FTC Safeguards Managed Security Program

For organizations that need a little more help, our Managed Program offering builds upon the Self-Directed Security Program by supporting you through ongoing program management with the help of a dedicated BPM security expert. As an FTC Safeguards Managed Program customer, BPM consultants will through your security program implementation, working alongside you to help you navigate the cybersecurity and regulatory nuances that non-security personnel often struggle with. The Managed Program includes:

  • Initial Program Risk Assessment
  • Assisting you with the completion of  Program Templates, such as:
    • Identification and inventory of Customer Information Repositories
    • Assignment of internal Business Owners to repositories of Customer Information
    • Identifying repository-specific protection requirements, including system, network, and data protection safeguards
    • Review of requirements associated with other regulatory and contractual obligations
    • Guidance to reduce risk by minimizing collection and retention of unneeded data
    • Minimum and maximum retention duration guidance
  • Security Architecture observations and recommendations

 

If you are looking for a more custom consulting and managed service experience, check out our Custom Security Program.

Buy the FTC Safeguards Managed Security Program

Month 1:

$5,125.00

Month 2-12:

$1,025.00

Discounted pricing with one-time payment available at checkout. Please select payment option and proceed accordingly.

One-time total: $15,134.00
Monthly plan total: $16,400.00

We don’t try to make complex security programs fit your business. Our packages meet your organization where it's at today in the FTC Safeguard journey.

What does the FTC Safeguards Managed Security Program include?

  • Security policy tailed to the requirements of the FTC Safeguards Rule
    • Approved Asset and Inventory Worksheet
    • Approved Software Inventory Worksheet
    • Network Boundary Worksheet
    • Cybersecurity Incident Response Plan Template
    • Risk Assessment questionnaire
    • Risk Management Process Template
    • Change Management Process Template
    • Cybersecurity awareness training slides for use in annual cybersecurity awareness training
    • Secure Customer Information Disposal Process Template
    • Governing Body Security Reporting Template
  • Initial program risk assessment
  • Assisted completion of client’s security policy and incident response plan
  • Assisted completion of program templates with:
    • Identification and inventory of approved customer information repositories, software inventory, computing asset inventory, and boundary inventory worksheets
    • Assignment of internal Business Owners to repositories of Customer Information
    • Repository-specific protection requirements, including system, network, data protection safeguards
    • Review of requirements associated with applicable regulatory and contractual obligations
    • Guidance to reduce risk by minimizing collection and retention of unneeded data
    • Minimum and maximum retention duration guidance
    • Security architecture observations and recommendations Monthly Vulnerability Scans or Annual Penetration Tests
  • Monthly Vulnerability Scans or Annual Penetration Tests (client’s choice)
  • Assisting client with quarterly review and updates to asset inventory, software inventory, and boundary worksheets
  • Annual Cybersecurity Awareness Training delivered by BPM (customized for your business and replaces the Gold Package’s pre-recorded training)
  • Annual Risk Assessment of customer information regulated by the FTC Safeguards Rule
  • Annual Risk Assessment of client’s third-party service providers
  • Cyber Risk Management and Quarterly Risk Management Reporting
  • Annual report on the state of client’s security to its governing body

Cybersecurity Programs for FTC GLBA Safeguards Rule FAQ:

Does the FTC Safeguards Rule matter for my business?

According to the Code of Federal Regulations, § 314.2(h), if your business assists with loans or financing options, then yes, the FTC requirements apply to your business and compliance is required by June 9, 2023.

Is FTC Safeguards Rule compliance something that can wait until later?

Unfortunately, no. The deadline is June 9, 2023. This was previously extended from the original compliance date of December 9, 2022.

Is FTC Safeguards Rule compliance out of reach and unaffordable for my businesses?

No, it’s not. With the right plan, even small companies can implement prudent and affordable measures that achieve the required safeguards. Secentric makes compliance not only possible, but affordable and effective for small businesses.

What Areas Should a FTC GLBA Safeguards Rule Security Policy Cover?

A security policy that addresses FTC Safeguards Rule requirements will have several areas of focus. Secentric’s workflow assisted policy development will  help you understand these requirements and  construct a policy that’s tailored to fits your business. Essential topics to address in security policies for the FTC Safeguards Rule include:

  • Designate a Qualified Individual to implement and supervise your company’s information security program.
  • Conduct a risk assessment.
  • Design and implement safeguards to control the risks identified through your risk assessment.
  • Regularly monitor and test the effectiveness of your safeguards.
  • Train your staff
  • Monitor your service providers.
  • Keep your information security program current.
  • Create a written incident response plan.
  • Require your Qualified Individual to report to your Board of Directors.
  • Learn more at § 314.4 of the Safeguards Rule

How Can Businesses Comply With the FTC Safeguards Rule and Protect Themselves From Cyberattacks?

There are several fundamental practices a business can implement to improve their cybersecurity and achieve compliance with the FTC Safeguards Rule. One of the purposes and benefits of a security policy for your small business is that it sets up the structure for your security program and makes clear your expectations regarding areas such as:

  • Technical requirements
  • Security processes
  • Employee training and awareness
  • Expected behaviors

Each of these required topics are part of the FTC Safeguards Rule. Secentric will guide you through each of these areas to ensure the development of a comprehensive, compliance-ready policy!

Cybersecurity is not a one-and-done, overnight exercise. Keeping your business safe and secure is an ongoing process. At Secentric, we can help you create a cybersecurity policy and program that is purpose-built for your business and your needs.

Cybersecurity Resources for Small Businesses: