cybersecurity framework and compliance_Goliath Cyber Security Group

If your business touches consumer financial data as a lender, broker, tax preparer, credit counselor, collection agency, or dozens of other “financial institution” types under the Gramm-Leach-Bliley Act, you’re already living under the FTC’s Safeguards Rule.

At Goliath, we work with businesses every day that assumed they were “too small” or “not really a bank” to be covered. The Safeguards Rule casts a wider net than most people expect.

Who Actually Falls Under This Rule

The GLBA definition of “financial institution” has nothing to do with whether you have a bank charter. It covers any business “significantly engaged” in activities that are financial in nature. The FTC’s own guidance lists mortgage brokers, payday lenders, finance companies, check cashers, wire transferors, collection agencies, tax preparation firms, investment advisors not registered with the SEC, and even “finders” companies that just introduce buyers and sellers of financial products.

If your company receives, stores, or transmits nonpublic personal financial information about consumers, assume you’re covered until proven otherwise.

What the Rule Actually Requires

The Safeguards Rule requires a written information security program built around nine specific elements. In plain terms, you need to:

Designate a Qualified Individual to own and run your security program, this can be an internal hire or an outside provider, but someone has to be formally accountable. You need a written risk assessment that identifies foreseeable threats to customer data and gets revisited as your business changes. From there, you need actual technical safeguards: access controls, encryption of customer data at rest and in transit, multi-factor authentication for anyone touching customer information, and a data disposal schedule that doesn’t let old records linger indefinitely.

You’re also required to monitor and test your defenses on an ongoing basis, continuous monitoring, or at minimum annual penetration testing plus vulnerability scans every six months. Staff need real security training, not a once-and-done slideshow. Any service providers with access to customer data need to be vetted and contractually bound to their own safeguards. And you need a written incident response plan that spells out roles, communication steps, and a post-incident review process, because “we’ll figure it out when it happens” doesn’t satisfy the Rule.

Finally, your Qualified Individual has to report to your board (or a senior officer, if you don’t have a board) at least annually on how the program is actually performing.

Why This Keeps Tripping Businesses Up

Two things make the Safeguards Rule harder than it looks. First, it’s not a checkbox exercise, the FTC expects a program that’s genuinely proportional to your size, complexity, and the sensitivity of the data you hold, and that gets updated as your operations change. A written policy that sits in a drawer isn’t compliance. Second, the penalties are real: as of the FTC’s most recent inflation adjustment, violations can run up to roughly $53,000 per violation, with each day of a continuing violation potentially counted separately. And since May 2024, a breach affecting 500 or more consumers’ unencrypted information has to be reported to the FTC within 30 days of discovery, which means your incident response plan needs to actually work under pressure, not just exist on paper.

For a lean finance, lending, or tax business without a dedicated security team, building and maintaining all nine elements, risk assessments, MFA rollout, encryption, vendor oversight, testing cadences, board reporting is a lot to carry alongside running the business itself.

How Goliath Helps

This is exactly the gap we close. Goliath works with GLBA-covered businesses to build information security programs that hold up to FTC scrutiny and to real-world threats, not just to an auditor’s checklist. That means helping you understand whether and how the Rule applies to your specific operations, building out the written risk assessments and policies the Rule requires, implementing the technical safeguards (encryption, MFA, access controls, monitoring) that actually reduce your risk, and standing up an incident response plan that’s been tested, not just written.

We also help fill the “Qualified Individual” role for businesses that don’t have the internal bandwidth for a full-time security leader, and we handle the ongoing work, ongoing risk reassessments, ongoing testing, ongoing reporting the Rule assumes will happen, not just the one-time buildout.

If you’re not sure whether your business is covered, or you know you are and aren’t confident your program would survive an FTC inquiry, that’s a conversation worth having before there’s an incident to force it.

Reach out to Goliath to talk through where you stand.

Categories:

Comments are closed