RSS Amplifier

A Different Practice · Aug 12, 2026

The prompt that builds a security program in an afternoon

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

You don't need a security department. You need someone to ask you the right questions.

Testing and sharing what actually works in solo practice.

One of the unexpected perks of my marriage is that I get a window into a business completely different than mine.

My husband co-owns a software company. Even though we’re in different industries, we often talk shop and bounce ideas off each other. I geek out about the latest automation I built, while he works through topics that sound like he’s speaking another language: security reviews, vendor audits, compliance questionnaires.

A while back he asked whether I had a WISP for my firm.

“Do I whisper congratulations to myself when I land a new client?” I said. “Obviously.”

My joke gave me away: Not only did I not have one, but I didn’t know what one was.

When he explained it, I could see why it was necessary for his company with multiple employees in different states managing vendor requirements. But I didn’t think I needed one. I mean, my firm is just me. One person, a laptop, and a home office. Having a written security program for my practice felt like putting a fire sprinkler system in a shed.


Why “But, it’s just me” isn’t an excuse

Where I got it backward was thinking about the size of my firm. Having a security program is about the data, not the size of the business.

For example, if you hold Social Security numbers, account balances, medical information, or information about people’s children, that is sensitive data that needs to be protected. The person whose tax return is sitting in your cloud storage doesn’t care that you’re a firm of one. If it gets out, it’s the same nightmare as if it happened to a firm of two hundred.

There’s no escaping that we live in a digital world. Some states now require businesses holding personal information to maintain reasonable security measures. Your malpractice carrier may also ask about it when you renew.

Even if it’s small, the shed holds the same fuel as a warehouse, and we need a plan to protect it.


What’s a WISP?

A Written Information Security Program (WISP) is a document that says what you protect, how you protect it, and what you do when something goes wrong.

It covers three kinds of safeguards:

  1. Administrative is your policies, your training, and how you handle vendors.

  2. Technical is passwords, multi-factor authentication, encryption, and backups.

  3. Physical is the locked door, the locked drawer, and the laptop you left on the table while you ordered.

A complete WISP also names who’s responsible (you), inventories what data you hold and where it lives, assesses what could realistically go wrong, spells out what to do in the first 24 hours after a breach, and sets a schedule for retention, destruction, and review.

I know, it sounds like a lot. I thought the same thing. Ugh, one more thing I have to put together.

But all of it ended up covered in about four pages for a firm my size.


What I got wrong about the document

When I sat down to create my firm’s WISP (after, admittedly, putting it off for months), I expected the value to be in the finished document. It was something I could point to if anyone asked.

What I found was that the value was in the process of creating it.

Because I wasn’t entirely sure what I was doing or where to start, I asked Claude to walk me through the process, question by question. Sometimes the answers were easy peasy. Other times, I squirmed in my chair a bit. The process surfaced things I’d assumed were handled and weren’t. It uncovered places I was storing documents that I’d forgotten about. It reminded me of a tool with access that I hadn’t thought about since I set it up.

The report it produced was organized and useful. Reading through it, I felt empowered and in control of my practice. I felt better about my policies when I could see them in writing.

Of course, one document won’t fix your practice, but going through the process builds the habit, and the habit is where the protection gets strong.


The prompt

To create your own WISP for your practice, open Claude, paste the prompt below and adjust as needed, and answer honestly.

If you built a Practice Brief after reading Claude doesn’t know your practice. Here’s how to fix that.”, the interview will go faster, because half the context is already loaded.

You’re an expert in security programs. Your task is to help me create a first draft of a Written Information Security Program (WISP) for my solo law firm.

Interview me first. Ask one question at a time and wait for my answer before moving on. Keep your questions short and in plain language. If an answer is vague, ask a follow-up before continuing. Ask enough questions to create a comprehensive WISP.

Cover these areas:

  • My practice areas, my location, and what states my clients live in

  • What categories of sensitive information I hold

  • Every place that information lives: practice management software, cloud storage, my computer, my phone, my email, paper files

  • How information comes in and goes out, including channels I didn’t authorize

  • Who besides me can access any of it, including vendors, contractors, and anyone sharing a device with me

  • What technical protections exist now: passwords, multi-factor authentication, encryption, device locks, backups, software updates

  • What physical protections exist, and what happens if a laptop or phone is lost

  • My retention and destruction practices

  • What I’ve told clients about how I handle their information, and where I told them

  • What I would do in the first 24 hours if I discovered a breach

Then produce a Written Information Security Program with these sections: purpose and scope; person responsible; inventory of protected information and where it lives; risk assessment ranked by likelihood and harm; administrative safeguards; technical safeguards; physical safeguards; vendor and third-party access; incident response plan with the first 24 hours step by step; retention and destruction schedule; training and review schedule.

Then give me two more things. First, a gap list: everything missing or weak, ranked by risk. Second, a 30-day action plan with no more than five items, in the order I should do them.

Write in plain language. This is a working document for a firm of one, not a corporate policy manual. Flag anywhere I need to verify a requirement against my state’s rules of professional conduct or my malpractice carrier policies.

One thing to keep in mind as you work through the questions: describe categories, not contents. Say “client bank statements,” not the client’s name or the account number. Don’t paste credentials (usernames and passwords), and don’t upload a real client file. Writing a security plan is not the moment to create a new security risk.

One thing to keep in mind as you work through the questions: describe categories, not contents. Say “client bank statements,” not the client’s name or the account number. Never paste credentials (username/passwords), and don’t upload a real client file. Writing a security plan is not the moment to create a new security risk.


What to do with the results

Read through the document and adjust for accuracy and completeness. Pay particular attention to the gap list. It will show you where you need to focus to fill in any cracks.

Using the 30-day action plan, block time on your calendar to address the items. Having the plan sitting in a folder on your computer isn’t going to help you when you need it.

Set a reminder to revisit your WISP every year. I’m going to review mine during the year-end internal week I take every December. When your tools, software, and vendors change, the WISP should too.


The document is great, but the habit is the point.

I thought my husband was being dramatic. Turns out he was just right. WISPs are normal for business today, and the legal profession isn’t an exception.

A few pages and an afternoon can close most of the gap.

Your clients hand over sensitive information because they assume you have this handled. Spend an afternoon making that assumption true.

Happy WISPering,
Lauren

P.S. The most revealing question is the one about vendors. Every tool you’ve connected to your email or your files has some level of access, and most of us granted it once and never looked at it again. If you only have twenty minutes today, make a list of the vendors that have access. It might surprise you.

Read on adifferentpractice.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.