Skip to the main content.
Security Parity
16 CFR Part 314 reaches far past banks

Your team can move faster on Microsoft 365 with the same security a bank gets.

Access Business Technologies manages Microsoft 365 for more than 750 financial institutions. The security baseline is the same for every client, the price list has no industry column, and the federal rule behind it already covers a lot more businesses than the people running them realize.

  • One published price list. It does not ask what industry you are in.
  • The FTC Safeguards Rule implements the same statute behind bank exams.
  • Under 5,000 consumers waives four subsections, not the rule.
Watch, 55 seconds

Someone gives notice on Friday. On Monday their laptop still opens the files. Offboarding is where most businesses discover what their access controls actually do.

13
Non-bank business types the rule names by example as financial institutions
16 CFR 314.2(h)(2)
80
Policy Microsoft 365 security baseline deployed to every ABT client
ABT engineering verification
4
Subsections waived under 5,000 consumers, out of the whole rule
16 CFR 314.6
750+
Financial institutions whose Microsoft 365 tenants ABT manages
Access Business Technologies

What does bank-grade security actually mean?

In most marketing it means nothing. Here it means a specific, listable set of controls that ABT deploys identically to every client, and it is worth being precise about what is in it.

Bank-grade is only a useful phrase if someone will tell you what is in it. Otherwise it is an adjective doing the work of an argument. So here is the specific content of the phrase as ABT uses it, drawn from ABT's own engineering verification of the Guardian baseline rather than from a brochure.

ABT deploys an 80-policy Microsoft 365 security baseline purpose-built for financial institutions, with 62 policies formally mapped to Gramm-Leach-Bliley Safeguards Rule requirements. The baseline covers 169 Microsoft Secure Score controls, including data loss prevention, multi-factor authentication enforcement, audit logging, device compliance, and encryption. The 80 policy templates are organized across 11 categories, and each one carries the exact configuration to be deployed plus the comparison rules used to check it later.

Inside that baseline sit 11 Microsoft Entra ID Conditional Access policies that enforce multi-factor authentication, risk-based access controls, device compliance, geographic blocking, and legacy authentication blocking.

The part that makes the rest of this page possible is not any single control. It is this:

The 11 Conditional Access policy templates are consistent across all tenants. The same baseline applies to every customer. The consistency is a feature, not a gap.

ABT engineering verification of the Guardian security baseline

That is an engineering decision with a commercial consequence. Because the baseline does not vary by customer, there is no separate, thinner, cheaper version of it built for businesses that are not banks. There is one baseline. A firm with 60 people on Microsoft 365 gets the control set ABT built for institutions that sit federal IT examinations, because building a second-tier version of it was never on the table.

What that looks like in the tenant

1

Identity is the perimeter

Microsoft Entra ID Conditional Access policies enforce multi-factor authentication and evaluate sign-in risk, device compliance, and location before granting access. Legacy authentication protocols, the ones that quietly bypass multi-factor authentication, are blocked rather than merely discouraged.

2

Sensitive data is classified and watched

Microsoft Purview data loss prevention policies run across Exchange, SharePoint, OneDrive, and Teams, and they detect Social Security numbers, bank account numbers, credit card numbers, and Individual Taxpayer Identification Numbers in externally shared content. Matching email is automatically encrypted, and matches generate alerts. These use Microsoft's own built-in sensitive information types rather than hand-rolled definitions, which means Microsoft maintains and updates the pattern matching.

3

A risk signal ends the session, not just the login

Multi-factor authentication protects the moment a token is issued. It does much less about a session that is already running. ABT runs a custom automation that calls the Microsoft Graph revokeSignInSessions API on any risk detection, which invalidates that user's previously issued refresh tokens and sign-in sessions across every device. An attacker holding a stolen refresh token can no longer mint new access tokens from it, and every session has to authenticate again. Access tokens already issued remain valid until they expire or until continuous access evaluation cuts them, which is why the revocation is paired with Conditional Access rather than relied on alone.

4

Devices have to earn access

Microsoft Intune device compliance requirements covering firewall, antivirus, encryption, and Trusted Platform Module status are enforced through Conditional Access, so a device that drifts out of compliance is handled at its next authentication rather than at the next audit.

None of that is exotic. All of it is Microsoft 365 functionality, subject to the licensing each capability requires. That caveat is not decoration. Risk-based Conditional Access reads Microsoft Entra ID Protection signals, and Microsoft states that full access to Identity Protection requires Microsoft Entra ID P2 or the Microsoft Entra Suite. Microsoft also states that Microsoft 365 Business Premium includes Entra ID P1. So on a Business Premium tenant a policy that depends on sign-in risk can sit deployed and dormant, enforcing nothing, while the policy list looks complete.

That is a licensing fact, not an asterisk on the parity claim, and it cuts exactly the same way for a bank. A community bank on Business Premium has the identical dormant policy. What does not vary by industry is the control set ABT deploys and the price it charges to operate it. What varies, for every buyer in every industry, is the Microsoft plan underneath it. Telling you which controls your current licensing actually supports, which need a different Microsoft plan, and which are simply switched off is a large part of what the assessment below is for.

Is my business covered by the FTC Safeguards Rule?

The rule does not ask whether you are a bank. It asks what activities you engage in, and the list is wider than almost anyone expects.

Start with the sentence that surprises people. The FTC Safeguards Rule, 16 CFR Part 314, states its own purpose plainly: it is the part "which implements sections 501 and 505(b)(2) of the Gramm-Leach-Bliley Act." Its statutory authority is 15 U.S.C. 6801(b) and 6805(b)(2).

That is worth sitting with for a second. The security obligations that apply to a tax preparer are not a lighter cousin of the ones that apply to a bank. They descend from the same statute. Banks and credit unions answer to their own prudential regulators, which issued separate interagency standards under that statute, and everyone else answers to the Federal Trade Commission under Part 314. Different enforcer and a different implementing regulation, with one statutory standard underneath. That is why the security expectations land in recognisably the same place.

And the definition of who it covers is written in terms of activity, not charter. A financial institution is:

any institution the business of which is engaging in an activity that is financial in nature or incidental to such financial activities as described in section 4(k) of the Bank Holding Company Act of 1956.

16 CFR 314.2, definition of financial institution

The rule then supplies thirteen worked examples of businesses that qualify. Not one of them is a bank. Each entry below is drawn from the regulation's own worked examples, condensed to its subject, with the example number so you can read the full text yourself:

Named in the rule, part one

  • Accountants and tax preparation services in the business of completing income tax returnsExample (viii)
  • Automobile dealerships that lease on a nonoperating basis longer than 90 daysExample (ii)
  • Real estate and personal property appraisersExample (iii)
  • Entities providing real estate settlement services, which is where title and escrow sitExample (x)
  • Mortgage brokersExample (xi)
  • Investment advisory companies and credit counseling servicesExample (xii)

Named in the rule, part two

  • Retailers that issue their own credit card directly to consumersExample (i)
  • Businesses that regularly wire money to and from consumersExample (vi)
  • Check cashing businessesExample (vii)
  • Businesses that print and sell checks for consumersExample (v)
  • Career counselors serving people employed by or seeking work in finance, accounting, or auditExample (iv)
  • Travel agencies operating in connection with financial servicesExample (ix)
  • Finders, meaning a company that brings buyers and sellers together for transactions the parties negotiate themselvesExample (xiii)

Read that list again and notice what it is doing. A career counselor is on it. A check printer is on it. A travel agency, under the right conditions, is on it. The drafters were not trying to catch banks. They were describing an activity, and the activity turns out to be extremely common.

This page is not legal advice, and the edges are real

Whether a specific business is "significantly engaged" in a financial activity is a legal question that depends on facts this page cannot see. A dealership that never leases beyond 90 days sits differently from one that does. Counsel answers that question, not a vendor.

What ABT can do is the technical half: read your Microsoft 365 tenant and tell you, concretely, which of the rule's security elements your current configuration already satisfies and which it does not. That part does not require a legal opinion to be useful.

Grid showing nine of the thirteen business types the FTC Safeguards Rule names as financial institutions, including tax preparers, auto dealerships, appraisers, title and settlement services, mortgage brokers, and investment advisers, with Microsoft 365 product callouts
The rule defines a financial institution by activity, not by charter. Nine of the thirteen business types named in 16 CFR 314.2 are shown here; the full list is above.

Find out what your tenant already does, and what it does not.

ABT engineers read your Microsoft 365 tenant and report which of the rule's security elements your configuration satisfies today. No licence purchase, no obligation, and you keep the findings either way.

Request a free security assessment

Does the small business exemption get me out of it?

No, and this is the single most common misreading of the rule. The exemption removes four subsections. It does not remove the rule.

Here is the entire exemption, in full. It is one sentence long, which is part of why it gets summarized so badly:

Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.

16 CFR 314.6, Exceptions

Four named subsections. That is the whole scope of it, and everything else in section 314.4 continues to apply to a business of any size. Three of the four waived items are written artifacts: the risk assessment, the incident response plan, and the annual report. The fourth is not paperwork at all. Section 314.4(d)(2) is the testing regime, the continuous monitoring or, failing that, the annual penetration testing and vulnerability assessments, and a smaller institution genuinely does get relief from it. What survives untouched is the whole access-control and data-protection set in 314.4(c).

Waived under 5,000 consumers

  • The requirement that the risk assessment be written314.4(b)(1)
  • Continuous monitoring, or annual penetration testing plus vulnerability assessments314.4(d)(2)
  • The written incident response plan314.4(h)
  • The annual written report to the board or a senior officer314.4(i)

Still required, at every size

  • Multi-factor authentication for any individual accessing any information system, unless the Qualified Individual approves reasonably equivalent or more secure controls in writing314.4(c)(5)
  • Encryption of all customer information, at rest and in transit over external networks314.4(c)(3)
  • Access controls that authenticate and permit access only to authorized users314.4(c)(1)
  • Monitoring and logging of authorized user activity314.4(c)(8)
  • A designated Qualified Individual running the program314.4(a)
  • Security awareness training, kept current against identified risks314.4(e)

Notice which column the technical controls are in. Multi-factor authentication and encryption sit in 314.4(c), and 314.4(c) is not among the four subsections that 314.6 waives. Several of these carry their own internal flexibility, and the rule says so where it applies: the multi-factor requirement can be met with reasonably equivalent or more secure access controls where the Qualified Individual approves that in writing, and the encryption requirement has a parallel provision for effective alternative compensating controls. What none of them have is a size threshold.

Two column comparison showing the four Safeguards Rule subsections waived under 5,000 consumers against the six requirements including multi-factor authentication and encryption that still apply at every size
16 CFR 314.6 waives four subsections. The technical controls in 314.4(c) are not among them.

One more line worth knowing about

The rule requires a designated Qualified Individual to oversee the information security program. A lot of small businesses read that and conclude they need to hire a security officer. The rule says otherwise, in the same breath:

The Qualified Individual may be employed by you, an affiliate, or a service provider.

16 CFR 314.4(a)

If you use a service provider for that role, the rule attaches three conditions: you retain responsibility for compliance, you designate a senior member of your own personnel to direct and oversee that individual, and you require the provider to maintain a conforming information security program. The accountability does not transfer. The staffing can.

Why is the price the same as what a bank pays?

Because there is one price list, and it has no industry column. This is a fact about ABT's catalog rather than an offer, a discount, or a match.

The security service ABT sells is priced per user per month, published, and identical regardless of who is buying it. A community bank, a title agency, and a fourteen-person appraisal firm are all reading the same numbers. The reason is the one from earlier: since the baseline itself does not vary by customer, there is nothing to price differently.

