FTC Safeguards Rule Compliance for Nevada Businesses

The FTC Safeguards Rule requires non-bank financial businesses, including tax preparers, lenders, financial advisors and many auto dealers, to run a written information security program with nine required elements. Our managed security plans deliver many of the technical safeguards it requires, from MFA and monitoring to training and incident response, for Reno, Sparks and Carson City businesses.

Who the rule covers.

The rule implements the Gramm-Leach-Bliley Act (GLBA) for financial institutions under FTC jurisdiction. That reaches well beyond banks. The FTC's own examples include:1

  • Tax preparation firms
  • Mortgage lenders and brokers, payday lenders and finance companies
  • Financial advisors and investment advisors not registered with the SEC
  • Collection agencies and credit counselors
  • Check cashers and wire transferors
  • Non-federally insured credit unions

Auto dealers that arrange financing or leasing are generally covered too. If you are unsure, your attorney can confirm.

Enforcement dates.

The updated rule's requirements have been enforceable since June 2023, and the FTC breach notification requirement took effect in May 2024. The IRS also reminds tax professionals that the Safeguards Rule requires a written information security plan (WISP).

See how this plays out for accounting and CPA firms and for financial services firms in Northern Nevada.

What your security program must include.

Based on the FTC's guide to the rule.1 Your business stays responsible for its program. The right-hand column shows where our services can support each element.

FTC Safeguards Rule elements and how our services support them
Required elementWhat it meansHow we support it
1. Qualified IndividualA designated person oversees the programYour designation; vCISO guidance can advise whoever holds the role
2. Written risk assessmentIdentify foreseeable threats to customer information, in writingYour responsibility, with vCISO input; our free security assessment is a starting point, not a substitute
3. SafeguardsAccess controls, system and data inventory, encryption, MFA, secure disposal, change management, activity loggingZero trust (MFA, access), SIEM (logging), encrypted email
4. Monitor and testContinuous monitoring, or annual pen tests plus six-month vulnerability assessments24/7/365 MDR, vulnerability management (SecurityPlus), pen testing (separate)
5. Staff trainingSecurity awareness training with regular refreshersSecurity awareness training
6. Oversee service providersChoose capable providers, set security expectations in contracts and periodically assess themYour responsibility, with vCISO input
7. Keep the program currentUpdate for changes in operations, threats and staffYour responsibility, with vCISO input
8. Written incident response planGoals, roles, communications, remediation and post-incident reviewIncident response, included in both plans
9. Report to the boardThe Qualified Individual reports in writing at least annually to the board or a senior officerYour Qualified Individual's report, with vCISO input

MFA, encryption and testing.

  • MFA for anyone accessing customer information on your systems, using at least two different factor types.
  • Encryption of customer information at rest and in transit, or effective alternative controls approved by your Qualified Individual.
  • Testing: continuous monitoring, or an annual penetration test plus vulnerability assessments, including system-wide scans, every six months.
  • Logging: monitor and log the activity of authorized users and detect unauthorized access.

Notifying the FTC.

If unencrypted customer information on 500 or more consumers is acquired without authorization, you must notify the FTC as soon as possible and no later than 30 days after discovery. Encrypted data counts as unencrypted if the key was also taken.1

Nevada's NRS 603A adds its own duty to notify affected Nevada residents. Our incident response work gives your counsel the facts needed to meet both.

This page summarizes the FTC's published guidance and is not legal advice.

FTC Safeguards Rule FAQ

No. Financial institutions that maintain customer information on fewer than 5,000 consumers are exempt from only a few provisions: the written risk assessment, continuous monitoring or annual penetration testing and six-month vulnerability assessments, the written incident response plan, and the annual written report to the board. Every other element still applies, including MFA, encryption, access controls and training.
Yes, in most cases. The FTC lists tax preparation firms among the financial institutions the rule covers, and the IRS separately requires tax professionals to maintain a written information security plan. Your attorney can confirm how the rule applies to your specific practice.
When unencrypted customer information on at least 500 consumers is acquired without authorization, you must notify the FTC as soon as possible and no later than 30 days after discovery. Information counts as unencrypted if the encryption key was also accessed.
The Qualified Individual can be an employee, or someone who works for an affiliate or a service provider. If you use a service provider, you must still designate a senior employee to supervise them, and your business remains responsible for compliance.
The rule requires either continuous monitoring of your systems, or annual penetration testing plus vulnerability assessments, including system-wide scans, at least every six months, and testing after material changes to your operations or systems.
Cloud-hosted systems can be included in vulnerability management and in penetration testing, which is sold separately. Major cloud providers publish their own rules for security testing, and engagements follow them.

Find out where your business is exposed.

Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.