FTC Safeguards Rule
Prove the Person. Safeguard the Data
Support FTC Safeguards Rule compliance with phishing-resistant MFA
The FTC Safeguards Rule requires covered financial institutions to run multi-factor authentication, access controls, monitoring, and incident response. TokenCore™ delivers FIDO2-certified, phishing-resistant authentication that proves the authorized person before access is granted.
No shared secret. No code to phish. No fallback.
The Rule
Enforceable. And Expanding.
Understanding the FTC Safeguards Rule
The Safeguards Rule sets the security program requirements for covered financial institutions under the GLBA, with authentication now an explicit obligation.
16 CFR Part 314
The regulation that defines the required security program. Authentication is explicitly required.
Relationship to the GLBA
The Safeguards Rule implements the GLBA's data protection mandate for financial institutions.
Covered Financial Institutions
A broad definition that reaches well beyond banks. If you handle customer financial data, you are likely in scope.
2021 Rule Amendments
The amendments added specific technical safeguards, including multi-factor authentication.
June 2023 Enforcement
The updated requirements became enforceable. The expectation is now operational, not aspirational.
Expanded Authentication Obligations
Access to information systems has to prove the person. Identity is the control.
The Requirement
MFA, Made a Mandate.
What are the FTC Safeguards Rule MFA requirements?
The Safeguards Rule names multi-factor authentication as a required control for accessing information systems. The intent is strong, verifiable identity.
Section 314.4 (c)(5)
Multi-Factor Authentication
MFA for anyone accessing information systems, or an approved equivalent.
- MFA requirements
- Accessing information systems
- Equivalent control considerations
- Qualified Individual responsibilities
Why Authentication Became Core
The attacks moved to identity, so the rule did too.
- Credential theft
- Account takeover
- Modern phishing attacks
- Regulatory focus on identity

The Guide
Map Every Requirement.
Download the FTC Safeguards Rule Requirements Mapping Guide
The mapping guide lines up FTC Safeguards Rule controls against phishing-resistant FIDO2 authentication, requirement by requirement. A practical reference for teams building toward compliance.
See how TokenCore™ maps to each FTC Safeguards Rule requirement.
The Support
Strong Authentication. Proven Access.
How TokenCore™ supports FTC Safeguards Rule controls
Strong Multi-Factor Authentication (314.4(c)(5))
Possession and biometric proof, phishing-resistant by design.
- Possession factor
- Biometric factor
- FIDO2 authentication
- Phishing-resistant MFA
Access Control Protection (314.4(c)(1))
Access bound to the hardware and the individual.
- Device-bound identity
- Authorized access
- Hardware-based authentication
Encryption and Compensating Controls (314.4(c)(3))
Keys generated and held in a tamper-proof secure element.
- Secure element protection
- Private key security
- Authentication architecture
Monitoring and Auditability (314.4(c)(8))
Every access event traceable to the person behind it.
- Authentication logs
- Identity telemetry
- Audit evidence
Service Provider Security (314.4(f))
Provider access held to the same proven standard.
- MSP access
- Vendor access
- Third-party authentication
Incident Response Readiness (314.4(h))
Close the credential path attackers rely on.
- Account takeover prevention
- Ransomware reduction
- Security event mitigation
Beyond Legacy MFA
The Code Is the Weakness.
Why organizations are moving beyond OTP and push-based MFA
Risks of Traditional MFA
A one-time code can be entered by anyone who intercepts it. A shared secret is a secret an attacker can hold too.
Push Fatigue Attacks
Approval prompts can be worn down until someone taps yes. TokenCore™ has nothing to approve and nothing to pressure.
Reverse Proxy and AiTM Attacks
Relay pages capture codes in real time and pass them through. There is no code to relay when the fingerprint stays on the device.
Why FIDO2 Delivers Stronger Security
The credential is bound to the hardware and the person. Nothing to phish, nothing to reuse, nothing to send.
See It in Action
Make Identity Absolute
Strengthen authentication controls for FTC-regulated environments
See how TokenCore™ strengthens authentication controls, reduces identity-related cyber risk, and supports FTC Safeguards Rule security requirements across your institution.