Cybersecurity Glossary

What is FTC Safeguards Rule?

The FTC Safeguards Rule is a federal regulation under the Gramm-Leach-Bliley Act that requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer financial data.

FTC Safeguards Rule explained

The FTC Safeguards Rule was significantly updated in 2023 with specific, prescriptive security requirements that replaced the previously flexible standards. The updated rule applies broadly to "financial institutions," which the FTC defines to include not just banks and lenders but also auto dealers, mortgage brokers, tax preparers, accountants, real estate appraisers, and other businesses that handle consumer financial information. Key requirements of the updated rule include designating a qualified individual to oversee the information security program, conducting periodic risk assessments, implementing access controls, encrypting customer data in transit and at rest, deploying multi-factor authentication, maintaining audit logs, developing an incident response plan, conducting penetration testing and vulnerability assessments, and providing security awareness training to employees. The FTC has enforcement authority over the Safeguards Rule and has taken action against companies that fail to comply. Penalties can include fines, consent orders, and ongoing monitoring requirements. The updated rule transformed cybersecurity from a general obligation into a set of specific, measurable requirements that covered businesses must meet.

Why It Matters

Why ftc safeguards rule matters for your business

Many SMBs are covered by the FTC Safeguards Rule without realizing it. Auto dealerships, tax preparation firms, real estate settlement companies, and many other businesses that handle consumer financial data must comply. The updated rule's specific requirements for encryption, MFA, access controls, penetration testing, and incident response represent a significant compliance burden for organizations that have not yet formalized their security practices. Non-compliance exposes businesses to FTC enforcement actions, financial penalties, and reputational damage. However, the requirements closely align with cybersecurity best practices, meaning that compliance efforts directly improve the organization's actual security posture and resilience against cyberattacks.

How Cyber Defense Agent Helps

FTC Safeguards Rule and Cyber Defense Agent

Cyber Defense Agent assesses your compliance posture against FTC Safeguards Rule requirements, including email security, encryption, access controls, and vulnerability management. The platform identifies specific gaps and provides remediation guidance that helps you meet the rule's prescriptive requirements while simultaneously strengthening your overall security program.

Get your Cyber Defense Score™ in 60 seconds.

100 tools. No installation. No credit card.

Get My Cyber Defense Score™ →