Skip to the main content.
Home Security Title and Escrow
FTC Safeguards Rule · 16 CFR Part 314

Your title company is a financial institution. The rule says so in one sentence.

Most title, escrow, and settlement agencies have never read the sentence that puts them inside the FTC Safeguards Rule. It is not an interpretation and it is not a stretch. It is an example printed in the regulation itself, and a second sentence a few paragraphs earlier decides whose information you are holding.

  • The rule names real estate settlement services directly, at 16 CFR 314.2(h)(2)(x)
  • The buyer at your closing table is your customer under the rule, which makes their file customer information
  • Nine elements, one written program, and a 30 day clock that starts at discovery
Watch · 23 sec
Wire Transfer Fraud
Why a recognized voice on the phone is not an authorization control.
$20.877B
Reported to the FBI in 2025
FBI IC3 2025 Annual Report
2nd
Business email compromise, by loss
IC3 2025, behind investment fraud
58%
Of attempted theft frozen when the FBI kill chain runs
IC3 2025, 3,900 incidents
30 days
To notify the FTC after discovery, at 500 consumers
16 CFR 314.4(j)(1)

Is a title company a financial institution under the FTC Safeguards Rule?

Yes. The rule does not leave this to be argued. Among the thirteen worked examples the FTC prints in its own definition section, one of them is you.

An entity that provides real estate settlement services is a financial institution because providing real estate settlement services is a financial activity listed in 12 CFR 225.28(b)(2)(viii) and referenced in section 4(k)(4)(F) of the Bank Holding Company Act, 12 U.S.C. 1843(k)(4)(F). 16 CFR 314.2(h)(2)(x)

The word financial institution is doing unfamiliar work here. In conversation it means a bank. In the Gramm-Leach-Bliley Act, which the Safeguards Rule implements, it means any business significantly engaged in an activity that is financial in nature, and Congress delegated the list of those activities to banking regulation written for bank holding companies. Real estate settlement is on that list. So is appraisal, at 16 CFR 314.2(h)(2)(iii), which means the appraiser on the file is covered on the same basis you are.

There is no revenue threshold in the definition, no employee count, and no carve out for agencies that consider themselves too small to be regulated. A two person escrow office and a national underwriter are financial institutions on identical grounds. Size changes four obligations later in the rule, which we get to below, and it changes nothing about whether the rule applies.

Whose information are you actually holding?

The identity sentence gets quoted often enough. The one that decides your exposure sits a few paragraphs earlier and almost never gets quoted at all. The rule defines when a consumer has a continuing relationship with you, and lists the ways that relationship forms:

A consumer has a continuing relationship with you if the consumer ... Obtains real estate settlement services from you. 16 CFR 314.2(e)(2)(i)(K)

Follow the chain, because each link is a definition rather than an inference. A consumer with a continuing relationship is a customer under 16 CFR 314.2(c). Any record containing nonpublic personal information about a customer is customer information under 16 CFR 314.2(d), and the definition explicitly covers records held in paper, electronic, or other form, including records handled on your behalf by someone else.

1
Every buyer and seller who closes with you is a customer. Not a counterparty, not the lender's customer who happens to pass through your office. Yours, by the rule's own definition, from the moment they obtain settlement services.
2
Their closing file is customer information. Social Security numbers, bank account and routing numbers, loan documents, payoff statements, identity documents, and the wire instructions themselves. That is the category the entire rule is built to protect.
3
The email attachment counts. The definition says any record, in any form. A PDF sitting in a producer's mailbox is customer information in exactly the way the copy in your production system is, and it is usually the copy nobody has inventoried.
4
Information handled on your behalf still counts. The definition reaches records maintained by or on behalf of you or your affiliates, which is why the rule has a service provider oversight element and why your vendors' security becomes your problem in writing.

Put the two sentences together and the picture is unambiguous. The rule says you are a financial institution, and it says the people at your closing table are your customers, which pulls the whole of 16 CFR 314.4 down onto the files you already hold. Neither half requires anyone's interpretation. Both are printed in the regulation.

What most agencies believe, and what the regulation says

Every row on the right is a direct reading of the cited paragraph. None of it is ABT's opinion about best practice.

The common assumption What it gets wrong What the rule actually says
"We are a title agency, not a financial institution." Uses the conversational meaning of the phrase Real estate settlement services are named as an example of a financial institution. 16 CFR 314.2(h)(2)(x)
"The lender is the regulated party. We just handle the closing." Assumes the customer relationship belongs to whoever originated the loan A consumer who obtains settlement services from you has a continuing relationship with you, which makes them your customer. 16 CFR 314.2(e)(2)(i)(K) and (c)
"We are under the threshold, so we are exempt." Reads a partial exception as a full exemption Below five thousand consumers, exactly four paragraphs stop applying. The rest, including the written program itself, still binds. 16 CFR 314.6
"Our policies are documented across a few systems and manuals." Treats scattered documentation as a program A comprehensive program, written in one or more readily accessible parts. 16 CFR 314.3(a)
"We use Microsoft 365, so encryption is handled." Confuses a licence with a configuration Encrypt customer information in transit over external networks and at rest, or document compensating controls approved in writing by your Qualified Individual. 16 CFR 314.4(c)(3)
"We turned on multifactor authentication for the office staff." Scopes the requirement to employees and to email Multifactor authentication for any individual accessing any information system, unless equivalent or stronger controls are approved in writing. 16 CFR 314.4(c)(5)
"Our IT provider handles security, so it is on them." Assumes outsourcing transfers accountability Your Qualified Individual may work for a service provider, but you retain responsibility for compliance and must name a senior person of your own to oversee them. 16 CFR 314.4(a)(1) and (2)
"If something happened, we would deal with it then." Ignores that the clock starts before anyone escalates Notice to the FTC within 30 days of discovery at 500 consumers, and an event counts as discovered the first day it is known to any employee or agent. 16 CFR 314.4(j)

Read the cited paragraphs yourself. Every one is public at the eCFR, and the sources for this page are listed at the bottom.

Find out what is actually switched on
Our engineers read your Microsoft 365 tenant and report what is configured for multifactor authentication, encryption, access control, and logging, with each finding tied to the element of the rule it belongs to. No cost, no obligation.

The nine elements, and where Microsoft 365 carries the weight

Section 314.4 sets out nine elements your information security program must include. Two of them are where Microsoft 365 does the work. The other seven are organizational or documentary, and no product satisfies them, which is worth knowing before anyone sells you a compliance package.

The nine elements of the FTC Safeguards Rule at 16 CFR 314.4, with the two technical elements mapped to Microsoft Entra ID, Microsoft Purview, Microsoft Defender, and audit logging, and the seven organizational elements marked as satisfied by no product
The nine elements at 16 CFR 314.4. Two are technical and land in Microsoft 365. Seven are organizational.

Designate a Qualified Individual

One named person accountable for overseeing, implementing, and enforcing the program. Organizational. The rule permits this person to work for a service provider, with conditions covered below.

16 CFR 314.4(a)

Base the program on a risk assessment

Identify foreseeable internal and external risks to customer information and judge whether existing safeguards control them. Organizational, though what your tenant reports is the raw material.

16 CFR 314.4(b)

Access controls, encryption, and multifactor authentication

The technical core, and the largest element in the rule. Access controls that authenticate authorized users and limit them to what their duties require, encryption of customer information in transit over external networks and at rest, multifactor authentication for any individual accessing any information system, secure disposal, change management, and logging. Microsoft Entra ID and Microsoft Purview are where most of this is configured and evidenced.

16 CFR 314.4(c)(1), (3), (5)

Test and monitor the safeguards

The second technical element. Regularly test or monitor the effectiveness of key controls, including detection of attempted intrusions. Either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months. Microsoft Defender and audit logging carry the monitoring half.

16 CFR 314.4(d)

Train your people

Security awareness training updated to reflect the risks your assessment identified, plus qualified security personnel and current knowledge of changing threats. Organizational, and the element most directly aimed at the fraud pattern that targets closings.

16 CFR 314.4(e)

Oversee your service providers

Select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically reassess them against the risk they present. Organizational, and it is where your production system, your document vendor, and your IT provider all land.

16 CFR 314.4(f)

Evaluate and adjust the program

Revise the program in light of testing results, material changes to your operations, and anything else you know may have a material impact on it. Organizational, though what your tenant reports is what should trigger it. Settings drift and offices reorganize, and the program is expected to notice.

16 CFR 314.4(g)

Keep a written incident response plan

Goals, internal response processes, defined roles and decision authority, internal and external communications, remediation requirements, documentation, and post-incident revision. Seven specified areas, and this is one of the four paragraphs the small agency exception lifts.