M365 Guardian published list prices per user per month
Service level Microsoft licensing through ABT Microsoft licensing elsewhere
Guardian Foundation
Hardened Microsoft 365 tenant and Guardian Security Insights reporting
IncludedNo additional charge Not sold separately
Guardian Contain
Adds monitoring and automated containment
$18per user per month, 50-user floor $21per user per month, 50-user floor
Guardian Respond
Adds ABT engineers on covered incidents during business hours
$27per user per month, 50-user floor $32per user per month, 50-user floor
Guardian Resolve
Adds a person on the incident at any hour
$36per user per month, 50-user floor $42per user per month, 50-user floor

List prices as published on the M365 Guardian page. A 50-user monthly floor applies at every level, so a 50-user organization pays exactly the list rate. Microsoft licensing, Microsoft 365 Copilot, end-user helpdesk hours, and virtual CISO work are quoted as their own separate lines, and Microsoft licensing is billed at Microsoft's price.

What the parity claim does and does not cover

It covers ABT's own service prices, which is what the table above shows. It does not claim that every organization's total bill comes out identical, because Microsoft sets its own licensing prices by organization type. Nonprofit grant pricing from Microsoft is a real example of that, and it is Microsoft's arrangement rather than ABT's.

So the honest version of the claim is narrow and checkable: the price list for the security service does not ask what industry you are in. You can verify it in about fifteen seconds by opening the M365 Guardian page and looking for an industry column. There is not one.

Where does my industry fit?

The rule is the same everywhere, but what triggers it and what examiners or clients ask for differs by trade. These pages go deeper on the specifics.

1

CPA and accounting firms

Named directly in the rule at example (viii). Accounting firms also carry client data that is attractive well beyond tax season, and the professional obligations arrive from more than one direction at once.

Microsoft 365 security for CPA firms
2

Tax preparers

The written information security plan question is the one preparers actually get asked, and it has a specific answer with specific required elements rather than a general instruction to be careful.

The tax preparer WISP requirement
3

Mortgage companies and brokers

Mortgage brokers are named at example (xi). This is ABT's largest customer segment by a wide margin, and the FTC rather than the FFIEC is the operative regulator for most non-bank lenders.

The Safeguards Rule for mortgage lenders
4

Banks and credit unions

Examined institutions work to FFIEC, NCUA, and GLBA expectations, which is the environment the Guardian baseline was built inside in the first place.

M365 Guardian

Title and escrow, appraisal, auto dealership finance and insurance desks, investment advisory, and collection agencies are all inside the same rule, and pages for several of those are in progress. If yours is not listed yet, the assessment does not depend on having a page: the tenant review is the same work regardless of the trade.

A free security assessment of your Microsoft 365 tenant

The fastest way to find out where you stand is to have somebody read the configuration rather than guess at it.

No cost, no licence purchase required

What ABT engineers actually look at

  • Identity and access. Which accounts have multi-factor authentication and which do not, what your Conditional Access policies actually enforce as opposed to what they are named, and whether legacy authentication is still reachable.
  • Administrator exposure. How many accounts hold privileged roles, whether those roles are permanent, and what would happen if one of them were taken over.
  • Data handling. Whether anything classifies or protects Social Security numbers, account numbers, and tax identification numbers as they move through Exchange, SharePoint, OneDrive, and Teams.
  • Device posture. Which devices are enrolled and compliant, and which are reaching company data from outside any management at all.
  • Third-party access. Which applications hold consent into your tenant, what they can reach, and whether anyone still needs them.
  • A written result you keep. Findings mapped to the elements of 16 CFR 314.4, in order of what matters, whether or not you ever become a customer.

The assessment is a technical review and is not a quote, a legal opinion, or a compliance certification. ABT manages Microsoft 365 tenants and hosts Azure environments for more than 750 financial institutions. ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies.

Where the facts on this page come from

Every regulatory claim above traces to the regulation itself. Passages shown in quotation marks are reproduced verbatim; the list of covered business types is condensed to its subjects, with example numbers so each can be read in full. Here is where to check each one.

