FTC Safeguards Compliance
Lenders, underwriters, and insurers are starting to ask for proof of a real security program - not just a promise.
If your business handles customer financial data, federal law already requires you to have one. We do the heavy lifting - the risk assessment, the documentation, the incident response plan - and keep it accurate as your business changes, so you're never caught with an outdated program.






























Who this applies to, and why it matters
"Financial institution" sounds like it means banks. Under federal law, it also means mortgage lenders and brokers, title and escrow companies, CPA and tax firms, auto dealers who finance or lease, and consumer finance companies - among others. If that's you, this isn't optional. It's often the difference between:
- Keeping a lender or underwriter relationship, or losing it, because you can't produce proof of a real security program
- Having documentation ready the moment a regulator, insurer, or auditor asks - instead of scrambling to produce it after the fact
- Catching a gap before it becomes a breach, a lawsuit, or a penalty that was entirely avoidable
What the rule actually requires
The FTC Safeguards Rule (16 CFR Part 314) applies to a wider range of businesses than the name suggests - not just banks. If it applies to you, you need to:
Get a compliance assessmentName someone responsible for your security program
Complete a written risk assessment
Put technical safeguards in place: encryption, MFA, access controls and more
Test and monitor those safeguards on an ongoing basis
Vet and contractually bind vendors who touch customer data
Train staff who handle sensitive information
Maintain a written incident response plan
Report on the program's status to leadership periodically
Who we help
The Safeguards Rule reaches further than most people expect. Five industries make up the core of what we do.

Mortgage Lenders & Brokers
Named directly in the FTC's rule - coverage isn't in question.
- FHA-approved lenders must report a breach within 36 hours - a real, dated requirement that applies to most lenders your size.
- Fannie Mae, Freddie Mac, and Ginnie Mae now require larger seller/servicers and issuers to run documented, fast-reporting security programs.
- LoanDepot paid a $25M class-action settlement after a 2024 breach exposed 16.9 million customers' Social Security numbers.
- Real-estate wire fraud losses hit $275M in 2025, up from $173M the year before.

Title & Escrow Companies
Handling closing funds and buyer data puts you squarely under the rule.
- ALTA's own Best Practices standard already requires member title companies to have a written security program, privacy plan, and incident response plan.
- The FBI reported $275.1M in real-estate wire-fraud losses across more than 12,000 complaints in 2025.
- Multiple named title companies have disclosed ransomware breaches and class actions in the past year.

CPA & Tax Preparation Firms
The clearest coverage of any industry we work with - applies regardless of firm size, per the IRS's own guidance.
- The New York Attorney General settled with a small accounting firm for $60,000 after it failed to encrypt client Social Security numbers.
- The AICPA's own ethics code treats weak data security as a professional violation - separate from the FTC angle.
- We keep your program audit-ready year-round - tracked, updated, and ready to show - instead of a one-time document that goes stale.

Auto Dealers
Covered if you finance, arrange financing, or lease vehicles for more than 90 days.
- The 2024 CDK Global ransomware attack disrupted roughly 15,000 dealerships and cost the industry more than $1 billion.
- The FTC's 2019 settlement with DealerBuilt remains a live enforcement precedent for exactly this kind of documentation gap.
- Dealer financing almost always triggers the Red Flags Rule, requiring a written Identity Theft Prevention Program built around how your F&I department actually works.

Consumer Finance Companies
Named directly as a covered financial institution - no ambiguity about whether this applies to you.
- Real breaches have hit peer lenders, exposing Social Security numbers and financial account data.
- Cyber insurers increasingly require a documented security program before they'll bind or renew coverage.
- Very few providers build specifically for this industry - most treat it as an afterthought.
Don't see your industry? The rule covers more than these five. Reach out and we'll help you find out if it applies to you.




Download: The FTC Safeguards Rule Checklist
A short, plain-English breakdown of all 9 required elements. Free, no obligation.

What you get
Concrete, audit-ready deliverables - not a stack of generic templates.
A written security program (WISP), built around your actual environment
A real risk assessment - not a checkbox exercise
An incident response plan with a clear notification process
A tracked risk register - every open gap has an owner and a deadline
Regular reporting on your program's status
Once you're on board, we don't just send you a questionnaire - we take a real look at your systems too. Most compliance gaps live in the space between what a form says and what's actually there, and that's exactly where we look first.
Compliance questions, answered
The questions we hear most from owners weighing whether the Safeguards Rule applies to them.
