Skip to content
compliancecybersecurityfinancial

The FTC Safeguards Rule Probably Applies to You

Accountants, tax preparers, financial advisors, and auto dealers are all covered by the FTC Safeguards Rule — and most don't know it. Here's what it actually requires.

By MSP Asheville ·

Most of the businesses covered by the FTC Safeguards Rule have never heard of it. That’s the problem.

The rule sits under the Gramm-Leach-Bliley Act, and it applies to “financial institutions” — a term the FTC defines far more broadly than most people expect. It covers tax preparers, accountants, financial advisors, mortgage brokers, auto dealers arranging financing, collection agencies, and a long tail of businesses that would never describe themselves as a bank.

If your business handles customer financial information, assume it applies until someone qualified tells you otherwise.

What it actually requires

The rule asks for a written information security program with nine specific elements. In practice, that means:

Designate a qualified individual. Someone has to own this. It can be an employee or a service provider, but a name has to go in the document.

Conduct a written risk assessment. Not a mental exercise — a document that identifies foreseeable risks to customer information and evaluates how well your current safeguards address them. It has to be periodically reassessed.

Implement access controls. Multi-factor authentication is explicitly required for anyone accessing customer information. So is the principle of least privilege: people get access to what their job requires, and nothing more.

Encrypt customer information. Both at rest and in transit. If encryption is genuinely infeasible for something, the qualified individual has to approve a documented alternative.

Inventory your data. You cannot protect information you have not located. This means knowing where customer data lives — including the spreadsheet on someone’s desktop and the old server nobody has logged into since 2021.

Test your safeguards. Either continuous monitoring, or annual penetration testing plus twice-yearly vulnerability assessments.

Train your staff. Security awareness training, and specific training for anyone with security responsibilities.

Oversee your service providers. You have to select providers capable of maintaining appropriate safeguards, and require those safeguards by contract.

Have a written incident response plan. Before you need it, not during.

The part that catches people

Two things trip up most firms.

The first is scope. Firms assume the rule covers their client portal and stop there. It covers customer information wherever it lives — email attachments, local file shares, backup archives, the laptop a partner takes home.

The second is documentation. Many firms have decent technical controls and no written program at all. From an enforcement perspective, undocumented security is very close to no security: you cannot demonstrate what you cannot produce.

Where to start

Find your data first. Run the risk assessment second. Everything else follows from those two, and doing them in the other order produces a program that protects things you don’t have and misses things you do.

If you want help with that, our compliance practice runs exactly this assessment, and our free assessment will tell you where you currently stand at no cost.

This is general information about a regulation, not legal advice. Whether and how the Safeguards Rule applies to your specific business is a question for your counsel.

← All resources

Not sure where your gaps are?

Book a free, no-obligation assessment. We look at your network, security posture, and backups, then tell you plainly what we found — whether or not you hire us.