GLBA: Proposed Changes

Cybersecurity staff sitting at desk reviewing security protocols.
Cybersecurity staff sitting at desk reviewing security protocols.

On March 5th, the Federal Trade Commission (“FTC”) proposed amendments to the Safeguards Rule and Privacy Rule under the Gramm-Leach-Bliley Act (“GLBA”).  These amendments are significant in several ways. However, the most impactful will be the changes to the Safeguards Rule which governs the information security programs of financial institutions. 

Proposed Revisions

Until now, the Safeguards Rule, which first went into effect in 2003, provided general guidance requiring companies to develop, implement and maintain a “comprehensive information security program.”  The proposed revisions now provide prescriptive requirements intended to provide greater protection to consumers and greater certainty to businesses. These changes include requiring:

  • The designation of a Chief Information Security Officer (CISO), responsible for overseeing and implementing the program.
  • The CISO to report at least annually to the board on issues related to the information security program.
  • Additional requirements to risk assessments, mandating that the report be written, performed regularly and include recommendations for addressing identified risks.
  • Accession control (physical security) to limit access to locations containing customer data to authorized individuals.
  • Customer data to be encrypted at rest and in transit.
  • Multi-factor authentication (MFA) for any individual accessing customer data.
  • Audit logs to include information events designed to detect and respond to security events
  • Regular testing and continuous monitoring of critical controls, systems, and procedures.
  • Appropriate training and education.
  • Key personnel take steps to maintain current cybersecurity knowledge.
  • Companies to utilize qualified security personnel.
  • Companies to oversee and assess service providers based on the risk they present to information security.
  • Companies to implement and maintain an Incident Response Plan.
  • Procedures that clearly define the secure disposal of customer information.
  • Policies and procedures for change management.
  • Policies and procedures for monitoring authorized and unauthorized access, use and modification of customer information.

Who Will Be Affected

The proposed changes also expand the definition of “financial institutions” to include finders (those who charge a fee to connect consumers to lenders) and companies who engage in activities “incidental to financial activities.” As with any prescriptive cybersecurity guidelines, those organizations who have not previously been governed by GLBA, those that did not already have a strong governance plan as well as smaller entities will be affected the most.

Responses to the Proposed Revisions

Until now, GLBA has offered general guidelines. It is unlikely that the proposed changes will be accepted with open arms. There are also concerns about the impact on smaller organizations as well as the FTC’s ability to measure and enforce these new guidelines. Those wishing to weigh in on the proposed changes have 60 days after the publication in the Federal Register.¹

Takeaways

  1. This is the opportunity to review your current information security program.
  2.  If you haven’t already, reconsider your current partnerships and any processes by which you evaluate vendors.
  3. Establish a relationship with a reputable security vendor.

We Can Help.

If your organization is concerned about compliance or feels there may be a gap in your current security posture, we would love the opportunity to earn your business.  You can speak with a member of our team by contacting us today.

¹ https://www.ftc.gov/news-events/press-releases/2019/03/ftc-seeks-comment-proposed-amendments-safeguards-privacy-rules

Corsica Technologies
Corsica Technologies is an MSP specializing in cybersecurity solutions, managed IT services, digital transformation, and data integration. Corsica provides solutions for midmarket businesses including network monitoring, data protection, incident response, and IT support. Corsica offers unmetered technology services for fully managed or co-managed teams to address all technology needs under a one-flat monthly fee. 

Related Cybersecurity and IT Reads

Microsoft 365 price increase - Corsica Technologies
Microsoft 365
Garrett Wiesenberg

Microsoft 365 Price Increase: What You Can Do

Microsoft has increased the price for its Microsoft 365 business licensing in 2025. Whether you work with a provider for M365 managed services or handle everything yourself, you need to understand how price increases may affect you—and what your options

Read more

Sign Up For Our Newsletter

Stay up-to-date on the Managed Services and Cybersecurity landscape, and be the first to find out about events and special offers.

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.