The FTC’s amended Safeguards Rule took full effect in June 2023. Since May 2024, covered businesses must also notify the FTC within 30 days of discovering a security event involving the unencrypted information of at least 500 consumers.
Who GLBA / FTC Safeguards applies to
- Tax preparers and accounting firms that prepare returns
- Mortgage brokers, lenders and loan servicers
- Many financial advisors and investment-related businesses not regulated by a bank regulator
- Collection agencies, check cashers and certain auto dealers
- Other businesses “significantly engaged” in financial activities
What GLBA / FTC Safeguards means for a small business
The Safeguards Rule is unusually specific for a federal rule, which is helpful: it tells you what an examiner expects to find. Tax preparers are a notable group, since the IRS also requires them to maintain a written information security plan.
Firms that maintain customer information on fewer than 5,000 consumers are exempt from a few requirements, including the written risk assessment, continuous monitoring or annual penetration testing and vulnerability assessments, the written incident response plan and the annual report to the board. The core program, MFA, encryption and training still apply. Bank-regulated institutions follow parallel interagency guidelines instead.
GLBA / FTC Safeguards requirements and how we meet them
| Requirement | How Vail Valley IT handles it |
|---|---|
| Qualified Individual to oversee the program§314.4(a) | We can serve as or support your designated Qualified Individual, with you retaining responsibility. |
| Written risk assessment§314.4(b) | Documented assessment of risks to customer information and how each is addressed. Cybersecurity Risk Assessment |
| Access controls, encryption and MFA§314.4(c) | Least-privilege access, encryption in transit and at rest, and MFA for anyone accessing customer information. Compliance & Cybersecurity |
| Continuous monitoring, or annual pen testing plus vulnerability assessments every six months§314.4(d)(2) | Managed monitoring, or scheduled penetration tests and semiannual vulnerability scans with reports. Penetration Testing & Vulnerability Scanning |
| Security awareness training§314.4(e) | Recurring training and phishing simulations with completion records. Security Awareness Training |
| Service provider oversight§314.4(f) | Vendor inventory, security expectations and periodic review. |
| Written incident response plan§314.4(h) | Plan covering roles, containment, notification (including the FTC 30-day rule) and lessons learned. Virus & Malware Removal |
| Annual report to the board or owner§314.4(i) | Plain-language annual report on the program, risks and recommendations. |
Common GLBA / FTC Safeguards gaps we find in valley businesses
- No written information security program, or a template nobody follows
- MFA on email but not on tax, CRM or document portals
- Client documents shared through personal email or unencrypted links
- No penetration test or vulnerability scan on record
- No designated Qualified Individual
- Vendors with access to client data that have never been reviewed
Evidence to keep on file
- Written information security program (WISP)
- Risk assessment
- MFA and encryption configuration records
- Penetration test and vulnerability scan reports, or monitoring evidence
- Training records
- Vendor review records
- Incident response plan
- Annual report to the board or owner
How we get you there
Gap assessment
We compare your current setup to GLBA / FTC Safeguards and list what is missing.
Remediation plan
Prioritized fixes with a flat price, in plain language.
Implement & train
Controls, policies and staff training put in place.
Test & document
Scans, pen tests and an evidence file you can hand to an auditor.
Frequently asked questions
Does the FTC Safeguards Rule apply to small accounting and tax firms?
Yes. Tax preparers are considered financial institutions under GLBA and must comply with the Safeguards Rule. Firms with information on fewer than 5,000 consumers are exempt from a few requirements, but must still maintain a written program, MFA, encryption and training.
Does the Safeguards Rule require penetration testing?
Unless you use continuous monitoring, the rule requires annual penetration testing and vulnerability assessments at least every six months. Firms with fewer than 5,000 consumers are exempt from this specific requirement.
What is a WISP?
A written information security program, the document that describes how your firm protects customer information. Both the FTC Safeguards Rule and the IRS expect tax and financial firms to have one, and it should match how your systems are actually configured.
brand