16 CFR 314.4(h)

Report to your governing body

The Qualified Individual reports in writing, at least annually, on program status and material matters. Where there is no board, the report goes to a senior officer. Also lifted by the small agency exception.

16 CFR 314.4(i)

Two of the technical requirements deserve a closer read than they usually get. The encryption paragraph covers customer information at rest, not only in transit, and if you decide encryption is infeasible anywhere the rule wants compensating controls reviewed and approved in writing by your Qualified Individual. The multifactor paragraph says any individual accessing any information system. Not employees only, not email only. Both are the kind of sentence that reads as boilerplate until someone reads it against your actual configuration.

There is also a disposal requirement that catches title and escrow work squarely. Customer information must be securely disposed of no later than two years after the last date it was used in connection with providing a service, unless it is needed for business operations, required to be retained by law or regulation, or targeted disposal is not reasonably feasible given how the information is kept. Closing files are retained under state law and underwriter agreements, so the exception usually applies. What the rule then expects is that you periodically review your retention policy to minimize unnecessary retention, which is a different obligation from keeping everything forever by default.

We handle fewer than 5,000 consumers. Does the rule still apply?

Yes, it still applies. This is the single most common misreading, and it is understandable, because a threshold that sounds like an exemption is written as a list of four paragraph numbers.

Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers. 16 CFR 314.6

Four paragraphs. Here is what each one is, and then what is conspicuously not on the list.

Comparison showing the four paragraphs of the FTC Safeguards Rule lifted below five thousand consumers against the requirements that still apply, including the written program, encryption, multifactor authentication in Microsoft 365, training, service provider oversight, and FTC breach notification
What the under five thousand consumer exception at 16 CFR 314.6 lifts, and what it leaves entirely in place.
b1
The written risk assessment. You still have to base the program on a risk assessment under 314.4(b). What lifts is the requirement that it be written and contain the prescribed evaluation criteria.
d2
The prescribed testing schedule. Annual penetration testing and vulnerability assessments every six months. The general duty in 314.4(d)(1) to regularly test or monitor the effectiveness of your key controls does not lift.
h
The written incident response plan. The seven part plan is not required. The obligation to notify the FTC after a qualifying breach is in a different paragraph and is untouched, which is an awkward pairing worth thinking about.
i
The annual written report. Your Qualified Individual does not have to file a written annual report to a board or senior officer.

Now the part that matters more. The exception reaches into 314.4 only. It never touches 16 CFR 314.3, so the comprehensive written information security program is required of a two person escrow office exactly as it is of a national underwriter. It does not lift encryption, multifactor authentication, access controls, secure disposal, logging, training, service provider oversight, or the duty to notify the FTC. Roughly speaking, four documentation obligations lift and every safeguard stays.

One more detail decides whether you are under the threshold at all, and it is easy to get wrong. The test counts consumers whose information you maintain, not files you closed this year. Prior years count for as long as you still hold the records, which for a title agency operating under state retention requirements is usually a long time. Agencies that assume they are comfortably under five thousand are often counting annual volume rather than the archive.

Thirty days, five hundred consumers, and the word that starts the clock

Since 13 May 2024, covered financial institutions have owed the FTC notice of qualifying breaches. The requirement is short and the two conditions inside it carry all the weight.

Upon discovery of a notification event ... if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event. 16 CFR 314.4(j)(1)

The notice goes in electronically through a form on the FTC website and asks for the types of information involved, the date or date range where determinable, the number of consumers affected, and a general description of what happened. Law enforcement can request a delay of up to 30 days, extendable by up to 60 more in writing, where public disclosure would impede an investigation.

The trap is in the definition of discovery, which the rule supplies rather than leaving to common sense:

A notification event shall be treated as discovered as of the first day on which such event is known to you. You shall be deemed to have knowledge of a notification event if such event is known to any person, other than the person committing the breach, who is your employee, officer, or other agent. 16 CFR 314.4(j)(2)

Be precise about what is being discovered, because it is not any odd occurrence. The thing discovered has to be a notification event, which the rule defines as unauthorized acquisition of unencrypted customer information, and the 30 day duty attaches only where at least 500 consumers are involved. Plenty of alarming Tuesdays never become notification events at all.

