GLBA Safeguards Guidance for Financial Institutions.
Practical guidance for banks, credit unions, mortgage companies, investment firms, insurance organizations, and other financial institutions implementing the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule.
GLBA Compliance Learning Paths
Start with the GLBA Safeguards Rule and progress through risk management, technical safeguards, third-party oversight, and executive governance.
GLBA Safeguards Rule Explained
Understand the updated Safeguards Rule and the cybersecurity requirements placed on financial institutions.
Coming Soon → Path 02Protect Customer Information
Learn how administrative, technical, and physical safeguards work together to protect nonpublic customer information.
Coming Soon → Path 03Build a GLBA Security Program
Translate GLBA requirements into operational security controls, governance, and ongoing compliance.
Explore Services →Browse by Compliance Area
This framework page will expand as additional GLBA implementation guidance is published.
GLBA Fundamentals
Learn the structure of the GLBA Safeguards Rule and financial institution responsibilities.
Protect Customer Information
Identity security, MFA, encryption, endpoint protection, monitoring, and secure remote access.
Operational Security
Security operations, vulnerability management, incident response, awareness training, and resilience.
Oversight & Vendor Risk
Board reporting, service provider oversight, evidence collection, and examination readiness.
Start with a clear view of your risk, readiness, and next steps.
DBT’s Security Readiness Assessment helps identify gaps across cybersecurity operations, identity, compliance, infrastructure, monitoring, and resilience so your team can prioritize practical improvements.