Resource
What the FTC Safeguards Rule means for your business.
Most small firms who think they're exempt from the FTC Safeguards Rule are wrong about why. The 5,000-record threshold doesn't mean what most people think, and that misunderstanding is leaving real exposure in place.
The exemption almost everyone misreads.
A firm sees a reference to a 5,000-consumer threshold and assumes two things: that the number means something like their current client count, and that being under it means the whole rule doesn't apply. Both are wrong.
The threshold isn't your client list. It's every consumer whose information your business has ever maintained, past clients, prospects who never signed on, anyone whose financial information passed through your systems. A record is any single piece of nonpublic personal or financial information: names, Social Security numbers, bank or credit account numbers, tax documents, income and credit history, and similar information. A single client file usually contains multiple records, which is why a small firm with modest current headcount can accumulate more than 5,000 records over a few years of operation. The number sounds like it's reserved for large institutions. It's easier to cross than it looks.
Second, being under that threshold doesn't exempt you from the rule. It exempts you from three specific requirements: a written risk assessment, a documented incident response plan, and annual board reporting. Everything else still applies. The written information security plan, a designated Qualified Individual, access controls, MFA, encryption, vendor oversight.
One more distinction worth making here. Even if the Safeguards Rule doesn't require an incident response plan for your business, your cyber insurance carrier likely does. Most applications ask for exactly that document regardless of size or regulatory exemption. Skipping it because the FTC doesn't require it solves the wrong problem and it tends to show up at renewal or at claim time instead.
Firms that believe they're fully exempt typically have nothing in place. No WISP, no designated owner, no documented controls. That's not a gray area. It's non-compliance with a rule that explicitly applies to them.

Who's actually covered.
The Safeguards Rule applies to financial institutions under FTC jurisdiction. Broader than most assume. It explicitly includes mortgage lenders, finance companies, mortgage brokers, account servicers, collection agencies, credit counselors and financial advisors, tax preparation firms, non-federally insured credit unions, investment advisors not required to register with the SEC, and businesses that broker financial transactions. Auto dealers who extend credit or arrange financing are covered too.
If your business prepares tax returns, advises on financial matters, services accounts, extends credit, or otherwise handles consumer financial information, you're very likely covered. Even if "financial institution" isn't how you'd describe yourself.
What the rule actually requires.
Someone has to be accountable. A Qualified Individual designated to implement and supervise the program. No specific degree required. Just real-world competence suited to the business. If you bring in an outside provider to implement the program, the legal responsibility doesn't transfer to them. You still need someone internal accountable for that relationship.
A written plan has to exist. The WISP documents what controls are in place, who's responsible, and how the program addresses your specific risks. It has to be tailored to your business, not a generic template.
MFA is a named requirement. Employees with access to customer information need a second verification method beyond a password. Not a recommendation. A specific control the rule names directly.
Access has to be controlled and monitored. Who can reach customer information, how access is granted, how it's reviewed.
Data has to be protected in transit and at rest. Encryption, secure storage, and a clear picture of where customer information actually lives.
Vendors have to be overseen. If a third party touches customer information on your behalf, you're expected to have evaluated and monitored that relationship.
Breaches above a threshold have to be reported. A separate, much smaller number from the exemption above. If unauthorized access affects 500 or more consumers' unencrypted information, the rule requires notifying the FTC within 30 days of discovery.
Two numbers, two different things.
5,000 records is a cumulative count of everyone whose information your business has ever maintained, not your current client list, and it's the threshold for a partial exemption from three paperwork requirements.
500 records is the threshold for mandatory breach notification. It applies regardless of size or exemption status, with a 30-day clock from discovery.
A business can be under the 5,000 threshold and still have to notify the FTC if a breach affects 500 or more records. Confusing the two is exactly how firms end up believing they have no obligations at all.
Why this connects directly to how IT gets managed.
Every element of the rule maps to something a standards-led environment should already be doing. MFA enforced everywhere. Access reviewed on a schedule. Backup tested, not assumed. Vendor relationships evaluated, not taken on faith. Documentation that exists and is current.
A business managed to CIS Controls, the framework we align to, produces most of what the rule requires as a byproduct of how the environment runs, not as a separate project. The WISP becomes a description of what's actually true, not a document written to satisfy a checkbox. The same overlap exists with cyber insurance: the controls regulators and carriers ask about are addressing the same underlying risks.
What to check right now.
Do you know roughly how many consumer records your business has accumulated over its history, not just current clients?
Do you have a written information security plan that reflects what's actually in place?
Is someone specifically designated and accountable for your security program?
Is MFA enforced, not just available, on every system touching customer information?
If a breach affecting 500 or more records happened tomorrow, would you know within 30 days?
If any of those are uncertain, that's where the exposure lives.
What changes when this is handled correctly.
The WISP reflects reality. Leadership knows who's accountable and what that covers. MFA, access controls, and encryption exist because they're part of how the environment is managed, not because a deadline forced a scramble. If a regulator or auditor asks, the documentation is current.
If you're not sure whether your business is covered, or you've assumed an exemption that doesn't apply the way you think, that's what an IT Environment Review is for.
Templates and checklists
Take the Safeguards work with you.
The checklist is a free download. The WISP and incident response plan templates are starting points we share when you tell us a little about your firm.
Common questions
Questions leadership usually asks first.
Continue reading
Related work and reading.
Governance, Risk & Compliance
The WISP, designated owner, MFA, access, and vendor oversight the rule requires, produced as ongoing work.
Read more: Governance, Risk & ComplianceAccounting & Financial Firms
How the rule lands specifically for tax prep, advisory, and financial services firms.
Read more: Accounting & Financial FirmsCyber Insurance IT Requirements
The overlap between what the FTC requires and what carriers ask for on the application.
Read more: Cyber Insurance IT RequirementsNext step
Schedule an IT Environment Review.
Find out whether your business is covered, whether your exemption is real, and what controls are actually in place against the Safeguards Rule and your cyber insurance requirements.
