Since June 9, 2023, every non-bank financial institution under GLBA must run a full information-security program under the FTC's amended Safeguards Rule. That means a written program, a designated Qualified Individual, a written risk assessment, encryption and MFA, continuous monitoring or twice-yearly vulnerability scans plus annual penetration testing, vendor oversight, an incident-response plan, and an annual written report to the board or owner. Since May 2024, institutions must also notify the FTC within 30 days of a breach affecting 500 or more consumers.
Most small financial institutions — auto dealers, mortgage brokers, tax preparers, collection agencies — have no CISO, no compliance staff, and no idea how to produce a defensible WISP or run a penetration test. They face two bad options: buy compliance software they must operate themselves, or hire a virtual CISO at $2,600–$11,600 per month. Both leave the actual work on the dealer's desk.
SafeguardOps productizes the entire obligation as a managed service. An internal AI engine drafts, maps controls, gathers evidence, and monitors continuously; a named human security lead makes the risk calls and signs the report. We sell the outcome — 'you are Safeguards-compliant, with a signed file behind every requirement.'