ALTA Best Practices Pillar 3: Information Security, Handled
The American Land Title Association’s Best Practices — version 4.2, effective August 19, 2025 — organize a well-run title and settlement operation into seven pillars. One of them lands squarely on your technology. Pillar 3, Information Security, calls for a written information security program (WISP) and privacy program protecting non-public personal information (NPI), multi-factor authentication, and secured networks, cloud services, and datacenters.
We build and run that pillar for title agents, escrow officers, and settlement companies — from drafting the WISP to hosting escrow platforms in production in our own private cloud.
What Pillar 3 asks for — and what we put in place
Six pillars live mostly in your policies and procedures. Pillar 3 lives in your infrastructure, requirement by requirement:
| Pillar 3 requirement | How CRC Cloud delivers it |
|---|---|
| A WISP and privacy program protecting NPI | WISP development support: we help draft the written plan around your actual operation, then implement and document the safeguards it promises — so the program matches reality |
| Multi-factor authentication | MFA rolled out and enforced across mailboxes, VPN, workstations, and the escrow platforms your team signs into |
| Network security | Managed firewall, network segmentation, endpoint detection and response (EDR), and scheduled patching on every managed device |
| Cloud and datacenter security | Private cloud hosting on infrastructure we own, in a facility held to published standards — not a reseller’s slice of someone else’s cloud |
| Background checks on personnel | A personnel control your firm runs — we supply the technology half: role-based access controls and audit trails that show who touched which file, and when |
What we do, and what we don't. ALTA Best Practices compliance is self-certified by your firm, and underwriters may ask for third-party assessment. CRC Cloud does not issue compliance certifications — we get your IT ready for the people who do. We build and run the controls, find the gaps and close them, and have the evidence organized before the assessor or underwriter arrives, so the review is a formality rather than a discovery exercise. If they flag something, we remediate it fast. Align, implement and prepare — never certify or guarantee.
Wondering how these controls fit a transaction business day to day? See the real estate & escrow playbook →
Escrow platforms run here in production — we just won’t say whose
For a settlement operation, hosting is where Pillar 3 gets real: the production system that moves your closings holds NPI for every party in every file. Escrow platforms run in our private cloud today, on hardware we own, with geo-separate replication behind them, with point-in-time backup available at published per-server rates.
Our infrastructure runs in a Southern California facility engineered to a concurrently maintainable, Tier III-standard design, whose operator holds SOC 1 and SOC 2 Type II attestations, ISO 27001 and PCI-DSS certifications and NIST 800-53 (PE) High alignment, with N+1 redundant power and cooling and a 99.9% uptime service level. And we treat discretion as a control in its own right: we never name clients, vendors, or the datacenter’s location.
- Escrow production systems on owned infrastructure, never resold capacity
- Per-file access controls and encryption in transit and at rest for NPI
- Senior engineers who understand that closing deadlines don’t move
Tour the datacenter standards →
The pillar was written for the day a wire goes sideways
Title and escrow concentrate money, identities, and deadline pressure in one inbox — exactly the mix business email compromise preys on. The numbers behind the urgency:
$3.05B
U.S. losses to business email compromise in 2025 — the scam behind diverted closing wires
FBI IC3 202526%
of small-business breaches start with an exploited vulnerability — the most common way in
Verizon DBIR 2026247
days — average time to identify and contain a breach; a hijacked thread has months to study your closings
IBM Cost of a Data Breach 2026Secure IT puts a 24/7 SOC on your mailboxes and endpoints, so a compromise is caught in its watching phase — before fake instructions go out. See how Secure IT responds → Or read how attackers now fake the boss’s voice, too: deepfake CEO fraud & BEC →
GLBA made it federal before ALTA made it best practice
Pillar 3 didn’t invent the WISP — federal law did. Under the Gramm-Leach-Bliley Act, providing real estate settlement services is a financial activity, which makes settlement and escrow providers financial institutions in the law’s eyes. The FTC’s Safeguards Rule (16 CFR Part 314) requires covered financial institutions to develop, implement, and maintain a written information security program — with a designated program lead, a written risk assessment, access controls, encryption, multi-factor authentication, monitoring, vendor oversight, and an incident response plan.
ALTA’s pillar and the federal rule rhyme on purpose. Build Pillar 3 properly and you’re simultaneously building the safeguards program GLBA expects — one set of controls, two frameworks satisfied by the same evidence.
