Penetration testing for mortgage brokers and lenders under the FTC Safeguards Rule

Mortgage brokers and non-bank mortgage lenders are financial institutions under the FTC Safeguards Rule. The rule asks for a penetration test every year and a vulnerability assessment every six months. Here is what that means for a mortgage company, and how to get it done this week without a sales call.

Penetration testing for mortgage brokers and lenders under the FTC Safeguards Rule

Why a mortgage company is covered

The rule names mortgage brokers in its own list of examples, because brokering loans is a financial activity. The FTC's guidance also lists mortgage lenders, and the rule lists real estate settlement services. Banks and federally insured credit unions answer to their own regulators instead. If you are a broker, a non-bank lender, or a settlement company, the FTC rule is the one that applies to you.

Your state examiner may ask too

The Conference of State Bank Supervisors, the group that represents state financial regulators, published a model data security law for non-bank financial companies in 2023. It is largely based on the FTC Safeguards Rule. If your state regulator examines you, you may be asked about the same testing. Companies licensed in New York also answer to the New York Department of Financial Services.

What you are protecting

A loan file is one of the most complete records of a person that exists: the application, tax returns, pay stubs, bank statements, a credit report, and a Social Security number. The systems in scope are the ones you control: your website and online application forms, your office and branch networks, the laptops your loan officers carry, and the remote access your staff use.

What the rule asks for

Section 314.4(d)(2) of the rule (16 CFR Part 314) says that unless you have continuous monitoring in place, you must conduct "annual penetration testing" of your information systems and vulnerability assessments "at least every six months," and again whenever your operations change in a material way.

The rule defines a penetration test as an attempt "to circumvent or defeat the security features of an information system" from outside or inside your systems. A vulnerability scan on its own does not meet that definition. You need both.

What about your loan origination system

If your loan software is hosted by a vendor, that vendor is your service provider under the rule. You are expected to require it to keep safeguards in place and to check on it from time to time. Ask the vendor for its most recent penetration test summary. Their test covers their platform. Your own network, website, and computers are yours to test.

The small company exception

If you keep customer information on fewer than 5,000 consumers, section 314.6 exempts you from the fixed testing schedule above. The count is the number of consumers whose information you keep, so borrowers from past years who are still in your files count too. You still have to protect customer information and regularly test your safeguards.

Both requirements, one checkout

  • Automated external penetration test, from $1,995 for a 30-day window (1 external IP or domain). You set the scope, it starts in minutes, it safely attempts real exploitation, it includes retests after you fix things, and it ends with a report you can hand to an examiner.
  • Automated internal penetration test, from $2,995 for a 30-day window (up to 25 internal hosts), for your office or branch network.
  • External vulnerability scanning, from $595 a year (10 IPs), run on a schedule so the every-six-months assessment is covered all year.
  • Companies with several branches or websites: the Standard external test covers 10 external IPs or domains for $3,495, and annual programs start at $5,995 a year.

When you need an engineer

If your examiner, insurer, or attorney asks for a test led by a named engineer, our managed penetration testing team does that.

This page is general information, not legal advice. Ask your attorney or compliance advisor how the rule applies to your business.

Will your auditor accept it? See what is in the report.

See pen test pricing and buy online · Talk to a specialist

Related: FTC Safeguards Rule overview, New York DFS, auto dealerships, tax and accounting firms, penetration test cost

Ready when you are

Ready to get your pen test done this week?

Automated penetration testing from Clone Systems starts at $1,995 for an external test and $2,995 for an internal test. Buy it online, start in minutes, and retest for free within your 30-day window.