Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeServicesFTC Safeguards Rule Compliance
New from The NetSys Group

FTC Safeguards Rule Compliance for Auto Dealers, Accountants and Non-Bank Lenders

FTC Safeguards Rule compliance became a specific engineering job when the FTC rewrote the rule. It no longer asks for a 'reasonable' program in the abstract; it names the controls: a qualified individual, a written risk assessment, encryption, multifactor authentication, logging, testing, vendor oversight and an incident response plan. NetSys implements those for dealerships, accounting firms and lenders with no security staff, and keeps the records.

Take a Free Assessment

The short answer

The FTC Safeguards Rule, part of the Gramm-Leach-Bliley Act, requires non-bank financial institutions under the FTC's jurisdiction to develop, implement and maintain a written information security program to protect customer information. Covered businesses include auto dealers that arrange financing or leasing, mortgage brokers and non-bank lenders, tax preparers and accounting firms, collection agencies and similar firms. The rule requires a designated qualified individual, a written risk assessment, access controls, encryption, MFA for anyone accessing customer information, logging, testing, training, service provider oversight, an incident response plan and reporting to leadership. NetSys delivers FTC Safeguards Rule compliance as a managed engagement, implementing and operating the controls and supporting the qualified individual. We are not a law firm and cannot certify compliance.

FTC Safeguards Rule Compliance by The NetSys Group

A dealership's F&I office holds credit applications for thousands of people. A tax practice holds every client's Social Security number and bank account. Neither thinks of itself as a financial institution, but the FTC does. The IRS reinforces it for tax professionals by requiring a written information security plan.

Our FTC Safeguards Rule compliance work maps each element of the rule to a control we can configure, a document we can draft with you, or a record we can produce. The dealer management system, the tax software, the shared drive and the email tenant are all in scope, and the rule's requirement for MFA applies to every one of them. We build the program so the qualified individual has something true to report.

Inventory the Customer Information, Then Protect Every Path to It

We begin with a free assessment or our free Tier 1 external penetration test. Then we inventory where customer information lives and flows, write the risk assessment with your qualified individual, and implement the controls: MFA and conditional access in Entra ID, device encryption through Intune, email encryption and data loss prevention, endpoint detection with monitoring, logging, backups and secure disposal. Service providers who touch customer information are inventoried and their contracts reviewed. Testing and reporting go on a calendar, so the annual written report to ownership is assembled from records.

What Our FTC Safeguards Rule Compliance Covers

Program and Qualified Individual

The rule wants a named person and a written plan.

  • Qualified individual designated, with vCISO support or a vCISO in the role as the rule permits
  • Written information security program and risk assessment, tailored to your business
  • Annual written report to the board or owners, prepared from evidence
  • Policies for access, retention, disposal and change management

Required Technical Controls

Encryption, MFA, logging and the rest, as configured systems.

  • MFA for every user who reaches customer information, including the DMS and tax software
  • Encryption of customer information at rest on devices and in transit by email
  • Access controls and a data inventory that limit who can see what
  • Activity logging and monitoring for unauthorized access, with alerts reviewed

Testing and Vendor Oversight

Prove the controls work; make vendors prove theirs.

  • Penetration testing and vulnerability assessments on the rule's schedule, or continuous monitoring in their place
  • Service provider inventory, due diligence questionnaires and contract terms requiring safeguards
  • Secure disposal of customer information when it is no longer needed
  • Security awareness training with phishing simulations built on dealership and tax-season lures

Incident Response and Evidence

A plan before the breach, and records after.

  • Written incident response plan with roles, notification duties and counsel's role defined
  • Backups tested for restoration and a disaster recovery plan
  • Evidence organized by rule element for the FTC, insurers and, for tax firms, the IRS
  • Delivered remotely nationwide; on-site in our coverage areas
Why NetSys

Why Dealers and Firms Choose NetSys for FTC Safeguards Rule Compliance

Let The Netsys Group assess and help you resolve your exposure. Call 845-203-3914 for your complimentary risk assessment consultation today!

  • Every element of the amended rule is tied to a specific control, document or record
  • MFA, encryption, monitoring and disaster recovery are included in the managed agreement
  • Experience with the dealer management systems and tax platforms the rule sweeps in
  • A vCISO can carry the qualified individual role for firms with no security staff
  • Month to month, starting with a free assessment or free external penetration test
Common Questions

FTC Safeguards Rule Compliance FAQs

What is the FTC Safeguards Rule?

The Safeguards Rule is the Federal Trade Commission's regulation under the Gramm-Leach-Bliley Act requiring non-bank financial institutions to protect customer information with a written security program. The amended rule specifies the program's elements: a qualified individual, a risk assessment, access controls, encryption, MFA, logging, testing, training, vendor oversight, secure disposal, an incident response plan and reporting to leadership, plus notice to the FTC after qualifying security events.

Who has to comply with the FTC Safeguards Rule?

Financial institutions that are not regulated by a federal banking agency or the SEC: auto dealers that finance or lease vehicles, mortgage brokers and lenders, tax preparers and accounting firms that prepare returns, payday and consumer lenders, and collection agencies. Smaller firms holding limited customer information are exempt from some written-program elements but never from the core safeguards.

How much does FTC Safeguards Rule compliance cost?

It depends on how many systems hold customer information and how much of the required control set already exists. For a NetSys managed client the technical controls are part of the monthly agreement, so the added cost is the program documents, vendor reviews and qualified individual support. We do not publish prices. A free assessment establishes what is missing before anyone talks numbers.

What does the Safeguards Rule require of auto dealers?

A dealership that arranges financing is a financial institution under the rule, so it needs the full program: a qualified individual, a risk assessment covering the DMS, F&I tools and email, MFA on those systems, encryption of customer data, logging, vendor oversight of the DMS and lender portals, staff training, an incident response plan and an annual report to ownership.

Can NetSys be our qualified individual?

The rule allows the qualified individual to be employed by the institution, an affiliate or a service provider, provided the institution keeps responsibility for compliance, designates a senior employee to direct and oversee the qualified individual. A NetSys vCISO can fill the role on that basis. We still cannot certify compliance; the program remains yours and the FTC judges it.

Do accountants and tax preparers have to comply with the FTC Safeguards Rule?

Yes. Tax preparation is a financial activity, so CPA firms, enrolled agents and other preparers that hold client information are covered. The IRS separately requires paid preparers to maintain a written information security plan and asks about it at PTIN renewal. One program satisfies both; we build it to the Safeguards Rule's element list and format the WISP the way IRS guidance describes.

Ready to get started?

Protect your business before the next threat strikes.

Take control of your security today. Schedule your comprehensive cybersecurity assessment with The NetSys Group and stay one step ahead of every threat.