FTC Safeguards Rule Explained: 2023–2025 Updates and What Changed

Espresso Labs Team
7 min read
FTC Safeguards Rule Explained: 2023–2025 Updates and What Changed

The FTC’s revised Safeguards Rule (16 CFR Part 314) has been reshaping GLBA compliance in stages since 2023 — and it hasn’t stood still since. Specific technical controls took effect in June 2023, a mandatory breach reporting requirement followed in May 2024, and the FTC issued fresh compliance guidance in 2025. The original 2003 Safeguards Rule was largely principles-based — it told companies to protect customer information but left implementation details to their discretion. Each update since 2023 has made the rule more specific, prescriptive, and demanding.

What the Original Safeguards Rule Said (2003)

The original Safeguards Rule required financial institutions to:

  • Develop a written information security program
  • Designate an employee to coordinate the program
  • Identify and assess risks to customer information
  • Design and implement safeguards to control identified risks
  • Oversee service providers
  • Evaluate and adjust the program regularly

While these were sensible requirements in principle, the rule offered almost no specifics on what safeguards were required. Organizations could (and many did) maintain minimal security programs with vague policies and claim compliance.

What Changed in 2023

The revised rule added concrete, measurable requirements across several areas:

New: Specific Technical Controls

The 2023 rule introduced mandatory technical controls that were not in the original:

Control2003 Rule2023 Rule
Multi-factor authenticationNot requiredRequired for remote access and privileged accounts
Encryption at restNot specifiedRequired for customer NPI
Encryption in transitNot specifiedRequired for customer NPI
Penetration testingNot requiredAnnual (for 5,000+ customers)
Vulnerability scanningNot requiredBiannual (for 5,000+ customers)
Audit loggingNot specifiedRequired for detecting unauthorized access

New: Qualified Individual Requirement

The 2023 rule requires designation of a “qualified individual” — someone with knowledge, skills, and experience appropriate to run an information security program. This is more specific than the original “designate an employee” language. The qualified individual can be internal or a third party (such as a vCISO), but the financial institution must actively oversee them.

New: Annual Board Reporting

Organizations with 5,000+ customer records must now have the qualified individual report to the board of directors (or equivalent senior management) at least annually on the information security program. This elevates cybersecurity from a back-office IT function to a board-level governance item.

New: Written Incident Response Plan

The 2023 rule requires a formal, written incident response plan addressing goals, processes, roles, communications, and post-incident review. The original rule referenced incident response only in passing.

New: FTC Breach Notification (Finalized 2023, Effective 2024)

The FTC finalized a new breach notification requirement in October 2023, giving institutions a six-month runway before it took effect (see What Changed in 2024 below). Financial institutions must notify the FTC as soon as possible — and no later than 30 days after discovery — of a breach affecting 500 or more customers involving unencrypted customer information.

New: Service Provider Contractual Requirements

Contracts with service providers must now include requirements for the provider to implement appropriate safeguards and notify the institution if they experience a breach affecting the institution’s customer information.

What Changed in 2024

New: Breach Notification Requirement Took Effect

The FTC breach notification amendment officially became enforceable on May 13, 2024. Covered financial institutions must now report any “notification event” affecting 500 or more consumers to the FTC within 30 days of discovery, including the institution’s name, the date and scope of the breach, the type of information involved, and a summary of what happened.

New: Public Breach Database

The FTC began publishing submitted breach reports in a public database, using its Safeguards Rule Security Event Reporting Form. Unlike a private regulatory filing, this creates real reputational exposure — a reported breach is discoverable by customers, competitors, and the press, not just regulators.

New: Enforcement Against Poor Security Practices

In February 2024, the FTC settled with data platform provider Blackbaud, Inc. over Safeguards Rule violations tied to a 2020 breach that went undetected for three months and exposed unencrypted donor and customer data. The case reinforced that “reasonable safeguards” now means demonstrable technical controls, monitoring, and timely detection — not just a written policy on file.

What Changed in 2025

New: FTC FAQ Guidance on Practical Compliance

In June 2025, the FTC published detailed FAQ guidance clarifying how the Safeguards Rule applies in practice — initially aimed at motor vehicle dealers, but broadly instructive for any financial institution. The guidance reinforced that:

  • Encryption and multi-factor authentication are expected baseline controls, not optional best practices
  • Risk assessments must be tailored to the institution’s actual size, complexity, and the sensitivity of the customer data it holds — a generic, boilerplate risk assessment does not satisfy the rule
  • Continuous monitoring and regular penetration testing are expected as ongoing practices, not one-time projects
  • Vendor oversight obligations apply even to mandated or unavoidable third-party platforms — institutions can’t exempt a vendor from oversight just because using it isn’t optional
  • The definition of protected customer information (NPI) is broader than many institutions assume, covering data obtained in connection with any financial product or service

New: Broader Enforcement Reach

In December 2025, the FTC and the Colorado Attorney General reached a $24 million settlement with Greystar, the largest multifamily rental property manager in the U.S. The complaint alleged, among other things, that Greystar’s deceptive fee practices violated GLBA’s pretexting provisions by using false pretenses to induce consumers to hand over financial account information through rental applications. The case signals that GLBA enforcement is reaching well beyond traditional banks and lenders — any business that collects financial information as part of a transaction can be treated as a “financial institution” under the Act.

Small Business Exemption

The 2023 rule created a limited exemption for institutions with fewer than 5,000 customer records from the following requirements:

  • Annual penetration testing
  • Biannual vulnerability scanning
  • Written incident response plan (still recommended but not required)
  • Annual board reporting

These smaller institutions still must maintain a written information security program, designate a qualified individual, conduct risk assessments, implement access controls and encryption, and oversee service providers.

Key Implementation Deadlines (Now Past)

  • June 2023: Revised Safeguards Rule technical controls fully effective
  • October 2023: FTC finalizes the breach notification amendment
  • May 13, 2024: FTC breach notification requirement takes effect; public breach database goes live
  • February 2024: FTC settles first major Safeguards Rule enforcement action post-amendment (Blackbaud)
  • June 2025: FTC issues FAQ guidance clarifying encryption, MFA, risk assessment, monitoring, and vendor oversight expectations
  • December 2025: FTC/Colorado AG settlement signals GLBA enforcement extending beyond traditional financial institutions

All covered financial institutions should now be in full compliance with the 2023 and 2024 requirements, and should review the 2025 FTC guidance against their current program. Organizations that haven’t updated their programs accordingly face potential FTC enforcement if they experience an incident.

How Espresso Labs Helps

Espresso Labs builds and runs GLBA Safeguards Rule compliance programs as a managed service — giving financial institutions the technical controls, monitoring, breach reporting readiness, board reporting support, and vendor oversight they need to stay compliant with the 2023, 2024, and 2025 requirements without building a large internal security team. Contact us to assess your current Safeguards Rule gaps and see how quickly we can close them.

Frequently Asked Questions

Ready to Get Started?

CMMC compliance does not have to require a large internal team or a 6-figure budget. Espresso Labs delivers it as an automated, managed service so you can focus on winning contracts, not managing controls.

Talk to our team