Back to blog
Compliance

The GLBA Safeguards Rule: The US Regulator Already Made the Case for Continuous Testing

SpartanX Research7 min read
The GLBA Safeguards Rule: The US Regulator Already Made the Case for Continuous Testing

Most compliance mandates tell you to run a test. The FTC's GLBA Safeguards Rule did something more interesting: it gave US financial institutions a choice, and in doing so it described the future of testing in a single sentence. Either continuously monitor the effectiveness of your safeguards, or fall back to annual penetration testing plus vulnerability assessments every six months.

Read the structure of the sentence. Continuous monitoring is named first, and the pentest regime is what you owe absent it: "Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, you shall conduct..." The FTC never says it prefers one path. But it wrote the annual test as the fallback position, and for anyone deciding how to test in 2026, that structure matters.

What the Safeguards Rule requires

The revised Safeguards Rule (16 CFR 314.4), with requirements that took effect on June 9, 2023, requires covered financial institutions to maintain a written information security program and to regularly test the safeguards in it. On testing specifically, the Rule gives two paths:

  • Continuous monitoring of the effectiveness of your safeguards, or, if you do not have that,
  • Annual penetration testing of systems handling customer information, plus vulnerability assessments at least every six months, whenever there are material changes to your operations or business arrangements, and whenever there are circumstances you know or have reason to know may have a material impact on your information security program.

Testing must be risk-based and scoped by your risk assessment. The Rule does not impose a documentation requirement on the test itself, but the results have to survive contact with paper: the Qualified Individual's written report to the board, required at least annually, must address the results of testing.

Who this actually covers is the part most summaries get wrong. GLBA splits enforcement across agencies, and the FTC gets the slice nobody else supervises. Banks, savings associations, and federally insured credit unions answer to the federal banking agencies and the NCUA under a parallel set of Safeguards Guidelines, not to the FTC. Insurers answer to their state insurance authority. SEC-registered advisers and broker-dealers answer to the SEC. What lands on the FTC is the non-bank world: mortgage lenders and brokers, motor vehicle dealers that arrange financing, finance companies, account servicers, wire transferors and check cashers, collection agencies, tax preparation firms, credit counselors, non-federally-insured credit unions, investment advisers not required to register with the SEC, and a long tail of fintech and financial-adjacent businesses that never thought of themselves as FTC-regulated. If you are a bank, the argument below still applies to you, but your rulebook is the interagency guidance rather than 16 CFR 314.

One exemption matters. Under 16 CFR 314.6, financial institutions maintaining customer information on fewer than 5,000 consumers are exempt from Section 314.4(d)(2) entirely, along with the written risk assessment, the written incident response plan, and the annual board report. They still owe the general duty to regularly test or otherwise monitor the effectiveness of their safeguards under 314.4(d)(1). They just do not owe the continuous-monitoring-or-pentest choice.

Why the point-in-time path is a treadmill

Most firms default to the second path, the annual pentest plus semiannual scans, because it is familiar. It is also the harder path to sustain well.

It is a treadmill of scheduled events. An annual test and two scans are three calendar commitments that each capture a moment. In between, your environment keeps changing, and your evidence keeps aging. You are always either just past a test and slowly going stale, or just before one and scrambling. Each of those events proves a point and then stops; a continuous adversary campaign never stops, which is exactly the gap the Rule's continuous-monitoring path is written to close.

Scans are not proof. Semiannual vulnerability assessments produce long lists of theoretical issues, most of which are not actually exploitable. Sorting the real risk from the noise, twice a year, is exactly the work a small or stretched team cannot keep up with.

The window stays open. A weakness introduced the week after your annual pentest can sit exploitable for almost a year. The Rule's whole intent is to keep safeguards effective over time, which a once-a-year test cannot guarantee.

The continuous path is the harder one to actually build. The Rule offers it as a full alternative to the annual test, but for most firms "continuous" has meant continuous scanning, not continuous proof, because running real, continuous, adversary-grade testing by hand is not feasible.

How SpartanX supports your Safeguards Rule program

This is where Autonomous Exposure Management (AEM) fits the Rule almost exactly. SpartanX is the first AEM platform: an autonomous adversary that runs the full offensive loop continuously and proves every finding with evidence. It makes the continuous path practical for the first time.

For a Safeguards Rule program:

  • Continuous, not calendar-bound. Instead of an annual test and two scans, SpartanX tests the systems that handle customer information continuously, including after material changes, which is the continuous posture the Rule accepts in place of the annual test.
  • Proof, not just a scan list. Every finding is exploit-validated with proof-of-concept evidence, so your team works the handful of issues that are genuinely exploitable rather than triaging thousands that are not.
  • Risk-based and documented. SpartanX prioritizes by business impact and produces the documented, audit-ready evidence the Rule expects, with remediation driven through and retested.
  • Inside and out. On the outside, that includes your mobile apps and the APIs behind them, where customers actually interact with their information. With NodeX, SpartanX also tests internally, where customer information lives and where an attacker pivots to reach it.

To be precise about the boundary: SpartanX supports and strengthens the testing component of your Safeguards Rule program and gives you the documented evidence behind it. It does not by itself make you GLBA compliant, and it does not replace your written security program, your qualified individual, or your own governance. What it does is let you take the continuous path the FTC describes, with proof, instead of running the annual-test treadmill.

Why now

The core program requirements at 16 CFR 314.4 took effect in June 2023, and the FTC's breach-notification requirement followed in May 2024. The FTC has brought Safeguards Rule cases before, against an online tax preparer, a peer-to-peer payments app, and an auto-dealer software vendor, none of which looked like a bank, and the amended Rule gives it considerably more to work with. For 2026, the practical question is no longer whether you are covered, but which testing path you are on. The firms moving to continuous, evidence-based testing now are converting a recurring compliance scramble into a steady state, and closing the exposure window the annual model leaves open.

The shift in one line

The FTC wrote continuous monitoring as a full alternative to the annual test, and the annual test as what you owe without it. Autonomous Exposure Management is how you actually run continuous, with proof rather than just more scanning.

SpartanX is The Ultimate Adversary™, pointed at the systems that hold your customers' information, continuously. Request a guided proof-of-value, or learn what Autonomous Exposure Management is.

Ready to see SpartanX in action?

See how a continuous adversary maps your whole attack surface, inside and out, and proves what is actually exploitable.