Compliance · FTC Safeguards Rule

FTC Safeguards Rule compliance in Tulsa — the written information security program, done and kept current

The IRS asks about your WISP at PTIN renewal. Your cyber-insurance application asks about MFA and backups. The Safeguards Rule asks for a qualified individual, a risk assessment, and a program in writing — and since 2024, for a report to the FTC if enough client records are ever exposed. They are all asking for the same thing: proof. You should not have to become a security officer to run a CPA firm or a dealership.

Quick answer: NSN Management provides FTC Safeguards Rule compliance services in Tulsa for CPA firms, tax preparers, auto dealers with financing, and mortgage brokers: a written information security program (WISP) aligned to 16 CFR Part 314 and IRS Publication 4557, a documented risk assessment, MFA, encryption, monitoring, training, vendor oversight, and an incident-response plan — from a Tulsa-owned IT team.
Who it applies to

Who the Safeguards Rule applies to

Under the Gramm-Leach-Bliley Act, a surprising number of ordinary businesses are “financial institutions.” If you are one, the Rule applies whether you have five people or fifty.

  • CPA firms, tax preparers, and enrolled agents — anyone who prepares returns for compensation (the IRS points to the same WISP in Publication 4557 and at PTIN renewal)
  • Auto dealers that arrange or provide financing or leasing, and other retailers that extend credit
  • Mortgage brokers and lenders, non-bank finance companies, payday and title lenders, check cashers, and collection agencies
  • Investment advisers not registered with the SEC, financial planners, real-estate settlement services, and “finders” that connect consumers to lenders
  • Businesses holding information on fewer than 5,000 consumers are exempt from a few elements — the written risk assessment, the written incident-response plan, and the annual written report — but not from the safeguards themselves
What the rule says

What the Safeguards Rule requires

The 2021 amendments, in force since June 2023, replaced “reasonable safeguards” with a specific list. Here it is in plain language.

  • A qualified individualOne named person — an employee or a service provider — accountable for the information security program, reporting to your ownership or board at least annually in writing.
  • A written risk assessmentIdentify where customer information lives and what threatens it, rate the risks, and reassess periodically.
  • Specific safeguardsAccess controls and least privilege; an inventory of data, systems, and devices; encryption of customer information at rest and in transit; secure development practices for any in-house software; multi-factor authentication for anyone accessing customer information; secure disposal within two years of last use; change management; and monitoring and logging of who accesses customer information and what they do.
  • TestingContinuous monitoring, or an annual penetration test plus vulnerability assessments at least every six months and whenever there is a material change.
  • Training, vendors, and upkeepSecurity-awareness training for staff; selecting and periodically assessing service providers and requiring safeguards by contract; and keeping the program current as your business and the threats change.
  • Incident response and FTC notificationA written incident-response plan; and, since May 2024, notification to the FTC within 30 days of discovering an event in which unencrypted information on 500 or more consumers was acquired without authorization.
Included

What NSN Management does for Safeguards Rule compliance

The Rule was written with an IT program in mind. Most of its elements are things a well-run managed IT service already does — the work is doing them on purpose and writing them down.

  • The written information security program (WISP), drafted with you and aligned to 16 CFR Part 314 and IRS Publication 4557, naming the qualified individual and documenting every control below
  • A written risk assessment — data and system inventory, threats, likelihood and impact, and a treatment plan — repeated on a schedule
  • Multi-factor authentication on email, remote access, tax and practice software, and administrative accounts
  • Encryption at rest on laptops, servers, and removable media, and in transit; secure client portals in place of email attachments
  • Access controls and least privilege, with joiner/leaver procedures for seasonal staff
  • Endpoint detection and response, patching, email security, and centralized logging — continuous monitoring in the Rule’s sense — with alerts reviewed by people
  • Vulnerability assessments on the Rule’s cadence, and coordination of penetration testing where you choose that route
  • Secure disposal procedures for devices and data, and change management for the systems that hold customer information
  • Security-awareness training with completion records, and a vendor-oversight list with the contract language the Rule expects
  • A written incident-response plan mapped to the FTC’s 30-day notification requirement, and the annual written report to ownership — drafted for the qualified individual to sign

What this service is — and isn’t

NSN Management is a managed IT provider, not a law firm. We implement and document the safeguards, draft the WISP with you, and can serve as — or support — your qualified individual for the technical program; interpretation of the Rule for your specific business, and any regulatory correspondence, belongs with your counsel. The IRS, the FTC, and your carrier each want to see the program working; our job is to make sure it is.

The plan

How it starts

Where you stand today, what the rule actually asks of a business your size, and the shortest honest path between the two.

  1. Book a Discovery Call

    A focused conversation about how FTC Safeguards touches your business, what you already have in place, and what is being asked of you — no obligation, no scare tactics.

  2. Get a gap assessment

    We compare the rule’s requirements to your actual environment and documentation and hand you a plain-language plan: what is done, what is missing, and what to fix first.

  3. Implement, document, maintain

    The safeguards go in, the documentation gets written, your people get trained — and the same team keeps it current as the rule and your business change.

