The FTC Safeguards Rule in plain language
Many non-bank financial businesses, including tax preparers, mortgage brokers, some lenders and certain advisory and insurance-related businesses, must maintain a written information security program under the FTC Safeguards Rule. Core requirements include a designated qualified individual to oversee the program, a written risk assessment, access controls, encryption of customer information, multi-factor authentication, monitoring, staff training, vendor oversight and an incident response plan. Covered businesses must also notify the FTC of certain security events.
Insurance agencies and broker-dealers may have additional state or industry requirements. We help you identify the technical controls that apply and put them in place. See our guides to the FTC Safeguards Rule and SEC Regulation S-P. This is general information, not legal advice.
Wire fraud and impersonation
Financial and title offices are prime targets for business email compromise. We deploy advanced email security, alerts for suspicious sign-ins and forwarding rules, and help set out-of-band verification procedures for any change to payment instructions.
One insurance agency client put it this way: “Todd has helped get our team protected at a level we had no idea existed.”
What financial & insurance businesses need from IT
- Written information security program support
- MFA on every system with customer data
- Encrypted devices and secure file sharing
- Email security and impersonation protection
- Monitoring and incident response
- Vendor and access reviews
Frequently asked questions
Does the FTC Safeguards Rule apply to my small firm?
It applies to many non-bank financial institutions, including tax preparers, mortgage brokers and certain lenders and advisors, with some reduced requirements for firms that maintain information on fewer than 5,000 consumers. Confirm applicability with your compliance advisor or attorney.
What IT controls do financial firms need?
At minimum: multi-factor authentication, encryption of customer data, access controls, monitoring and logging, tested backups, staff security training, vendor oversight and a written incident response plan.
brand