Most financial firms don’t realize how much the regulatory landscape has shifted until they’re suddenly asked for things they’ve never formally documented: a written security program, proof of MFA everywhere, a real risk assessment, or evidence that their vendors are being vetted properly. The FTC Safeguards Rule and DOL cybersecurity guidance have raised expectations dramatically, and the penalties are no longer theoretical.

What Changed, and Why It Matters Now

The FTC’s updated Safeguards Rule, which took full effect in June 2023, transformed what was previously a set of general guidelines into a prescriptive set of technical and administrative requirements. Financial institutions covered by the Gramm-Leach-Bliley Act, including tax preparers, accounting firms, broker-dealers, investment advisors, and insurance companies, must now maintain:

  • A written information security program with a designated qualified individual overseeing it
  • Multi-factor authentication on every system that accesses customer financial data
  • Encryption of customer information both at rest and in transit
  • Regular risk assessments and documented penetration testing
  • Vendor and service provider oversight with contractual security requirements
  • An incident response plan that is tested and updated regularly

Separately, the Department of Labor issued cybersecurity guidance for ERISA-covered retirement plans, making plan fiduciaries and their service providers responsible for protecting participant data. If your firm touches retirement plan information, you’re now expected to demonstrate cybersecurity maturity and to document it.

Regulatory Update

January 2026: the DOL made cybersecurity a top-tier enforcement priority, auditing plans covering 156+ million workers and retirees.

Enforcement is real, and penalties under both the FTC Act and GLBA can be severe (see footnotes below).

Where Most Firms Get Caught

The challenge isn’t that these requirements are unreasonable. It’s that most small and mid-sized firms were never built to operate at this level of documented, continuous security. Common gaps include:

  • Partial MFA, enforced on some systems but not all, especially legacy applications or shared admin accounts
  • Backup assumptions, where backups exist but have never been tested under real recovery conditions
  • Default Microsoft 365 settings, leaving email, SharePoint, and OneDrive exposed to common attack patterns
  • Unpatched endpoints missing critical security updates across laptops, servers, and mobile devices
  • No incident response plan, or one that has never been tested or updated
  • Vendor blind spots, where third-party access to client data is never formally reviewed
Six common security gaps: partial MFA, backup assumptions, default M365 settings, unpatched endpoints, no incident plan, vendor blind spots
Six gaps regulators and insurers flag most often

These gaps translate into real consequences: higher insurance premiums, failed audits, operational disruption during tax or reporting season, regulatory exposure, inability to obtain or renew cyber insurance, a ransomware event that halts operations for weeks or even months, and ultimately a breach that damages client trust and pushes clients to competitors.

Building a Security Posture That Satisfies Regulators

Meeting FTC and DOL requirements isn’t about buying a single product or passing a single audit. It requires an operational security baseline that runs continuously, not a project that spins up every time a regulator or insurer asks questions.

That baseline includes endpoint protection across every device, identity and access management with multi-factor authentication enforced, encryption of data at rest and in transit, tested backup and disaster recovery, documented incident response procedures, and ongoing risk assessment with remediation tracking.

Documentation

A Written Information Security Program (WISP) is a core Safeguards Rule deliverable. Philotech builds yours to match the controls actually running in your environment.

For firms that need to shore up core cybersecurity and recovery capabilities, Philotech’s PhiloSecure delivers a focused stack of security controls and disaster recovery tailored to regulated industries. Most firms ultimately choose PhiloWork, which includes everything in PhiloSecure plus full management of Microsoft 365, identity and access controls, and day-to-day IT operations. In practice, that means security, data protection, and the platform your team works in every day are handled as one integrated program.

Beyond the Checkbox

The FTC and DOL aren’t asking financial firms to become cybersecurity experts. They’re demanding that firms prove they take client data seriously, with documented processes, enforced controls, tested backups, hardened environments, and clear evidence of active risk management. Most SMBs don’t have the internal bandwidth, technical depth, or compliance experience to meet those requirements consistently.

Philotech gives firms the structure, discipline, and visibility required to stay compliant long-term. With PhiloSecure, you gain the focused cybersecurity and disaster-recovery capabilities regulators expect. With PhiloWork, you get that plus full, ongoing management of the Microsoft 365 environment where most financial-sector breaches actually occur.

The Bottom Line

Compliance isn’t about avoiding fines. It’s about protecting your reputation and keeping your attention on the work that matters.

FTC Act §5(m) civil penalties can reach $50,120 per violation per day. GLBA criminal penalties can reach $100,000 for individuals, with higher fines possible for institutions. The DOL’s EBSA has broad authority to investigate and enforce fiduciary obligations under ERISA, including cybersecurity-related deficiencies.