The FTC Safeguards Rule is where GLBA stops being abstract. While GLBA establishes the obligation to protect nonpublic personal information (NPI), the Safeguards Rule defines how regulators expect you to do it - especially from a cybersecurity and IT operations standpoint.
The amended rule significantly raised the bar. Cybersecurity controls, documentation, and accountability are now explicit requirements, not implied expectations.
The FTC Safeguards Rule is a federal regulation issued under the Gramm-Leach-Bliley Act that requires covered financial institutions to develop, implement, and maintain a comprehensive written information security program to protect customer information. Its formal name is the Standards for Safeguarding Customer Information, codified at 16 CFR Part 314.
Unlike many regulations, the Safeguards Rule is explicit and prescriptive. It names the controls, the roles, the testing cadence, and the reporting duties - and it expects evidence for each.
The rule is administered and enforced by the Federal Trade Commission.
The Safeguards Rule applies to financial institutions regulated by the FTC - which includes many organizations that do not consider themselves "financial companies."
Covered entities include:
A scoping fact most overviews miss: institutions maintaining customer information on fewer than 5,000 consumers are exempt from several written-program requirements - the written risk assessment (§314.4(b)(1)), the penetration-testing and vulnerability-assessment cadence (§314.4(d)(2)), the written incident response plan (§314.4(h)), and the annual written report to the board (16 CFR 314.6). The core safeguards still apply - the exemption trims documentation, not security.
If your organization handles customer financial information to provide a financial product or service, the Safeguards Rule likely applies.
The Safeguards Rule protects customer information - any record containing nonpublic personal information about a customer, in any form.
That includes:
From an IT perspective, this data typically spreads across multiple systems, cloud platforms, and third-party vendors. Every copy is in scope.
The relationship between the financial data rules is simpler than it looks.
GLBA establishes the legal requirement to protect customer information. The FTC Safeguards Rule defines the minimum security program expectations. FFIEC provides the exam guidance banking regulators use to test institutions they supervise. NIST and ISO frameworks provide the best-practice control structures underneath all three.
In short: GLBA is the "what." The FTC Safeguards Rule is the "how."
The Safeguards Rule names its requirements. Here is what each one asks of your IT environment.
Designated security leadership - the Qualified Individual. The rule requires you to "designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program" (16 CFR 314.4(a)). Note what the rule does not say: it requires a qualified individual, not a CISO by title, and imposes no specific certification requirement.
The rule also expressly permits outsourcing this role: "The Qualified Individual may be employed by you, an affiliate, or a service provider." If you use an affiliate or service provider, three conditions apply (§314.4(a)):
1. Retain responsibility: you must "retain responsibility for compliance with this part." Outsourcing the role never outsources the obligation. 2. Designate internal oversight: you must "designate a senior member of your personnel responsible for direction and oversight of the Qualified Individual." 3. Require a compliant program: you must "require the service provider or affiliate to maintain an information security program that protects you in accordance with the requirements of this part."
This is the direct regulatory basis for a fractional CISO arrangement. The rule anticipates it - provided all three conditions are met.
Formal risk assessments. You must identify reasonably foreseeable internal and external risks, assess the sufficiency of safeguards, and produce a written risk assessment that drives your security decisions (§314.4(b)). Risk assessments are no longer optional.
Explicit security controls. The rule names controls in §314.4(c): multi-factor authentication (MFA), encryption of customer information at rest and in transit, access controls, secure development and configuration practices, monitoring and logging, and secure disposal. For encryption (§314.4(c)(3)) and MFA (§314.4(c)(5)), the rule allows alternatives only with documented written approval by the Qualified Individual - a narrow exception, not an opt-out.
Continuous monitoring and testing. Absent effective continuous monitoring, the rule requires annual penetration testing and vulnerability assessments at least every six months (§314.4(d)). "We test periodically" does not meet a named cadence.
Incident response and FTC breach notification. You must maintain a written incident response plan (§314.4(h)) - and since May 2024, you must also report to the regulator: a notification event involving the information of at least 500 consumers must be reported to the FTC electronically, on the FTC's form, as soon as possible and no later than 30 days after discovery (§314.4(j)). Internal response alone no longer discharges the duty.
Vendor and service-provider oversight. Service-provider oversight is an explicit rule requirement: select providers capable of maintaining appropriate safeguards, require safeguards by contract, and periodically assess them (§314.4(f)).
