The short answer
The FTC amended the Gramm-Leach-Bliley Act Safeguards Rule in 2021 and 2023, with the most recent breach notification requirements taking effect in May 2024. Financial institutions subject to FTC jurisdiction must now maintain written information security programs meeting specific technical standards and report qualifying data breaches within 30 days. Leadership faces accountability for security outcomes without always having clear ownership or governance in place.
The Federal Trade Commission has strengthened requirements under the Gramm-Leach-Bliley Act Safeguards Rule, with the most recent amendments taking effect on May 13, 2024. Financial institutions subject to FTC jurisdiction now face both more specific technical requirements and mandatory breach notification obligations. Leadership is accountable for demonstrating reasonable security practices and timely disclosure, which requires clear governance and executive ownership.
1Who the Rule Covers
The Safeguards Rule applies to financial institutions under FTC jurisdiction that are not supervised by another banking regulator. The definition of financial institution is broader than traditional banking and includes entities engaged in activities that are financial in nature under the Bank Holding Company Act.
The Rule specifies 13 categories of covered entities: mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, investment advisors not required to register with the SEC, and finders who bring together buyers and sellers. What matters is the type of activity your organization undertakes, not how you categorize the business.
The FTC has exempted institutions that maintain customer information for fewer than 5,000 consumers from certain provisions. Organizations should review the definition periodically as operations evolve, since business activities that did not trigger coverage a decade ago may bring the company within scope today.
2What Changed in the 2021 and 2023 Amendments
The FTC amended the Safeguards Rule in 2021 to provide more concrete guidance while preserving flexibility. The revised Rule took effect on June 9, 2023, and reflects core data security principles aligned with current technology.
In October 2023, the FTC announced additional amendments requiring covered financial institutions to report certain data breaches and security incidents. The Commission gave institutions six months to prepare, and these breach notification provisions took effect on May 13, 2024.
3Breach Notification Requirements
Financial institutions must notify the FTC as soon as possible, and no later than 30 days after discovery, of a security breach involving the information of at least 500 consumers. The Rule defines a notifiable incident as an acquisition of unencrypted customer information without authorization of the individual to whom the information pertains. Customer information is considered unencrypted if the encryption key was accessed by an unauthorized person.
Unauthorized acquisition is presumed to include unauthorized access to unencrypted customer information unless the institution has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition. The FTC provides an online form explaining the specific information institutions must provide when reporting.
Compliance with the Safeguards Rule does not substitute for obligations under other state and federal breach notification laws.
4Required Elements of an Information Security Program
Covered financial institutions must develop, implement and maintain a written information security program with administrative, technical and physical safeguards designed to protect customer information. The program must be appropriate to the size and complexity of the institution, the nature and scope of activities, and the sensitivity of the information.
Customer information means any record containing nonpublic personal information about a customer, whether in paper, electronic or other form, that is handled or maintained by or on behalf of the institution or its affiliates. This includes information about the institution's own customers and information about customers of other financial institutions that has been provided to the covered entity.
The objectives of the information security program are to ensure the security and confidentiality of customer information, protect against anticipated threats or hazards to the security or integrity of that information, and protect against unauthorized access that could result in substantial harm or inconvenience to any customer.
Section 314.4 of the Rule identifies nine elements that an information security program must include. The first is designation of a qualified individual to oversee and implement the program. The remaining elements address risk assessment, safeguard design and implementation, service provider oversight, program evaluation and adjustment, incident response planning, and periodic reporting to the board of directors or equivalent governing body.
5The Governance Gap in Most Financial Institutions
The Safeguards Rule holds leadership accountable for security outcomes, yet many financial institutions lack clear executive ownership of the program. General counsel often owns regulatory interpretation and board reporting. Information technology leadership implements controls and manages vendors. Compliance tracks documentation and testing. Internal audit reviews the program periodically. No single executive may own the strategic decisions, risk judgments and cross-functional coordination the Rule envisions.
The requirement for a qualified individual to oversee the program is not satisfied by distributing responsibilities across several departments, each acting within its traditional remit. The Rule anticipates an executive who can assess business risk in security terms, make resource allocation decisions, represent the institution's security posture to regulators and the board, and direct remediation when gaps appear.
Institutions that lack this level of executive ownership may meet the letter of the Rule through documentation and technical implementation while missing the governance substance regulators examine during investigations and enforcement actions.
6What Regulators Examine
The FTC has issued guidance specifically for automobile dealers and other covered entities explaining how the Safeguards Rule applies in practice. Enforcement actions and consent orders demonstrate that regulators look for evidence of genuine governance, not merely compliance artifacts.