What the definition does change is whose knowledge counts, and that is the part worth planning around. If a closing coordinator sees the mailbox activity that later turns out to be the acquisition, and says nothing for two weeks, the firm is deemed to have known from the day she saw it. Discovery is not the day it reached the owner, and it is not the day a forensic engagement confirmed the numbers. In practice you will be reconstructing that date afterwards, from logs, under time pressure, to a regulator.

That is why detection capability and the 30 day clock are the same problem wearing different clothes. An agency that cannot see unusual mailbox activity does not get a slower clock. It gets a clock that may already be running, measured from a date it will have to reconstruct afterwards. The same logic applies to the word unencrypted in the definition of a notification event: encryption changes the exposure of an incident before one happens, not after.

State breach notification statutes, underwriter agreements, and your insurer impose separate duties on their own timetables, and several of them are shorter. Confirm your specific obligations with counsel rather than with a vendor.

The fraud that targets closings is an email problem before it is a wire problem

Before quoting any statistic here, one clarification is owed, because the obvious number is the wrong one. The FBI's Internet Crime Complaint Center publishes a crime category called Real Estate, and its own appendix defines it as "Loss of funds from a real estate investment or fraud involving rental or timeshare property." That category is not closing wire fraud. Diverted closing funds are counted under business email compromise, so that is the number that speaks to this audience.

In the 2025 IC3 annual report, the FBI recorded 1,008,597 complaints and $20.877 billion in reported losses, a 26 percent increase over 2024. On the composition, the report is direct: "Investment-related fraud was once again the largest component of these losses, followed by business email compromises and tech support scams." Second by loss, out of every category the FBI tracks.

From the FBI record, August 2025

Individuals closing on a home received an email impersonating their legitimate attorneys. A wire for more than $449,000 was submitted at their bank and sent to the recipient bank. After the fraud was discovered, the buyers reported it to their bank and their attorneys made separate attempts to reach the recipient bank, with no result.

Only when the IC3 complaint reached the FBI's Recovery Asset Team, which initiated the Financial Fraud Kill Chain to request a freeze, did the recipient bank confirm the full amount was still in the account and on hold.

Three things in that account are worth sitting with. The impersonated party was the professional the buyers trusted most in the transaction. The victims and their own attorneys could not recover the funds through ordinary channels. And recovery happened only because a federal process reached the receiving bank while the money was still sitting there.

The kill chain works when it is fast. Across 2025 the FBI initiated 3,900 of these actions against $1,163,919,846 in attempted theft and froze $679,013,183, a 58 percent success rate. The bureau's own guidance leads with the reason: "If you discover a fraudulent transfer, time is of the essence."

Notice what that implies about the control that matters. Wire verification callbacks are necessary and every serious agency has them. But the fraud does not begin at the wire. It begins in a mailbox, days or weeks earlier, where someone is reading the thread and waiting for the closing date. The controls that reach that stage are the ones the Safeguards Rule already requires you to have: multifactor authentication on every information system, logging that would show a mailbox rule nobody created, and the ability to notice an unusual sign in while the file is still open.

ALTA has been pointing at a written plan for years

None of this should feel foreign. The American Land Title Association maintains the ALTA Best Practices 4.0 Framework, organized across seven pillars, along with an assessment readiness guide, policy and procedure templates, and vendor vetting guidance. Underwriters and lenders have been asking agencies about it for years.

ALTA also publishes WISP Guidance and FAQ, currently at version 09-17-2024. A written information security plan is the same artifact 16 CFR 314.3(a) requires when it calls for a comprehensive program written in one or more readily accessible parts. Your trade association and the federal regulator are asking for the same document.

Which reframes the work in front of you. For a great many agencies this is not a program built from nothing. It is a Best Practices posture that already exists on paper, checked honestly against what the tenant is actually doing, with the gaps closed and the whole thing written down where someone can find it. The uncomfortable part is rarely the writing. It is discovering that a control the plan claims has not been switched on for two years.

We already work under this rule, on the other side of your closings

Access Business Technologies manages Microsoft 365 for more than 750 financial institutions, and hosts their Azure environments. Banks, credit unions, and mortgage companies. The lenders on your files.

That adjacency is the entire reason this page exists, and it is worth being precise about why it matters. ABT's Microsoft 365 security baseline runs 80 policies across 11 categories, deployed from day one, including 11 Conditional Access policies. 62 of those 80 policies are formally mapped to Gramm-Leach-Bliley Safeguards Rule subsections at 16 CFR 314.4, and the baseline covers 169 Microsoft Secure Score controls.

