FTC Safeguards Rule — GLBA Security, Built and Run
If your firm handles customers’ financial information — and “financial institution” under GLBA means far more than banks — the FTC Safeguards Rule requires a written security program with real controls: MFA, encryption, monitoring, and a person accountable for it. We build and operate the technical backbone that program stands on.
It has been fully enforceable since June 2023, and it now carries a breach-reporting duty. The controls are cheaper than the disclosure letter.
The Safeguards Rule in plain English
The Gramm-Leach-Bliley Act (GLBA) tells “financial institutions” to protect customers’ nonpublic personal information; the FTC’s Safeguards Rule is how it’s enforced. A 2021 amendment, fully in force since June 2023, replaced vague good intentions with specific, checkable controls — the same shift toward prescription you see across every framework now.
| Required element | What it means in practice |
|---|---|
| Qualified Individual | One accountable owner for the security program — may be your staff or ours; if ours, you keep compliance responsibility and name a senior person to oversee us |
| MFA & access control | Multi-factor authentication for anyone reaching customer information; least-privilege access |
| Encryption | Customer information encrypted at rest and in transit |
| Monitoring & testing | Continuous monitoring, or annual penetration tests plus twice-yearly vulnerability scans |
| Program & response | A written information security program, incident-response plan, training, and vendor oversight |
What we do, and what we don't. The Safeguards Rule has no certificate to earn — your firm is either meeting it or it is not. CRC Cloud does not issue compliance certifications — we get your IT ready for the people who do. We build and run the controls, find the gaps and close them, and have the evidence organized before the regulator or examiner arrives, so the review is a formality rather than a discovery exercise. If they flag something, we remediate it fast. Align, implement and prepare — never certify or guarantee.
The Qualified Individual can be your person or ours — the rule allows either. What never moves is your firm's responsibility for compliance, and the senior person you name to direct and oversee the role. Our job is to make sure what the program describes is actually running — and can be proven.
The Safeguards controls we implement and operate
The technical program the rule requires is the security operation we run every day:
MFA & Access Control
Multi-factor authentication on every system that holds customer financial information, with least-privilege access — the rule’s most explicit and most tested requirement.
Encryption
Customer information encrypted at rest and in transit, including email — or documented, approved alternatives where a legacy system genuinely can’t.
Monitoring & SIEM
Continuous monitoring with SIEM log correlation — the path most firms choose over the alternative of scheduled penetration tests, and the one that catches trouble early.
Risk Assessment & Scanning
A written risk assessment kept current, internal vulnerability scanning with remediation, and coordinated penetration testing (independent firm, published rate) where you take the test-based route.
Incident Response
A written, tested incident-response plan built for the rule’s breach-notification duty — so a reportable event meets a rehearsed process, not improvisation.
Training & Vendor Oversight
Recurring staff security-awareness training (Secure IT) with records, plus support for the service-provider oversight the program requires you to document.
Where Safeguards readiness lives in our plans
MFA, encryption, SIEM monitoring, vulnerability scanning, and incident response are the substance of Secure IT, on Core IT’s foundation. It’s a natural fit for the firms we already serve — accounting and CPA, real estate and escrow, and third-party administrators. Already have internal IT? Co-Managed IT adds the depth. See every published rate →
Auditing yourself first? Our printable FTC Safeguards checklist maps the nine required elements one-for-one — free, no form wall.
Safeguards is one lane of a wider practice. See how we approach the closely related IRS WISP, plus SOC 2 and the rest on our compliance hub →
The Safeguards Rule, asked and answered
Does the FTC Safeguards Rule apply to my business?
It depends on whether you are a “financial institution” under the FTC’s GLBA jurisdiction — not simply on whether you hold financial data. That definition is far broader than banks: it reaches tax preparers, accountants and CPAs, mortgage brokers and lenders, auto dealers, real estate settlement and escrow agents, investment advisers, and collection agencies. If you receive, maintain, or transmit nonpublic personal financial information about consumers, the Safeguards Rule is your obligation.
What are the headline requirements?
Nine elements, but a few carry real teeth. A designated Qualified Individual to run the program. A written risk assessment. Multi-factor authentication for anyone reaching systems that hold customer information, and encryption of that information at rest and in transit. Continuous monitoring, or regular penetration testing plus vulnerability scans. Oversight of your service providers, a written incident-response plan, and staff training — all documented in a written information security program.
Who is the “Qualified Individual,” and can you be it?
The Qualified Individual is the single person accountable for overseeing, implementing and enforcing your security program. The rule is more flexible here than most firms realise: 16 CFR 314.4(a) says that person may be employed by you, by an affiliate, or by a service provider — so yes, the role can sit with us. What the rule does not allow is treating that as a transfer of responsibility. If you use an outside Qualified Individual, three things still bind you: you retain responsibility for compliance with the rule; you must designate a senior member of your own personnel to direct and oversee that individual; and you must require the provider to maintain a security program that protects you to the standard the rule sets.
We are happy to hold the role on those terms, and equally happy to be the security team behind your own designee. Either way one of your senior people stays accountable, and no provider can honestly tell you otherwise.
How is this different from the IRS WISP we already have?
They’re two names for closely related obligations. The IRS requires tax preparers to maintain a Written Information Security Plan — and that WISP requirement is grounded in the same GLBA Safeguards Rule the FTC enforces. If you’re a tax or accounting firm, satisfying the FTC Safeguards Rule and maintaining your WISP are largely the same project, done once, properly.
Which Safeguards controls does CRC Cloud implement and operate?
The technical backbone of the program: MFA on every system with customer information, encryption at rest and in transit, access controls with a current inventory of where data lives, continuous monitoring with SIEM (Secure IT), internal vulnerability scanning with coordinated penetration testing (independent firm, published rate), and a written, tested incident-response plan. We also support the service-provider oversight and staff-training elements, and keep the written program current as your environment changes.
What happens if we ignore it?
Enforcement is no longer theoretical. The amended rule has been fully in effect since June 2023, and it now includes a breach-notification obligation: security events affecting 500 or more consumers must be reported to the FTC. Beyond fines, the practical exposure is a breach you have to disclose while explaining why the required controls weren’t running. The controls are cheaper than the letter.
Do you provide the written program itself, or just the tech?
Both, on the IT side. We implement and operate the technical safeguards and produce the documentation your written information security program depends on — the risk assessment inputs, the monitoring and access evidence, the incident-response plan. Whoever holds the Qualified Individual role — your person or ours — the program has to be signed by someone who can stand behind it, and our job is to make sure what it describes is actually true.
Priced openly, like everything else we do. FTC Safeguards (GLBA) work carries a published uplift of +10% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $275 per user per month — covering the written program, annual review and Qualified Individual support. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →