FTC Safeguards Compliance
FTC Safeguards compliance support for dealerships and other businesses that need practical, security first path forward
“There is quite a lot that dealers must do between now and December, and the time for dealers to act is now in order to ensure compliance by the deadline.” – NADA
Barcom Has Your Back
The revised FTC Safeguards Rule has many dealerships across the country scrambling to meeting compliance by the June 9th deadline. Dealers who fail to meet compliance may face penalties of up to $43,792 per violation.
The Barcom Technology Solutions team have provided extensive cybersecurity and IT services to dealerships across the country, with compliance being a large part of our focus.
If you would like to schedule a private consultation reach out to Ava Mattei.
(210) 870-1948
What does the revised Safeguards Rule require?
Barcom has gone through every page to find the rules that will impact dealers the most
- Submit a periodic written report to the dealership’s board of director or senior officer on compliance with these new requirements and overall status and results of the Information Security Program (ISP).
- Implement a written “Incident Response Plan”.
- Perform periodic written risk assessments that adhere to certain requirements.
- Encrypt all data in transit over external networks and at rest.
- Require Multi-Factor Authentication (MFA), such as an SMS/text verification code, for all systems containing customer nonpublic personal information (NPI).
- Implement a data retention policy and dispose of customer information within two years after the end of a customer relationship, unless doing so conflicts with state or federal law.
- Adopt procedures for IT “change management”.
- Appoint a single “Qualified Individual” to oversee the dealership’s ISP.
- Monitor and log the activity of authorized users and detect unauthorized use or access of customer information.
- Implement a system or software for continuous monitoring of cybersecurity threats, including annual penetration tests and bi-annual vulnerability tests.
- Perform “security awareness” training for all employees.
- Periodically assess service providers for their adequacy of physical and technical safeguards.
For a full description of the Safeguards Rule, we have included the FTC Website for your convenience.
What Is FTC Safeguards Compliance?
In plain English, FTC Safeguards compliance means building and maintaining a written information security program designed to protect customer information.
The FTC Safeguards Rule applies to certain financial institutions under FTC jurisdiction. Depending on the business model, that can include auto dealerships, finance-related businesses, and other organizations handling covered customer financial information.
The rule is not just about policy on paper. It reaches into the real guts of your business, including:
- Risk assessments
- Access controls
- Multi-factor authentication
- Encryption or approved alternatives
- Employee security awareness training
- Service provider oversight
- Incident response planning
- Ongoing testing and monitoring
- Reporting to leadership on the security program
WHO NEEDS FTC SAFEGUARDS RULE COMPLIANCE HELP?
Barcom’s FTC Safeguards Simplified service is built for organizations that know customer information needs stronger protection and do not want to gamble with loose controls, inconsistent processes, or half-finished compliance work.
This page is especially relevant for:
- Auto dealerships
- Dealer groups with multiple rooftops
- Finance-related businesses under FTC jurisdiction
- Organizations handling nonpublic customer information
- Companies that need outside support for security and compliance execution
- Internal IT teams that need reinforcements, not another lecture deck
For dealerships, the pressure is especially real. Sales systems, service systems, user access, third-party vendors, finance workflows, and customer data all collide in one noisy environment. That is exactly why FTC compliance for auto dealerships cannot be treated like a box-checking exercise.
Why FTC Safeguards Compliance Matters Now
This is not shelf-decor compliance.
The FTC Safeguards Rule expects covered businesses to maintain a real security program that protects customer information through administrative, technical, and physical safeguards. That includes areas like risk assessment, multi-factor authentication, training, incident response, testing, and oversight.
There is also added urgency. The FTC’s breach notification requirement took effect in 2024 for certain breaches involving 500 or more consumers. For affected covered businesses, that raises the stakes on visibility, readiness, and response.
Translation: weak controls are no longer just a technical problem. They can become a compliance problem, a business continuity problem, and a reputation problem all at once. Nasty little domino line.
WHAT’S INCLUDED IN A TYPICAL FTC SAFEGUARDS ENGAGEMENT?
Depending on your environment, Barcom can help with a focused or broader FTC Safeguards compliance engagement.
