FTC Enhances Cybersecurity Stance with New Safeguards Rule Amendment for Non-Banking Financial Institutions

On October 27, 2023, the Federal Trade Commission (FTC) issued a significant amendment to the agency’s Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA). According to a report by Thompson Coburn LLP, this amendment demonstrates a more stringent stance by the FTC on cybersecurity matters, introducing a requirement for non-banking financial institutions to report certain data breaches and security events.

Prior to this, the prudential banking regulators were the only ones that had data breach notice requirements, which they introduced in 2005 under the authority of the GLBA. For non-banking financial institutions, the mandate now imposes an obligation not previously required, although prudentially regulated banking institutions had been subject to similar rules.

The FTC amendment is a striking reminder of the increasingly pivotal role cybersecurity plays in our world today, particularly within financial sectors. The requirement of certain non-bank financial institutions to promptly report data breaches and security events to the Commission and consumers serves an important role in mitigating the harm caused by these breaches. The FTC has issued the final version of the rule, signaling an assertive approach by the agency towards cybersecurity.

Given the impact this amendment will have on non-bank financial institutions, it is recommended that legal professionals working with or within these institutions take steps to understand the implications this rule will have on their operations.