If you run an auto dealership, you have probably heard the term WISP before.
It stands for Written Information Security Program.
At first, it can sound like another compliance document that needs to be created, signed, and filed away somewhere.
It isn't.
A good WISP should be much more than a document sitting in a folder. It should describe how your dealership protects customer information, who is responsible for protecting it, what safeguards are in place, and what happens when something goes wrong.
For dealerships covered by the FTC Safeguards Rule, having a comprehensive written information security program is not optional. The FTC says covered automobile dealers must develop, implement, and maintain a program appropriate to the dealership's size and complexity, its activities, and the sensitivity of the customer information it handles.
So what should actually be in it? Let's break it down.
First, what exactly is a WISP?
Think of your WISP as the blueprint for your dealership's information security program. It should explain how your dealership identifies customer information, evaluates security risks, protects sensitive information, controls access, manages employees, oversees vendors, responds to security incidents, tests security controls, handles physical records, updates its security program, and documents what it does.
The FTC describes an information security program as the administrative, technical, and physical safeguards used to access, collect, process, store, transmit, protect, and dispose of customer information.
That definition is important. A WISP isn't simply an IT document. It covers the people, processes, technology, and physical environment involved in protecting customer information.
1. Start with your dealership
A common mistake is taking a generic WISP from the internet, changing the company name, and calling it done. That's not what you want.
Your WISP should describe your dealership — its locations, business activities, number of employees, key departments, systems used, types of customer information handled, major service providers, and who's responsible for the program.
Why does this matter? Because the FTC recognizes that a dealership's information security program should be appropriate to its size, complexity, activities, and the sensitivity of the information it handles. A small independent dealership shouldn't necessarily have the same program as a large automotive group. The important thing is that the program makes sense for your actual environment.
2. Identify your customer information
Before you can protect information, you need to know what you have. For an auto dealership, that may include Social Security numbers, driver's license information, credit applications, income and employment information, financial account information, financing and leasing records, customer addresses, and other nonpublic personal information.
The FTC's auto-dealer guidance specifically identifies financing and leasing applications and financial information associated with customers as examples of information that may be protected under the Safeguards Rule.
3. Document where customer information lives
This is one of the most useful parts of a WISP. Customer information doesn't necessarily sit in one database — it may be spread across your DMS, CRM, F&I applications, email, Microsoft 365 or Google Workspace, shared drives, cloud applications, laptops, workstations, mobile devices, paper files, backup systems, and third-party vendor systems.
The FTC recommends starting with an understanding of what customer information you have and where it is stored before developing your information security program. If you don't know where your sensitive information is, it's difficult to know whether you've protected it properly.
4. Include your risk assessment
Your WISP should be built around a written risk assessment — identifying the reasonably foreseeable internal and external risks to customer information and evaluating the safeguards you currently have in place. For example:
Risk: Employee credentials are compromised through phishing. Potential impact: Unauthorized access to customer information. Current safeguard: Multifactor authentication and security awareness training. Gap: Training records are inconsistent. Remediation: Implement recurring training and centralized completion tracking.
That's much more useful than simply writing "the dealership is protected against phishing."
The FTC specifically requires the risk assessment to be written and to include criteria for evaluating risks and threats. It should also be periodically reassessed as the dealership's operations and threats change.
5. Identify your Qualified Individual
Someone needs to be responsible for overseeing the information security program. The Safeguards Rule requires covered financial institutions to designate a Qualified Individual to oversee and implement the program. That individual can be an employee or someone working for an affiliate or service provider.
Your WISP should clearly identify who the Qualified Individual is, their responsibilities, who they report to, what authority they have, how security issues are escalated, and how the program is reviewed.
This is an important distinction: your IT company may manage your technology. That doesn't automatically mean your IT company owns your compliance program. The FTC makes clear that responsibility for the program remains with the covered business even when a service provider helps implement or supervise it.
6. Describe your access controls
Not every employee needs access to every piece of customer information. Your WISP should explain how access is controlled — user accounts individually assigned, access based on job responsibilities, restricted administrative privileges, prompt removal for former employees, access adjusted when roles change, additional protection for privileged accounts, and periodic access reviews.
Think about your finance department. Does every salesperson need access to a customer's full credit application? Probably not. The principle is simple: give people the access they need to do their jobs, and no more than they need. Access controls are specifically identified among the safeguards addressed by the FTC's Safeguards Rule.
