If your business collects or stores customer financial information, protecting that data should be more than a line on your IT checklist. Depending on what your company does and the types of information it handles, you may also have obligations under the Federal Trade Commission's (FTC) Safeguards Rule.
The Safeguards Rule covers more than traditional financial institutions such as banks. Depending on their activities, businesses such as tax preparers, mortgage brokers, and financial advisors may also be subject to the rule’s requirements.
For businesses that fall under the rule, compliance involves more than having basic security measures in place. It starts with understanding whether the rule applies to your business, then looking at the systems, people, and processes you use to protect customer information.
Determine whether the rule applies to you
Not every business that handles financial information is automatically covered by the Safeguards Rule. Whether it applies depends on the nature of your business and the activities you perform.
That makes determining whether your company falls under the rule an important first step. If you are covered, you need to understand what information you collect, how it moves through your business, and where it is stored.
As your business grows, this information can spread across more systems, users, and third-party services.
Maintaining consistent security controls becomes more challenging as new tools, employees, and vendors are added. Knowing where customer information is stored and handled makes it easier to identify the safeguards your business needs to comply with the rule.
Build your security program around your actual risks
Covered businesses must have a written information security program (WISP) in place. That program should be informed by a written risk assessment that evaluates potential threats to customer information.
In practical terms, this means looking at how your business handles financial data and asking where things could go wrong. Who can access customer records? What happens if an employee loses a laptop? Are remote employees connecting securely? What happens when an employee leaves the company? Do your vendors have access to sensitive information?
The answers can help identify which safeguards your business needs.
Make access harder for the wrong people
Employees should have access to the information and systems they need for their jobs, but they do not necessarily need access to everything your company stores. Limiting permissions can minimize the impact of a compromised account by restricting what that account can access.
The Safeguards Rule also requires covered businesses to use multifactor authentication for anyone accessing information systems. Other safeguards can include encryption, secure disposal procedures, monitoring, testing, and employee security training.
The goal is not to make technology difficult for employees to use. It is to put reasonable barriers between sensitive customer information and the people or events that could compromise it.
Your vendors matter too
Your business may have strong internal security controls, but customer information does not necessarily stay inside your network. You may rely on a cloud accounting platform, a third-party payroll software, or a managed IT services provider that can access customer information. Under the Safeguards Rule, covered businesses have responsibilities when selecting and monitoring service providers that handle customer information.
That means security should be part of your vendor evaluation process. Before giving a third party access to sensitive information, understand what protections it has in place and what your agreement requires it to do.
Have an incident response plan in place
Covered businesses need a written incident response plan that addresses how they will respond to security events. That can include assigning responsibilities, deciding how incidents will be investigated and documented, communicating with the appropriate parties, and addressing weaknesses discovered during the response.
The FTC also requires certain covered businesses to report breaches involving unencrypted customer information. For incidents involving at least 500 consumers, businesses must notify the FTC within 30 days of discovering the incident.
Treat compliance as an ongoing responsibility
For a business handling customer financial data, the Safeguards Rule should not be treated as a one-time compliance project. Your employees, applications, vendors, and security risks can change as the business grows, so your security program needs to keep up.
Find out whether the rule applies to your company. For covered businesses, reviewing access controls, data protection practices, and incident response procedures can show where improvements are needed. Revisit those measures periodically as your technology and operations change.
If you need help reviewing your technology and security practices, Healthy IT can identify your company’s weaknesses, strengthen its IT environment, and put practical security measures in place. Reach out to discuss how your organization can better protect the customer information it handles.

