Customer Data Brings Security Obligations

Financial and insurance offices hold account numbers, policy details, income records and identification documents.

That data attracts phishing, business email compromise and wire-fraud attempts, and one compromised mailbox can redirect a payment or expose hundreds of customers.

Regulators, carriers and cyber insurers increasingly ask to see a written security program, multi-factor authentication and tested backups.

Rules That Often Apply

Which rules apply depends on your license and your regulator. These are the most common for Michigan financial and insurance offices:

FTC Safeguards Rule (Gramm-Leach-Bliley Act): non-bank financial institutions, such as mortgage brokers and lenders, finance companies, collection agencies and investment advisers not registered with the SEC, must keep a written information security program with MFA, encryption, staff training, service provider oversight and an incident response plan, and notify the FTC within 30 days of a breach affecting 500 or more people.

Michigan Insurance Data Security Law (MCL 500.550–500.565): licensed insurers and producers must keep a written information security program based on a risk assessment and notify DIFS of a cybersecurity event within 10 business days. Licensees with fewer than 25 employees are exempt from the program requirement but not from the notice requirement.

SEC Regulation S-P: broker-dealers and SEC-registered investment advisers must keep a written incident response program and notify affected customers; smaller firms had to comply by June 3, 2026.

Banks and credit unions follow their federal regulators’ guidance, which draws on the same safeguards.

Computer Ties does not provide legal advice. We help you put the technical safeguards in place and document them; your compliance team or counsel decides what applies.

Official guidance: the FTC Safeguards Rule guide, Michigan DIFS insurance data security information and the SEC Regulation S-P final rule (PDF).

How Computer Ties Supports Financial Offices

Email & Wire-Fraud Protection

Email filtering, impersonation protection and MFA help stop the business email compromise attempts that target payment instructions.

Access Control & MFA

Individual accounts, MFA and prompt offboarding keep customer systems limited to the people who need them.

Encryption & Data Protection

Encrypted laptops, secure file sharing and protected backups keep customer records safe on devices and in transit.

Monitoring & Patching

Updates, endpoint protection and monitoring reduce the chance that a known vulnerability becomes a breach.

CTi Tech Plaza conference room with a long meeting table and black chairs

Documentation for Audits and Questionnaires

Examiners, carriers and cyber insurance applications ask the same questions: Do you use MFA? Are devices encrypted? Are backups tested? Who can access customer data?

Computer Ties keeps an inventory of your devices and accounts and documents your security settings, so your answers are accurate and easy to support.

We can also work with your auditors or compliance consultants when they need technical details.

Frequently Asked Questions

Does the FTC Safeguards Rule apply to my business?

It applies to many non-bank financial institutions, including mortgage brokers, finance companies and investment advisers not registered with the SEC. Your compliance advisor can confirm which rules apply to you; we help with the technical safeguards the rule describes.

Do small insurance agencies have to follow Michigan’s data security law?

Agencies with fewer than 25 employees are exempt from the written program requirement, but every licensee must still notify DIFS of a cybersecurity event within 10 business days. Many small agencies adopt the same safeguards anyway because carriers ask for them.

Can you help with cyber insurance applications?

Yes. We can help you answer the technical questions accurately, such as whether MFA, endpoint protection and offline backups are in place, and close gaps before renewal.

Do you work with our existing software vendors?

Yes. We support the computers, network, Microsoft 365 and backups your agency management, lending or portfolio software runs on, and work with the vendor when a problem is inside the application.

Computer Ties circular red and blue emblem

Build a More Secure Financial Office

Talk with Computer Ties about how customer data is stored, accessed and backed up in your office. We will recommend practical steps that fit your regulators’ expectations and your budget.