Skip to content
DefendGen

Financial services

Security monitoring for firms the FTC Safeguards Rule now covers.

Tax preparers, CPA firms, auto dealers, mortgage brokers, and registered advisors. The Safeguards Rule brought a lot of small firms under obligations that used to apply only to banks.

FTC Safeguards RulePCI DSS where cards are takenSEC and FINRA expectationsCyber insurance controls

The problem

Regulated like a large organisation, staffed like a small one.

The Safeguards Rule expects a written security programme, a qualified individual accountable for it, continuous monitoring or annual testing, multi-factor authentication, encryption, and an incident response plan. For a fifteen person tax practice that reads like a full-time job. It is not, but it does need somebody watching, and it needs the evidence to exist before anyone asks for it.

What we see

Three attacks that land here.

  1. 01

    Client data theft in filing season

    Attackers time campaigns to the busiest weeks, when staff are moving fast and a malicious attachment looks like one more client document.

  2. 02

    Wire and payment fraud

    A compromised mailbox is used to change bank details on a real transaction. The money is usually gone before anyone notices.

  3. 03

    Credential stuffing on client portals

    Reused passwords are tested at scale against the portal where clients upload their financial documents.

How we fit

What this looks like for a financial services business.

The service is the same one every client gets. What changes is which evidence matters to you and who is going to ask for it.

  • Continuous monitoring that satisfies the Safeguards Rule expectation rather than an annual scan you have to remember to book.
  • Multi-factor authentication enforcement checks, reported monthly, because that is the control most often found missing after an incident.
  • An evidence package mapped to the Rule, ready when your carrier or regulator asks.
  • Analyst coverage through filing season nights and weekends, when the campaigns actually land.

Where to start

A 45 minute assessment, then a decision.

We review your identity, endpoint, email, and backup controls against what your insurer and your framework expect. You receive a written scorecard and a 90 day roadmap within five business days, yours to keep whether or not you engage us. You can see the reporting format on our sample report page first.