Outcomes

What changes for you

  • A WISP that is realA program you can hand to the IRS, the FTC, a carrier, or a client — because the controls in it are actually running.
  • Busy season protectedMFA, endpoint detection, and tested backups where the phishing and the ransomware actually land.
  • A qualified individual with backupOne accountable name, and a team behind it doing the monitoring, testing, and reporting.

What the gap costs

  • A PTIN renewal or an IRS Publication 4557 checklist answered “yes” with no WISP behind it
  • A phished email account during tax season exposing hundreds of client returns — and a 30-day clock to notify the FTC
  • A cyber-insurance claim denied because the MFA or backup answers on the application were not true
  • Client data on an unencrypted laptop left in a car
  • Seasonal staff who still have access in June

Compliance from the team that runs your IT

NSN Management is a Tulsa-owned managed IT provider that has run technology for regulated Tulsa-area businesses since 2012. FTC Safeguards compliance is delivered by the same people who manage your identity, email, devices, network, and backups — so the safeguards are not a binder that drifts away from reality, and the evidence is a by-product of how your IT is run, with timely response and resolution, a truly local team, and regular meetings and communication.

FTC Safeguards compliance sits under our IT compliance services and leans on cybersecurity services and backup and disaster recovery. Not sure where you stand? Book a Discovery Call.

An NSN Management team member working across service dashboards

Service at a glance

Key facts about NSN Management’s FTC Safeguards compliance services
FrameworkFTC Safeguards Rule (Gramm-Leach-Bliley Act)
Part ofIT compliance services · Cybersecurity · Managed IT
Also seeHIPAA compliance · PCI DSS compliance
Service areaAcross the Tulsa metro: Tulsa, Broken Arrow, Jenks, Bixby, Sand Springs, Sapulpa, and Owasso
Best fitOrganizations with 10–100 people
Phone918-770-9150
FAQ

Your FTC Safeguards questions, answered

What is the FTC Safeguards Rule, and does it apply to my business?

The Safeguards Rule (16 CFR Part 314) implements the Gramm-Leach-Bliley Act’s requirement that non-bank “financial institutions” protect customer information. It applies to CPA firms and tax preparers, auto dealers that finance or lease, mortgage brokers, non-bank lenders, collection agencies, and many others that handle consumer financial information. If you prepare tax returns for a fee, assume it applies to you.

What is a WISP and why does the IRS ask about it?

A written information security plan is the document that describes your security program: who is responsible, what you protect, the risks you identified, the safeguards in place, how staff are trained, how vendors are managed, and how you respond to an incident. The FTC requires it; the IRS points to the same document in Publication 4557 and asks tax professionals to confirm they have one at PTIN renewal. NSN Management drafts it with you and keeps it current.

Who should be our qualified individual?

The Rule lets the qualified individual be an employee or an affiliate or service provider’s employee, as long as you retain oversight and someone senior in your firm is responsible for the outcome. In a small firm the practical answer is often a partner or office manager as the accountable person, with NSN Management running the technical program, producing the reports, and standing behind them.

Do we need a penetration test?

Only if you do not have continuous monitoring. The Rule offers two paths: continuous monitoring of your systems, or an annual penetration test plus vulnerability assessments every six months and after material changes. Managed detection and response with centralized logging generally satisfies the first path; we still recommend periodic vulnerability scanning and can coordinate a penetration test if you want the assurance.

What has to be encrypted?

Customer information at rest and in transit — laptops, servers, backups, removable media, and email or file transfers containing client data. In practice that means full-disk encryption on every device, encrypted backups, secure client portals instead of attachments, and email encryption where attachments are unavoidable. If encryption is truly infeasible somewhere, the qualified individual has to approve an equivalent control in writing.

What is the FTC breach-notification requirement?

Since May 13, 2024, a covered business must notify the FTC within 30 days of discovering a “notification event” — unauthorized acquisition of unencrypted customer information involving at least 500 consumers. It is separate from state breach-notification laws and from any duty to tell affected clients. Your incident-response plan needs to account for all of them, which is one reason it has to be written down in advance.

We already have cyber insurance. Isn’t that enough?

Insurance is what pays after something goes wrong; the Safeguards Rule is about preventing it and proving you tried. They overlap usefully — the MFA, endpoint protection, encryption, and tested backups your carrier requires are the same controls the Rule requires — but a policy is not a program, and claims have been denied when the answers on the application turned out not to be true.

Do you provide Safeguards Rule compliance services outside Tulsa?

Yes. NSN Management serves CPA firms, dealerships, and other covered businesses across the Tulsa metro, including Broken Arrow, Jenks, Bixby, Sand Springs, Sapulpa, and Owasso — remotely for most of the program, and on-site when the network or a server needs hands in the building.

Want a WISP you would be comfortable handing to the IRS?

Book a Discovery Call and we’ll walk through the Rule’s elements against what your firm has today — most firms are closer than they think, and the gaps are specific. Or call 918-770-9150.