16 CFR 314.4 is the paragraph this whole page has been quoting. It is the same rule. Not a bank framework adapted for title work, and not a compliance overlay invented for a new market. The mapping already speaks your regulation because ABT's mortgage clients have lived under it for years.

No cost

A free security assessment of your Microsoft 365 tenant

Our engineers read the tenant and report what is actually there, with each finding tied to the element of the rule it belongs to.

  • Multifactor authentication coverage, by user and by system, against 16 CFR 314.4(c)(5)
  • Encryption posture for information in transit and at rest, against 314.4(c)(3)
  • Access controls and whether staff can reach files their duties do not require, against 314.4(c)(1)
  • Audit logging and retention, the evidence any incident response depends on, against 314.4(c)(8)
  • Where closing files have actually ended up, including the copies in mailboxes and shared drives
  • A plain reading of what your written plan can honestly claim today

The assessment is a technical review of your Microsoft 365 configuration. It is not legal advice and not a determination of regulatory compliance. Whether your firm is covered, and whether your program satisfies the rule, are questions for your counsel.

If the review turns up work worth doing, one thing is worth knowing before you ask. ABT publishes a single price list and it has no industry dimension anywhere in it. A title agency sees the same numbers a community bank sees, because there is only one set of numbers. That is a fact about the catalog rather than a discount or a match. Guardian Foundation, a hardened tenant with Guardian Security Insights, is included at no additional charge with Microsoft licensing through ABT, and the managed tiers above it, along with their per user rates and published minimums, are listed openly on the M365 Guardian page.

ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies.

There is no obligation attached to the assessment, and plenty of agencies take the report to their existing provider. That is a fine outcome. The report is more useful than the sales conversation.

Where the facts on this page come from

Every regulatory quotation was read from the current text of the regulation, and every statistic from the primary report, on 28 August 2026.

  • 16 CFR Part 314, the FTC Safeguards Rule, current text via the Electronic Code of Federal Regulations. Sections quoted: 314.2(c), 314.2(d), 314.2(e)(2)(i)(K), 314.2(h)(2)(iii), 314.2(h)(2)(x), 314.2(k), 314.3(a), 314.4(a) through (j), and 314.6. ecfr.gov
  • FBI Internet Crime Complaint Center, 2025 Internet Crime Report. Source of the 2025 complaint and loss totals, the statement that business email compromise was the second largest loss component, the Financial Fraud Kill Chain figures, the August 2025 closing case, and the definition of the Real Estate crime category. ic3.gov
  • American Land Title Association, Best Practices 4.0 Framework and WISP Guidance and FAQ (version 09-17-2024). alta.org
  • Microsoft product documentation for the capabilities named on this page: Microsoft Entra ID, Microsoft Purview, Microsoft Defender, and Microsoft Intune. learn.microsoft.com

Nothing on this page is legal advice. Whether a particular business is covered by the FTC Safeguards Rule, and whether its program satisfies the rule, are determinations for its own counsel.