Board reporting. The Qualified Individual must report in writing, at least annually, to the board of directors or equivalent governing body - or to a senior officer if no board exists - on the program's status, material risks, control effectiveness, and security incidents (§314.4(i)). Cybersecurity is explicitly an executive responsibility.
The FTC Safeguards Rule is actively enforced. Enforcement can result in regulatory investigations, consent orders, court-ordered relief, mandatory remediation programs, and long-term regulatory oversight.
Enforcement actions frequently cite the same failures:
The Safeguards Rule aligns closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, SOC 2, and GLBA and FFIEC expectations.
Organizations that follow these frameworks typically meet - or exceed - Safeguards Rule requirements. The rule's named controls are the same fundamentals every mature security program already runs.
That overlap is leverage: one well-built program, evidenced once, satisfies multiple obligations.
Here is the key takeaway: the FTC Safeguards Rule does not require exotic security. It requires accountability and proof.
Most requirements are basic cybersecurity practices any organization handling sensitive data should already have in place.
The difference is that now, regulators expect evidence. A control without documentation is a control you cannot defend.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment tests your program element by element against 16 CFR 314.4 - from the Qualified Individual designation through vendor oversight, testing cadence, and the written incident response plan.
Document where customer data is stored, how it flows between systems, who has access, and which vendors are involved. Scope drives everything that follows.
Assess threats (phishing, ransomware, insider risk), vulnerabilities (misconfigurations, outdated systems), likelihood and impact, and mitigation steps. The rule requires the assessment in writing (16 CFR 314.4(b)).
At minimum: MFA for system access, encryption of data and backups, endpoint and email security, logging and monitoring, and secure remote access. Document any written-approval alternatives - the rule permits them only that way.
Ensure policies reflect real-world controls, the incident response plan is written, roles are clear, and testing occurs on the named cadence. Build the FTC notification step (500+ consumers, 30 days, §314.4(j)) into the plan before you need it.
Confirm vendors meet security expectations, contracts include safeguard requirements, and ongoing monitoring exists. Service-provider oversight is an explicit rule requirement (§314.4(f)).
Prepare the Qualified Individual's written report to the board or equivalent - at least annually - covering program status, material risks, control effectiveness, and incidents (§314.4(i)).
If the FTC is your regulator and your business provides financial products or services - auto financing, tax preparation, mortgage brokering, debt collection, credit counseling, non-SEC investment advice, fintech - the rule applies. Many covered businesses have never thought of themselves as financial institutions. That is precisely who enforcement reaches.
Anyone qualified to oversee, implement, and enforce your security program - the rule requires no specific title or certification. It expressly permits the Qualified Individual to be employed by an affiliate or a service provider (16 CFR 314.4(a)), provided you retain responsibility for compliance, designate a senior internal person to direct and oversee them, and require the provider to maintain a program that protects you. That is the regulatory basis for a fractional CISO.
Yes, above a threshold. Since May 2024, a notification event involving the information of at least 500 consumers must be reported to the FTC electronically on its form, as soon as possible and no later than 30 days after discovery (16 CFR 314.4(j)). State breach-notification laws apply on their own clocks in parallel.
Partially. Institutions maintaining customer information on fewer than 5,000 consumers are exempt from the written risk assessment, the named testing cadence, the written incident response plan, and the annual board report (16 CFR 314.6). The substantive safeguards - MFA, encryption, access controls, vendor oversight - still apply.
The rule sets the cadence: absent effective continuous monitoring, annual penetration testing and vulnerability assessments at least every six months (16 CFR 314.4(d)). Continuous monitoring that genuinely detects changes and vulnerabilities can substitute.
Yes, for any individual accessing any information system - unless your Qualified Individual approves, in writing, a reasonably equivalent or more secure alternative (16 CFR 314.4(c)(5)). The exception is documented and narrow, not a matter of preference.
It depends on how far your current controls sit from the rule's named requirements - many businesses already run half of them and simply lack the documentation. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.
Start with the gap, not the tools. Our Cyber Risk & Compliance Gap Assessment tests your environment against each element of 16 CFR 314.4, shows you exactly what is missing, and sequences the fixes - so you build the program once, correctly.
The Safeguards Rule's FTC notification and Florida's breach law run on separate clocks - a single incident can trigger both.
The Treasure Coast is dense with exactly the businesses the FTC's definition captures - tax preparers, CPA firms, auto dealers offering financing, mortgage and title offices, and financial advisors across Martin, St. Lucie, and Palm Beach counties. Most are covered and few have been told.
Official source: Federal Trade Commission
Secondary source: eCFR, 16 CFR Part 314
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25