GLBA Safeguards Rule: What Financial Institutions Must Do Now

Compliance — GLBA Safeguards Rule

GLBA Safeguards Rule: What Financial Institutions Must Do Now

The FTC’s updated Safeguards Rule under the Gramm-Leach-Bliley Act took full effect in June 2023, imposing specific, prescriptive technical controls on non-bank financial institutions that many organizations are still not meeting. If your company is subject to the Safeguards Rule and has not verified each of the nine required program elements, your compliance posture has a gap. Armorstack’s VERITY advisory and SENTRY security operations teams help regulated financial institutions build, document, and continuously operate a program the FTC would expect to see.

Who’s Covered

Who the Safeguards Rule Covers

The GLBA Safeguards Rule applies to financial institutions subject to FTC jurisdiction — a category broader than most organizations recognize. Mortgage brokers, auto dealers that arrange financing, payday lenders, tax preparers, accounting firms, investment advisors not registered with the SEC, and any company that is “significantly engaged” in financial activities all fall under the rule. Banks and credit unions are covered by their respective prudential regulators, not the FTC — but the practical standards are substantively similar.

The 2023 amendments specifically targeted non-bank financial institutions that had been operating under looser standards. If you process loan applications, manage customer financial accounts, provide financial advice, or facilitate payment transactions, the threshold for coverage is almost certainly met. The question is whether your program is built to the updated standard.

The Requirements

The Nine Required Program Elements

The updated Safeguards Rule replaces the previous principles-based language with nine specific program elements that must be present in a compliant written information security program. Each has operational implications that go well beyond a policy document.

  1. 1Designate a Qualified Individual. A specific person — an employee or a service provider — must be designated to oversee and implement the information security program. This individual must report to your board of directors or equivalent governing body at least annually. The FTC refers to this person as a “Qualified Individual.” See GLBA Qualified Individual requirements for a detailed breakdown of this obligation and what it means when the role is fulfilled by an outside provider.
  2. 2Conduct a Risk Assessment. The program must be based on a written risk assessment that identifies foreseeable internal and external risks to the security, confidentiality, and integrity of customer information. The assessment must evaluate the sufficiency of existing safeguards. Risk assessments are not annual checkboxes — they must be updated whenever material changes to the business or threat environment occur.
  3. 3Implement Safeguards Based on the Risk Assessment. The program must implement and test safeguards to control the identified risks. The rule specifies eight technical and operational controls that must be addressed: access controls, data inventory, encryption, secure development practices, authentication, data disposal, change management, and monitoring.
  4. 4Regularly Test and Monitor Safeguards. Continuous monitoring or periodic penetration testing and vulnerability assessments are required. Organizations with 5,000 or more customer records must conduct annual penetration testing and semi-annual vulnerability assessments. Organizations below that threshold must conduct periodic testing appropriate to the risk environment.
  5. 5Train and Manage Staff. Security awareness training must be delivered to all personnel with access to customer information. Training must be updated to reflect current threats — a 2019 phishing module does not satisfy this requirement in 2026.
  6. 6Oversee Service Providers. Service providers with access to customer information must be selected and monitored based on their ability to maintain appropriate safeguards. Contracts must require service providers to implement and maintain such safeguards. This applies to cloud providers, payment processors, IT vendors, and any other third party handling customer financial data.
  7. 7Keep the Program Current. The information security program must be evaluated and adjusted in response to changes in operations, business arrangements, threat landscape, and results of testing and monitoring. A program that was compliant at implementation can become non-compliant if the environment changes and the program does not.
  8. 8Establish an Incident Response Plan. A written incident response plan is required. The plan must address the goals of the program, internal processes for responding to a security event, clear roles and responsibilities, external communications protocols, and a process for remediation and post-incident review. Notification to the FTC is required for security events affecting 500 or more customers within 30 days of discovery.
  9. 9Require Board-Level Reporting. The Qualified Individual must report in writing to the board of directors or equivalent governing body at least annually. The report must cover the overall status of the information security program and material matters relating to the program, including risk assessment results, risk management and control decisions, service provider arrangements, test results, and any security events.
Named Controls