  • 16 CFR Part 314, the FTC Safeguards Rule. The purpose clause implementing Gramm-Leach-Bliley sections 501 and 505(b)(2), the activity-based definition of a financial institution, the thirteen worked examples, and the elements in 314.4. Electronic Code of Federal Regulations, Part 314. Retrieved August 27, 2026.
  • 16 CFR 314.6, Exceptions. The full text of the fewer-than-five-thousand-consumers exception and the four subsections it names. Same source, retrieved August 27, 2026.
  • 16 CFR 314.4(a). The Qualified Individual requirement and the provision permitting that person to be employed by an affiliate or a service provider, together with the three conditions attached. Same source.
  • 16 CFR 314.4(c)(3) and (c)(5). The encryption and multi-factor authentication requirements quoted in the comparison above. Same source.
  • 15 U.S.C. 6801(b) and 6805(b)(2). The statutory authority for Part 314, as stated in the authority note of the regulation.
  • ABT engineering verification of the Guardian security baseline. The 80-policy baseline across 11 categories, the 62 policies mapped to Safeguards Rule requirements, the 169 Microsoft Secure Score controls, the 11 Conditional Access policy templates, the data loss prevention scope and sensitive information types, and the session revocation automation. Internal engineering documentation, current as of this build. These are point-in-time counts of a baseline ABT maintains, and Microsoft revises the Secure Score control set periodically, so treat the control figure as an as-of number rather than a fixed constant.
  • Microsoft Entra ID Protection licensing. Microsoft states that "The Microsoft Entra ID P2 or Microsoft Entra Suite license is required for full access to Microsoft Entra ID Protection features." Microsoft Learn, configure risk policies. Retrieved August 27, 2026.
  • Microsoft 365 Business Premium identity tier. Microsoft states that "Entra ID P1 is also included in Microsoft 365 Business Premium for small to medium businesses." Microsoft Learn, Entra licensing. Retrieved August 27, 2026.
  • M365 Guardian published price list. All service levels, list prices, and the 50-user monthly floor. myabt.com/microsoft-365-guardian, checked August 27, 2026.

Bank-grade security, answered from the regulation

They are related but not identical, and the distinction matters. Gramm-Leach-Bliley is the statute. The Safeguards Rule at 16 CFR Part 314 is one regulation implementing it, and it says so directly: it is the part "which implements sections 501 and 505(b)(2) of the Gramm-Leach-Bliley Act," on authority of 15 U.S.C. 6801(b) and 6805(b)(2). It is the Federal Trade Commission's implementation, and it binds the institutions under FTC jurisdiction. Banks and credit unions are not under Part 314. They are supervised by their own prudential regulators, which issued separate interagency information security standards under the same statute. So a bank and a tax preparer are covered by different regulations enforced by different agencies, both descending from the same statutory security standard, which is why the expectations land in recognisably the same place.

It depends on your activities rather than your charter. The rule defines a financial institution as "any institution the business of which is engaging in an activity that is financial in nature or incidental to such financial activities as described in section 4(k) of the Bank Holding Company Act of 1956," and adds that an institution "significantly engaged" in such activities is a financial institution. The regulation then gives thirteen examples, none of which is a bank: accountants and tax preparation services, automobile dealerships leasing on a nonoperating basis longer than 90 days, real estate and personal property appraisers, entities providing real estate settlement services, mortgage brokers, investment advisory companies and credit counseling services, retailers issuing their own credit cards, businesses that regularly wire money, check cashing businesses, businesses that print and sell checks, career counselors serving the financial sector, travel agencies operating in connection with financial services, and finders who bring buyers and sellers together for transactions the parties negotiate themselves. Whether a specific business is "significantly engaged" is a legal question for counsel.

No. There is a partial exception, and it is much narrower than its reputation. Section 314.6 states in full: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." That waives four things: the requirement that the risk assessment be written, the continuous monitoring or annual penetration testing and vulnerability assessment obligation, the written incident response plan, and the annual written report to the board or a senior officer. Everything else still applies. In particular, section 314.4(c) is not on that list, so the multi-factor authentication requirement at 314.4(c)(5) and the encryption requirement at 314.4(c)(3) apply to a covered financial institution of any size.

