FTC Safeguards Rule (GLBA) Readiness Assessment
The FTC Safeguards Rule (16 CFR Part 314, issued under the Gramm-Leach-Bliley Act) reaches the non-bank businesses the FTC calls financial institutions — auto dealers that arrange financing, mortgage brokers and lenders, finance companies, tax-preparation and accounting firms, collection agencies, credit counselors and investment advisers not registered with the SEC — and since its 2023 amendments it names the controls: a designated Qualified Individual, a written risk assessment, eight specific safeguards including multi-factor authentication and encryption, testing, training, service-provider oversight, a written incident response plan, an annual report to the board and, since 13 May 2024, notice to the FTC within 30 days when unencrypted information on 500 or more consumers is taken. This is a fixed-price, three-week readiness assessment that reviews each of those program elements against what your business actually has, maps the technical safeguards to the Microsoft 365 controls you already license — Microsoft Entra MFA and Conditional Access, Purview data inventory, DLP and sensitivity labels, encryption in transit and at rest including encrypted email, Intune, audit logging, retention and disposal — and hands you a gap report and roadmap, a written information security program (WISP) outline, a service-provider oversight checklist, an incident-response and FTC-notification procedure, and a board-report template. $3,950 fixed for one Microsoft 365 tenant and one information security program. We are Microsoft 365 engineers, not a law firm: whether the rule covers you and what a notice must say are your counsel's calls, and this engagement is built to hand them evidence. You keep the Qualified Individual designation, and nothing here certifies or guarantees compliance — no assessment from anyone can.
What this engagement is
The Safeguards Rule used to ask for 'reasonable' safeguards and leave the rest to you. The amended rule, in force since June 2023, names them: a Qualified Individual who owns the program, a written risk assessment, eight specific safeguards in 16 CFR 314.4(c) — access controls, a data and systems inventory, encryption of customer information in transit over external networks and at rest, secure development practices, multi-factor authentication for anyone accessing any information system, secure disposal, change management, and logging of user activity — plus testing or continuous monitoring, staff training, oversight of service providers, a program that is kept current, a written incident response plan and an annual written report to your board or senior officer. In November 2023 the FTC added a notification duty that took effect on 13 May 2024: when unencrypted customer information on 500 or more consumers is acquired without authorization, the FTC is told as soon as possible and no later than 30 days after discovery. In June 2025 the FTC published FAQs for auto dealers that, among other things, make clear that a vendor you were required to use by your manufacturer is still your service provider to oversee. The businesses in scope are mostly 10-500 seat organizations with no security team — dealerships and dealer groups, mortgage and finance companies, tax and accounting firms, collection agencies, advisers — running Microsoft 365, with the customer information that matters living in a dealer management system, a tax or CRM platform and, more than anyone admits, in email, shared mailboxes, OneDrive and Teams. This assessment starts with coverage, because everything else depends on it: with your counsel's input we record why the business is (or is not) a financial institution under the rule's definition, roughly how many consumers' information you hold — the rule's 314.6 exceptions relieve institutions holding information on fewer than 5,000 consumers of the written risk assessment, the penetration-testing cadence, the written incident response plan and the annual report, but not of MFA, encryption or the other safeguards — and which systems hold customer information. Then we review all nine program elements by interview and by document: who the Qualified Individual is and whether the designation is written down, whether a risk assessment exists and says what the rule wants it to say, what training has happened, which vendors have access and what their contracts require, what the incident plan says, and when the board last received a report. The technical safeguards get the deep treatment, read-only, in your tenant: MFA coverage for every identity including administrators, shared mailboxes and service accounts, Conditional Access and legacy-authentication exposure, privileged roles, Purview's data classification against the sensitive information types that define this data — Social Security numbers, bank account and card numbers, driver's license numbers — DLP and sensitivity labels, encryption in transit and at rest including Purview Message Encryption for mail to consumers, BitLocker and device compliance through Intune, Purview audit logging and its retention period, retention and deletion policies against the rule's disposal expectation, external sharing and guest access, and what Defender is watching. Each of the eight safeguards ends up in a control map that names the setting, the workload and the evidence — the exhibit an examiner, a carrier or a manufacturer audit actually asks for. What you receive is built to be used, not filed. The gap report ties every finding to the paragraph of 314.4 it serves and ranks it by exposure and effort. The roadmap names the setting, the workload and the owner for each item and separates what your own staff can do next week