Qualified individual under FTC Safeguards
The role the rule makes you appoint is filled.
$2,500 per month per company.
Who did you name as responsible for your data protection programme?
Usually the bookkeeper, or whoever sits closest to the computers. The rule asks for work, not a signature: a written risk assessment, vulnerability testing twice a year, an annual report to the board. An examiner asks for documents, not for a name on an order.
The papers are ready before anyone asks
We take the role ourselves — a written appointment with a named person. The rule allows this outright. This is not consulting: the work the rule lists is done and signed by us, not by your bookkeeper on our advice.
Through the year we do what the rule lists point by point: a written risk assessment, multi-factor sign-in everywhere data can be reached, and vulnerability testing at least every six months.
Once a year we write the report to the board or the owner — the very document asked for first if questions ever start.
What the role covers
- included: Appointment of the qualified individual, put in writing
- included: A written risk assessment, updated every year
- included: Multi-factor sign-in everywhere client data can be reached
- included: Vulnerability testing at least every six months
- included: A written plan for the day you are breached
- included: A written annual report to the board or the owner
- included: Vetting of the contractors who receive your data
- paid to the vendor: Software licences and the auditor's fee — at the supplier's invoice
Your price
Qualified individual
$2,500 a month
The whole role: assessment, testing, plan, report.
What the tier includes
- included: A named qualified individual, a written programme and the annual report
- included: Vulnerability testing twice a year and a walk-through of the results
Extras
- not included: An annual penetration test$4,480 per perimeter
- not included: We watch for attacks around the clock$18 per endpoint a month
- not included: If you are breached, we investigate — monthly$670 a month
- not included: Backups and a check that they actually restore$1,340 a year
- not included: Questionnaires your client has sent$1,350 per questionnaire
- not included: Preparing for a cyber policy renewal$2,250 one-off
- not included: Fractional chief information security officerfrom $2,500 a month
- not included: Employee computers looked afterfrom $102 per seat
Questions
We are a car dealership of twenty people. Does the rule apply to us?
Yes. The rule looks not at your size but at whether you handle client financial data: car dealerships, accounting firms, mortgage brokers, debt collectors, estate agents. Only the smallest by number of clients are exempt.
Can we appoint one of our own staff?
You can, and the rule treats that the same as someone from outside. The question is who will do the work it lists and sign the report. If you have that person, we are usually needed only for the testing.
What will an examiner ask for first?
The written risk assessment, the written programme, the appointment document, the vulnerability test results and the latest annual report. All five documents are made here and kept by you.
Is a penetration test required every year?
Yes, unless your systems are under continuous monitoring: the rule says so plainly. That is why the price sits on its own line above — it is a separate job with its own report, not part of the monthly fee for the role.
Tell us what your company does and who holds this role today — we will send the quote by email.
We have your request
We answer during the hours listed in the contacts at the foot of the page. The quote and the conversation come first — nothing is signed and nothing is charged.