s90

Home / Compliance / FTC Safeguards Rule

For non-bank financial businesses under the FTC

Compliance: FTC SafeguardsRegulated

Proof your security program has every control the FTC requires.

The FTC Safeguards Rule requires a written information security program with specific controls: a qualified individual in charge, a risk assessment, multi-factor authentication, encryption, monitoring and a written report to leadership every year. Compliance: FTC Safeguards gives you quarterly evidence for each one, without you having to ask.

A Dell laptop in a small lending office with a hardware security key plugged into its side, beside a closed loan file and a pen.

At a glance

Package
Compliance: FTC Safeguards
Evidence
Compliance Posture Report, quarterly
Stacks on
Complete IT: Managed or Co-Managed

Does this apply to you?

It likely applies if your firm is one of these:

What the rule asks for, and what you receive.

  1. 01

    Keep a written information security program overseen by a qualified individual

    Documentation of the program and the controls behind it

    Evidence your qualified individual can use in the annual report to leadership

  2. 02

    Complete a written risk assessment

    Risk assessment support, kept current

    Risk assessment records

  3. 03

    Use access controls, encryption and multi-factor authentication

    Access controls, encryption and multi-factor sign-in

    Multi-factor authentication and encryption evidence

  4. 04

    Monitor continuously or test regularly, and train staff

    Monitoring, testing and awareness training

    Monitoring and testing records

  5. 05

    Oversee service providers and keep an incident response plan

    A service provider inventory and a response runbook

    Provider reviews and incident records

  6. 06

    Notify the FTC within 30 days of a breach involving 500 or more people

    The incident facts the notice needs

    A timeline record for every incident

  7. 07

    Report to your leadership in writing at least once a year

    The evidence the report needs, gathered every quarter

    The Compliance Posture Report itself

We provide the evidence. You decide.

s90 does

  • Runs the controls the framework calls for
  • Keeps the documentation current
  • Delivers a Compliance Posture Report every quarter

You decide

  • Whether the evidence meets your obligations
  • Which open gaps to close first
  • Whether your firm is compliant

The Compliance Posture Report

Scoped to FTC Safeguards, delivered every quarter without asking. The proof in your hands is never more than three months old.

Get the sample Compliance Posture Report by email

Sample · Compliance Posture Report

ACME Corp · Quarter 3 · FTC Safeguards

Evidence your qualified individual can use in the annual report to leadership
Current
Risk assessment records
Current
Multi-factor authentication and encryption evidence
Enforced

Sample report for a fictional business. Example figures.

Other frameworks you may answer to.

Bundle discounts available.

Low-rise office buildings with tile roofs among oaks and palms in the south Orange County foothills, with Saddleback Mountain in the morning haze beyond.
s90

One question to ask yourself

If the FTC or an insurer asked tomorrow, could your firm show the evidence?

Up to$500,000Cyber WarrantyBacked by Cork Inc.

In 30 minutes, we talk through your setup and you leave knowing which plan fits.

Book a call

See exactly what you'd receive each quarter, by email.

Get the sample Posture Report by email