FTC Safeguards Self-Directed Security Program

Organizations with in-house security expertise can now fast-track their compliance efforts by leveraging our self-guided compliance program content, which includes all of the critical program material required to implement and maintain an FTC Safeguards Rule-compliant security program, including:

  • Security Policy to addresses stated FTC Safeguards Rule requirements and provides mitigations for prevailing cybersecurity risks
  • Computing Asset, Software, and Network Boundary Inventory Worksheets to help you identify and secure your regulated systems
  • Cybersecurity Incident Response Plan Template to ensure you are prepared to deal with potentially disruptive security incidents
  • Risk Management Process Template to help you effectively assess and manage risk on your own
  • Change Management Process Template to help you avoid security disruption or degradation stemming from changes in your environment
  • Annual Cybersecurity Awareness Training presentation (pre-recorded) to ensure your team is equipped with the knowledge necessary to identify and thwart common attacks used to target them
  • Secure Customer Information (CI) Disposal Process Template to avoid CI exposure on end-of-life assets
  • Reporting Template to help you provide an effective annual security report to your organization’s governing body

Buy the FTC Safeguards Self-Directed Security Program

Month 1:

$1,899.00

Month 2-12:

$399.00

Discounted pricing with one-time payment available at checkout. Please select payment option and proceed accordingly.

One-time total: $5,533.00
Monthly plan total: $6,288.00

We don’t try to make complex security programs fit your business. Our packages meet your organization where it's at today in the FTC Safeguard journey.

What does the FTC Safeguards Self-Directed Security Program include?

  • Security Policy tailed to the requirements of the FTC Safeguards Rule
  • Approved Asset and Inventory Worksheet
  • Approved Software Inventory Worksheet
  • Network Boundary Worksheet
  • Cybersecurity Incident Response Plan Template
  • Self-guided risk assessment questionnaire
  • Risk Management Process Template 
  • Change Management Process Template 
  • Cybersecurity awareness training slides for use in annual cybersecurity awareness training
  • Secure Customer Information Disposal Process Template
  • Governing Body Security Reporting Template

Cybersecurity Programs for FTC GLBA Safeguards Rule FAQ:

Does the FTC Safeguards Rule matter for my business?

According to the Code of Federal Regulations, § 314.2(h), if your business assists with loans or financing options, then yes, the FTC requirements apply to your business and compliance is required by June 9, 2023.

Is FTC Safeguards Rule compliance something that can wait until later?

Unfortunately, no. The deadline is June 9, 2023. This was previously extended from the original compliance date of December 9, 2022.

Is FTC Safeguards Rule compliance out of reach and unaffordable for my businesses?

No, it’s not. With the right plan, even small companies can implement prudent and affordable measures that achieve the required safeguards. Secentric makes compliance not only possible, but affordable and effective for small businesses.

What Areas Should a FTC GLBA Safeguards Rule Security Policy Cover?

A security policy that addresses FTC Safeguards Rule requirements will have several areas of focus. Secentric’s workflow assisted policy development will  help you understand these requirements and  construct a policy that’s tailored to fits your business. Essential topics to address in security policies for the FTC Safeguards Rule include:

  • Designate a Qualified Individual to implement and supervise your company’s information security program.
  • Conduct a risk assessment.
  • Design and implement safeguards to control the risks identified through your risk assessment.
  • Regularly monitor and test the effectiveness of your safeguards.
  • Train your staff
  • Monitor your service providers.
  • Keep your information security program current.
  • Create a written incident response plan.
  • Require your Qualified Individual to report to your Board of Directors.
  • Learn more at § 314.4 of the Safeguards Rule

How Can Businesses Comply With the FTC Safeguards Rule and Protect Themselves From Cyberattacks?

There are several fundamental practices a business can implement to improve their cybersecurity and achieve compliance with the FTC Safeguards Rule. One of the purposes and benefits of a security policy for your small business is that it sets up the structure for your security program and makes clear your expectations regarding areas such as:

  • Technical requirements
  • Security processes
  • Employee training and awareness
  • Expected behaviors

Each of these required topics are part of the FTC Safeguards Rule. Secentric will guide you through each of these areas to ensure the development of a comprehensive, compliance-ready policy!

Cybersecurity is not a one-and-done, overnight exercise. Keeping your business safe and secure is an ongoing process. At Secentric, we can help you create a cybersecurity policy and program that is purpose-built for your business and your needs.