Managed IT and Managed Security · Leesburg, VA

FTC Safeguards Rule

The FTC Safeguards Rule, With the Technical Parts Run for You.

The Safeguards Rule asks firms that handle consumer financial information for a written information security program and the controls behind it. We run the controls, and our Compliance Division delivers the formal compliance work.

For CPA firms, tax preparers, mortgage brokers, investment advisers and other businesses the rule treats as financial institutions.

Who Does the FTC Safeguards Rule Apply To?

The rule is 16 CFR Part 314, issued under the Gramm-Leach-Bliley Act. It applies to the financial institutions under the FTC's jurisdiction (16 CFR 314.1(b)), and the definition reaches well beyond banks.

The rule's own examples include an accountant or other tax preparation service that completes income tax returns, a mortgage broker, an investment advisory company, a credit counseling service, a real estate settlement services provider and a check cashing business (16 CFR 314.2(h)(2)). If you prepare returns or handle client financial data, assume it applies and confirm with your own counsel.

What Must the Information Security Program Include?

A comprehensive information security program, written in one or more readily accessible parts, with administrative, technical and physical safeguards suited to your size and the sensitivity of the data (16 CFR 314.3(a)). It is commonly called a WISP.

The elements are in 16 CFR 314.4: a designated Qualified Individual, a written risk assessment, safeguards including access controls, encryption, multi-factor authentication, secure disposal, change management and activity logging, regular testing or monitoring, staff training, oversight of service providers, a written incident response plan, an annual written report to the board or a senior officer, and notice to the FTC after certain breaches.

Do Smaller Firms Get Any Exceptions?

Yes. A financial institution that maintains customer information on fewer than five thousand consumers is exempt from four elements: the written risk assessment, the continuous monitoring or penetration testing requirement, the written incident response plan and the annual report (16 CFR 314.6). Every other element still applies, including the written program, multi-factor authentication, encryption and training.

When Must We Notify the FTC?

When unencrypted customer information on at least 500 consumers is acquired without authorization, the firm must notify the FTC as soon as possible and no later than 30 days after discovery, using the FTC's online form (16 CFR 314.4(j)). This requirement has been effective since May 13, 2024 (16 CFR 314.5). Information counts as unencrypted if the encryption key was also accessed.

Which Parts Do We Run as Your IT and Security Provider?

The technical safeguards in 16 CFR 314.4(c): access controls, encryption of customer information in transit over external networks and at rest, multi-factor authentication for anyone accessing any information system, change management, and monitoring and logging of user activity. We also deliver the testing in 314.4(d): continuous monitoring, or annual penetration testing with vulnerability assessments at least every six months, and the staff security awareness training in 314.4(e).

The written program, the risk assessment and how the Qualified Individual role is filled are formal compliance work, delivered by our Compliance Division, Capital Cyber Compliance.

What Is Included

6 PARTS

Multi-Factor Authentication

On every account that reaches an information system, as 314.4(c)(5) asks.

Encryption

Customer information encrypted at rest and in transit over external networks.

Monitoring and Logging

User activity logged and watched for unauthorized access or tampering, around the clock.

Testing

Vulnerability assessments and penetration testing on the schedule the rule sets, with a retest.

Security Awareness Training

Training for every staff member, updated as risks change, with phishing simulations.

Change Management and Backups

Changes planned and recorded, and tested backups behind the systems that hold client data.

Frequently Asked Questions

5 QUESTIONS
Does the FTC Safeguards Rule apply to CPA firms?

The rule lists an accountant or other tax preparation service that completes income tax returns as an example of a financial institution (16 CFR 314.2(h)(2)(viii)). If your firm prepares returns, assume it applies and confirm with your own counsel.

Does the Safeguards Rule require multi-factor authentication?

Yes, for any individual accessing any information system, unless your Qualified Individual approves in writing reasonably equivalent or more secure access controls (16 CFR 314.4(c)(5)).

Does the Safeguards Rule require penetration testing?

Without effective continuous monitoring, the rule requires annual penetration testing and vulnerability assessments at least every six months (16 CFR 314.4(d)(2)). Firms with customer information on fewer than five thousand consumers are exempt from this element (16 CFR 314.6).

Can a service provider be our Qualified Individual?

The rule allows the Qualified Individual to be employed by you, an affiliate or a service provider. If it is a service provider, you keep responsibility for compliance, designate a senior person to oversee them, and require them to maintain a program that protects you (16 CFR 314.4(a)).

Is this page legal advice?

No. It explains the rule's text. Whether and how the rule applies to your firm is a question for your counsel; the formal compliance work is delivered by our Compliance Division, Capital Cyber Compliance.

Related Services and Industries

MFA and Endpoint Protection (EDR)

Multi-factor authentication, endpoint detection and response, and application control on every device.

Microsoft 365 and Email Security

Microsoft 365 set up, secured and run, with email protection against phishing and spoofing.

Vulnerability Assessment and Penetration Testing

Find the weaknesses before an attacker does, then retest every fix.

Security Awareness Training

Training and phishing simulations that turn staff into a line of defense.

For Accounting and CPA Firms

Managed IT and security for CPA firms, with the WISP and FTC Safeguards Rule in view.

Talk Through Your Firm's Safeguards.

Pick a time. Tell us how many people handle client financial data and where it lives.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call