you’re not sure whether your current WISP would hold up in an audit, IronShield can walk you through a focused review and update plan tailored to your store.

 
 
 

Comments


bottom of page