FTC Safeguards Rule

Prove the Person. Safeguard the Data

Support FTC Safeguards Rule compliance with phishing-resistant MFA

The FTC Safeguards Rule requires covered financial institutions to run multi-factor authentication, access controls, monitoring, and incident response. TokenCore™ delivers FIDO2-certified, phishing-resistant authentication that proves the authorized person before access is granted.

No shared secret. No code to phish. No fallback.

FTC Safeguards Rule

The Rule

Enforceable. And Expanding.

Understanding the FTC Safeguards Rule

The Safeguards Rule sets the security program requirements for covered financial institutions under the GLBA, with authentication now an explicit obligation.

16 CFR Part 314

The regulation that defines the required security program. Authentication is explicitly required.

Relationship to the GLBA

The Safeguards Rule implements the GLBA's data protection mandate for financial institutions.

Covered Financial Institutions

A broad definition that reaches well beyond banks. If you handle customer financial data, you are likely in scope.

2021 Rule Amendments

The amendments added specific technical safeguards, including multi-factor authentication.

June 2023 Enforcement

The updated requirements became enforceable. The expectation is now operational, not aspirational.

Expanded Authentication Obligations

Access to information systems has to prove the person. Identity is the control.

The Requirement

MFA, Made a Mandate.

What are the FTC Safeguards Rule MFA requirements?

The Safeguards Rule names multi-factor authentication as a required control for accessing information systems. The intent is strong, verifiable identity.

Section 314.4 (c)(5)
Multi-Factor Authentication

MFA for anyone accessing information systems, or an approved equivalent.

  • MFA requirements
  • Accessing information systems
  • Equivalent control considerations
  • Qualified Individual responsibilities
Section 314.4 (c)(5) Multi-Factor Authentication

Why Authentication Became Core

The attacks moved to identity, so the rule did too.

  • Credential theft
  • Account takeover
  • Modern phishing attacks
  • Regulatory focus on identity
Why Authentication Became Core
Group 21782-1

The Guide

Map Every Requirement.

Download the FTC Safeguards Rule Requirements Mapping Guide

The mapping guide lines up FTC Safeguards Rule controls against phishing-resistant FIDO2 authentication, requirement by requirement. A practical reference for teams building toward compliance.

See how TokenCore™ maps to each FTC Safeguards Rule requirement.

The Support

Strong Authentication. Proven Access.

How TokenCore™ supports FTC Safeguards Rule controls

Strong Multi-Factor Authentication (314.4(c)(5))

Strong Multi-Factor Authentication (314.4(c)(5))

Possession and biometric proof, phishing-resistant by design.

  • Possession factor
  • Biometric factor
  • FIDO2 authentication
  • Phishing-resistant MFA
Access Control Protection (314.4(c)(1))

Access Control Protection (314.4(c)(1))

Access bound to the hardware and the individual.

  • Device-bound identity
  • Authorized access
  • Hardware-based authentication
Encryption and Compensating Controls (314.4(c)(3))

Encryption and Compensating Controls (314.4(c)(3))

Keys generated and held in a tamper-proof secure element.

  • Secure element protection
  • Private key security
  • Authentication architecture
Monitoring and auditability (3.14.4(c)(8))

Monitoring and Auditability (314.4(c)(8))

Every access event traceable to the person behind it.

  • Authentication logs
  • Identity telemetry
  • Audit evidence
Service provides security (3.14.4(f))

Service Provider Security (314.4(f))

Provider access held to the same proven standard.

  • MSP access
  • Vendor access
  • Third-party authentication
Incident Response Readiness (314.4(h))

Incident Response Readiness (314.4(h))

Close the credential path attackers rely on.

  • Account takeover prevention
  • Ransomware reduction
  • Security event mitigation

Beyond Legacy MFA

The Code Is the Weakness.

Why organizations are moving beyond OTP and push-based MFA

Risks of Traditional MFA

A one-time code can be entered by anyone who intercepts it. A shared secret is a secret an attacker can hold too.

Push Fatigue Attacks

Approval prompts can be worn down until someone taps yes. TokenCore™ has nothing to approve and nothing to pressure.

Reverse Proxy and AiTM Attacks

Relay pages capture codes in real time and pass them through. There is no code to relay when the fingerprint stays on the device.

Why FIDO2 Delivers Stronger Security

The credential is bound to the hardware and the person. Nothing to phish, nothing to reuse, nothing to send.

See It in Action

Make Identity Absolute

Strengthen authentication controls for FTC-regulated environments

See how TokenCore™ strengthens authentication controls, reduces identity-related cyber risk, and supports FTC Safeguards Rule security requirements across your institution.