Financial services firms are subject to a web of security obligations that continues to evolve. These requirements come from multiple sources, including the Gramm-Leach-Bliley Act, the Federal Trade Commission's enforcement of data protection standards, and increasingly detailed frameworks for measuring and reporting cybersecurity risk. The complexity lies not in a single new rule, but in the cumulative effect of overlapping requirements, updated guidance, and the practical difficulty of demonstrating to regulators, boards, and clients that controls are adequate and maintained.

For chief executives, chief financial officers, and boards, the central problem is often straightforward: security obligations exist, leadership is accountable, but there is no single owner translating those obligations into strategy, governance, and evidence of compliance. This article explains the sources of security regulation for financial services, the obligations they impose, and the ownership model that makes compliance defensible.

Where Financial Services Security Obligations Come From

The Gramm-Leach-Bliley Act requires financial institutions—defined broadly as companies that offer consumers financial products or services such as loans, financial or investment advice, or insurance—to explain their information-sharing practices to customers and to safeguard sensitive data. This is the foundational obligation for most regulated firms, but it is not the only one.

The FTC enforces data security obligations through its authority under Section 5 of the FTC Act, which prohibits unfair and deceptive acts. If a company makes privacy promises, either expressly or by implication, the FTC requires the firm to live up to those claims. Even if no specific claims are made, companies still have an obligation to maintain security that is appropriate given the nature of the data they possess. This creates a floor beneath explicit regulatory requirements: inadequate security can itself constitute an unfair practice.

Additional obligations arise from data breach notification requirements. The Health Breach Notification Rule may apply to firms handling health-related information, and the FTC has issued guidance clarifying that breaches involving health apps and connected devices trigger specific notification and remediation steps. The Fair Credit Reporting Act imposes obligations on companies that use consumer reports or credit reports to evaluate creditworthiness, employment, leases, or insurance applications.

The NIST Cybersecurity Framework, now in version 2.0, is a voluntary tool developed to help organizations reduce cybersecurity risks. While not binding on its own, the framework is increasingly referenced by regulators, courts, and boards as a baseline for what constitutes reasonable security practice. The framework is designed for industry, government, and organizations to manage cybersecurity risk more consistently. It is accompanied by profiles, quick-start guides, and mappings to other standards, and has been updated to support evidence-ready automation and reporting.

The NIST Privacy Framework is a separate voluntary tool intended to help organizations identify and manage privacy risk. Like the Cybersecurity Framework, it is not a regulation, but its structure is increasingly used to demonstrate that privacy considerations are integrated into enterprise risk management. Privacy Framework 1.1 is in initial public draft as of the time the referenced sources were published.

Why This Matters to the Business

Regulatory non-compliance exposes the firm to enforcement actions, civil penalties, and reputational harm. The FTC's enforcement powers are broad, and enforcement priorities shift. A firm that was compliant three years ago may not be today if its controls have not kept pace with updated guidance or if its privacy policy makes promises its practices no longer support.

Beyond enforcement risk, inadequate security creates operational and strategic constraints. Customers increasingly ask detailed questions about data protection, and larger partners require evidence of specific controls before entering into agreements. Board members and audit committees expect regular reporting on the firm's security posture and its alignment with regulatory obligations. Without clear ownership, these requests become ad hoc exercises rather than outputs of ongoing governance.

The gap is often not in the controls themselves but in the absence of a coherent view of what the firm is required to do, how current controls map to those requirements, and how leadership can demonstrate to regulators and boards that the security program is adequate. This gap cannot be closed by deploying additional technology or adding staff to an IT function. It requires executive-level ownership of the regulatory position and the risk decisions that flow from it.

Practical Explanation of the Obligations

The Gramm-Leach-Bliley Act requires financial institutions to develop, implement, and maintain a comprehensive information security program. This program must include administrative, technical, and physical safeguards designed to protect customer information. The firm must also provide clear privacy notices to customers explaining what information is collected, how it is shared, and what choices customers have regarding that sharing.

Under the FTC's interpretation of its authority, firms must maintain security that is reasonable in light of the data they hold. This is not a static standard. What is reasonable changes as threats evolve, as new protective technologies become available, and as the volume and sensitivity of data held by the firm increases. The FTC has pursued enforcement actions against firms whose security was inadequate even where no specific regulation was violated, on the basis that inadequate security constitutes an unfair practice.

