What is the FTC Safeguards Rule? GLBA Security Requirements for Non-Bank Financial Institutions
The FTC Safeguards Rule requires auto dealers, lenders, brokers, and other non-bank financial institutions to run a specific security program and report breaches. What it requires and who is exposed.
Who Is Covered
The Rule applies to financial institutions as defined by GLBA, which is broader than the everyday meaning. The test is whether the business is significantly engaged in activities that are financial in nature. Arranging or extending credit qualifies, which is why an auto dealership that sends a buyer's application to lenders is a financial institution. So is a mortgage broker, a payday or installment lender, a finance company, a tax preparer, a debt collector, a real estate settlement service, a check casher, and an investment adviser too small to register with the SEC. The 2021 amendment also brought in finders, businesses that bring together buyers and sellers of a financial product.
Service providers to covered institutions are not directly covered, but the institution must oversee them by contract and by assessment. In practice that pulls dealer management system vendors, lending platforms, and managed IT providers into the compliance perimeter.
What the Rule Requires
Governance
A Qualified Individual, employee or outside provider, responsible for the program. A written risk assessment identifying foreseeable internal and external risks to customer information, the sufficiency of existing safeguards, and how risks will be mitigated. A written incident response plan. An annual written report from the Qualified Individual to the board or its equivalent, covering the program's status, material matters, and recommendations.
Technical Controls
Access controls that limit customer information to authorized users and only what they need. An inventory of the data, personnel, devices, systems, and facilities that handle customer information. Encryption of customer information in transit over external networks and at rest, or a Qualified Individual-approved compensating control. Multi-factor authentication for any individual accessing any information system that holds customer information. Secure development practices for in-house applications. Secure disposal of customer information no later than two years after last use unless retention is required. Change management procedures. Monitoring and logging of authorized users' activity to detect unauthorized access.
Testing and Training
Either continuous monitoring or annual penetration testing plus vulnerability assessments every six months and after material changes. Security awareness training for staff, and qualified personnel to run the program. Service provider selection, contractual requirements, and periodic assessment.
Small Institution Exemptions
Institutions that maintain customer information on fewer than 5,000 consumers are exempt from the written risk assessment, the continuous monitoring or penetration testing requirement, the written incident response plan, and the annual board report. MFA, encryption, access controls, and the other core requirements still apply.
The Breach Notification Requirement
Since May 2024, a covered institution that discovers a notification event, unauthorized acquisition of unencrypted customer information involving 500 or more consumers, must notify the FTC as soon as possible and no later than 30 days after discovery. Notification is through a form on the FTC's website and asks for the institution's identity, a description of the event, the types of information involved, the date or date range, the number of consumers affected, and whether law enforcement has requested a delay in public disclosure. The FTC publishes the notifications.
The 500-consumer threshold is low. A single compromised mailbox at a dealership finance office, with a year of credit applications in it, clears it. The 30-day clock runs from discovery, not from confirmation of scope, which is the reason a compromise assessment that finds the event is preferable to a customer complaint that reveals it.
How the Rule Maps to Other Frameworks
The Rule's control list is not novel. Every requirement corresponds to a NIST SP 800-53 control family: access control (AC), identification and authentication (IA), audit and accountability (AU), system and communications protection (SC), risk assessment (RA), incident response (IR), and so on. The FTC has said as much, pointing covered institutions toward NIST and CIS as acceptable ways to implement the program. A risk register built on 800-53 produces the Safeguards Rule crosswalk mechanically. The Rule's MFA requirement maps to the same IA-2 control the CIS Microsoft 365 Benchmark checks, which is why a dealership group's Microsoft 365 tenant assessment is most of its Safeguards Rule evidence.
Where Covered Institutions Fail
The failures are consistent across engagements. The Qualified Individual is the general manager or the outside IT vendor and has never produced the annual report. The written risk assessment exists as a template downloaded from a trade association and never completed. MFA is enabled for email but not for the dealer management system, the lending portal, or the remote desktop the F&I manager uses from home. Customer information sits in shared mailboxes, network folders, and scanned-document repositories with no inventory and no retention. Penetration testing has never been done. Service provider contracts predate the Rule and contain no security terms. And the breach that meets the 500-consumer threshold is discovered by the consumer, or by a lender, months after the mailbox was taken.
The Safeguards Rule in Private Equity
Auto retail, consumer lending, tax preparation, and collections are all consolidation theses, and every location acquired is a covered institution. Three diligence questions follow. Does the target have a designated Qualified Individual, a completed written risk assessment, and an annual board report, or does it have a binder? Is MFA actually enforced on every system that holds customer information, including the dealer management system and remote access, or only on email? Has the target ever been assessed for active compromise, or would a notification event be discovered by a consumer after close and reported under the sponsor's platform name?
Post-close, the Rule's program-level requirements are well suited to a platform: one Qualified Individual, one written program, one annual report, one set of service provider terms, applied across every location. That is an efficiency the sponsor can capture. The technical requirements, MFA and encryption and monitoring on every location's systems, are the remediation cost the sponsor should have priced.
Executive Implications
For a CFO at a covered institution, the Rule is a documented list of controls the FTC can examine and a 30-day clock that starts before the organization knows how bad the event is. For a GC, the annual board report is a signed statement about program status that will be read against the environment after an incident; it should describe the environment that exists. For a board, the Rule is unusual in requiring a report to the board by name, which means the board cannot later say it was not told.
Related Reading
Real-World Example: CDK Global and the Dealer Supply Chain
In June 2024, a ransomware attack on CDK Global, the dealer management system used by roughly 15,000 North American dealerships, took the platform offline for most of two weeks. Dealerships could not process sales, financing, service, or parts. Publicly traded dealer groups disclosed the revenue impact in SEC filings; industry estimates put the total dealer loss above a billion dollars.
For Safeguards Rule purposes, the incident is a service provider case. Every affected dealership was a covered financial institution whose customer information lived in a third-party system, and the Rule requires those institutions to select providers capable of maintaining appropriate safeguards, require it by contract, and periodically assess them. Few dealerships could show any of the three. The incident did not change the Rule. It demonstrated which requirement the industry had treated as paperwork. Cloudskope's breach analysis covers the operational and deal-room consequences.
The consumer threshold above which a covered institution must notify the FTC of a breach of unencrypted customer information within 30 days of discovery, in effect since May 2024. The FTC publishes the notifications. Auto dealership groups, the most consolidated covered industry, report under the group name.
How Cloudskope Can Help
Cloudskope’s register is built on NIST SP 800-53, so the Safeguards Rule crosswalk is mechanical: each finding already carries the control the Rule’s requirement cites. Cloudskope SARTUS™ assesses the Microsoft 365 tenant, endpoints, credential exposure, and active-compromise indicators where dealership and lender customer information actually lives, closes the MFA, logging, and access findings in the same week, and produces the dated artifact a Qualified Individual can attach to the annual board report. For sponsors consolidating covered industries, the same engagement runs across locations before a notification event is reported under the platform name. See how the register maps across frameworks.
.png)