FTC Safeguards Rule
Applies to many non-bank financial businesses, such as mortgage lenders and brokers, tax preparers, debt collectors and some investment advisers. It requires a written information security programme and, unless you use continuous monitoring, annual penetration testing and vulnerability assessments every six months. Since May 13, 2024, certain breaches affecting 500 or more consumers must be reported to the FTC within 30 days.
Source: FTC: Safeguards Rule, what your business needs to know