from what needs an engagement — commonly MFA for every user, DLP policies for the data types the rule protects, encrypted email, security awareness training and phishing simulation for the training element, and managed detection and response where the Qualified Individual chooses continuous monitoring over annual penetration testing. The WISP outline gives your program the structure the rule expects, with the client-specific content marked for you and counsel to complete. The service-provider oversight checklist and vendor register turn 314.4(f) into a list with names on it. The incident-response and FTC-notification procedure puts the 500-consumer, 30-day trigger and the contents of the notice into a page your team can follow at 2 a.m. The board-report template covers what 314.4(i) says the annual report must address. When the assessment is done, the Compliance Evidence and Audit Readiness Retainer can keep the evidence current month by month, and the Virtual CISO retainer can support the person you designate as Qualified Individual. Three things we say plainly because the market does not. We are Microsoft 365 engineers, not a law firm, a CPA firm or a certification body: the coverage determination, the reading of any state breach law and the wording of a notice belong with your counsel, and our regulatory summaries are our engineering reading of the public rule text and the FTC's business guidance as of September 2026. The Qualified Individual is yours — the rule lets a service provider's employee hold the role, but only if you retain responsibility for compliance, designate a senior member of your own staff to direct and oversee that person, and require the provider to keep its own information security program; this engagement does not take the designation, and it says so in the report. And nothing certifies FTC Safeguards compliance — there is no certificate, and a vendor selling one is telling you something about themselves. What exists is a documented program with evidence behind it, and that is what this assessment produces for the Microsoft 365 part of your business.
Success criteria
What you receive
How the work unfolds
We record your coverage position with counsel's input, the consumer-count band that decides the 314.6 exceptions, the entities and locations that share the tenant and the program, and the systems that hold customer information. Read-oriented, time-bound access to Microsoft 365, Entra ID, Purview, Intune and Defender is granted for the engagement window, and the documents that exist — WISP, risk assessment, incident plan, training records, vendor contracts, last board report — are collected. Absence is a finding, not a blocker.
Structured interviews with the Qualified Individual or the person you intend to designate, the owner or controller, and whoever runs IT: how the program is run today, who decides, what has been written down, what training has happened, which vendors touch customer information and under what contract, what happens when something goes wrong. Each of the nine elements gets a draft finding.
Read-only review of the tenant against the eight 314.4(c) safeguards: MFA and Conditional Access for every identity, legacy authentication, privileged roles, Purview data classification for Social Security, bank account, card and driver's license numbers across Exchange, SharePoint, OneDrive and Teams, DLP and sensitivity labels, encryption in transit and at rest and encrypted email, BitLocker and device compliance in Intune, Purview audit status and retention, retention and deletion policies, external sharing and guest access, Defender coverage. Evidence is exported to your SharePoint as it is gathered.
Every vendor with access to customer information — dealer management system, CRM, tax or practice software, lender and finance portals, e-signature, document storage, payroll, your IT provider, and any platform your manufacturer requires — is registered with the contract security language you supply, the evidence you hold, and a reassessment cadence. Microsoft's side is documented from its published Product Terms and audit reports.
Findings are validated with your stakeholders, ranked by exposure and effort, and assembled into the gap report and roadmap. The WISP outline, the service-provider oversight checklist, the incident-response and FTC-notification procedure and the board-report template are drafted from the findings, with counsel's items marked.
The report, roadmap and program documents are presented to the owner or senior leadership and the Qualified Individual. We walk the priority items, agree what your own staff execute from the roadmap and what, if anything, is scoped as separate fixed-price work, and remove our access.
Prerequisites
Who does what
IT Partner
- Record the coverage position and the scope with the reasoning written down, and state in the report what was and was not assessed.
- Review all nine program elements by interview and by document, and document a finding for each with its 314.4 citation and evidence.
- Review the Microsoft 365 tenant read-only against the eight 314.4(c) safeguards and export the evidence to your SharePoint as it is gathered.
- Build the service-provider register and oversight checklist from the vendor list and contracts you supply.
- Rank the gaps by exposure and effort and produce the roadmap with settings, workloads and owners named.
- Draft the WISP outline, the incident-response and FTC-notification procedure and the board-report template from the findings, marking every item that needs counsel's or the business's input.
- Deliver the readout in plain language, answer the Qualified Individual's platform questions, and remove our access at the end.
