The FTC’s Safeguards Rule compliance deadline is right around the corner – June 9. The Safeguards Rule requires non-banking financial institutions to develop, implement, and maintain a comprehensive security program to keep their customers’ information safe (we discussed the Safeguards Rule in a previous blog post here).
Many provisions of the rule went into effect 30 days after publication of the rule in the Federal Register. Other sections of the rule were set to go into effect on December 9, 2022. The provisions of the updated rule specifically affected by the six-month extensioninclude requirements that covered financial institutions:
- designate a qualified individual to oversee their information security program,
- develop a written risk assessment,
- limit and monitor who can access sensitive customer information,
- encrypt all sensitive information,
- train security personnel,
- develop an incident response plan,
- periodically assess the security practices of service providers, and
- implement multi-factor authentication or another method with equivalent protection for any individual accessing customer information.
Putting in into Practice: Financial institutions should continue in their efforts to expeditiously comply with all of the new requirements of the rule.