The Controls the FTC Now Requires by Name

Unlike the original Safeguards Rule, the 2023 amendments name specific technical controls rather than leaving implementation to organizational discretion. Financial institutions must implement multi-factor authentication for any individual accessing any information system with customer information — unless compensating controls are documented and approved by the Qualified Individual. Encryption of customer information is required both in transit and at rest. Access controls must limit access to customer information to individuals who need it to perform their job functions. These are not suggestions — they are enumerated elements of a legally required program.

Armorstack’s SENTRY portfolio delivers the continuous monitoring, endpoint protection, and SIEM coverage that supports the testing and monitoring requirements. CORE managed IT services handles the encryption configuration, access control implementation, and patch management that the technical controls demand. VERITY advisory builds and governs the written program, conducts the risk assessment, and prepares the annual board report. Learn more about the GLBA WISP requirements and how the written program is structured.

Enforcement

What Happens When the FTC Investigates

FTC enforcement under GLBA is not limited to formal regulatory actions. In practice, a breach that triggers customer notification obligations almost always triggers FTC scrutiny of the underlying security program. If the program is found to be deficient — if risk assessments are missing, if MFA was not implemented, if service providers lacked contractual safeguard requirements — the FTC has authority to impose civil penalties and require remediation under consent orders that can last decades.

The standard for a defensible program is not perfection. It is documented, reasonable, tested, and appropriate to the size and complexity of the institution. What the FTC finds indefensible is an absence of program elements that the rule explicitly requires. Return to the GLBA compliance overview for the full framework context, or explore all compliance frameworks Armorstack supports.

Engagement Model

How Armorstack Builds Your Safeguards Program

Armorstack’s engagement for GLBA Safeguards Rule compliance follows a structured sequence: baseline assessment against all nine program elements, gap identification with a prioritized remediation roadmap, program build-out across written policies and operational controls, Qualified Individual designation or fulfillment, technical control implementation through CORE and SENTRY, and ongoing board reporting through VERITY. The 90-Day Proof engagement is designed to demonstrate measurable compliance progress within a bounded, no-contract window. Armorstack’s managed detection and response supports the continuous monitoring the FTC now requires. Start the 90-Day Proof →

Common Questions

Frequently Asked Questions

Who must comply with the FTC Safeguards Rule under GLBA?

Non-bank financial institutions subject to FTC jurisdiction must comply. This includes mortgage brokers, auto dealers that arrange financing, payday lenders, tax preparers, accounting firms, investment advisors not registered with the SEC, and any company significantly engaged in financial activities. Banks and credit unions are regulated by their prudential regulators under substantially similar standards.

Does the updated Safeguards Rule require multi-factor authentication?

Yes. The 2023 FTC Safeguards Rule amendments require multi-factor authentication for any individual accessing any information system containing customer information, unless the Qualified Individual approves and documents compensating controls in writing. MFA is now an enumerated requirement, not a recommended best practice.

When must a security event be reported to the FTC under the Safeguards Rule?

Financial institutions must notify the FTC within 30 days of discovering a security event that has resulted in, or is reasonably likely to result in, the unauthorized acquisition of unencrypted customer information affecting 500 or more customers.

What is the difference between the original GLBA Safeguards Rule and the 2023 amendments?

The original rule was principles-based, requiring a reasonable information security program without specifying controls. The 2023 amendments are prescriptive: they enumerate nine required program elements, name specific technical controls including MFA and encryption, require a designated Qualified Individual who reports to the board annually, and impose a 30-day FTC notification deadline for qualifying security events affecting 500 or more customers.

Ready to Close the Safeguards Rule Gap?

Armorstack’s VERITY advisory and SENTRY security operations teams help regulated financial institutions verify all nine required program elements and build a program the FTC would expect to see — not just a documentation exercise. Talk to an Expert →

877-890-5508 · [email protected]