The Gramm-Leach-Bliley Act requires financial institutions to safeguard sensitive customer data. The June 2023 amendments to the Safeguards Rule made three fundamental changes: they formalized incident response planning requirements, introduced annual reporting obligations, and clarified board-level accountability. These are not technical updates. They represent a shift in regulatory expectation about who owns cybersecurity risk and how leadership demonstrates that ownership.

The result is a common organizational problem: executives and boards are accountable for a security outcome without always having a clear owner, a coherent sequence of work, or a method for measuring progress that satisfies both operational needs and regulatory obligations.

What the Safeguards Rule Requires

The Gramm-Leach-Bliley Act, administered by the Federal Trade Commission, requires covered financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data. The Safeguards Rule operationalizes the second obligation by requiring a written information security program.

That program must be appropriate to the size, complexity, and activities of the organization. It must be designed to protect customer information, overseen by a qualified individual, and include administrative, technical, and physical safeguards. The FTC provides resources on data security and the Gramm-Leach-Bliley Act for financial institutions at varying scales.

What Changed in June 2023

The 2023 amendments introduced requirements that shift the center of gravity from program documentation to operational readiness and executive accountability. Three provisions matter most:

  • Incident response planning that addresses detection, containment, notification, and recovery, tested and updated periodically.
  • Annual written reporting to the board or equivalent governing body on the state of the security program, including testing results, risk assessment findings, and significant incidents.
  • Designation of a qualified individual to oversee and implement the information security program, with authority and reporting lines that allow effective governance.

These are governance requirements. They assume leadership has visibility into cybersecurity posture, understands what adequate readiness looks like, and can verify that the program functions as designed. They create accountability at board level for outcomes that depend on decisions made throughout the organization.

The Structural Gap Leadership Faces

Most financial institutions operate in one of two conditions. Either they maintain internal IT staff who handle operational security alongside other responsibilities, or they engage managed service providers for infrastructure, monitoring, and remediation. Neither arrangement is inherently inadequate, but neither automatically provides the governance layer the Safeguards Rule now expects.

Internal IT teams understand the environment but may lack capacity, authority, or specialized expertise to design enterprise-wide programs, conduct board-level reporting, or translate regulatory language into risk decisions. Managed service providers deliver valuable operational capability—monitoring, patching, backup, response—but do not make governance decisions, assess business risk, or define what adequate compliance looks like for a particular institution.

The gap is not technical. It is a missing executive function: someone accountable for translating regulatory requirements into organizational decisions, defining what readiness means, establishing measurement, and reporting progress in terms the board can act on.

Who Owns What Under the Rule

The Safeguards Rule requires designation of a qualified individual to oversee the information security program. This person must have sufficient authority and resources to implement the program and must report to the board or equivalent governing body at least annually. The board, in turn, is responsible for oversight and for ensuring the program meets regulatory standards.

In practice, this means three distinct ownership responsibilities:

  • The board owns accountability for the adequacy of the program and for ensuring the qualified individual has authority and resources.
  • The qualified individual owns program design, risk assessment, testing, incident response planning, and reporting to the board.
  • Operational staff and service providers own execution of controls, monitoring, response activities, and technical implementation.

The challenge arises when an organization has capable people in the third category but no one clearly occupying the second. Without that role, boards receive operational reports but lack risk context, testing happens inconsistently or focuses on the wrong measures, and incident response plans exist on paper without integration into business continuity or communication protocols.

How Virtual CISO Leadership Closes the Gap

A [virtual CISO engagement](/vciso/) provides the governance function the Safeguards Rule requires: an executive-level owner who defines the security program, makes risk decisions, establishes testing and measurement, and reports to leadership in business terms. This is not operational delivery. It is strategy, governance, and accountability.

For GLBA compliance specifically, the virtual CISO acts as the qualified individual, designing and overseeing the information security program, conducting risk assessments, establishing incident response protocols, and preparing annual board reports. The vCISO works with existing IT staff and service providers but makes decisions about what controls are necessary, what risks are acceptable, and what constitutes adequate readiness given the institution's profile.

This separates governance from execution. Managed service providers continue operational work under clearer direction. Internal staff have executive-level support for security initiatives and defined priorities. The board receives reporting that connects security posture to business risk and regulatory position, with a single accountable owner who can answer both strategic and technical questions.

Relationship to Broader Framework Readiness

The GLBA Safeguards Rule does not prescribe specific controls or frameworks. Organizations may use the NIST Cybersecurity Framework, NIST Privacy Framework, or other structured approaches to design their programs, provided they meet the rule's requirements. The FTC expects institutions to tailor their programs to their size, complexity, and risk profile.

Regulatory and framework readiness means establishing governance that allows leadership to make informed decisions about which frameworks, controls, and standards apply, how to implement them proportionally, and how to measure whether the resulting program achieves the regulatory outcome. The GLBA amendments make this explicit: boards must receive annual reporting on program effectiveness, which requires measurement against defined standards.

Heights approaches this by working backward from regulatory requirements to operational decisions. Rather than implementing a generic framework, the vCISO identifies what the institution must demonstrate, defines what adequate evidence looks like, and builds the governance structure that produces that evidence reliably. Frameworks serve this objective rather than driving it.

What Leadership Should Do Next

If your institution is subject to the GLBA Safeguards Rule, three steps establish whether you have the governance the rule expects:

  • Identify the qualified individual responsible for overseeing your information security program. Confirm they have the authority, resources, and reporting relationship the rule requires.
  • Review your most recent board-level security reporting. Determine whether it addresses program effectiveness, testing results, risk assessment findings, and incident response readiness in terms the board can act on.
  • Examine your incident response plan. Verify it includes detection, containment, notification, and recovery procedures, has been tested within the last twelve months, and is integrated with broader business continuity and communication protocols.

If any of those elements are missing or unclear, the gap is not operational—it is a governance problem. You need executive-level ownership that can design, measure, and report on the program in a way that satisfies regulatory expectations and supports business decisions.

Heights provides that ownership through virtual CISO engagements structured around regulatory accountability. If you would benefit from a confidential discussion about your current governance, your regulatory position, and what adequate ownership looks like for your institution, contact us directly. We work with one financial services client at a time to ensure undivided attention and avoid conflicts. That conversation is offered once and remains confidential regardless of outcome.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Regulatory and Framework Readiness

Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.

Read about Regulatory and Framework Readiness