New FTC Safeguards Rule Will Radically Change How Small Businesses Operate
Getty

New FTC Safeguards Rule Will Radically Change How Small Businesses Operate

A little over a year ago, the FTC made several amendments to the existing Safeguards Rule requiring even very small businesses to ensure the protection of client data. These changes, set to go into effect back in December of 2022, are now going to be enforced starting June 9, 2023 – and it’s very likely that your business, regardless of how small or how your tech is being handled, WILL be required to implement certain new security protocols.


These changes are substantive and so are the fines for non-compliance, which can be as high as?$43,972 per violation per day.


The Safeguards Rule was originally created for financial institutions. However, the new amendments broaden the definition of financial institutions to include real estate appraisers, car dealerships and payday lenders. The FTC goes so far as to include any business that regularly wires money to and from consumers. These organizations are required to develop, implement and maintain a comprehensive security program to keep their customers’ information safe.


Here are the provisions you must implement:


  • Designate a qualified individual to oversee their information security program. That means someone at these companies need to be trained in information security, receive continuing security education and be in charge of ensuring the organization is correctly executing the written information security plan. If no one on your team meets this requirement, we can provide someone.


  • Develop a written risk assessment. A risk assessment is done in two parts: one, a technical scan, and two, a questionnaire designed to reveal common security loopholes. This is typically outsourced to an IT firm like ours and needs to be reviewed annually (by law), but best practices should be quarterly if not monthly in situations where a business is handling a lot of sensitive information and the tolerance for risk by the owner is low. If you need this risk assessment, contact us.


  • Limit and monitor who can access sensitive customer information. For example, don’t give your entire team access to your credit card processing system. Only allow one employee (the one who works in it day in and day out), as well as one backup person (possibly you, the owner), to be able to log in and access this information.?


  • Encrypt all sensitive information. Again, this is typically done by an outsourced IT company like ours, unless your company is large enough to have a robust cyber security team that can handle it. “Sensitive information” is not just medical records and credit cards, but clients’ e-mail addresses, phone numbers, Social Security information, driver’s license information and birthdays. ALL of this can be used by hackers to exploit your customers using the data you host.


  • Train security personnel. Employee awareness training is another key component to not only this law, but also to get and keep insurance coverage on cyber liability, crime and other insurance policies.?


  • Develop an incident response plan. Specifically, if (when?) you get compromised, you need to have a plan in place for how you will respond. This is also another service we offer to our clients but should be reviewed by your insurance agent, leadership team, board and other key players in the organization.


  • Periodically assess the security practices of service providers. This law also requires you to ensure any companies you are doing business with – specifically ones where sensitive information is shared – to be secure and compliant. This may include requiring that vendors state in their contracts that they are adhering to the Safeguards Rule and to certain security frameworks, like CIS or NIST.?


  • Implement multifactor authentication or another method with equivalent protection for any individual accessing customer information. Also known as “2FA,” this process ensures anyone logging in to your accounts must authenticate that request via another device, such as a cell phone or e-mail.?


If you want to discuss this new rule with us and how to get started with a Risk Assessment, click here Matrixforce (Bookings) to schedule a phone consultation to discuss your concerns, questions and specific situation. If you prefer, you can call us at 918-622-1167.

For more thought leadership, follow?Kevin Fream.

Tim Golden

I’m on a mission to help MSPs turn compliance into a revenue generating service…not a burden. If you’re a 3–25 person MSP struggling to package, price, or deliver GRC, you’re not alone.. ComplianceScorecard.com

1 年

It’s funny/surprising how very little how many still don’t know just how this will actually affect them!

回复

要查看或添加评论,请登录

Kevin Fream的更多文章

  • Use Skills

    Use Skills

    T - Minus 307 Days Another Delta session. "Why do we always have to work on getting better?", one of my veterans asked.

  • Do Hard Things

    Do Hard Things

    T - Minus 308 Days It's been 4 days and the script still doesn't work. "Bad Request" for the critical part is the vague…

  • Shocking Tactics

    Shocking Tactics

    T - Minus 309 Days It could be called business porn that's not about nudity but instead sells a dream. The victims…

  • Routine Habits

    Routine Habits

    T - Minus 310 Days I often wake early making my side of the bed while Sherri sleeps. Then let Neo out to then brush my…

  • Business Rundown

    Business Rundown

    T - Minus 311 Days It's only mid 50's but it feels like Summer as Neo and I walk the whole neighborhood. Every year…

  • Well Played

    Well Played

    T - Minus 312 Days Alan Ritcher as Reacher lives a life most people can't imagine - having only the clothes on your…

  • Please Don't Stop The Music

    Please Don't Stop The Music

    T - Minus 313 Days Tom MacDonald is smart enough to know if you enable copyright on YouTube videos, then they can't be…

  • Untouchable Leadership

    Untouchable Leadership

    T - Minus 314 Days It didn't make a lot of sense how Al Capone couldn't be arrested. There would be crazy shootouts…

  • Fewer Choices

    Fewer Choices

    T - Minus 315 Days 2019 was going to be our best year ever until Covid and putting Netflix on continuous play seemed…

  • Cold Plunge

    Cold Plunge

    T - Minus 316 Days It's 3 and feels like -15 so Neo and I played follow-the-leader all through the house instead of…

社区洞察

其他会员也浏览了