• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Cisco Umbrella

Enterprise network security

  • Contact Sales
  • Login
    • Umbrella Login
    • Cloudlock Login
  • Search
Search
  • Why Us
    • Why Cisco Umbrella
      • Why Try Umbrella
      • Why DNS Security
      • Why Umbrella SASE
      • Our Customers
      • Customer Stories
      • Why Cisco Security
    • Fast Reliable Cloud
      • Global Cloud Architecture
      • Cloud Network Status
      • Global Cloud Network Activity
    • Unmatched Intelligence
      • A New Approach to Cybersecurity
      • Interactive Intelligence
      • Cyber Attack Prevention
      • Umbrella and Cisco Talos Threat Intelligence
    • Extensive Integrations
      • IT Security Integrations
      • Hardware Integrations
      • Meraki Integration
      • Cisco Security for Chromebook
  • Products
    • Cisco Umbrella Products
      • Cisco Umbrella Cloud Security Service
      • Recursive DNS Services
      • Cisco Umbrella SIG
      • Umbrella Investigate
      • What’s New
    • Product Packages
      • Cisco Umbrella and Cisco Secure Access Packages
      • – DNS Security Essentials Package
      • – DNS Security Advantage Package
      • – SIG Essentials Package
      • – SIG Advantage Package
      • Umbrella Support Packages
      • Cisco Umbrella for Government Packages
    • Functionality
      • DNS-Layer Security
      • Secure Web Gateway
      • Cloud Access Security Broker (CASB)
      • Cloud Data Loss Prevention (DLP)
      • Cloud-Delivered Firewall
      • Cloud Malware Protection
      • Remote Browser Isolation (RBI)
    • Man on a laptop with headphones on. He is attending a Cisco Umbrella Live Demo
  • Solutions
    • SASE & SSE Solutions
      • Your SSE journey with Cisco
      • Cisco Umbrella SASE
      • Secure Access Service Edge (SASE)
      • What is SASE
    • Functionality Solutions
      • Web Content Filtering
      • Secure Direct Internet Access
      • Shadow IT Discovery & App Blocking
      • Fast Incident Response
      • Unified Threat Management
      • Protect Mobile Users
      • Securing Remote and Roaming Users
      • Umbrella and Duo Layered Protection
    • Network Solutions
      • Guest Wi-Fi Security
      • SD-WAN Security
      • Off-Network Endpoint Security
    • Industry Solutions
      • Government and Public Sector Cybersecurity
      • Financial Services Security
        • – FTC Safeguards Rule Compliance 2023
      • Cybersecurity for Manufacturing
      • Higher Education Security
      • K-12 Schools Security
      • Healthcare, Retail and Hospitality Security
      • Enterprise Cloud Security
      • Small Business Cybersecurity
  • Resources
    • Content Library
      • Top Resources
      • Research Reports
      • Case Studies
      • Videos
      • Datasheets
      • eBooks
      • Solution Briefs
      • Cybersecurity Webinars
    • International Documents
      • Deutsch/German
      • Español/Spanish
      • Français/French
      • Italiano/Italian
      • 日本語/Japanese
    • Security Definitions
      • What is DNS Security
      • What is a Secure Web Gateway
      • What is a Cloud Access Security Broker (CASB)
      • What is Security Service Edge (SSE)
      • What is Secure Access Service Edge (SASE)
      • Cyber Threat Categories and Definitions
    • For Customers
      • Support
      • Customer Success Webinars
      • Free Trial Quick Start Guide
      • Free Trial Help and Tips
  • Trends & Threats
    • Market Trends
      • Generative AI Cybersecurity Risks and Rewards
      • Hybrid Workforce
      • Rise of Remote Workers
      • Secure Internet Gateway (SIG)
    • Security Threats
      • How to Stop Phishing Attacks
      • Malware Detection and Protection
      • Ransomware is on the Rise
      • Cryptomining Malware Protection
      • Cybersecurity Threat Landscape
      • Global Cyber Threat Intelligence
    •  
    • Woman connecting confidently to any device anywhere
  • Partners
    • Channel Partners
      • Partner Program
      • Become a Partner
    • Service Providers
      • Secure Connectivity
      • Managed Security for MSSPs
      • Managed IT for MSPs
    •  
    • Person looking down at laptop. They are connecting and working securely
  • Blog
    • News & Product Posts
      • Latest Posts
      • Products & Services
      • Customer Focus
      • Feature Spotlight
    • Cybersecurity Posts
      • Security
      • Threats
      • Cybersecurity Threat Spotlight
      • Research
    •  
    • Register for a webinar - with illustration of connecting securely to the cloud
  • Contact Us
  • Umbrella Login
  • Cloudlock Login
  • Free Trial
Clearing search keywords
Spotlight

