FTC Safeguards Rule Explained: 2023–2025 Updates and What Changed
The FTC’s revised Safeguards Rule (16 CFR Part 314) has been reshaping GLBA compliance in stages since 2023 — and it hasn’t stood still since. Specific technical controls took effect in June 2023, a mandatory breach reporting requirement followed in May 2024, and the FTC issued fresh compliance guidance in 2025. The original 2003 Safeguards Rule was largely principles-based — it told companies to protect customer information but left implementation details to their discretion. Each update since 2023 has made the rule more specific, prescriptive, and demanding.
What the Original Safeguards Rule Said (2003)
The original Safeguards Rule required financial institutions to:
- Develop a written information security program
- Designate an employee to coordinate the program
- Identify and assess risks to customer information
- Design and implement safeguards to control identified risks
- Oversee service providers
- Evaluate and adjust the program regularly
While these were sensible requirements in principle, the rule offered almost no specifics on what safeguards were required. Organizations could (and many did) maintain minimal security programs with vague policies and claim compliance.
What Changed in 2023
The revised rule added concrete, measurable requirements across several areas:
New: Specific Technical Controls
The 2023 rule introduced mandatory technical controls that were not in the original:
| Control | 2003 Rule | 2023 Rule |
|---|---|---|
| Multi-factor authentication | Not required | Required for remote access and privileged accounts |
| Encryption at rest | Not specified | Required for customer NPI |
| Encryption in transit | Not specified | Required for customer NPI |
| Penetration testing | Not required | Annual (for 5,000+ customers) |
| Vulnerability scanning | Not required | Biannual (for 5,000+ customers) |
| Audit logging | Not specified | Required for detecting unauthorized access |
New: Qualified Individual Requirement
The 2023 rule requires designation of a “qualified individual” — someone with knowledge, skills, and experience appropriate to run an information security program. This is more specific than the original “designate an employee” language. The qualified individual can be internal or a third party (such as a vCISO), but the financial institution must actively oversee them.
New: Annual Board Reporting
Organizations with 5,000+ customer records must now have the qualified individual report to the board of directors (or equivalent senior management) at least annually on the information security program. This elevates cybersecurity from a back-office IT function to a board-level governance item.
New: Written Incident Response Plan
The 2023 rule requires a formal, written incident response plan addressing goals, processes, roles, communications, and post-incident review. The original rule referenced incident response only in passing.
New: FTC Breach Notification (Finalized 2023, Effective 2024)
The FTC finalized a new breach notification requirement in October 2023, giving institutions a six-month runway before it took effect (see What Changed in 2024 below). Financial institutions must notify the FTC as soon as possible — and no later than 30 days after discovery — of a breach affecting 500 or more customers involving unencrypted customer information.
New: Service Provider Contractual Requirements
Contracts with service providers must now include requirements for the provider to implement appropriate safeguards and notify the institution if they experience a breach affecting the institution’s customer information.
What Changed in 2024
New: Breach Notification Requirement Took Effect
The FTC breach notification amendment officially became enforceable on May 13, 2024. Covered financial institutions must now report any “notification event” affecting 500 or more consumers to the FTC within 30 days of discovery, including the institution’s name, the date and scope of the breach, the type of information involved, and a summary of what happened.
New: Public Breach Database
The FTC began publishing submitted breach reports in a public database, using its Safeguards Rule Security Event Reporting Form. Unlike a private regulatory filing, this creates real reputational exposure — a reported breach is discoverable by customers, competitors, and the press, not just regulators.
New: Enforcement Against Poor Security Practices
In February 2024, the FTC settled with data platform provider Blackbaud, Inc. over Safeguards Rule violations tied to a 2020 breach that went undetected for three months and exposed unencrypted donor and customer data. The case reinforced that “reasonable safeguards” now means demonstrable technical controls, monitoring, and timely detection — not just a written policy on file.
What Changed in 2025
New: FTC FAQ Guidance on Practical Compliance
In June 2025, the FTC published detailed FAQ guidance clarifying how the Safeguards Rule applies in practice — initially aimed at motor vehicle dealers, but broadly instructive for any financial institution. The guidance reinforced that:
- Encryption and multi-factor authentication are expected baseline controls, not optional best practices
- Risk assessments must be tailored to the institution’s actual size, complexity, and the sensitivity of the customer data it holds — a generic, boilerplate risk assessment does not satisfy the rule
- Continuous monitoring and regular penetration testing are expected as ongoing practices, not one-time projects
- Vendor oversight obligations apply even to mandated or unavoidable third-party platforms — institutions can’t exempt a vendor from oversight just because using it isn’t optional
- The definition of protected customer information (NPI) is broader than many institutions assume, covering data obtained in connection with any financial product or service
New: Broader Enforcement Reach
In December 2025, the FTC and the Colorado Attorney General reached a $24 million settlement with Greystar, the largest multifamily rental property manager in the U.S. The complaint alleged, among other things, that Greystar’s deceptive fee practices violated GLBA’s pretexting provisions by using false pretenses to induce consumers to hand over financial account information through rental applications. The case signals that GLBA enforcement is reaching well beyond traditional banks and lenders — any business that collects financial information as part of a transaction can be treated as a “financial institution” under the Act.
Small Business Exemption
The 2023 rule created a limited exemption for institutions with fewer than 5,000 customer records from the following requirements:
- Annual penetration testing
- Biannual vulnerability scanning
- Written incident response plan (still recommended but not required)
- Annual board reporting
These smaller institutions still must maintain a written information security program, designate a qualified individual, conduct risk assessments, implement access controls and encryption, and oversee service providers.
Key Implementation Deadlines (Now Past)
- June 2023: Revised Safeguards Rule technical controls fully effective
- October 2023: FTC finalizes the breach notification amendment
- May 13, 2024: FTC breach notification requirement takes effect; public breach database goes live
- February 2024: FTC settles first major Safeguards Rule enforcement action post-amendment (Blackbaud)
- June 2025: FTC issues FAQ guidance clarifying encryption, MFA, risk assessment, monitoring, and vendor oversight expectations
- December 2025: FTC/Colorado AG settlement signals GLBA enforcement extending beyond traditional financial institutions
All covered financial institutions should now be in full compliance with the 2023 and 2024 requirements, and should review the 2025 FTC guidance against their current program. Organizations that haven’t updated their programs accordingly face potential FTC enforcement if they experience an incident.
How Espresso Labs Helps
Espresso Labs builds and runs GLBA Safeguards Rule compliance programs as a managed service — giving financial institutions the technical controls, monitoring, breach reporting readiness, board reporting support, and vendor oversight they need to stay compliant with the 2023, 2024, and 2025 requirements without building a large internal security team. Contact us to assess your current Safeguards Rule gaps and see how quickly we can close them.