It names a person.
And it starts a 30-day public clock.
The FTC Safeguards Rule is the financial-services data-security law most firms underestimate. It requires a named Qualified Individual accountable for your program — and since May 2024, a breach of 500+ consumers means notifying the FTC within 30 days, in a database the public can read. We build the program and the proof.
Book a GLBA Strategy Call →// WHY GLBA, WHY NOW
This rule doesn't grade your firewalls. It grades your program.
30 DAYS
To notify the FTC — publicly
Since May 2024, a breach of 500+ consumers' unencrypted data means reporting to the FTC within 30 days of discovery — into a database that's generally public.
1 PERSON
Named and accountable
The Rule requires a Qualified Individual to own the program. One of the most common FTC findings: a Qualified Individual who was never designated or lacks the right background.
9 + 8
Elements and safeguards
Nine required program elements and eight specific safeguard controls — from MFA and encryption to a written risk assessment, WISP, and tested incident response.
// TOOLS AREN'T A PROGRAM
We have good security tools, so we're covered.
The Rule grades the program and the paper, not the products.
Strong tools are necessary but they're not what the Safeguards Rule measures. It's a program and documentation standard: a designated Qualified Individual, a written risk assessment, a WISP, periodic penetration testing, service-provider oversight, an annual board report, and a tested incident response plan. The most common findings aren't missing firewalls — they're a missing WISP, no annual report, or a Qualified Individual who exists only on paper. Under this Rule, the documentation and accountability are the compliance.
// THE FOUR PILLARS OF THE SAFEGUARDS RULE
Nine elements. One that holds the rest together.
The Rule's nine required elements organize into four operational pillars. The Qualified Individual + WISP is the structural center — the named human and the master document the other three pillars report into.
The accountable core of the program: the Qualified Individual is the named human who owns it, the WISP (Written Information Security Program) is the master document that ties everything together, and the annual board report is the artifact the FTC examines. The three pillars below are the substantive content the WISP documents and the Qualified Individual oversees.
// PILLAR · ELEMENT 2
Risk Assessment
The written risk assessment the WISP and all safeguards derive from. The foundation everything else is built on.
// PILLAR · ELEMENT 3
Designed Safeguards
Eight specific controls: access, asset inventory, encryption, secure dev, MFA, disposal, change mgmt, logging.
// PILLAR · ELEMENT 7 + TESTING
Incident Response
A written, tested plan rehearsing the 30-day FTC notification clock when a reportable event occurs.
Every FTC action traces to one of these pillars — most often a missing WISP or undesignated Qualified Individual.
// THE PATH
Six stages, two accountability moments.
From confirming the Rule applies to running the program day to day. The amber stages are the accountability moments the FTC looks for — the named Qualified Individual, and the annual board report.
Applicability
Coverage Analysis
WK 1–2
Designate
Qualified Individual
WK 2–4
Risk + WISP
Assess & Author
MO 1–3
Safeguards
Implement Controls
MO 2–5
Board Report
Annual Report + Testing
ANNUAL
Operations
Ops + Notification
CONTINUOUS
Amber stages are the accountability moments the FTC examines — designating a Qualified Individual with the right background, and the annual written report to your board or a senior officer. The program is sustained continuously, with the 30-day clock always live.
// IS THIS YOU?
Three signs the Safeguards Rule is already on you.
// 01 // NO QI
No one is formally named
You can't point to a designated Qualified Individual with the right security background and a documented mandate. That's the first thing the FTC looks for — and a frequent finding.
// 02 // NO CURRENT WISP
Your WISP is missing or stale
You have no Written Information Security Program, or it predates the revised rule and the 30-day notification requirement. Without a current WISP, you can't demonstrate compliance.
// 03 // FINANCIAL DATA
You handle customer financial info
You're a lender, advisor, tax preparer, dealer that finances, or similar — "significantly engaged" in financial services. If you're not bank-regulated, the FTC's rule is yours.
// WHAT WE DO
The named owner, the program, and the proof.
// Phase 01 · Establish
Applicability & the Qualified Individual
We confirm the Rule applies and which regulator oversees you, then stand up the Qualified Individual role — including in a fractional capacity if you don't have the in-house security leadership.