Typical areas of support include:
- Risk Assessment Support
- Review current systems, workflows, access, and weak points affecting customer information security.
- Written Program Support
- Help organize the technical and operational pieces that support a written information security program.
- Multi-Factor Authentication
- Strengthen account security across critical systems and user roles.
- User Access Controls
- Review who has access to what, where permissions are too loose, and where controls need tightening.
- Security Awareness Training
- Help reduce human-error risk through practical employee training.
- Vulnerability Testing and Penetration Testing
- Support testing efforts that help uncover gaps before attackers do.
- Incident Response Planning
- Improve readiness for security events with a clearer response structure.
- Monitoring and Security Visibility
- Support stronger logging, monitoring, and visibility across systems handling sensitive information.
- Remediation Planning
- Prioritize what needs to happen first, next, and after that — without turning the whole thing into a circus.
Why Choose Barcom for FTC Safeguards Rule Compliance Support?
FTC Safeguards Rule compliance lives at the intersection of cybersecurity, operations, user behavior, infrastructure, and accountability. That means the job usually falls apart when it gets split across too many disconnected vendors.
Barcom brings those moving pieces together.
Businesses choose Barcom because we help align compliance needs with the actual systems and safeguards that support them, including:
- Managed IT
- Cybersecurity controls
- Security awareness training
- Incident response planning
- Infrastructure support
- Monitoring and remediation planning
- Ongoing operational support
For dealerships, that practical support matters even more. Dealership environments move fast, rely on multiple systems, and juggle sensitive customer information across teams, locations, and vendors. Barcom understands how to support that reality without pretending the answer is just “buy one more tool.”
Barcom also provides support across Texas, with headquarters in San Antonio and service coverage across key business markets. That means you are not stuck with a remote-only vendor tossing policy language over the wall and calling it a day.
Our FTC Safeguards Simplified Process
1. Review the Current State
We start by identifying the systems, users, risks, and operational gaps that affect customer information security.
2. Identify Priority Gaps
Not every issue should trigger the same five-alarm fire. We help sort the high-risk problems from the background noise.
3. Strengthen Core Safeguards
We support the rollout or improvement of key safeguards like MFA, access controls, training, testing, and monitoring.
4. Improve Response Readiness
We help strengthen incident response planning and the operational discipline needed to support a more resilient security program.
5. Support Ongoing Improvement
FTC Safeguards compliance is not a one-and-done event. Systems change, vendors change, threats change, and teams change. Your safeguards need to keep up.
Built for Texas Businesses
Barcom supports organizations across Texas, including businesses in San Antonio, Austin, Houston, Fort Worth, and the Rio Grande Valley.
That matters because compliance work is never purely abstract. It touches the way your people work, how your systems are managed, how vendors are handled, and how incidents get escalated. Barcom helps businesses simplify that work with practical support grounded in real operations, not theory alone.
Remote IT Support & On‑Site IT Services
Whether your team is in the office or remote, Barcom provides fast Houston IT support to keep them working.
- Remote IT support: Quick troubleshooting, software installs, and user support via secure remote tools.
- On‑site IT support in Houston: When hands‑on help is needed—hardware failures, cabling, new equipment installs—we dispatch certified technicians to your location.
Our Services and Benefits Include:
Reduced overhead cost. We've invested in advanced technologies so you don't have to.
24 / 7 / 365, remote-in Help Desk
Expedited Field Team for any on-site needs
Dedicated Solutions Team for consistent, familiar consulting
Reduced Project Rate for any work outside of contract.
Emergency Response Team
Holistic, thorough network documentation, updated at the time any work is completed
Quarterly Security & Performance Audits
Receive priority over non-contracted clients.
30 Day Out. We stand by the quality of our work and don't need to lock our clients into extended contracts.
Protect Your Business Today
Protect your business today with our advanced security solutions tailored to meet your specific needs, ensuring you have full visibility and control over your operations.
Don’t let IT hurdles slow your growth. Contact Barcom Technology Solutions today for a comprehensive assessment of your Houston IT services and discover how our managed support can transform your business.
