GLBAFinancialUnited StatesFinancial Services

Gramm-Leach-Bliley Act

U.S. law requiring financial institutions to protect customer financial information and explain data sharing practices. Enforced by FTC, SEC, and banking regulators.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

GLBASafeguards RulePatching, hardening, and exposureA record of access

Information Security Program

Financial institutions MUST develop, implement, and maintain a comprehensive security program.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

GLBA314.4(c)Least privilege and privileged useSpotting the abnormal

Access Controls

MUST implement access controls on customer information systems, including monitoring of access.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

GLBA314.4(d)Spotting the abnormal

Activity Monitoring

MUST monitor systems and procedures to detect actual and attempted attacks or intrusions.

Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.

GLBASafeguards RuleRouting and evidencing the response

Incident Response

MUST implement procedures to respond to security incidents affecting customer information.

Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.

What GLBA covers

16 CFR 314.2 — customer information; nonpublic personal information at 16 CFR 313.3

Nonpublic personal information about a customer of a financial institution, in any form the institution handles.

In scope

  • Information a consumer provides to obtain a financial product or service
  • Information about a transaction between the consumer and the institution
  • Information otherwise obtained about a consumer in connection with providing a product or service

What falls outside

Publicly available information, but only where the institution has a reasonable basis to believe it is lawfully public — the burden sits on the institution, not on the assumption.

16 CFR 314.2 · as at 2026-08

How GLBA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The FTC, the SEC, and the federal banking regulators, depending on the institution.

Published maximumChargedAs at
USD 100,000per violation, against the institution2026-08

The Safeguards Rule obliges financial institutions to maintain a written information security programme with named accountability. Enforcement is by the functional regulator, and the statute reaches the officers and directors as well as the institution.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

Who is personally on the hook

Who can be charged
Any person who obtains customer information from a financial institution under false pretences, including officers and employees who do so
For what
obtaining customer information from a financial institution under false pretences
Maximum
Imprisonment for up to 5 years, rising to 10 years where the offence is aggravated. The officer-level fine of USD 10,000 per violation is widely cited but sits in the general enforcement provisions rather than in the criminal section
Brought by
The US Department of Justice
PrisonPersonal fineNot indemnifiable

Uncapped exposure that sits outside this instrument

These come from company law rather than from GLBA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for GLBA,
not configured for it afterwards

Policy Template

Customer Financial Data Monitoring

Track access to account numbers, balances, transaction histories

Report

GLBA Safeguards Report

Evidence of security program implementation

Classification

Financial Account Patterns

Detect account numbers, routing numbers, financial identifiers

Alert

Unauthorized Access Detection

Detect attempts to access customer data without authorization

Walk into the GLBA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment