The FTC Just Fined a Company $1.5 Million — Because They Skipped the Basics
In 2023, the FTC settled with Chegg for $3.5 million after four separate data breaches exposed tens of millions of customer records. Employees had been sharing login credentials. Sensitive data sat in plain text. Multi-factor authentication was nowhere to be found. If you think the FTC only goes after tech giants, that case should change your mind.
Understanding FTC cybersecurity requirements for businesses isn't optional anymore. The Federal Trade Commission has made it clear — through consent orders, rule updates, and aggressive enforcement — that every company handling consumer data must meet baseline security standards. This post breaks down exactly what those requirements look like, what triggers enforcement, and what your organization needs to do right now.
What the FTC Actually Requires: The Legal Foundation
The FTC doesn't publish a neat checklist labeled "cybersecurity rules." Instead, it derives its authority from Section 5 of the FTC Act, which prohibits unfair or deceptive acts. If your privacy policy promises you protect customer data and you don't, that's deception. If your security practices are so lax that a breach was foreseeable, that's unfairness.
On top of Section 5, the FTC enforces the Gramm-Leach-Bliley Safeguards Rule, which was significantly updated and went into effect in June 2023. That rule applies to financial institutions — but the FTC defines "financial institutions" broadly. Mortgage brokers, auto dealers, tax preparers, payday lenders, and even colleges offering financial aid fall under it.
The updated Safeguards Rule is the closest thing we have to a concrete FTC cybersecurity mandate. It requires a written information security program, a designated qualified individual, risk assessments, access controls, encryption, MFA, and continuous monitoring. You can read the full rule on the FTC's Safeguards Rule page.
FTC Cybersecurity Requirements for Businesses: The Core Obligations
Whether your business falls under the Safeguards Rule or under Section 5's broader reach, here's what the FTC expects based on decades of enforcement actions and published guidance:
- Designate a qualified individual responsible for your information security program. This can be an employee or a third-party service provider.
- Conduct regular risk assessments that identify internal and external threats to customer information.
- Implement access controls so that employees only access the data they need for their job.
- Use multi-factor authentication for any system containing customer data.
- Encrypt sensitive data both in transit and at rest.
- Train your employees on security awareness — including phishing, social engineering, and credential theft.
- Monitor and log activity across systems that store or process consumer data.
- Have an incident response plan that you've actually tested.
- Vet your service providers and require them to maintain adequate safeguards.
- Report to your board (or equivalent) annually on the status of your security program.
That last point catches many small businesses off guard. Even if you don't have a formal board of directors, the FTC expects documented oversight of your security posture.
What Triggers an FTC Enforcement Action?
I've reviewed dozens of FTC consent orders, and the patterns are remarkably consistent. The FTC doesn't usually come after companies for getting breached. They come after companies for failing to take reasonable precautions before the breach happened.
The Mistakes That Land Companies in FTC Crosshairs
In the Chegg case, employees shared a single S3 credential across the organization. In the case against CafePress, the company stored Social Security numbers and passwords in plain text and failed to investigate known security incidents. SkyMed stored consumer health data in a cloud database without any access restrictions.
The common thread? These weren't sophisticated zero-day attacks from advanced threat actors. They were basic failures: no encryption, no MFA, no access controls, no employee training, no monitoring. The FTC's position is simple — if you collect consumer data, you must protect it with reasonable measures. "Reasonable" is defined by what's standard in the industry, what's proportional to the sensitivity of the data, and what was feasible given your resources.
Does This Apply to Small Businesses?
Short Answer: Yes
The FTC has explicitly stated that its cybersecurity expectations apply to businesses of all sizes. In fact, many of its enforcement actions have targeted small and mid-size companies — not Fortune 500 corporations. The reasoning is straightforward: consumers trust you with their data regardless of how many employees you have.
The 2023 Verizon Data Breach Investigations Report found that 43% of all data breaches involved small businesses. If you're processing credit card numbers, storing health information, or collecting Social Security numbers, you're a target — and the FTC expects you to act like one. You can review the Verizon DBIR findings at their official DBIR page.
Employee Training Isn't Optional — It's an FTC Expectation
Nearly every FTC consent order I've read includes a requirement for employee security awareness training. This isn't a coincidence. The FTC recognizes that phishing, social engineering, and credential theft are the primary entry points for data breaches. Your firewall is meaningless if an employee hands over their password to a phishing email.
The Safeguards Rule specifically requires that your information security program include "security awareness training" for personnel. The FTC's guidance documents reinforce this point repeatedly. Training must be ongoing — not a one-time onboarding video that employees forget by lunch.
If you're looking for a practical starting point, our cybersecurity awareness training program covers the exact topics the FTC expects businesses to address: phishing recognition, social engineering tactics, password hygiene, and data handling procedures.
Phishing Simulation: The FTC's Favorite Benchmark
Several FTC orders have specifically referenced phishing as a primary attack vector. Running regular phishing simulations isn't just a best practice — it's becoming a de facto compliance requirement. Organizations that can demonstrate they test employees regularly, measure click rates, and remediate failures are in a far stronger position if the FTC comes knocking.
Our phishing awareness training for organizations lets you run realistic simulations and track results over time. That kind of documentation is exactly what the FTC looks for when evaluating whether your security program is "reasonable."
The Overlap With Zero Trust and Modern Security Frameworks
If you're already implementing a zero trust architecture, you're ahead of most FTC requirements. Zero trust principles — verify every user, limit access to the minimum necessary, assume breach — map directly to what the FTC expects: access controls, MFA, encryption, monitoring, and least privilege.
NIST's Cybersecurity Framework is another solid benchmark. The FTC has cited NIST standards in guidance documents, and aligning your program with the NIST Cybersecurity Framework gives you a defensible position if your practices are ever questioned.
Ransomware, Data Breaches, and the FTC's Expanding Reach
The threat landscape has changed dramatically. Ransomware attacks now routinely include data exfiltration — threat actors steal your data before they encrypt it. That means a ransomware incident is also a data breach, which means the FTC's consumer protection authority applies.
In 2024, the FTC expanded its use of the Health Breach Notification Rule to cover health apps and connected devices. If your business touches health data in any form — even a fitness app or a wellness questionnaire — you may have FTC reporting obligations you didn't know about.
The FTC has also signaled increased attention to AI-related data practices, biometric information, and children's data under COPPA. The regulatory surface area is growing, not shrinking.
Your FTC Compliance Checklist for 2026
Here's a practical starting point for meeting FTC cybersecurity requirements for businesses this year:
- Appoint a security lead. Document who's responsible for your information security program.
- Run a risk assessment. Identify where consumer data lives, who can access it, and what threats exist.
- Deploy MFA everywhere. Start with email, cloud storage, and any system holding PII.
- Encrypt sensitive data. Both at rest and in transit. No exceptions.
- Train your people. Quarterly at minimum. Include phishing simulations.
- Write an incident response plan. Then test it with a tabletop exercise.
- Vet your vendors. Require security commitments in contracts.
- Document everything. The FTC evaluates your program based on evidence, not intentions.
The Bottom Line: Compliance Is Cheaper Than Enforcement
The FTC has imposed multi-million-dollar penalties, 20-year consent orders, mandatory third-party audits, and personal liability on executives. These aren't theoretical consequences. They've happened to businesses that skipped the fundamentals.
You don't need a massive budget to meet FTC cybersecurity requirements for businesses. You need a written plan, consistent execution, documented training, and basic technical controls. The bar isn't perfection — it's reasonableness. But "we didn't know" has never been an acceptable defense, and in 2026, the FTC is making sure everyone knows it.