Readiness check
- See exactly what's required
- See what you're missing
- A clear quote for the rest
- No obligation
If you're an auto dealer, tax preparer, accountant, insurance agency or mortgage broker, federal law requires you to have a written information-security program. The fines reach about $53,000 per violation — and most owners haven't set it up. We handle the whole thing for a flat monthly fee.
The FTC Safeguards Rule covers ordinary local businesses that handle customers' financial information, not just banks.
Any dealer that arranges financing or leasing — franchise, independent, and buy-here-pay-here.
Covered by the Rule, and the IRS separately requires a written security plan (Pub 4557).
Firms that prepare taxes or hold client financial data.
Agencies and brokers handling customers' financial information.
Mortgage brokers, lenders and consumer-finance companies.
Payday, title and other businesses extending credit to consumers.
In plain English, the program the FTC expects you to have and maintain.
We do the work and stay on as your named security lead, so you don't have to become a security expert.
A short questionnaire and a look at your public setup — a plain two-page summary of where you stand and what's missing. No obligation.
We write the security program, name your Qualified Individual, turn on MFA and encryption, run the risk assessment and set up the breach plan.
We stay on as your named security lead: monthly check-ins, the annual review, and we keep the evidence — so you're ready when someone asks.
Does this really apply to a small business like mine?
Yes. The Rule has no size exemption for being covered — a one-person tax office or a small used-car lot is a “financial institution” under it. Firms with fewer than 5,000 records get a lighter version, but still need the written program, a named lead, MFA and encryption.
What are the penalties, really?
Fines run up to about $53,000 per violation, and the bigger risk for most owners is a data breach or a lawsuit where not having the program is the thing that sinks you. A breach of 500+ consumers' unencrypted data must be reported to the FTC within 30 days.
How much does it cost?
A one-time setup to build the program (typically $1,500–$7,000 by size), then a flat monthly fee to keep you compliant and be your named security lead — usually $1,200–$4,000/month. We quote you exactly after the free readiness check.
We already have an IT person.
Great — most IT handles the computers. The Safeguards program is a specific set of written documents and controls the FTC asks for. We check in minutes whether that paperwork exists; if it does, you're set.
A two-page readiness check, no obligation. Then we make the problem go away.
Golden Rock builds and maintains your security program to the requirements of the FTC Safeguards Rule (16 CFR Part 314). This is a compliance and security service, not legal advice, and does not guarantee against enforcement or a breach.
Hi! Tell me what’s going on with your business tech and I’ll point you to the right service. A website, IT trouble, a security worry, or AI?
AI-generated guidance. For bookings, email [email protected].