What does the GLBA Safeguards Rule require of a financial institution?
A written security program owned by a named qualified individual, built on a written risk assessment, with access controls, inventory, encryption, multi-factor authentication, secure disposal, monitoring, training, oversight of service providers, an incident response plan and an annual written report to the board.
The answer differs between the federal level and the states, see the rows below.
The answer by level
Federal level
A financial institution maintains a written information security program with a qualified individual in charge, a written risk assessment, access controls, encryption, multi-factor authentication and an incident response plan.
16 CFR Part 314Sector rule
Notification to the Commission is required as soon as possible and no later than 30 days after discovery of a notification event affecting at least 500 consumers.
16 CFR Part 314, Safeguards RuleState level
New York adds an annual certification of compliance, a named chief information security officer and a 72 hour notification duty for covered entities.
23 NYCRR Part 500
Source lines
- The rule applies to financial institutions under the Commission's jurisdiction, a category far broader than banks and including many lenders, advisers and dealers.
- Institutions maintaining information on fewer than five thousand consumers are exempt from several elements, including the written risk assessment and the annual report.
- A notification event affecting at least 500 consumers is reported to the Commission within 30 days of discovery.
What it means for the company
The obligation is documentary as much as technical. An institution that runs strong controls but cannot show the written risk assessment and the annual board report is still exposed.
| Level | Requirement | Source |
|---|---|---|
| Federal level | A financial institution maintains a written information security program with a qualified individual in charge, a written risk assessment, access controls, encryption, multi-factor authentication and an incident response plan. | 16 CFR Part 314 |
| Sector rule | Notification to the Commission is required as soon as possible and no later than 30 days after discovery of a notification event affecting at least 500 consumers. | 16 CFR Part 314, Safeguards Rule |
| State level | New York adds an annual certification of compliance, a named chief information security officer and a 72 hour notification duty for covered entities. | 23 NYCRR Part 500 |
What it means for the individual
Customer information covered by the rule includes records held about people who are not customers of the institution, when the institution received the data from another institution.
Source lines
- GLBA Safeguards Rule16 CFR Part 314 · read 2026-08-25 · proof 9b9860e70d7311b7
- NYDFS Cybersecurity Regulation23 NYCRR Part 500 · read 2026-08-25 · proof 9b9860e70d7311b7
- Electronic Code of Federal Regulations16 CFR Part 314, Safeguards Rule · read 2026-08-25 · proof 9b9860e70d7311b7Official source
- New York State Department of Financial Services23 NYCRR Part 500 · read 2026-08-25 · proof 9b9860e70d7311b7Official source
Next step
Name the qualified individual in writing, date the risk assessment, and calendar the annual board report.
This page reports what the sources say, with the identifier and address of the publisher. It is not legal advice and does not decide an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.