Somebody at a conference mentions the Safeguards Rule and you nod along like you know what that is. Two weeks later your cyber insurance renewal asks whether you maintain a written information security program and whether you have designated a Qualified Individual to run it. There is no box for “what is that.” You search it, land on a Federal Trade Commission page, and learn the rule covers tax preparers and auto dealers and mortgage brokers and, going by the description, you.

Then you find the compliance dates and your stomach drops, because they are behind you. Breathe. You are in enormous company, the rule is more reasonable than the panic articles suggest, and there is a sensible order to work through. Here is who is covered, what you missed, and what to do about it.

Standard note: this is general information, not legal, tax, or insurance advice. Whether you are covered is a legal determination about your business. Talk to your own attorney or CPA before deciding you are in or out.

The Word “Financial” Is Doing a Lot of Work Here

The Safeguards Rule lives at Title 16 of the Code of Federal Regulations, Part 314, and comes from the Gramm-Leach-Bliley Act, usually shortened to GLBA, a 1999 law about financial privacy. It applies to what it calls financial institutions, and that phrase is far broader than “bank.”

The regulation defines a financial institution as any institution whose business is an activity financial in nature or incidental to financial activities, and says you must be significantly engaged in those activities. The rule then gives its own examples, and this is the list that catches people:

  • Tax preparation firms and accounting practices. Named directly in the regulation. This is the single biggest group of small businesses that did not know.
  • Auto dealerships that lease or arrange financing. The FTC says dealers who finance vehicles, or facilitate financing, are financial institutions, as are those leasing for ninety days or more.
  • Mortgage brokers, real estate settlement services, and property appraisers. All three appear in the regulation’s examples.
  • Retailers that issue their own credit card. Your own store card counts. Accepting somebody else’s card does not.
  • Credit counselors, investment advisers, check cashers, and wire transfer services. Also listed, along with career counselors who place people in the financial industry.

The regulation is equally clear about who is out. A retailer accepting layaway, deferred payment, or credit cards issued by someone else is not a financial institution, and neither is a grocery store that cashes checks or lets regulars run a tab. If you are near the line, that is a conversation for your attorney, not a blog post.

The Dates You Missed

The first is June 9, 2023. The FTC amended the rule in 2021, then in November 2022 extended the deadline six months for eight specific provisions, citing a shortage of qualified security personnel and supply chain delays getting equipment. Those eight: designating a qualified individual, a written risk assessment, limiting and monitoring access to customer information, encryption, training security personnel, an incident response plan, periodically assessing service providers, and multi-factor authentication.

The second is May 13, 2024, when the breach notification requirement took effect. If there is an acquisition of unencrypted customer information without the authorization of the person it belongs to, involving at least 500 consumers, you must notify the FTC as soon as possible and no later than 30 days after discovery, using an online form the FTC built. Thirty days is not long, which is why the incident response plan is worth writing before you need it.

What the Rule Actually Asks For

The FTC frames this as nine elements of a written information security program. The ones with real teeth for a small business are these.

  • Name a Qualified Individual. One named human responsible for the program. Can be an employee or someone at a service provider, but somebody’s name goes on it.
  • Do a risk assessment, in writing. Where does customer information live, what could go wrong, and what are you doing about it.
  • Turn on multi-factor authentication. Multi-factor authentication, or MFA, means a password plus a second proof such as a code from an app. The rule requires it for anyone accessing your information systems unless the Qualified Individual approves an equivalent alternative in writing.
  • Encrypt customer information. Both in transit across outside networks and while sitting in storage. Encryption scrambles data so it is useless without the key. Where encryption is not feasible, the rule allows equivalent controls the Qualified Individual reviews and approves.
  • Dispose of customer information securely. The rule sets a two year clock after last use, with exceptions where you have a business or legal reason to keep it, and asks you to review retention practices periodically.
  • Vet your service providers. Anyone handling customer information for you, with contract language and periodic reassessment.
  • Train your people and write an incident response plan. Security awareness training, plus a written plan covering roles, communications, remediation, and documentation.

A note on disposal from our side of the desk: wiping a drive is fine for most purposes, but for drives holding customer financial information, physical destruction ends the argument. Harrison Ward Technology owns a Pure Leverage DCV71 hard drive crusher and runs roughly nine drives a minute, meeting recognized destruction standards. It produces a record you can point to, which matters as much as the destruction itself.

The Under 5,000 Exception, and Its Limits

The regulation includes a real break for small operations at 16 CFR 314.6. If you maintain customer information concerning fewer than five thousand consumers, four pieces do not apply: the written risk assessment requirements, the monitoring and testing requirements including annual penetration testing and vulnerability assessments every six months, the written incident response plan, and the annual written report from your Qualified Individual to your board or a senior officer.

Read that carefully, because it is narrower than most people hope. Everything else still applies. MFA, encryption, access controls, service provider oversight, secure disposal, staff training, and breach notification are all still yours. The exception spares you formal paperwork and expensive testing, not the actual security work. And five thousand is a count of information you maintain, not customers you served last year.

A Realistic Catch-Up Order

  1. Name the Qualified Individual today. It costs nothing, it is a prerequisite for other pieces, and it turns a vague obligation into someone’s actual job.
  2. Turn on MFA everywhere this week. Email first, then your practice or dealer management system, then remote access. Highest value item on the list, and mostly a settings change.
  3. Find the customer information. Not just the main system. Email attachments, the shared drive, laptops, the scanner folder, that one desktop under somebody’s desk. You cannot protect what you have not located.
  4. Confirm encryption is actually on. Full disk encryption on every laptop and desktop, plus encryption for anything crossing the internet. Most business machines can already do this and it is simply switched off.
  5. Write the short version of everything. A few pages covering your risk assessment, incident response steps, and retention and disposal practice beats a hundred page template you never open.
  6. Clean out what you no longer need. Old files, old drives, old machines in the closet. Every record you securely destroy is one you can never lose.

Bottom line: missing the deadline is not the emergency. Staying missed is. Nothing here requires an enterprise budget, and the highest value items, naming a person and turning on MFA, can be done this week for essentially nothing. Start there and the rest becomes a project instead of a crisis.

One more time, this is general information and not legal, tax, or insurance advice. Whether the rule covers your business is a real legal question, so raise it with your own attorney, CPA, or insurance agent. If you want help with the technical half, the MFA rollout, the encryption, finding where data actually lives, and secure destruction of old drives, contact Harrison Ward Technology. We do this work for businesses across Denton County.


Sources

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).