How is everyone actually handling the FTC Safeguards / WISP requirement?
Finally got around to reviewing our firm's WISP situation and honestly it's a mess. We have something from a couple years back but it's basically a template we filled in once and never touched. No real risk assessment, no evidence of controls, nothing documented about annual reviews.
How are other small firms handling this in practice? Using a service, doing it yourself, or is it mostly a document that lives in a folder and nobody looks at?