The same Safeguards Rule reaches tax and accounting practices through IRS Publication 4557. If your operation has a tax or accounting side — or you simply want to see the kinship — read our IRS WISP requirement page, or browse every framework we cover in the compliance library.
From gap list to evidence file
How we take a title or escrow operation from “we think we’re fine” to documented Pillar 3 controls:
- Assess. A free 30-minute, NIST CSF-based assessment, mapped against Pillar 3 — you leave with a concrete gap list whether or not you hire us.
- Prepare. WISP drafting support and a prioritized roadmap: which safeguards close which gaps, in what order, at what cost.
- Implement. MFA rollout, email security, EDR, network segmentation, encrypted and immutable backup — the controls the written plan promises.
- Evidence & manage. Monitoring, quarterly reviews, and audit-ready documentation, kept current as the operation and the threats change.
One line we hold: we align, prepare, and implement — we don’t certify. Your underwriters, assessors, and attorneys keep the sign-off; we make sure the controls and the evidence are there when they look.
ALTA Best Practices, asked and answered
What does Pillar 3 of the ALTA Best Practices require?
ALTA Best Practices version 4.2, effective August 19, 2025, organizes a title and settlement operation into seven pillars. Pillar 3 is Information Security: adopt and maintain a written information security program (WISP) and privacy program protecting non-public personal information (NPI), use multi-factor authentication, secure your networks, cloud services, and datacenters, and screen the people who handle the data. In practice, Pillar 3 is the pillar your IT provider either carries or drops.
Can CRC Cloud make our agency ALTA Best Practices compliant?
No provider can honestly sell "compliance" as a product, and we don't. Your underwriters and assessors decide what sign-off looks like. What we do is implement and manage the Pillar 3 controls that decision rests on — the WISP and the safeguards it promises, MFA, network and cloud security, monitoring, and tested backup (published retention rates) — and keep the documentation that makes the review shorter.
What counts as NPI in a title or escrow office?
Non-public personal information is the data a transaction can't happen without: Social Security numbers, bank account and wire details, loan applications, payoff statements, and the closing file that ties them together. GLBA and ALTA Pillar 3 both exist because a title and escrow office concentrates that information for every party in the deal — buyer, seller, lender, and agent — in one place.
Does GLBA really apply to a title or settlement company?
Yes. Under the Gramm-Leach-Bliley Act, providing real estate settlement services is a financial activity, so settlement and escrow providers are financial institutions in the law's eyes. That's why the FTC Safeguards Rule's written-information-security-program requirement shows up, nearly word for word, as the heart of ALTA Pillar 3.
Can you host our escrow or title production systems?
Yes — and we already do. Escrow platforms run in production in our private cloud today, on hardware we own. Our infrastructure runs in a Southern California facility engineered to a concurrently maintainable, Tier III-standard design, whose operator holds SOC 1 and SOC 2 Type II attestations, ISO 27001 and PCI-DSS certifications and NIST 800-53 (PE) High alignment, with N+1 redundant power and cooling and a 99.9% uptime service level. We name the standards, never the clients — discretion is part of the security model.
How does Pillar 3 relate to wire-fraud prevention?
They're the same fight. Business email compromise — the scam behind nearly every diverted closing wire — succeeds when a mailbox lacks MFA, a spoofed message slips through unfiltered, or a compromised account goes unwatched. Pillar 3's controls are the countermeasures: multi-factor authentication, email filtering, and monitored detection that catches an intrusion in its quiet watching phase, before fake wire instructions go out. The FBI's IC3 put U.S. business email compromise losses at $3.05 billion in 2025.
How do we find out where we stand on Pillar 3?
Start with our free 30-minute IT assessment — it's NIST CSF-based, and we map the findings against Pillar 3 so you leave with a concrete gap list. From there, published pricing: settlement and escrow work starts on Secure IT at $250 per user per month with a 24/7 Security Operations Center — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds — and Safeguards work carries a published +10% uplift, $275 per user. Cloud Complete for hosted escrow environments is $300 per user per month on Secure IT.
Priced openly, like everything else we do. GLBA / FTC Safeguards program work — which covers escrow and settlement providers — carries a published uplift of +10% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $275 per user per month. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →