Skip to content
CELADONINSURANCE GROUP
← InsightsJune 18, 2026 · 5 min read

The Safeguards Rule Quietly Got Bigger. Here's What It Means for Your Business.

The federal data-security rules that used to apply only to banks now reach a much wider circle of businesses — including some that never thought of themselves as financial institutions.

A few years ago, a client of mine ran a mid-sized firm that did a little seller financing on the side. He had never once described his company as a financial institution. Then the federal definition shifted underneath him, and overnight he was holding obligations he didn't know he had.

That story is more common than it should be. The Federal Trade Commission's Safeguards Rule — the data-security standard that sits under the Gramm-Leach-Bliley Act — used to feel like something for banks and lenders to worry about. It doesn't anymore. The rule was expanded, and the circle of businesses it now reaches is wider than most owners assume.

I want to walk you through what changed, in plain terms, so you can decide whether it touches your business before someone else decides for you.

Who the rule covers now

The first and most important change is the definition. “Financial institution” no longer means just the obvious players. It now reaches businesses engaged in activities that are incidental to or connected with a financial transaction — including what the rule calls “finders,” who simply bring two parties together for a deal.

In practice, that pulls in companies most people would never file under “finance.” If you extend credit to customers, broker introductions, collect sensitive customer information as part of a transaction, or sit anywhere adjacent to the flow of money, you may be inside the line. The point isn't to alarm you. It's to say the old mental shortcut — we're not a bank, so this isn't us — is no longer reliable.

What the rule actually asks of you

Strip away the legal language and the Safeguards Rule comes down to a handful of disciplines. At a glance, a compliant business is expected to have:

  • A written information-security program — not a binder you assemble after an incident, but a living document, owned by a named person.
  • A real risk assessment, repeated on a schedule. You identify where customer information lives, what could go wrong, and you revisit that picture periodically.
  • Access controls and encryption — the right people reach sensitive data, the wrong people don't, and the data is protected both at rest and in transit.
  • Multi-factor authentication for anyone touching systems that hold customer information. This one is not optional, and it is the gap I see most often.
  • A written incident-response plan — a decision made calmly in advance about who does what when something goes wrong.
  • Staff training and monitoring, plus secure development practices for anything you build in-house.
  • At least annual reporting on the program to your board or senior leadership.

None of these are exotic. Taken together, they describe a business that treats customer information as something it has been trusted with, rather than something it happens to store.

Why this is worth your attention now

The penalties for getting this wrong are not small, and they are not the only cost. A data event in a business that handles money is a reputational event first and a regulatory one second. The clients you most want to keep are exactly the ones who will leave quietly if they feel their information wasn't taken seriously.

Here is the part I'd ask you to hold onto. Done early, this work is inexpensive — a clear program, MFA turned on, a plan written down, a recurring review on the calendar. Done late, after an incident, it is expensive in every way that matters. The spread between those two outcomes is almost entirely a function of when you start.

I'm not your attorney and I'm not your IT department, and good compliance here usually involves both. What I do is sit in the middle of risk — helping owners see an exposure clearly, size it correctly, and bring the right specialists to the table before it becomes a problem rather than after. Data security has quietly become a core piece of the risk picture for any business that touches a transaction, and it belongs in the same conversation as your property, your liability, and your cyber coverage.

If you're not sure whether the Safeguards Rule reaches your business — or you suspect it does and aren't certain you've covered the basics — that's a worthwhile half-hour.

Request a review

Send us your current policies. We'll give you an honest read on where you stand.

Request a risk review