What Is the FTC Safeguards Rule?
The FTC Safeguards Rule (updated and effective June 9, 2023) requires financial institutions to develop, implement, and maintain a comprehensive information security program. This is not optional — it is a federal mandate with real enforcement consequences.
The rule applies to a broad range of businesses that handle consumer financial data, far beyond what most people consider "financial institutions."
Who Must Comply with the FTC Safeguards Rule?
The Safeguards Rule applies to all "financial institutions" under the FTC's jurisdiction, including:
- CPA firms and accounting practices — all sizes, including solo practitioners
- Tax preparation services — including seasonal preparers
- Financial advisors and planners — RIAs, fee-only advisors, broker-dealers
- Mortgage brokers and lenders — including loan officers
- Real estate settlement services — title companies, escrow agents
- Auto dealerships — any dealer that arranges financing
- Payday lenders and collection agencies
- Investment companies not regulated by the SEC
If your business handles consumer financial information in any capacity, you likely must comply.
→ Check your compliance exposure — compare cyber insurance quotes free
Key Requirements of the Safeguards Rule
The updated rule requires these specific security measures:
- Designate a Qualified Individual to oversee your security program
- Conduct a risk assessment identifying threats to customer information
- Implement safeguards including access controls, encryption, MFA, and secure disposal
- Monitor and test your security controls regularly
- Train employees on security awareness and procedures
- Create an incident response plan for data breaches
- Assess service providers who access customer data
- Report to your board (or senior leadership) on security program status
Penalties for Non-Compliance
The FTC has enforcement authority and has been increasingly active:
- Fines up to $50,120 per violation (adjusted annually for inflation)
- Consent orders requiring ongoing compliance monitoring at your expense
- Mandatory third-party audits for years after an enforcement action
- Public disclosure of enforcement actions — reputation damage to your firm
- Personal liability — the FTC can pursue individual officers and directors
How Cyber Insurance Supports FTC Compliance
While cyber insurance does not replace a security program, it is a critical safety net:
- Regulatory defense coverage pays legal costs if the FTC investigates or brings an enforcement action against your firm
- Breach response services help you execute your incident response plan (a Safeguards Rule requirement)
- Risk assessment tools provided by many carriers help you identify and address security gaps
- Vendor assessment resources help evaluate third-party service providers (another requirement)
- Compliance documentation — having cyber insurance demonstrates to regulators that you take data security seriously
→ Compare FTC compliance cyber insurance quotes from top carriers
Top Carriers for Safeguards Rule Coverage
- Hartford: Strong regulatory defense coverage, compliance resources, competitive rates for small financial firms
- Chubb: Premium coverage with dedicated regulatory defense limits, proactive compliance support
- Hiscox: Affordable policies for solo practitioners and small firms, built-in regulatory defense
- Cowbell: Continuous compliance monitoring with AI-driven risk assessment
Cost of Compliance Cyber Insurance
| Business Type | Typical Premium |
|---|---|
| Solo tax preparer/CPA | $500–$1,200/yr |
| Small accounting firm | $1,200–$2,500/yr |
| Financial advisor/RIA | $1,000–$2,000/yr |
| Mortgage broker | $1,200–$2,800/yr |
| Auto dealership (F&I) | $2,000–$4,000/yr |
The cost of a cyber insurance policy is a fraction of a single FTC fine — and far less than the cost of an enforcement action.
→ See what your business would pay — get a free compliance quote





