Penetration testing for the FTC Safeguards Rule

If your business handles consumer financial information, the FTC Safeguards Rule probably applies to you, even if you have never thought of yourself as a financial institution. Car dealerships, tax preparers, and mortgage brokers are all on the list. The rule asks for a penetration test every year and a vulnerability assessment every six months. This page explains who is covered, what the rule says, and how to get both done this week without hiring a consulting firm.

Penetration testing for the FTC Safeguards Rule

Who the rule covers

The rule applies to non-bank "financial institutions," and the FTC defines that broadly. Its own examples include:

  • Automobile dealerships that lease vehicles or arrange financing
  • Tax preparers and accountants who prepare income tax returns
  • Mortgage brokers and lenders
  • Payday lenders and finance companies
  • Collection agencies
  • Check cashers and wire transfer businesses
  • Credit counselors and some financial advisors
  • Real estate settlement services

What the rule says

Section 314.4(d)(2) of the rule (16 CFR Part 314) says that unless you have continuous monitoring in place, you must conduct "annual penetration testing" of your information systems and vulnerability assessments "at least every six months," and again whenever your operations change in a material way.

The rule defines a penetration test as an attempt "to circumvent or defeat the security features of an information system" from outside or inside your systems. A vulnerability scan on its own does not meet that definition. You need both.

The small business exception

If you keep customer information on fewer than 5,000 consumers, section 314.6 exempts you from the specific testing schedule above. You still have to protect customer information and regularly test your safeguards, and many small firms run the same tests anyway because an insurer, a lender, or a software partner asks for them.

Both requirements, one checkout

  • Automated external penetration test, from $1,995 for a 30-day window (1 external IP or domain). It starts the same day, safely attempts real exploitation, includes retests after you fix things, and ends with a report you can hand to an examiner.
  • Automated internal penetration test, from $2,995 for a 30-day window (up to 25 internal hosts), for your office network.
  • External vulnerability scanning, from $595 a year (10 IPs), run on a schedule so the every-six-months assessment is covered all year.

When you need an engineer

If your examiner, insurer, or attorney asks for a test led by a named engineer, our managed penetration testing team does that.

This page is general information, not legal advice. Ask your attorney or compliance advisor how the rule applies to your business.

See pen test pricing and buy online · Talk to a specialist

Related: SOC 2, HIPAA, ISO 27001, PCI DSS 11.4, penetration test cost

Ready when you are

Ready to get your pen test done this week?

Automated penetration testing from Clone Systems starts at $1,995 for an external test and $2,995 for an internal test. Buy it online, start in minutes, and retest for free within your 30-day window.