Written Information Security Program for New York Businesses

Who wrote your
security program?

Who approved it?

New York's SHIELD Act, General Business Law section 899-bb, says any business holding computerized private information of a New York resident must develop, implement, and maintain reasonable administrative, technical, and physical safeguards. It does not hand you a checklist, and it does not require the program to be written down. It hands you a reasonableness standard. Writing the program down is how you show what you decided and why: a Written Information Security Program, a WISP.

A program is only as good as its fit to what you actually run. Some businesses have nothing in writing. Others have a WISP written when the business looked different than it does today. Either way, the first question is not "what should the document say?" It is "what is really there?"

So every engagement starts with the same deliverable: a crosswalk map of your technology environment. It shows where your private information lives, which systems and vendors touch it, what protects it today, which statutory safeguard each protection answers, and where the gaps are, in the order worth acting on. It does not fix what it finds. What it gives you is the confidence you did not have before: someone looked in all the right places, and you have it in writing.

From the map, one of two things happens. If your case is small enough, we write the WISP. If you already have one, we review it against the map and show you where the program and your environment line up, and where they have moved apart.

$2,500 for the crosswalk map and a WISP for a small business starting from nothing. Ten business days from the intake call. One revision round. No subscription, no platform, no lock-in. Already have a program, or a larger environment? The map is the same; the rest is scoped and quoted after the intake call.

What you get.

In every case: the crosswalk map. It is an assessment of the reality of your current technology environment, laid against the three safeguard classes the statute names (administrative, technical, physical) and cross-referenced to the NIST Cybersecurity Framework vocabulary that carriers and security questionnaires already use. It is yours, in a format you own and can export.

Think of it as a map, not a repair. It names what you have, what is missing, and what to do about it, ranked. You act on it yourself, with your IT provider, or with us under a separate scope. Nothing in the engagement changes a setting on your systems. It is not an attestation, it is not a certification, and it is not legal advice.

The crosswalk map. Always included.

  • One ninety-minute intake call. Bring whoever knows where the data lives.
  • A vendor and data inventory: which systems hold private information, who your sub-processors are, and where the data physically sits.
  • A control-by-control crosswalk: what protects each system today, which statutory safeguard class it answers, and where coverage is current, thin, or missing.
  • A ranked gap list, in the order worth acting on.
  • One revision round after you read the draft.

Then one of two, depending on where you start.

A WISP written for you, if the case is small enough. A five-to-fifty person business with a handful of systems holding private information usually is. The program is built from the map and covers the three safeguard classes, an incident response section so the first breach-day decision is not improvised, a designated security coordinator (the statute wants a name), and a one-year review date so it does not quietly go stale. It is the document you can hand to a carrier at renewal or to a client who sends a security questionnaire.

A review of the WISP you already have. We read your program against the map and show you where it is current, where it is thin, and where your environment has changed since it was written. You get the findings; updating the document is a separate, quoted scope if you want us to do it.

Deliberately excluded.

Naming what is out is what keeps the ten days honest and the price fixed. Each of these is a separate engagement if you want it.

  • Implementation of any control the program calls for.
  • Remediation of anything the map surfaces. The program tells you what to fix and in what order; fixing it is yours to action.
  • Employee training delivery.
  • Ongoing monitoring or operations of any kind.
  • Certification or attestation. This is a program document, not a stamp.
  • Legal advice or legal review. We are not a law firm. If you want a lawyer to review the program, we can introduce you to one; that review is a separate engagement between you and the lawyer.

Where you start decides what comes after the map.

Many businesses have something: a policy binder, a PDF from an IT provider, a template someone filled in years ago, or answers to last year's insurance questionnaire. That is not wasted work, and we do not start over on top of it.

Nothing written, small environment.

The crosswalk map, then a WISP built from it. $2,500, ten business days.

Something already written.

The crosswalk map, then a review of your program against it. The review is scoped to what you have, and you get the scope and the quote after the intake call, before anything starts.

Nothing written, larger environment.

With more systems, sites, or vendors, the crosswalk map comes first, and writing the program becomes its own quoted scope, sized from what the map shows.

Not sure which you are? Say so on the form. Most people find out on the intake call.

The legal hook, named.

Whether the SHIELD Act applies turns on one defined term.

Section 899-bb reaches any business that owns or licenses computerized "private information" of a New York resident, regardless of where the business is located. Private information is narrower than it sounds. It means a person's name or other identifier combined with a Social Security number, a driver's license number, a financial account or card number with the code that unlocks it, biometric data, medical information, or health insurance information; or a username or email address combined with the password or security answer to the account.