Your team
- Own the determination of whether the rule applies to the business, made with counsel, and the reading of any state breach-notification law.
- Designate and retain the Qualified Individual; where a service provider's employee holds the role, retain responsibility for compliance, designate a senior member of your staff to direct and oversee that person, and require the provider to maintain its own information security program.
- Provide access, stakeholders, the vendor list, contracts and existing documents on the agreed schedule.
- Report the MFA and security status of non-Microsoft systems as you understand it; we list them, we do not test them.
- Validate draft findings for factual accuracy within the review window.
- Decide remediation priorities and own the risk acceptance for gaps deliberately left open.
- Complete the WISP, the procedure and the board report from the outlines with counsel's input, execute the roadmap internally or scope follow-on work separately, and maintain the program over time — a point-in-time report ages as the tenant changes.
What's not included
Limitations & technical notes
Frequently asked questions
Does the FTC Safeguards Rule apply to our business?
If you are significantly engaged in providing financial products or services to consumers and no other federal regulator has enforcement authority over you, the FTC's reading is that you are a financial institution under its rule. The FTC's own examples include mortgage lenders and brokers, payday lenders, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisers, tax-preparation firms, non-federally insured credit unions, investment advisers not required to register with the SEC, and — through their financing activity — automobile dealers. That is our reading of the rule's definitions and the FTC's guidance, not a legal opinion; the determination is yours and your counsel's, and the first deliverable records it with its reasoning.
What does the rule actually require?
Nine things, as we read 16 CFR 314.4: designate a Qualified Individual to own the program; base the program on a written risk assessment; implement eight named safeguards — access controls, a data and systems inventory, encryption in transit and at rest, secure development practices for in-house applications, multi-factor authentication, secure disposal, change management, and logging and monitoring of user activity; test or continuously monitor; train staff; oversee service providers; keep the program current; maintain a written incident response plan; and report in writing to the board or a senior officer at least annually. Since 13 May 2024 there is a tenth duty: notify the FTC within 30 days of discovering that unencrypted customer information on 500 or more consumers was acquired without authorization.
We hold information on fewer than 5,000 consumers. Are we exempt?
Partly, and not from the parts that bite. As we read 314.6, an institution holding customer information on fewer than 5,000 consumers is relieved of the written risk assessment, the penetration-testing and vulnerability-assessment cadence, the written incident response plan and the annual board report. It still needs a Qualified Individual, a risk assessment on which the program is based, all eight safeguards including MFA and encryption, training, service-provider oversight and the FTC notification duty. Counting is also less obvious than it sounds — applicants and former customers count, and a dealership that has been financing cars for a decade usually crosses the line. We record the band you are in and counsel confirms the position.
Does the rule really require MFA on everything — even the dealer management system?
As written, 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system, unless your Qualified Individual approves in writing reasonably equivalent or more secure access controls. That reaches the DMS, the CRM, lender portals, remote access and email alike. In Microsoft 365 we verify MFA and Conditional Access coverage for every identity — users, administrators, shared mailboxes, service accounts — and whether legacy authentication is still letting passwords through the back door. For the non-Microsoft systems we list what you report and flag every 'off' for the Qualified Individual's attention; where a vendor genuinely cannot do MFA, the written exception is theirs to approve and document, and we say so.
We are on Microsoft 365. Does that make us compliant?
No — but it gives you most of the technical safeguards without buying anything. Microsoft 365 Business Premium, for example, already carries Conditional Access for MFA, Purview data classification and DLP, service-side encryption at rest and TLS in transit, encrypted email, Intune for device encryption and compliance, retention policies for disposal, audit logging and Defender for Business. Whether those controls are switched on, cover everyone and are evidenced is the question, and default settings are tuned for collaboration, not for 314.4(c). Measuring that gap, setting by setting, is what the control map does. The organizational elements — Qualified Individual, risk assessment, training, vendor oversight, incident plan, board report — no platform can do for you.
What is the FTC notification requirement?
Since 13 May 2024, as we read 314.4(j), a notification event — unencrypted customer information on at least 500 consumers acquired without authorization — must be reported to the FTC as soon as possible and no later than 30 days after discovery, using the FTC's reporting form. The notice covers who you are, the types of information involved, the date or date range if you can determine it, the number of consumers affected and a general description of what happened. Information counts as unencrypted if the encryption key was also taken. This is separate from the state breach-notification laws that govern notice to the consumers themselves, which is where counsel comes in. Our procedure puts the trigger, the decision points and the contents on one page; the decision to file is counsel's.