Title and escrow questions, answered from the rule text

Yes. The rule states it directly. Among the worked examples at 16 CFR 314.2(h)(2)(x): "An entity that provides real estate settlement services is a financial institution because providing real estate settlement services is a financial activity listed in 12 CFR 225.28(b)(2)(viii) and referenced in section 4(k)(4)(F) of the Bank Holding Company Act, 12 U.S.C. 1843(k)(4)(F)." The term is defined far more broadly in the Gramm-Leach-Bliley Act than it is in conversation, and it covers any business significantly engaged in an activity that is financial in nature. There is no revenue or headcount threshold in the definition, so a two person escrow office is covered on the same basis as a national underwriter. Real estate appraisers are separately named at 16 CFR 314.2(h)(2)(iii).
Yes, and this is the sentence that decides your exposure. 16 CFR 314.2(e)(2)(i)(K) states that a consumer has a continuing relationship with you if the consumer "Obtains real estate settlement services from you." A consumer with a continuing relationship is a customer under 16 CFR 314.2(c), and any record containing nonpublic personal information about a customer is customer information under 16 CFR 314.2(d), in paper, electronic, or other form, including records handled on your behalf. That chain is what pulls the whole of 16 CFR 314.4 down onto the closing files you already hold, including the copies sitting in mailboxes.
A comprehensive information security program, written in one or more readily accessible parts under 16 CFR 314.3(a), containing the nine elements at 16 CFR 314.4. They are: designate a Qualified Individual; base the program on a risk assessment; implement safeguards including access controls, encryption, and multifactor authentication; regularly test or monitor those safeguards; train personnel; oversee service providers; evaluate and adjust the program; keep a written incident response plan; and have the Qualified Individual report to the governing body at least annually. A further paragraph, 314.4(j), adds notice to the FTC after a qualifying breach. Two of the nine are where Microsoft 365 does the work. The other seven are organizational or documentary and no product satisfies them.
No. The rule still applies and a narrow exception lifts four specific paragraphs. 16 CFR 314.6 states that "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Those four are the written risk assessment, the prescribed penetration testing and vulnerability assessment schedule, the written incident response plan, and the annual written report to your governing body. The exception never touches 16 CFR 314.3, so the written program itself is still required, and it does not lift encryption, multifactor authentication, access controls, secure disposal, logging, training, service provider oversight, or the duty to notify the FTC. Note also that the threshold counts every consumer whose information you maintain, including prior years, not the files you closed this season.
Yes. 16 CFR 314.4(a) states that the Qualified Individual "may be employed by you, an affiliate, or a service provider." Three conditions come with that choice. You retain responsibility for compliance with the rule, you must designate a senior member of your own personnel responsible for direction and oversight of the Qualified Individual, and you must require the service provider or affiliate to maintain an information security program that protects you in accordance with the rule. Outsourcing the role is permitted. Outsourcing the accountability is not.
Two clocks start, and they are not the same clock. Operationally, recovery depends on speed: the FBI states that "if you discover a fraudulent transfer, time is of the essence," and its Recovery Asset Team froze $679,013,183 of $1,163,919,846 in attempted theft across 3,900 Financial Fraud Kill Chain actions in 2025, a 58 percent success rate. Contact your financial institution immediately to request a recall, and file at ic3.gov. Separately, under 16 CFR 314.4(j)(1), if a notification event involves the unencrypted information of at least 500 consumers you must notify the FTC as soon as possible and no later than 30 days after discovery. Discovery is defined at 314.4(j)(2) as the first day the event is known to any employee, officer, or agent other than the person who committed it, so the clock can start well before the matter reaches management. State laws, underwriter agreements, and your insurer impose separate duties. Confirm yours with counsel.
They are closely related but they are not the same instrument, and one does not automatically discharge the other. ALTA maintains the Best Practices 4.0 Framework across seven pillars and separately publishes WISP Guidance and FAQ, currently at version 09-17-2024, so a written information security plan is already familiar ground in this industry. The federal requirement at 16 CFR 314.3(a) is for a comprehensive program written in one or more readily accessible parts and containing the nine elements of 314.4. For many agencies the practical work is checking an existing Best Practices posture honestly against what the tenant is actually configured to do, closing the gaps, and writing the result down. Whether any particular program satisfies the rule is a determination for your counsel.
No, and treat any vendor who says otherwise with suspicion. Compliance is a property of your program, not of a product. What Microsoft 365 gives you is the place several of the nine elements are actually satisfied: Microsoft Entra ID for access controls and multifactor authentication, Microsoft Purview for encryption and data classification, Microsoft Defender and Microsoft Intune for monitoring and device state, and audit logging for the evidence any incident response depends on. Those capabilities have to be configured, verified, and kept configured, and buying the licence does not switch them on. Seven of the nine elements are organizational or documentary rather than technical, including naming a Qualified Individual, running a risk assessment, training staff, overseeing service providers, evaluating and adjusting the program, keeping an incident response plan, and reporting to your governing body, and no software closes those.
Talk to an Expert

Find out what your tenant
can honestly claim.

Tell us roughly how many people are in the agency and how many consumers' information you still hold, counting prior years. Our engineers will read the tenant and come back with what is switched on, what is not, and which element of the rule each finding belongs to.

SOC 1 Type 2 · Security Controls
SOC 2 Type 1
Tier-1 CSP
Zero Trust Baseline
25+
Years on Microsoft
750+
Institutions Served
$0
Assessment Cost
Get Your Free Security Assessment
Response within one business day. No obligation.
I am interested in... (optional)
First name is required
Last name is required
Valid email is required
Response within 1 business day. No obligation.
You are in.
An ABT security specialist will review your request and reach out within one business day.