Examiners review whether the qualified individual has appropriate authority, whether the board receives substantive reporting on security risks and program effectiveness, whether the institution conducts meaningful risk assessments that inform safeguard selection, whether service provider agreements address security requirements, and whether the institution can demonstrate that it evaluates and adjusts the program in response to changes in the threat environment or business operations.
The breach notification requirement now provides regulators with early visibility into security incidents, which may trigger broader examination of the institution's overall program. Institutions should expect that any notification will lead to scrutiny of whether the program was reasonable before the breach occurred and whether the institution's response demonstrates the kind of preparedness the Rule requires.
7Who Owns What Inside the Organization
The chief executive is accountable to the board for compliance with the Safeguards Rule. The qualified individual designated under the Rule owns the information security program and reports to executive leadership and the board on its effectiveness.
General counsel owns regulatory interpretation, determines whether activities bring the institution within the Rule's scope, and ensures the institution meets notification obligations when breaches occur. Information technology leadership implements the technical, administrative and physical safeguards the qualified individual directs, manages relationships with service providers that handle customer information, and maintains the infrastructure that supports the security program.
Compliance tracks documentation, coordinates testing and audit activities, and maintains the evidence that demonstrates program adequacy. Internal audit evaluates program effectiveness independently and reports findings to the board.
These roles are complementary but not interchangeable. The qualified individual role is strategic and cross-functional. Many institutions find that existing executives lack either the technical depth to oversee information security or the bandwidth to take on this responsibility alongside their primary duties. Virtual CISO leadership provides the strategic security ownership the Rule requires without the overhead of a permanent executive position.
8Practical Steps for Leadership
Leadership should begin by confirming whether the institution is covered. Review the definition in Section 314.1(b) and the examples in Section 314.2(h) against current business activities. If the institution has changed its service offerings, expanded into new markets, or added product lines since it last reviewed coverage, reassess now.
If the institution is covered, identify who currently serves as the qualified individual under the Rule. Review whether that person has the authority, resources and technical competence to oversee the program effectively. Examine whether the board receives substantive reporting on security risks, program effectiveness and material changes to the threat environment.
Confirm that the institution has a written information security program that addresses all nine elements in Section 314.4. Review whether the program reflects current business operations, technology environment and risk profile. Assess whether the institution can demonstrate that it evaluates and adjusts the program periodically.
Verify that the institution has an incident response plan that includes procedures for determining whether a breach meets the notification threshold and for submitting the required report within 30 days of discovery. Ensure that personnel responsible for detecting and investigating security incidents understand the notification requirements.
Document the rationale for key security decisions. Regulators do not expect institutions to eliminate all risk or to implement every possible safeguard. They expect institutions to assess risks, make informed decisions about appropriate safeguards based on the institution's specific circumstances, and be able to explain those decisions.
9How This Relates to Broader Regulatory Readiness
The Safeguards Rule is one element in a larger regulatory landscape that includes state data breach notification laws, consumer protection statutes, industry-specific requirements and contractual obligations. Institutions subject to the Rule often face overlapping requirements from multiple regulators and jurisdictions.
Effective compliance requires governance that can identify applicable requirements, assess their interaction, establish controls that satisfy multiple frameworks efficiently, and adapt the program as regulations evolve. The qualified individual role under the Safeguards Rule aligns naturally with broader regulatory readiness responsibilities.
Institutions that establish executive ownership for the information security program often extend that ownership to include regulatory coordination, vendor risk management, third-party audit readiness, and board education on emerging risks. This consolidation reduces fragmentation and provides leadership with a single point of accountability for the institution's security posture.
10Next Steps
Financial institutions subject to the Safeguards Rule should review their current information security program against the requirements in 16 CFR Part 314, confirm that they have designated a qualified individual with appropriate authority and competence, verify that they can meet the 30-day breach notification deadline, and assess whether their board receives substantive reporting on security risks and program effectiveness.
Institutions that identify gaps in executive ownership, program documentation, or governance processes face a choice between assigning these responsibilities to an existing executive, hiring a permanent security leader, or engaging fractional leadership. The decision depends on the institution's size, risk profile, budget and timeline for achieving compliance.
Heights Consulting Group provides virtual CISO leadership that establishes the strategic security ownership, governance structure and regulatory readiness the Safeguards Rule requires. If you are accountable for compliance but lack clear ownership or a path to demonstrating program adequacy, a confidential consultation will clarify your options and what reasonable assurance looks like for your institution.
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.