Answer · Updated August 2026
Does the FTC Safeguards Rule apply to law firms?
Direct answer
Sometimes. The FTC Safeguards Rule implements the Gramm-Leach-Bliley Act for non-bank 'financial institutions,' and a law firm is covered only when its work qualifies as a financial activity — certain real-estate settlement, tax, or debt-collection practices, for example. But many firms comply voluntarily regardless, because clients, banks, and cyber insurers treat the Safeguards framework as the de facto baseline for protecting client financial data.
Who is actually covered
The Rule applies to businesses 'significantly engaged' in financial activities. Most litigation and advisory practices fall outside that definition, but coverage is activity-based, not profession-based — a firm running a settlement operation or providing certain financial-services work can be in scope. When in doubt, get a coverage analysis from counsel rather than assuming either way.
What the Rule requires
The 2021-amended Rule is prescriptive. Its core elements:
- A designated qualified individual accountable for the security program
- A written risk assessment and a Written Information Security Program (WISP)
- Encryption of customer data at rest and in transit, and multi-factor authentication
- Annual penetration testing and biannual vulnerability assessments, or continuous monitoring designed to detect equivalent changes
- A written incident-response plan and periodic reports to the board or equivalent leadership
Why uncovered firms follow it anyway
Outside-counsel guidelines from banks, insurers, and financial-services clients frequently incorporate Safeguards-style controls by reference. Cyber-insurance applications ask the same questions. Treating the Rule as your checklist — WISP, MFA, encryption, testing cadence, IR plan — puts you ahead of both regulators and the client audits that actually arrive.
Related questions
What is the testing schedule the Rule names?
Annual penetration testing plus vulnerability assessments every six months, or continuous monitoring and other systems reasonably designed to detect changes. That schedule is why continuous assessment has become the practical default.
Does the Rule require a WISP?
Yes — a Written Information Security Program is the centerpiece document, and it is also the first thing insurers and corporate clients ask to see. Our WISP template for law firms maps each section to the Safeguards elements.
What are the penalties for covered firms that ignore it?
FTC enforcement can bring civil penalties per violation plus long-term consent decrees with mandated monitoring. For most firms, though, the more immediate risk is commercial: failing a client's security review or an insurer's claim investigation.