Can you be our Qualified Individual?
Not in this engagement, and we think you should be careful about anyone who offers it as a line item. The rule allows the Qualified Individual to be employed by a service provider, but only if you retain responsibility for compliance, designate a senior member of your own staff to direct and oversee that person, and require the provider to maintain its own information security program. The designation, in other words, never really leaves your building. What we offer is support for the person you designate — the Virtual CISO retainer gives them a security program, policy governance and reporting cadence — while the role and the accountability stay with you.
Is this a penetration test?
No. The rule's testing element, 314.4(d), gives the Qualified Individual a choice: continuous monitoring, or an annual penetration test plus vulnerability assessments at least every six months and whenever the environment materially changes. This assessment documents which path you are on and what evidence it needs. For many Microsoft 365 organizations the practical answer is continuous monitoring — Defender's vulnerability management and a managed detection service watching the tenant and endpoints — and we say when that is the better fit. Whether it satisfies the rule for you is the Qualified Individual's documented decision; a penetration test, if you choose that path, is separate work from a testing provider.
What is a WISP and do you write it for us?
A written information security program is the document the rule expects your program to live in — who the Qualified Individual is, what the risk assessment found, what safeguards you run, how you test, train, oversee vendors, respond to incidents and report to the board. We deliver the outline: the structure section by section, with the Microsoft 365 findings already in the places they belong and the business-specific and legal content clearly marked. You and counsel complete it, or the vCISO retainer helps you do so. Tax and accounting firms should note that the IRS separately expects paid preparers to maintain a written information security plan and points at the same Safeguards Rule; the same document does double duty.
We are a dealership. What about the DMS, the OEM tools and the lender portals?
They are where most of your customer information actually lives, and the rule treats every one of those vendors as a service provider you must select carefully, bind by contract and periodically reassess. The FTC's June 2025 FAQs for auto dealers make the point that a platform your manufacturer requires you to use is still your service provider to oversee — being mandated is not an exemption. We do not assess those systems' configuration; we put every one of them in the vendor register with the MFA and security status you report, the contract language you hold, and what to ask for, so your oversight has names and dates on it. The Microsoft 365 side — where deal documents get emailed, scanned to OneDrive and shared in Teams — we assess in depth.
We are a tax or accounting firm. Anything different for us?
The platform mechanics are the same, but the data is denser — Social Security numbers, bank account numbers and full returns arrive by email and portal every day, and the seasonal rhythm means staff, devices and shared mailboxes change fast. Purview's data classification usually shows returns and W-2s sitting in mailboxes and OneDrive well beyond the season, which is exactly what the disposal safeguard is about, and encrypted email for outbound client documents is the single most common gap. The IRS's own expectations for tax professionals point at the same rule, so the WISP outline serves both.
What does the remediation roadmap look like, and can you do the work?
A ranked list, not a lecture: each item names the finding it closes, the 314.4 paragraph it serves, the setting and workload, an effort class, and whether your own team can do it from the report. Quick wins — MFA gaps, legacy authentication, anonymous-link settings, audit logging — are separated from projects such as a DLP rollout for the data types the rule protects, encrypted email, or retention design. Yes, we can execute any of it as separately quoted, fixed-price work, and deliberately not as part of the assessment, so the findings stay honest and you keep the choice of who fixes what. Many clients do the quick wins themselves, which we consider a good outcome.
How much of our staff's time does this take?
A handful of hours. The technical review is read-only work in admin portals — no configuration changes, no agents, no downtime, no access to customer records. The human load is the interviews in week one (the Qualified Individual or the person you intend to designate, the owner or controller, whoever runs IT), assembling the vendor list and any existing documents, a validation pass in week three and the readout. If your IT is outsourced, your provider joins the technical questions; they are usually a vendor in the register too.
Why is the price fixed at $3,950, and what does it cover?
Because the scope is fixed: one Microsoft 365 tenant, one information security program, the nine-element review, the eight-safeguard control map, the program documents and three weeks. A dealer group or firm with several locations or affiliated entities sharing one tenant and one program is one engagement. Separate tenants, or separately regulated entities that need their own programs, are quoted in writing before anything starts. The price is quoted in writing before work begins and you pay after you approve delivery; if the scoping call shows the fit is wrong, we say so then, not mid-project.