7. Address multifactor authentication
Your WISP should explain which systems require MFA, who is required to use it, how privileged accounts are protected, how exceptions are handled, and who is responsible for managing it.
The FTC specifically addresses multifactor authentication for individuals accessing information systems containing customer information. Don't just write "the dealership uses MFA." Document where, why, and how it's being used.
8. Explain encryption
Customer information needs appropriate protection both when it's stored and when it's transmitted. Your WISP should address encryption at rest, encryption in transit, devices containing customer information, email or file transmission, cloud storage, backup systems, and encryption key management or compensating controls where applicable.
The FTC specifically identifies encryption of customer information at rest and in transit among the safeguards addressed by the Rule.
9. Include employee security awareness
Your employees are one of the most important parts of your security program. Your WISP should explain who receives security awareness training, when it occurs, what topics are covered, how completion is recorded, how employees are reminded of their responsibilities, and whether specialized personnel receive additional training.
Training might cover phishing, password security, MFA, handling customer information, social engineering, email security, incident reporting, physical security, and remote work.
The FTC specifically identifies security awareness training as part of the information security program. And don't overlook the documentation — if you train 30 employees, you should be able to demonstrate that they were trained.
10. Address vendor management
This is a big one for auto dealerships. Your dealership probably relies on dozens of outside companies, and some may have direct or indirect access to customer information.
Your WISP should explain how the dealership identifies vendors with access to customer information, evaluates vendor risk, selects appropriate service providers, includes security requirements in contracts, reviews vendors periodically, tracks vendor agreements, and monitors vendor-related risks.
The FTC specifically requires covered institutions to take reasonable steps when selecting and retaining service providers, require appropriate safeguards contractually, and periodically assess those providers based on the risk they present. This is an area where a dealership can easily lose visibility — you may know your own systems very well, but do you know what security controls your vendors have?
11. Include security monitoring and testing
Your WISP should explain how your dealership determines whether its safeguards are actually working — security monitoring, vulnerability assessments, penetration testing, log monitoring, security alerts, endpoint monitoring, remediation tracking, and periodic reviews.
The FTC's guidance addresses continuous monitoring and, where continuous monitoring isn't used, vulnerability assessments at least every six months and penetration testing at least annually.
The important part isn't simply performing the test. It's what happens afterward. If a vulnerability is identified, your program should show: what was found → who owns it → what needs to happen → when it should be resolved → what evidence confirms the fix.
12. Have an incident response plan
Nobody wants a cybersecurity incident. But every dealership should plan as though one could happen. Your WISP should include — or reference — a written incident response plan covering who responds, who has decision-making authority, how incidents are reported, how systems are contained, how evidence is preserved, how weaknesses are remediated, who communicates with affected parties, documentation requirements, regulatory reporting considerations, and recovery procedures.
The FTC specifically requires a written incident response plan for covered financial institutions. And certain security incidents involving customer information can trigger FTC notification obligations, including a requirement to notify the FTC within 30 days of discovering a qualifying notification event involving at least 500 consumers' unencrypted information. That's not something you want to discover while you're in the middle of a crisis.
13. Don't forget physical security
A WISP isn't only about computers. What about the filing cabinet containing customer financing documents? What about printed credit applications sitting on a desk? What happens to documents that are no longer needed?
Your WISP should address physical access to sensitive records, locked storage, visitor access, secure disposal, paper document handling, workstation security, and office security.
The FTC specifically calls out physical safeguards, including securing file cabinets containing paper records with customer information. Sometimes the simplest risks are the easiest to overlook.
14. Address data retention and secure disposal
Your dealership should understand how long it keeps different categories of information and what happens when that information is no longer needed. Your WISP should address data retention, secure disposal, paper shredding, electronic media disposal, device retirement, vendor disposal practices, and who's responsible for approving disposal.
The goal is straightforward: don't keep sensitive information indefinitely without a reason, and when it's time to dispose of it, make sure it's disposed of securely.
15. Explain how the WISP is updated
This might be the most important section of all. Your WISP should not be frozen in time.
Your dealership changes. You add employees. You replace your DMS. You change CRM providers. You move systems to the cloud. You add another location. You acquire another dealership. You discover a vulnerability. A new threat emerges. Your WISP should change with you.