FTC Safeguards Rule: Get Compliant and Get on With Business

Author avatar of Nazanin HoglundNazanin Hoglund
Updated — February 27, 2024 • 4 minute read
View blog >

Are you writing loans at your car dealership, printing checks, issuing your own store credit card — or otherwise handling consumer financial data? You may not consider yourself a “financial institution” — but the U.S. Federal Trade Commission (FTC) sure does. FTC is classifying countless companies as a “non-banking financial institutions” subject to its revised Safeguards Rule cybersecurity regulation.

Confused? Concerned? Cisco is here to help you get compliant.

What is the revised FTC Safeguards Rule?

The FTC has stated that the Revised Safeguards Rule “provides more concrete guidance for businesses.” It mandates financial institutions establish and maintain a robust data security program, safeguarding sensitive customer information, including “non-public personal information.”

Among other things, the revised Safeguards Rule requires:

  1. Planning and action to address “reasonably foreseeable internal and external risks” – in other words, protection against data breaches, data leakage, phishing, and ransomware
  2. Implementation of multifactor authentication

Who does the revised FTC Safeguards Rule apply to?

The Safeguards Rule originally applied to organizations significantly engaged in financial activities, like banks. With the revision, the FTC’s expanded definition also includes businesses involved in “activities incidental to such financial activities.” This change has significantly broadened the scope of businesses that must comply.

Businesses classified by FTC as “financial institutions” include:

  • Auto dealers
  • Retailers providing store credit
  • Investment advisors
  • Mortgage brokers
  • Real estate appraisers
  • Real estate settlement services
  • Accountants and tax preparers
  • Check cashiers, money wirers
  • Consumer check printers and sellers

The Code of Federal Regulations provides an expanded list of covered organizations.

How Cisco’s cloud-native security can help

Cisco’s cloud-native security simplifies deployment, so you can deliver concrete results and quickly meet FTC Safeguards Rule requirements. Together, Cisco Umbrella and Cisco Duo provide robust converged threat defense and multi-factor authentication (MFA) to strengthen your security posture, pass audits, and delight your end-users. Cisco Security operates at the speed of business, improving network performance, protecting users both when they’re on and off the network, and authenticating them without impeding work.

Start getting compliant in 24 hours – and stay that way

With just two clicks, you can start demonstrating your commitment to FTC Safeguards Rule compliance, taking advantage of Umbrella’s foundational DNS-layer security. Umbrella blocks web threats and malicious IPs, mitigating risks and reducing security alerts by up to 70% before they even hit your firewall.

As you hone your threat model, you’ll find Umbrella and Duo great partners for your security journey. Umbrella’s capabilities are tightly integrated in a single manager, and include:

  • Data loss prevention (DLP) to mitigate exfiltration of sensitive data
  • Cloud malware sandboxing to identify malicious files
  • Cloud access security broker (CASB) for control of risky apps
  • Remote browser isolation (RBI) to isolate the browser threat vector

Each Umbrella component emphasizes ease-of-use and effectiveness. For instance, Umbrella features the industry’s only DLP that consolidates in-line and cloud DLP policies and logging, saving you time and ensuring greater visibility.

Cisco Umbrella SSE and SASE security components, which include: DNS-layer security, cloud-delivered firewall (CDFW), Cisco Talos Threat Intelligence, Secure Web Gateway (SWG), Remote Browser Isolation (RBI), and Cloud Access Security Broker (CASB). CASB includes the following functionality: app discovery and control, cloud malware detection, and data loss prevention (DLP).