A customer list of names and email addresses, on its own, is not private information. A payroll file with Social Security numbers, stored card numbers, or customer logins is. Small businesses (under fifty employees, under three million dollars in revenue, or under five million dollars in assets) are held to a standard scaled to their size and the sensitivity of the data. They are not exempt.

If you hold none of it, the statute may not reach you, and the map shows that too.

Sources: N.Y. Gen. Bus. Law section 899-bb (data security protections, effective March 21, 2020); section 899-aa(1) (definition of private information). Enforcement is by the New York Attorney General; the statute creates no private right of action.

A reasonableness standard with no control list bites hardest on the businesses least equipped to interpret it.

Large firms have counsel and a compliance function to translate "reasonable safeguards" into a program. Cottage businesses, seasonal operations, and single-location e-commerce sellers do not. They are covered, exposed, and without in-house capability, which is exactly where a fixed-scope written program is a buyable starting point.

For law firms, the same document can support Model Rule 1.6 and Rule 5.3 work.

Firms already carry a confidentiality duty and a duty to supervise nonlawyer assistance, which the ABA has said reaches AI vendors (Formal Opinion 512, July 2024). Most firms have baseline cyber coverage for competence and insurance reasons. What they usually lack is the written program that connects the technology decisions to the professional obligations. The program documents the safeguards; how they satisfy your professional duties remains your judgment and your bar's guidance. Same document skeleton, different lead paragraph. The attorneys assessment is the right place to start if you want the wider picture first.

Who this is for.

  • New York e-commerce businesses that keep customer account logins, stored payment details, or employee records, with a carrier renewal or a marketplace security questionnaire on the calendar.
  • Cottage industries: food producers, makers, home-based services with employees on payroll, customer accounts, or stored payment details, and no IT function.
  • The fair and festival circuit: vendors and organizers who run payroll for seasonal staff, keep ticketing or member logins, or store card details across a season, and have never written down how they protect them.
  • Solo and small law firms that already have coverage and now need the written program behind it.
  • Any five-to-fifty person business holding computerized private information on New York residents that has been asked, or expects to be asked, "who wrote your security program?"

What the map is: a scored read of what your business can prove today against the safeguards New York expects. It is not a certification, a SOC 2 report, or an audit, and it works alongside them. Firms that answer client audits and security questionnaires use it to show where they stand and what to close first.

How the ten days run.

The delivery is an assembly line, not a consulting engagement that expands to fill the time. Each step has one input and one artifact. This is the ten-day line for a small business starting from nothing; a review of an existing program runs the same first steps. The ten days assume your inventory answers come back within three business days. If they do not, the clock pauses and we tell you so in writing that day.

  • Day 0. Intake call, ninety minutes. Artifact: the data and vendor inventory, in draft.
  • Days 1 to 3. Inventory confirmed with you by email. Artifact: the signed-off inventory.
  • Days 4 to 5. Controls crosswalked against the three safeguard classes. Artifact: the crosswalk map and ranked gap list.
  • Days 6 to 7. Program drafted from the map, with incident response and the coordinator appointment (or, for an existing program, the review findings). Artifact: the draft.
  • Day 8. Map and draft delivered. You read them.
  • Days 9 to 10. One revision round. Artifact: the final map and program, in your name, in a format you own.

Legal review is not part of the $2,500. We can introduce you to a lawyer for it, as a separate engagement. If a lawyer reviews the program, the program names who approved it. If not, the program says no external reviewer was engaged. Either way, the document states its own limits.

The price, and what it is not.

$2,500 is the price for the crosswalk map plus a program built from nothing for a small business, and it sits deliberately between two failure points. Below roughly $1,500 a program reads as a template you could have downloaded, and you should. Above roughly $5,000 it triggers a procurement reflex the businesses this is for do not have the staff to run. The annual review and update, which re-runs the crosswalk and keeps the program current against vendor and regulatory change, is $1,000 a year and is optional. If you already have a program, or your environment is larger than a ten-day program can cover, the price follows the scope and is quoted before work starts.

It is not a subscription and it is not a platform. You pay once, you own what we deliver, and if you never speak to us again the map and the program are still yours. Whether it still matches how you operate is the question the review date exists to answer.

Request the intake call.

Tell us who you are and what kind of business holds the data. We reply with two or three intake-call times, usually within one business day. No payment is taken on this page, and nothing on this page is legal advice.

We reply here with intake-call times.
If you have one, we review it against the crosswalk map instead of starting over.

success.build/risk/wisp · [email protected] · crosswalk map in every case · you own what we deliver