The FTC expects covered institutions to keep their information security programs current and make adjustments based on monitoring, testing, risk assessments, vulnerabilities, and material changes to the business. A WISP that hasn't been updated in three years may technically be a document. But it may no longer describe your security program.
16. Include management reporting
Your information security program should eventually make its way into the boardroom — or, for many independent dealerships, to the dealer principal or other governing authority.
The FTC requires the Qualified Individual to provide a written report at least annually to the board of directors or other governing body concerning the overall status of the information security program and material matters related to it. That report can cover risk assessment results, major security issues, vendor risks, security incidents, testing results, remediation activities, program improvements, and overall compliance status.
This is where cybersecurity stops being "the IT person's problem" and becomes a management responsibility.
What a good WISP should feel like
When you open your WISP, you shouldn't feel like you're reading a legal document written for somebody else's business. You should be able to recognize your dealership.
You should know who is responsible, what information you have, where it lives, what the risks are, what safeguards are in place, what your employees are expected to do, what your vendors are responsible for, what happens when something goes wrong, how you know the program is working, and when it will be reviewed and updated.
That's what makes a WISP useful.
The biggest WISP mistake dealers make
The biggest mistake isn't necessarily having no WISP. It's having a WISP that doesn't match reality.
A dealership may have a beautifully written 40-page document. But if the document says the dealership reviews vendor security annually and nobody actually does it, there's a problem. If the WISP says employees receive annual training but there are no training records, there's a problem. If it says the dealership performs periodic risk assessments but nobody knows when the last one happened, there's a problem. If the document says one person is responsible for security but the dealership has never actually given that person responsibility, there's a problem.
A WISP should describe what your dealership actually does — and provide a framework for what it needs to do. That's the difference between a document and a program.
How Sterling Safeguard can help
This is one of the reasons we built Sterling Safeguard specifically for independent auto dealerships. Creating a WISP is only the beginning — the real challenge is maintaining everything that sits behind it. Sterling Safeguard brings those pieces together.
Build your WISP. The Living WISP Generator helps dealerships create a dealership-specific written information security program and keep it aligned with their compliance activities.
Start with a risk assessment. The Risk Assessment Engine helps identify risks, evaluate safeguards, uncover gaps, and establish a measurable compliance posture.
Keep your evidence organized. The Evidence Vault gives your dealership a centralized place to maintain policies, assessments, training records, vendor documentation, testing reports, and other compliance evidence.
Manage vendors. Track vendors, their risk levels, contracts, renewal dates, and access to customer information.
Track employee training. Know who has completed training, when they completed it, and where their training records are stored.
Manage incidents. The Incident Response Center gives your dealership a structured place to manage and document security incidents.
Stay on schedule. The compliance calendar helps keep recurring activities from being forgotten.
See your progress. The FTC Audit Readiness Score™ gives dealership leadership a simple way to understand the current state of their compliance program and identify areas that need attention.
The idea isn't to create more paperwork. It's to bring the paperwork, responsibilities, evidence, and ongoing activities into a system that can actually be managed.
Your WISP should be a living program
If your dealership has a WISP, take a few minutes and open it. Ask yourself: does this document describe how we actually operate today?
If the answer is yes, that's a good start. If the answer is no — or you're not sure — that's a sign the program needs attention.
A WISP shouldn't sit untouched in a folder until somebody asks for it. It should evolve as your dealership evolves. Because ultimately, the purpose of a WISP isn't to produce a document. It's to protect your customers and give your dealership a structured way to manage the risks that come with handling their information.
And when the time comes to demonstrate what you've been doing, you shouldn't have to scramble to put the pieces together. You should already have them.
Is your dealership's WISP actually working?
Sterling Safeguard helps independent auto dealerships build, manage, document, and maintain their FTC Safeguards Rule compliance program in one place.
Build your WISP. Understand your risks. Organize your evidence. Stay ready.
Sterling Safeguard — FTC Compliance Built for Independent Auto Dealerships.
This publication is for educational and informational purposes only and does not constitute legal advice. The FTC's Safeguards Rule may apply differently depending on a dealership's specific activities and circumstances. Dealerships should consult qualified legal or compliance professionals regarding their specific obligations.