FTC Safeguards Rule Compliance for Nevada Businesses
The FTC Safeguards Rule requires non-bank financial businesses, including tax preparers, lenders, financial advisors and many auto dealers, to run a written information security program with nine required elements. Our managed security plans deliver many of the technical safeguards it requires, from MFA and monitoring to training and incident response, for Reno, Sparks and Carson City businesses.
Who the rule covers.
The rule implements the Gramm-Leach-Bliley Act (GLBA) for financial institutions under FTC jurisdiction. That reaches well beyond banks. The FTC's own examples include:1
- Tax preparation firms
- Mortgage lenders and brokers, payday lenders and finance companies
- Financial advisors and investment advisors not registered with the SEC
- Collection agencies and credit counselors
- Check cashers and wire transferors
- Non-federally insured credit unions
Auto dealers that arrange financing or leasing are generally covered too. If you are unsure, your attorney can confirm.
Enforcement dates.
The updated rule's requirements have been enforceable since June 2023, and the FTC breach notification requirement took effect in May 2024. The IRS also reminds tax professionals that the Safeguards Rule requires a written information security plan (WISP).
See how this plays out for accounting and CPA firms and for financial services firms in Northern Nevada.
What your security program must include.
Based on the FTC's guide to the rule.1 Your business stays responsible for its program. The right-hand column shows where our services can support each element.
| Required element | What it means | How we support it |
|---|---|---|
| 1. Qualified Individual | A designated person oversees the program | Your designation; vCISO guidance can advise whoever holds the role |
| 2. Written risk assessment | Identify foreseeable threats to customer information, in writing | Your responsibility, with vCISO input; our free security assessment is a starting point, not a substitute |
| 3. Safeguards | Access controls, system and data inventory, encryption, MFA, secure disposal, change management, activity logging | Zero trust (MFA, access), SIEM (logging), encrypted email |
| 4. Monitor and test | Continuous monitoring, or annual pen tests plus six-month vulnerability assessments | 24/7/365 MDR, vulnerability management (SecurityPlus), pen testing (separate) |
| 5. Staff training | Security awareness training with regular refreshers | Security awareness training |
| 6. Oversee service providers | Choose capable providers, set security expectations in contracts and periodically assess them | Your responsibility, with vCISO input |
| 7. Keep the program current | Update for changes in operations, threats and staff | Your responsibility, with vCISO input |
| 8. Written incident response plan | Goals, roles, communications, remediation and post-incident review | Incident response, included in both plans |
| 9. Report to the board | The Qualified Individual reports in writing at least annually to the board or a senior officer | Your Qualified Individual's report, with vCISO input |
MFA, encryption and testing.
- MFA for anyone accessing customer information on your systems, using at least two different factor types.
- Encryption of customer information at rest and in transit, or effective alternative controls approved by your Qualified Individual.
- Testing: continuous monitoring, or an annual penetration test plus vulnerability assessments, including system-wide scans, every six months.
- Logging: monitor and log the activity of authorized users and detect unauthorized access.
Notifying the FTC.
If unencrypted customer information on 500 or more consumers is acquired without authorization, you must notify the FTC as soon as possible and no later than 30 days after discovery. Encrypted data counts as unencrypted if the key was also taken.1
Nevada's NRS 603A adds its own duty to notify affected Nevada residents. Our incident response work gives your counsel the facts needed to meet both.
This page summarizes the FTC's published guidance and is not legal advice.
FTC Safeguards Rule FAQ
Find out where your business is exposed.
Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.