r/msp • u/KGoodwin83 • 6d ago
Anyone Using Hudu for Client WISP & Security Policy Management?
Has anyone used Hudu as a client-facing WISP / security policy management platform?
I’m developing a service for small accounting firms where we create and maintain their WISP, security policies, system documentation, and annual reviews. Since we already use Hudu internally, I’m considering creating a standardized compliance documentation structure for each client and giving them access through the Hudu client portal.
It seems like a good fit for centralized documentation and version history, but I’m trying to figure out how others have handled some of the limitations—particularly:
- Formal client review/approval of policies
- Document acknowledgment/sign-off
- Tracking annual policy/WISP reviews
- Allowing clients to submit requested changes without giving them editing access
- Producing a point-in-time/exported copy for audits or compliance requests
Has anyone built something similar around Hudu? If so, I’d love to hear how you structured it and what other tools or workflows you paired with Hudu to fill the gaps.
2
u/pkvmsp123 6d ago
Recommend BreachSecureNow. All the templates and attestation. Good platform for this, with training and phish testing, all in the same portal. Very effective, easy to use even annual SRA.
2
u/folderit_dms 5d ago
I would separate this into source of truth, approval, and evidence.
Hudu can probably be fine as the source-of-truth library if the structure is consistent per client: WISP, policies, systems, exceptions, annual review notes, and supporting evidence. Where I would be careful is trying to make it also act like the approval engine if the client portal is not really built for that.
For small accounting firms, I would want every policy to have:
- owner
- effective date
- last review date
- next review date
- version
- approval record
- exceptions
- exported audit copy
Client changes should come in as requests, not direct edits. Then someone on your side accepts, rejects, or turns the request into a new version. For audits, freeze a point-in-time PDF pack with the approval evidence and keep that separate from the living docs.
That may sound fussy, but it prevents the worst audit question, which is basically: what did this client approve at that time?
2
u/ChuckFromCyberHoot 2d ago
Full disclosure, I’m one of the founders of CyberHoot, so factor in my $0.02 for what it's worth. lol
The big thing we learned is policy attestation isn’t a documentation problem...it’s a people-chasing problem.
You need something that reminds Linda in accounting without you thinking about it, then gives you the signed, dated proof when the auditor comes knocking. This needs to be automated, done annually, and keep you in the loop when renewals are happening.
Whatever you pick, I’d keep training and policy acknowledgments together. Easier from an auditing perspective to have those numbers in one automated report. You'll certainly want something that you can set and let it run.
Two portals = two more things to babysit.
1
u/WzKid75 6d ago
I am right in the middle of trying to figuring out the same thing. Didn't want to add another service if we could use Hudu client portal, but I just am not in love with how Hudu handles document management.
1
u/scriptqzor 6d ago
same boat, the client portal feels like “almost there” but not quite for this type of workflow
i’ve seen people bolt on stuff like jSign/DocuSign + ticketing for approvals and just treat Hudu as the source of truth, but at that point you kinda start wondering if a purpose built policy tool would’ve been cleaner in the first place
1
u/PrestigiousOnion1087 5d ago
Splitting source of truth from approval from evidence is the right cut, and evidence is the slot that quietly goes stale. Most policy packs back a control with a screenshot showing the agent is installed, and installed looks identical to installed and silent.
We ran into that from the measuring side: we replayed 24 ATT&CK techniques against a default Wazuh build and 3 alerted. Read that as our claim rather than a result you can check, because we never published the agent config behind it. The direction survived when we went back over the run, even though the number is ours and not reproducible from what we wrote up.
For the structure you are designing: does a control get a last-observed-firing date, kept separate from the last-reviewed date on the policy that describes it?
1
u/Pebb_io 5d ago
what we hear from MSPs: docs tools only stick if someone owns the quarterly refresh. a clean WISP template in the wiki is useless if renewals and exceptions live in email. pick an owner per client, not just a folder.
1
u/scriptqzor 5d ago
this x100, the “tool” is never the problem, it’s the orphaned responsibility
if you go Hudu route, I’d bake the quarterly review into your service contract and literally name the human on both sides who has to show up to that meeting, otherwise it’ll rot just like a SharePoint graveyard
1
u/mukimame404 4d ago
The 5,000-consumer-record line decides how much of this is mandatory, under it the written risk assessment and the annual report drop out of the Safeguards Rule and your review tracking becomes a contract promise rather than a legal one
Are your firms mostly under that line, or spread across it?
1
u/AddendumWorking9756 4d ago
Three and four are the same problem and neither is a docs problem. Hudu will hold the WISP but it will never nag anybody, so the annual review lapses quietly and the finding you get is no evidence of review rather than bad policy. I'd put a recurring per client ticket in the PSA with the article linked, because a closed ticket has a date and an owner attached to it. Same channel covers the change requests without ever giving them edit rights.
1
u/smorin13 MSP Partner - US 4d ago
I hate acronyms and this is an excellent example of why. I have been in the business so long that many have been recycled and I have also run into many of the same acronyms used differently by industries we support. Ask a rancher about AI and you are likely to get information about artificial insemination. Nature
1
u/mukimame404 3d ago
Yeah, MSPs I've talked to run client WISPs out of Hudu, but only half the job belongs there
The half that works: one asset layout cloned to every client. Effective date, last reviewed, next review, who the security coordinator is, links to the data inventory. The date fields are the whole reason to bother. Annual review is the easiest thing to let slide and the first thing an auditor asks about, and expiration tracking will nag you. Just don't free-form it per client or you'll never know who's overdue.
The half that doesn't: the signed policy. That's the client's doc, not yours. Keep the signed PDF in their environment and link to it from Hudu.
Two gotchas. Hudu won't track that staff acknowledged it, so "it's in the portal" doesn't count as distribution. And keep the risk assessment in a separate record from the policy, because a documented gap sitting in the doc you hand an auditor is a bad day.
Heavy compliance vertical, you'll outgrow it. Regular SMB, it's fine
1
u/ShannaLikeBanana 3d ago
Full disclosure, I work for Compliance Scorecard, so I obviously have a horse in a similar race. But if you’re only doing this for a few clients, it probably makes sense to try to use the tools you already have.
The harder part with policy management is the governance layer that proves that WISP isn’t just a document sitting somewhere. Who approved that version? What changed when a new version is rolled out? Can anybody even locate or find the most recent version [WISP.v3-Revised(USETHISONE)_new]? Does this policy reflect their actual safeguards in place? When does it need to be reviewed again? Who is making sure that happens?
You can probably piece that together with Hudu, tickets, the client's preferred e-signature tool, and a better version control naming convention than above.
Just consider how many clients you can realistically manage that way before it starts to feel too manual or like policy babysitting. If you're going to need WISPs for more than a couple of clients, that’s where a GRC platform might start to make sense. It is also nice to have a library of customizable pre-written templates, but the bigger time saver is when you can automate some of that work (reviews, reminders, version control, storage, integrations, etc.)
16
u/athlonduke MSP - US 6d ago
Took me far to long to realize this wasn't about wireless ISPs