- ✓Coverage and regulator applicability analysis
- ✓Qualified Individual designation or fractional support
- ✓Senior-oversight and authority structure
// Phase 02 · Build
Risk Assessment, WISP & Safeguards
We author the written risk assessment and the WISP, then implement the eight required safeguards with the evidence the program demands — not a binder that sits on a shelf.
- ✓Written risk assessment and WISP authoring
- ✓Eight safeguards: MFA, encryption, access, logging, more
- ✓Penetration testing and service-provider oversight
// Phase 03 · Sustain
Reporting & Notification Readiness
We produce the annual board report the FTC examines and build the incident response and notification process so a reportable event doesn't blow the 30-day clock.
- ✓Annual written report to the board or senior officer
- ✓Incident response plan and tabletop testing
- ✓30-day FTC notification readiness and runbook
// THE CLOCK STARTS AT DISCOVERY
When a breach hits, you have 30 days — and the report goes public.
// FREQUENTLY ASKED
The GLBA Safeguards questions teams keep asking.
Does the FTC Safeguards Rule even apply to us? We're not a bank.
Most likely yes — and not being a bank is exactly why. The Rule applies to nonbanking financial institutions under FTC jurisdiction, and the definition is far broader than people expect: mortgage brokers and lenders, auto dealers that arrange financing, tax preparers and accountants, financial advisors, collection agencies, check cashers, and many others "significantly engaged" in financial products or services. Banks are covered by their banking regulators instead, which is why the FTC's rule targets everyone else.
If you handle customer financial information and aren't supervised by a banking regulator, assume the Rule applies until a qualified analysis says otherwise. Confirming applicability — and which regulator oversees you — is the first thing we do, because building a program you don't need, or skipping one you do, are both expensive mistakes.
What is the Qualified Individual, and can it be outsourced?
The Qualified Individual is the single named person responsible for overseeing, implementing, and enforcing your information security program — the accountability the Rule places at the center. No specific degree or title is required; what matters is real-world security know-how appropriate to your size and complexity. The role can be filled by an employee, an affiliate, or a service provider, so it can be outsourced — including to a firm acting in a fractional security-leadership capacity.
But outsourcing the role doesn't outsource the accountability: you must retain responsibility, designate a senior member of your organization to direct and oversee the Qualified Individual, and ensure they have the authority and information to do the job. A Qualified Individual who exists only on paper, or who lacks the security background, is one of the most common deficiencies the FTC finds.
What is the 30-day breach notification requirement?
Since May 13, 2024, the Rule requires notifying the FTC of a "notification event" as soon as possible and no later than 30 days after discovery. A notification event is the unauthorized acquisition of unencrypted customer information involving at least 500 consumers — and the Rule treats unauthorized access as acquisition unless you have reliable evidence it wasn't.
Two things make this sharper than many state laws. The clock starts at discovery — the first day the event is known to you or any employee, officer, or agent — so detection and escalation matter enormously. And the report, filed through the FTC's online form, is generally made public in an FTC database, required even if the event poses no apparent risk of harm. Because it can become public and the window is short, the time to build your response process is before an event — which is what tabletop exercises rehearse.
We have cybersecurity tools in place. Isn't that enough?
Tools are necessary but not what the Rule grades you on. The Safeguards Rule is a program and documentation standard, not a checklist of products. Even with strong technical controls, it still requires a designated Qualified Individual, a written risk assessment that drives your safeguards, a WISP documenting the whole program, periodic penetration testing and vulnerability assessments, service-provider oversight, an annual written report to your board or a senior officer, and a tested incident response plan tied to the 30-day clock.
In practice the most common findings aren't missing firewalls — they're the absence of a current WISP, no annual board report, a Qualified Individual never formally designated or lacking the right background, or a response plan never tested against the notification timeline. We close the gap between "we have good security" and "we can demonstrate a compliant program," because under this Rule the documentation and accountability are the compliance.
// THE NEXT MOVE
Stand up the program before the 30-day clock ever starts.
Book a 30-minute GLBA strategy call with a WatchUr6 advisor. Bring what kind of financial services you provide, whether you've named a Qualified Individual, and whether you have a current WISP. You'll walk away knowing if the Rule applies to you, where your biggest gaps are, and a realistic path to a defensible program — whether you hire us or not.
Book a GLBA Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED