top of page
IronShield-Advisors-logo

Why Equipment Dealers Need a Written Information Security Program (WISP)

Writer: Kenny Mollitor
Kenny Mollitor
Jul 9
3 min read

If your equipment dealership offers in-house or floor-plan financing, the FTC Safeguards Rule expects you to have a Written Information Security Program (WISP). Simply telling regulators or lenders that "IT handles that" is no longer an acceptable defense.


Under the Gramm-Leach-Bliley Act (GLBA), if you assist customers with credit or financing, your dealership is treated as a financial institution. This means you are legally obligated to formally document how you protect customer data. Without a WISP, you are essentially guessing at your security posture and leaving your dealership exposed to severe penalties during an audit.


A proper WISP is not just a policy document; it is the defensible foundation of your entire compliance program. Here is why you need it and what the FTC requires.


What is a Written Information Security Program?

A WISP is a comprehensive, written document that outlines the administrative, technical, and physical safeguards your dealership uses to protect customer information. It is not a one-size-fits-all template. The FTC requires your WISP to be tailored to your dealership's specific size, complexity, and the nature of the customer information you handle.


The True Cost of Non-Compliance

If an OEM, floor-plan lender, or regulator audits your store tomorrow, your WISP is the first thing they will ask for. Without it, you cannot prove that you are actively managing risk. Failing to produce a compliant WISP can lead to significant fines, damaged relationships with lenders, and reputational harm.


The 9 Essential Elements of a Dealership WISP

The FTC Safeguards Rule outlines nine specific components that must be addressed in your WISP. If your current document is missing any of these, you are out of compliance.


1. Designate a Qualified Individual

You must appoint a specific person—either internally or an external partner—to oversee, implement, and enforce your security program.


2. Conduct a Written Risk Assessment

Your WISP must be based on a formal, written risk assessment that identifies internal and external threats to customer data and evaluates the effectiveness of your current safeguards.


3. Implement Specific Safeguards (Controls)

You must apply access controls, encrypt customer data in transit and at rest, and implement secure data disposal practices.


4. Continuous Monitoring and Testing

You must regularly test and monitor your safeguards, which includes either continuous monitoring of your systems or conducting annual penetration tests and bi-annual vulnerability assessments.


5. Employee Training and Awareness

Your security program must include regular, updated training for all employees on how to identify and avoid cybersecurity threats.


6. Strict Vendor Oversight

You are required to evaluate your service providers and ensure your contracts mandate they maintain adequate security measures for any customer data you share with them.


7. Keep Your Program Updated

Your WISP cannot sit in a drawer. It must be continually evaluated and adjusted based on testing results, material changes to your operations, or new risk assessments.


8. Document an Incident Response Plan

You must have a written plan detailing exactly how your dealership will respond to and recover from a cybersecurity event.


9. Annual Reporting to Leadership

The Qualified Individual must present a written report to your dealership's board of directors or governing body at least annually, detailing the status of the security program.


Stop Guessing and Start Documenting

If your WISP is a generic one-page document, or if you don't have one at all, your dealership is highly exposed. Lenders and regulators are moving quickly in this direction, and compliance is not optional.


Are you ready for your next floor-plan review? Contact IronShield Advisors today for a free 15-minute Safeguards gap check. We will help you identify what is missing from your WISP before it becomes an expensive problem.

 
 
 

Comments


bottom of page