Skip to content
Cyber Horizon
Back to Blog
GLBAFFIECFinancial Services

GLBA & FFIEC: Security Compliance for US Financial Services

21 August 2026·8 min read·Cyber Horizon Team

If your business touches US consumer financial data — as a bank, lender, broker, insurer, or the fintech serving one — two acronyms shape your security obligations: GLBA, the law, and FFIEC, the examiners’ playbook. Here’s what each actually requires, and how to build one control set that satisfies both.

GLBA in one paragraph

The Gramm-Leach-Bliley Act (1999) requires “financial institutions” — defined broadly enough to catch payday lenders, mortgage brokers, tax preparers, higher-education institutions handling federal loans, and many fintechs — to protect customers’ non-public personal information (NPI). Its teeth are in two rules: the Privacy Rule (notices and opt-outs for information sharing) and the Safeguards Rule (an information-security programme). The FTC’s 2023 amendments added a third obligation: breach notification to the FTC within 30 days for incidents affecting 500+ consumers.

What the Safeguards Rule requires

RequirementWhat examiners look for
Qualified IndividualA named person accountable for the security programme, reporting to the board (annually, in writing).
Written risk assessmentDocumented, criteria-based, and refreshed — not a one-off spreadsheet.
Access controls & MFAMFA for anyone accessing customer information systems; least-privilege reviews.
EncryptionNPI encrypted in transit and at rest — or a documented, approved compensating control.
Secure developmentSecurity built into in-house apps handling NPI; vendor software assessed.
Monitoring & testingContinuous monitoring, or annual penetration testing plus semi-annual vulnerability scans.
Vendor oversightService providers selected, contracted and periodically reassessed on security.
Incident response planA written plan covering roles, decision-making, remediation and post-incident review.

Where FFIEC fits

The Federal Financial Institutions Examination Council doesn’t write law — it writes the examination handbooks federal banking regulators (OCC, FDIC, Federal Reserve, NCUA) use when they walk through your door. The FFIEC IT Handbook’s Information Security booklet reads like a control framework: governance, risk identification, layered defences, monitoring, and service-provider management. If you’re examined by a banking regulator, FFIEC guidance is your de facto standard, and the (now-sunset) CAT is being replaced in practice by mappings to NIST CSF 2.0 and CISA performance goals.

One control set, both regimes

GLBA’s Safeguards Rule and FFIEC’s booklets overlap heavily with ISO 27001 and NIST CSF. The efficient play is to run one control library mapped across all of them: your MFA control satisfies the Safeguards Rule, the FFIEC access-management expectations, and ISO Annex A simultaneously — with one piece of evidence. That’s the crosswalk approach we’ve covered before, applied to financial services.

Quick self-check

  • Can you name your Qualified Individual — and produce their last written board report?
  • Is your risk assessment written, criteria-based, and less than 12 months old?
  • Does every path to customer data enforce MFA — including vendors and admins?
  • Could you notify the FTC within 30 days of discovering a 500+ consumer incident?
  • Do vendor contracts include security requirements, and are reassessments actually happening?

Miss two or more of those and you have your remediation roadmap — in the order an examiner would find them.

Map GLBA, FFIEC and 70+ frameworks from one control set

Cyber Horizon crosswalks your controls across GLBA, FFIEC guidance, NIST CSF and ISO 27001 — one register, one evidence trail, every regime covered.

Book a Demo