A DubLow Digital brandIT · Cybersecurity · Digital Marketing · Eagle County, CO

GLBA & FTC Safeguards Rule Compliance for Vail Valley Firms

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customer information, and for most non-bank financial businesses the FTC Safeguards Rule (16 CFR Part 314) spells out how. It requires a written information security program, a qualified individual to run it, a risk assessment, MFA, encryption, monitoring or testing, staff training and an incident response plan. Vail Valley IT implements those controls and the documentation for Eagle County firms.

Reviewed by Todd Whitelow · Updated October 2026 · General information, not legal advice

Regulatory update

The FTC’s amended Safeguards Rule took full effect in June 2023. Since May 2024, covered businesses must also notify the FTC within 30 days of discovering a security event involving the unencrypted information of at least 500 consumers.

Who GLBA / FTC Safeguards applies to

  • Tax preparers and accounting firms that prepare returns
  • Mortgage brokers, lenders and loan servicers
  • Many financial advisors and investment-related businesses not regulated by a bank regulator
  • Collection agencies, check cashers and certain auto dealers
  • Other businesses “significantly engaged” in financial activities

What GLBA / FTC Safeguards means for a small business

The Safeguards Rule is unusually specific for a federal rule, which is helpful: it tells you what an examiner expects to find. Tax preparers are a notable group, since the IRS also requires them to maintain a written information security plan.

Firms that maintain customer information on fewer than 5,000 consumers are exempt from a few requirements, including the written risk assessment, continuous monitoring or annual penetration testing and vulnerability assessments, the written incident response plan and the annual report to the board. The core program, MFA, encryption and training still apply. Bank-regulated institutions follow parallel interagency guidelines instead.

GLBA / FTC Safeguards requirements and how we meet them

RequirementHow Vail Valley IT handles it
Qualified Individual to oversee the program§314.4(a)We can serve as or support your designated Qualified Individual, with you retaining responsibility.
Written risk assessment§314.4(b)Documented assessment of risks to customer information and how each is addressed. Cybersecurity Risk Assessment
Access controls, encryption and MFA§314.4(c)Least-privilege access, encryption in transit and at rest, and MFA for anyone accessing customer information. Compliance & Cybersecurity
Continuous monitoring, or annual pen testing plus vulnerability assessments every six months§314.4(d)(2)Managed monitoring, or scheduled penetration tests and semiannual vulnerability scans with reports. Penetration Testing & Vulnerability Scanning
Security awareness training§314.4(e)Recurring training and phishing simulations with completion records. Security Awareness Training
Service provider oversight§314.4(f)Vendor inventory, security expectations and periodic review.
Written incident response plan§314.4(h)Plan covering roles, containment, notification (including the FTC 30-day rule) and lessons learned. Virus & Malware Removal
Annual report to the board or owner§314.4(i)Plain-language annual report on the program, risks and recommendations.

Common GLBA / FTC Safeguards gaps we find in valley businesses

  • No written information security program, or a template nobody follows
  • MFA on email but not on tax, CRM or document portals
  • Client documents shared through personal email or unencrypted links
  • No penetration test or vulnerability scan on record
  • No designated Qualified Individual
  • Vendors with access to client data that have never been reviewed

Evidence to keep on file

  • Written information security program (WISP)
  • Risk assessment
  • MFA and encryption configuration records
  • Penetration test and vulnerability scan reports, or monitoring evidence
  • Training records
  • Vendor review records
  • Incident response plan
  • Annual report to the board or owner

How we get you there

  1. Gap assessment

    We compare your current setup to GLBA / FTC Safeguards and list what is missing.

  2. Remediation plan

    Prioritized fixes with a flat price, in plain language.

  3. Implement & train

    Controls, policies and staff training put in place.

  4. Test & document

    Scans, pen tests and an evidence file you can hand to an auditor.

Not sure where you stand?Take the free 2-minute security check.
Take the check

Frequently asked questions

Does the FTC Safeguards Rule apply to small accounting and tax firms?

Yes. Tax preparers are considered financial institutions under GLBA and must comply with the Safeguards Rule. Firms with information on fewer than 5,000 consumers are exempt from a few requirements, but must still maintain a written program, MFA, encryption and training.

Does the Safeguards Rule require penetration testing?

Unless you use continuous monitoring, the rule requires annual penetration testing and vulnerability assessments at least every six months. Firms with fewer than 5,000 consumers are exempt from this specific requirement.

What is a WISP?

A written information security program, the document that describes how your firm protects customer information. Both the FTC Safeguards Rule and the IRS expect tax and financial firms to have one, and it should match how your systems are actually configured.

This page summarizes public regulations for general information and is not legal advice. Confirm obligations with your attorney or compliance advisor.

Get GLBA / FTC Safeguards-ready without the guesswork

Start with a free cybersecurity assessment. You get written findings and a flat price to close the gaps.