Considering working with a managed security provider (MSP/MSSP/MDR)? Insist upon one of the hundreds supporting Umbrella because its rich API streamlines management and enables efficient orchestration.

Protect your reputation – and bottom line – with leading threat defense

This year, Forrester Consulting independently interviewed multiple organizations to determine Umbrella’s return on investment in the real world. Forrester quantitively measured that Umbrella’s average payback period is less than twelve months — driven in great part by its security effectiveness.

Every day, over 400 researchers and analysts in the Cisco Talos threat intelligence team deliver updates to Umbrella to fight the latest threats. Additionally, Umbrella’s built-in data identifiers contribute to compliance with the FTC Safeguards Rule. They mitigate exfiltration of consumer financial data including U.S. persons names, bank routing and account information, credit cards, and Social Security and driver’s license numbers.

Additional third-party validation includes:

  • 2022 Frost and Sullivan Enabling Technology Leader Award, Global Secure Web Gateway Industry
  • Peer Spot 2022 GOLD awards for SWG, CASB, and SASE
  • 2022 SC Media Best Authentication Technology Award, which notes that, “Cisco Duo offers a strong, easy, and adaptive authentication.”

Defeat hackers, improve user experience

Umbrella and Duo are critical to FTC Safeguards Rule compliance. Together, they help protect every managed and unmanaged device and every application, allowing your users to continue working with the tools they love, anywhere, anytime. Cisco proactively identifies malicious IPs and the user device health and security posture, only permitting access when the requirements you set are met.

We never forget that availability and uptime are essential security attributes. Our highly redundant infrastructure, which has maintained continuous DNS uptime since 2006, ensures your organization stays connected and protected. You can see our uptime data for yourself.

We’re here to help you meet the 2023 FTC Safeguards Rule deadline

When you choose Umbrella, you’re joining 26,000+ other Umbrella customers that have enhanced their security posture while meeting multiple audit requirements.

See for yourself! Join a free Umbrella Studio workshop to:

  • Discover how Umbrella can address the use cases that matter to you
  • Learn how to configure and deploy Umbrella
  • Earn awards by completing fun challenges

Content is provided in a step-by-step format with self-contained lab resources each participant can use to deploy Umbrella in their own virtual environment. To learn more about how to comply with the FTC Safeguards Rule, check out our infographic on FTC Safeguards Rule Compliance or download our At-a-Glance Compliance Guide.

Umbrella and Duo are critical to FTC Safeguards Rule compliance. Together, they help protect every managed and unmanaged device and every application, allowing your users to continue working with the tools they love, anywhere, anytime.

Post this quote

Additional Resources

  • FTC Safeguards Rule Infographic
  • FTC Safeguards Compliance At-a-Glance

Suggested Blogs

  • Where Do I Start With SASE Evaluations? Gartner® Report September 10, 2024 3 minute read
  • Cisco Umbrella: A Leader in the GigaOm Radar for DNS Security June 26, 2024 3 minute read
  • The Perfect Blend: Qdoba’s SASE Transformation May 30, 2023 2 minute read

Share this blog

FacebookTweetLinkedIn
Subscribe to the Cisco Umbrella blog Subscribe

Follow Us

Facebook X LinkedIn Youtube

Footer Sections

What we make

  • Cloud Security Service
  • DNS-Layer Network Security
  • Secure Web Gateway
  • Security Packages

Who we are

  • Global Cloud Architecture
  • Cloud Network Status
  • Cloud Network Activity
  • OpenDNS is now Umbrella
  • Cisco Umbrella Blog

Learn more

  • Webinars
  • Careers
  • Support
  • Cisco Umbrella Live Demo
  • Contact Sales
Umbrella by Cisco
208.67.222.222+208.67.220.220
2620:119:35::35+2620:119:53::53
Sign up for a Free Trial
  • Cisco Online Privacy Statement
  • Terms of Service
  • Sitemap

© 2025 Cisco Umbrella