We act as your designated qualified individual under the FTC Safeguards Rule, build and maintain your WISP, run the required ongoing risk assessments, deliver employee training, and document everything you’d need to produce in an audit — for the IRS, your cyber insurer, or your clients.
Documented Written Information Security Plan (WISP)
Designated qualified individual (FTC Safeguards point of contact)
Initial and annual risk assessments
Information system inventory and data flow mapping
Access controls and authentication policy
Encryption-at-rest and in-transit standards
Vendor and service provider risk management
Incident response plan and testing
Employee security awareness training (with completion tracking)
Annual training refresh and phishing simulations
Audit-ready documentation portal
Ongoing program oversight and policy updates