Guide

GLBA Safeguards Rule: What the FTC's Amended Rule Actually Requires

The FTC's amended Safeguards Rule added specific, checkable requirements — a qualified individual, MFA, encryption, incident response, and board reporting. What each actually means for a non-bank financial institution.

Talk to a CISO

The business problem

Many businesses that count as "financial institutions" under GLBA don't think of themselves that way — mortgage brokers, dealers offering financing, non-bank lenders, financial advisors, and similar businesses are all in scope under the FTC's definition. The amended Safeguards Rule (16 CFR Part 314) turned what used to be a general "reasonable security" standard into a specific, checkable set of requirements.

Why it matters

Several of the amended rule's provisions are binary — either the requirement is in place or it isn't. A Qualified Individual is designated by name, or not. An incident response plan exists, or it doesn't. MFA covers the right access, or it doesn't. That specificity is good for clarity and bad for anyone who assumed a general sense of "reasonable security" was still sufficient.

“314.4(d)(2) doesn't ask whether you think your monitoring is adequate. It asks whether you have continuous monitoring in place, or, if not, annual penetration testing and semiannual vulnerability scans. There's no reasonable-judgment answer to that question.”

Signs the organization should pay attention now

  • No individual has been named, in writing, as the institution's Qualified Individual
  • Multi-factor authentication isn't specifically enforced across systems that touch customer information
  • The institution doesn't have continuous monitoring, and also hasn't scheduled annual penetration testing plus semiannual vulnerability scans — the rule's explicit alternative
  • No incident response plan exists, or one exists but has never been tested
  • The board, or an equivalent governing body, has never received a written report on the information security program's status

What good looks like

A designated Qualified Individual reports at least annually to the board — or, for institutions eligible under the rule's small-business exception, to senior management — on the program's status. The specific technical controls (MFA, encryption, a documented monitoring or testing cadence, vendor oversight) are all in place and demonstrable, not assumed.

Score your program against 16 CFR Part 314 in about 7 minutes.

Take the GLBA Safeguards Assessment

Practical guidance

Name the Qualified Individual formally in writing if that hasn't happened yet. Confirm the rule's two testing and monitoring paths and deliberately pick one, rather than defaulting into neither. And put the annual board reporting cadence on a calendar, rather than leaving it to happen only when there's something notable to report.

My CISO Partner's perspective

We see the Safeguards Rule's specificity as an advantage for leadership, not a burden — it replaces a vague standard with a checklist that can actually be verified, closed out, and reported on with confidence.

Where to go from here

If no one can name, in writing, who your Qualified Individual is or when the board last received a written security report, that's the gap an FTC inquiry would find first.

FAQ

Questions, answered directly.

Likely yes. The FTC's definition of "financial institution" under GLBA is broad and reaches many non-bank businesses that extend credit or handle consumer financial information.

The rule doesn't require a specific title, and the Qualified Individual can be a service provider rather than a full-time employee — but the institution remains accountable for the program either way.

Continuous monitoring, or — if that isn't in place — annual penetration testing plus semiannual vulnerability assessments.

Yes. Several of the amended rule's requirements, including the written risk assessment, incident response plan, and annual board reporting, include an exception for institutions that maintain customer information on fewer than 5,000 consumers.

Talk to a CISO about your Safeguards Rule program.

30 minutes. No obligation. No sales pitch.

Talk to a CISO