Yes, and the wording is broad. Section 314.4(c)(5) requires "multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls." Two details are worth noting. The scope is any individual and any information system, not just remote access or just administrators. And the escape hatch is not an informal judgment call: it requires the Qualified Individual to approve reasonably equivalent or more secure controls, in writing.

No. Section 314.4(a) states that "The Qualified Individual may be employed by you, an affiliate, or a service provider." Using a service provider comes with three conditions written into the same paragraph: you retain responsibility for compliance with the rule, you designate a senior member of your own personnel responsible for direction and oversight of the Qualified Individual, and you require the service provider or affiliate to maintain an information security program that protects you in accordance with the rule. The staffing can be outsourced. The accountability cannot.

A specific configuration rather than an adjective. ABT deploys an 80-policy Microsoft 365 security baseline purpose-built for financial institutions, with 62 policies formally mapped to Gramm-Leach-Bliley Safeguards Rule requirements. The baseline covers 169 Microsoft Secure Score controls including data loss prevention, multi-factor authentication enforcement, audit logging, device compliance, and encryption, and it is organized as 80 policy templates across 11 categories. Within it, 11 Microsoft Entra ID Conditional Access policies enforce multi-factor authentication, risk-based access controls, device compliance, geographic blocking, and legacy authentication blocking. Data loss prevention runs across Exchange, SharePoint, OneDrive, and Teams using Microsoft's built-in sensitive information types for Social Security numbers, bank account numbers, credit card numbers, and Individual Taxpayer Identification Numbers. On a risk detection, a custom automation calls the Microsoft Graph revokeSignInSessions API, which invalidates that user's previously issued refresh tokens and sign-in sessions across every device, so a stolen refresh token can no longer be used to mint new access tokens.

Because there is one published price list and it has no industry dimension. Guardian Foundation is included at no additional charge when Microsoft licensing runs through ABT. The published list prices per user per month are $18 for Guardian Contain, $27 for Guardian Respond, and $36 for Guardian Resolve when Microsoft licensing runs through ABT, and $21, $32, and $42 respectively when it does not. A 50-user monthly floor applies at every level, so a 50-user organization pays exactly the list rate. Those numbers do not change based on the buyer's industry, because the underlying security baseline does not change either. This is a description of a published catalog rather than a discount or a price match. Microsoft licensing, Microsoft 365 Copilot, end-user helpdesk hours, and virtual CISO work are quoted separately, and Microsoft licensing is billed at Microsoft's price.

ABT engineers read your Microsoft 365 tenant and report what the configuration actually does. That covers identity and access, including which accounts have multi-factor authentication and what your Conditional Access policies enforce as opposed to what they are named; administrator exposure and whether privileged roles are permanent; whether anything classifies or protects sensitive customer data moving through Exchange, SharePoint, OneDrive, and Teams; which devices are enrolled and compliant; and which third-party applications hold consent into the tenant. You receive a written result mapped to the elements of 16 CFR 314.4, and you keep it whether or not you become a customer. It is a technical review. It is not a quote, a legal opinion, or a compliance certification, and no licence purchase is required.

Talk to an Expert

Find out where your
tenant actually stands.

Tell us roughly how many people are in the business. Our engineers will read the Microsoft 365 tenant and come back with what your configuration does today, mapped to the elements of the rule, in order of what matters.

SOC 1 Type 2 · Security Controls
SOC 2 Type 1
Tier 1 Microsoft Cloud Solution Provider
750+
FINANCIAL INSTITUTIONS
25+
YEARS IN FINANCIAL SERVICES
Tier 1
MICROSOFT CSP
Request your assessment
A real engineer replies, usually within one business day.
What should we look at?
Safeguards Rule readiness
Microsoft 365 security review
MFA and access controls
Managed security service
Required
Required
Enter a valid work email
Required
No obligation. No licence purchase required.
Request received
One of our engineers will be in touch, usually within one business day. If you are working against a deadline of your own, say so in a reply and we will move.