The Gramm-Leach-Bliley Act's Safeguards Rule applies to a wider range of financial services businesses than most owners realize — not just banks, but registered investment advisors, mortgage brokers, accountants who prepare tax returns, and insurance agencies. If your firm handles customer financial information, GLBA's security requirements likely apply to you, whether or not you've ever been formally examined against them.
Here's what the rule actually requires in IT terms, and what examiners tend to focus on.
A qualified individual must be designated to oversee the information security program. This doesn't have to be a full-time CISO for a small firm — it can be an owner, a partner, or an outsourced security advisor — but it has to be a named, accountable person, not an implicit assumption that "IT handles it."
A written risk assessment is required, covering the specific ways customer information could be compromised — not a generic template, but one that reflects your actual systems: your CRM, your document management platform, your email, and any third-party tools that touch client financial data.
Access controls have to be role-based and reviewed periodically. Examiners specifically look for whether access is limited to what each role needs, and whether there's a documented process for removing access when someone leaves the firm — not just an assumption that it gets handled eventually.
Encryption of customer information, at rest and in transit, is explicitly required by the current Safeguards Rule — this is no longer a "consider it" item the way it once was.
Multi-factor authentication is required for anyone accessing customer information, including remote access and any cloud-based systems.
Vendor oversight is a named requirement, not an afterthought. The rule specifically requires firms to select service providers capable of maintaining appropriate safeguards, and to contractually require them to do so. A firm using a cloud-based portfolio management tool or an outsourced back-office provider needs to be able to show that oversight happened — not just assume the vendor handles it.
An incident response plan is required in writing, along with a process for notifying affected customers and, depending on the scope of the incident, potentially regulators.
Regular testing and monitoring of controls is required — vulnerability scans or penetration testing at a frequency appropriate to the firm's risk profile, not a one-time assessment done at onboarding and never repeated.
What tends to trip up smaller firms: treating GLBA as a document exercise rather than an operational one. A firm can have a beautifully written information security policy sitting in a shared drive that nobody follows day to day. Examiners increasingly ask for evidence — access logs, patch records, vendor contracts with security language — not just policy documents.
For financial services firms in the Inland Northwest working with a smaller internal team, the practical path is usually a partnership with an IT provider who understands GLBA specifically, rather than treating IT support and compliance oversight as two separate relationships that don't talk to each other.