Don’t do SECURITY. Do business SECURELY.

Updated FTC Safeguards Rule requirements take effect in the US

The main new requirements of the amended FTC Safeguards Rule now apply to US non-bank financial institutions, including MFA and encryption.

The key new requirements of the amended FTC Safeguards Rule (16 CFR Part 314) take effect today in the United States, after the Federal Trade Commission extended the original December 2022 deadline by six months.

Key points

  • Covered non-bank financial institutions must appoint a qualified individual to oversee their information security programme.
  • Written risk assessments, encryption of customer information and multi-factor authentication are now required.
  • Organisations must monitor or test controls, train staff, oversee service providers and maintain an incident response plan.
  • The qualified individual must report in writing to the board at least annually.

The rule reaches a wide range of businesses, including lenders, tax preparers and some consultancies. UK organisations acting as service providers to US financial firms should expect these requirements to flow down through contracts and due diligence.

Source: FTC Safeguards Rule final rule 2021 (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights