You May Be Under the FTC Safeguards Rule Without Knowing It

Most business owners who fall under the FTC Safeguards Rule do not think of themselves as financial institutions. That is the whole problem with it.

The rule applies to businesses "significantly engaged" in providing financial products or services to consumers, and the Federal Trade Commission reads that more broadly than the phrase suggests. Tax preparers and accounting firms. Auto dealers arranging financing. Mortgage brokers and lenders. Collection agencies. Real estate appraisers. Businesses that offer their own payment plans. Career counselors serving people in finance. Wire transfer services.

If your business touches consumers' financial information as part of what it does, the rule is worth reading rather than assuming it is about someone else.

What it actually requires

The core obligation is a written information security program appropriate to your size and complexity. Not a policy binder bought off the shelf, and not an assurance that your IT provider handles security. A written program, tied to your actual systems and actual data.

Within it, the rule is specific about several things:

  • A named person responsible for it. One qualified individual who owns the program. This can be someone internal or a service provider, but the accountability has to sit somewhere identifiable.
  • A written risk assessment. What consumer information you hold, where it lives, what could go wrong with it, and what you are doing about each risk. Written down, and revisited.
  • Access controls. Who can reach customer information, reviewed periodically rather than accumulated over years of staff changes.
  • An inventory of data and systems. You cannot protect what nobody has listed.
  • Encryption of customer information in transit and at rest, or a documented and approved alternative.
  • Multi-factor authentication for anyone accessing customer information.
  • Secure disposal of customer information, generally within two years of the last use unless there is a business or legal reason to keep it.
  • Change management, so security is considered when systems change.
  • Monitoring and testing. Either continuous monitoring, or annual penetration testing plus twice-yearly vulnerability assessments.
  • Staff training, and oversight of the service providers who handle your data.
  • A written incident response plan.
  • A report to your board or governing body at least annually from the person who owns the program.

There is also a breach notification requirement: certain security events affecting consumer information have to be reported to the FTC.

Why this catches people out

Three reasons, in our experience.

The name. "Financial institution" sounds like it means a bank. A four-person CPA practice does not read that phrase and think of itself.

The written part. Plenty of businesses genuinely have decent security, including MFA, managed endpoints and backups, and no document that says so. The rule requires the program, not just the controls. Doing the right things without documenting them does not satisfy it.

The assumption that IT covers it. We handle a great deal of what the rule asks about technically. But the risk assessment reflects your business processes, the disposal schedule reflects your retention decisions, and the annual report goes to your governing body. A provider cannot own those, and any provider who tells you they can has not read it carefully.

What we do and what stays with you

We want to be direct about this line, because it is where a lot of businesses end up with a false sense of coverage.

We implement and operate technical controls: multi-factor authentication, encryption, access control, logging and monitoring, patching, secure configuration, backup and recovery. We can produce evidence that those controls exist and are working, which is usually the hardest part of an assessment to assemble.

The compliance obligation itself stays with you. The written program is your document. The qualified individual is your appointment. The decision about what is an acceptable risk is a business decision rather than a technical one. We support that work and we do not pretend to absorb it.

A sensible starting point

If you think the rule might apply and you have nothing written:

  • Establish whether it applies, with your attorney or accountant rather than by reading a blog post, including this one.
  • Inventory the consumer financial information you hold and where it lives. Include the places it lives unofficially: inboxes, shared drives, someone's laptop.
  • Name the person who owns the program.
  • Write the risk assessment, even a short first version. A modest document that reflects your real business beats a thorough one that does not.
  • Fix the gaps that are cheap to fix, and record the ones that are not with a date against them.

Where we come in

If you want the technical side assessed against what the rule asks for, meaning what is in place, what is missing, and what the evidence looks like, book a discovery call.

We are not attorneys and this is not legal advice. Whether the Safeguards Rule applies to your business is a question for your counsel. What we can tell you is whether your systems would stand up if the answer is yes.

RELATED ARTICLE

May Be You Like