The Red Flags Rule requires certain businesses and organizations to implement a written Identity Theft Prevention Program designed to detect warning signs of identity theft in day-to-day operations. This applies to many financial services firms and to companies that use credit reports in employment, leasing, or insurance decisions. The program must be updated periodically to reflect new risks.

Data breach notification obligations vary depending on the type of data involved. Health-related data may trigger the Health Breach Notification Rule, which requires specific steps following a breach. The FTC has issued a statement clarifying that breaches involving health apps and connected devices fall within this framework. Consumer data breaches may trigger obligations under state laws, contractual obligations, or both.

The NIST Cybersecurity Framework provides a structure for organizing security activities into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Within each function, the framework defines categories and subcategories of activities. Organizations can use the framework to create a profile describing their current state, a target state, and a plan to close gaps. The framework includes mappings to other standards and controls, making it easier to demonstrate that a firm's controls satisfy multiple requirements simultaneously.

Leadership Considerations and Who Owns What

Chief executives and boards are accountable for the firm's security posture and its regulatory compliance, but they cannot own the day-to-day decisions about controls, risk acceptance, or incident response. IT leaders often own the technology but lack the authority or mandate to make risk decisions or represent the firm's position to regulators or auditors. Legal and compliance functions understand the obligations but often lack the technical depth to evaluate whether controls are adequate or to prioritize remediation.

Adequate ownership requires someone at the executive level who can translate regulatory obligations into strategy, maintain the governance artifacts regulators and boards expect, make risk decisions within delegated authority, and report progress in terms leadership can act on. This is the role of a Chief Information Security Officer. In firms where a full-time CISO is not yet warranted, a [virtual CISO](/vciso/) provides the same executive ownership on a fractional basis.

The vCISO owns the firm's information security strategy, maintains the inventory of regulatory obligations, ensures that controls map to those obligations, and provides the board and executive leadership with regular reporting on the security posture. The vCISO also serves as the primary interface to auditors, regulators, and clients who require evidence of specific controls. This ownership does not replace the IT function or the compliance function; it coordinates them and provides the executive layer those functions cannot.

For firms subject to the Gramm-Leach-Bliley Act, the vCISO ensures that the required written information security program exists, is maintained, and is updated as threats and the business change. For firms subject to FTC oversight, the vCISO ensures that privacy policies accurately describe practices and that security is demonstrably reasonable given the data held. For firms using the NIST Cybersecurity Framework, the vCISO maintains the current and target profiles and the roadmap connecting them.

What Leadership Should Do Next

Leadership should begin by confirming who currently owns the regulatory security position. If the answer is unclear, or if ownership is distributed across IT, legal, and compliance without coordination, the gap is material. The next step is to define what adequate ownership looks like: someone who can maintain the inventory of obligations, map controls to those obligations, make risk decisions, and report progress to the board and to regulators.

Once ownership is defined, leadership should assess whether the current state is documented in a way that would satisfy an auditor or regulator. This means having a written information security program if the firm is subject to the Gramm-Leach-Bliley Act, having a current inventory of data and controls, and having a clear position on how the firm's security satisfies the FTC's reasonableness standard. If these artifacts do not exist or are out of date, they should be prioritized.

Leadership should also consider whether the firm's privacy policies accurately describe current practices. If policies were written years ago and have not been updated as the business or its data handling has changed, they may create compliance exposure. The vCISO or legal counsel should review and update these policies to eliminate claims the firm cannot support.

Finally, leadership should establish a regular reporting cadence. The board and executive team should receive at least quarterly updates on the security posture, regulatory position, and any changes to obligations or risks. This reporting should be concise, focused on decisions rather than metrics, and structured so that leadership can act on it. Without regular reporting, security becomes reactive rather than governed.

If the firm does not currently have executive security ownership and the volume of regulatory obligations or the sensitivity of data held makes this gap material, a [virtual CISO engagement](/vciso/) may be the most direct path to establishing that ownership. Heights Consulting Group provides vCISO leadership designed specifically for firms that need executive security ownership but are not yet at the scale where a full-time CISO is warranted. If you would like to discuss your firm's regulatory position and how executive security ownership would close the gaps you face, a confidential consultation is available at no cost and with no obligation.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Talk this through with us

If this raises a question about your own organization, a confidential conversation is the fastest way to get a straight answer.

Schedule a Confidential Consultation