Financial Services

GLBA, PCI-DSS, and Examination-Ready Security for Financial Institutions

Safeguards Rule governance, cardholder-data protection, and AI-underwriting compliance risk for community banks, credit unions, wealth managers, and insurers — delivered across Armorstack’s four portfolios: VERITY, CORE, SENTRY, and CITADEL.

Community Banks & Credit Unions
Wealth & Asset Managers
Insurers & MGAs
Mortgage & Consumer Lenders
Fintech & Payment Processors
Why Financial Services Is Different

Multiple Regulators, One Attack Surface

Financial institutions answer to more overlapping regulators than almost any other mid-market sector — the FTC or a prudential banking regulator on GLBA, the card brands on PCI-DSS, state insurance commissioners on NAIC model laws, and now the CFPB on how algorithmic underwriting decisions get explained to declined applicants. Examiners don’t grade separately on each framework; they expect one coherent security and governance program that satisfies all of them at once. Armorstack builds that program once, then maps it to whichever examiner shows up.

The Regulatory Landscape

Five Frameworks Every Financial Institution Should Know

These are the real, named standards examiners, card brands, and the CFPB will hold you to — including a fair-lending rule that changed materially in 2026.

GLBA Safeguards Rule

The FTC’s updated Safeguards Rule, fully effective since June 2023, turned GLBA from a principles-based framework into a requirements-based one: a named Qualified Individual, a written information security program, encryption, and multi-factor authentication are no longer optional best practice — they’re auditable requirements.

Source: Federal Trade Commission, 16 CFR Part 314 (ftc.gov/safeguards)

PCI-DSS

Any organization that stores, processes, or transmits payment card data answers to the Payment Card Industry Data Security Standard — twelve requirements spanning network segmentation, encryption, access control, and continuous monitoring, enforced contractually by the card brands and acquiring banks rather than a government regulator.

Source: PCI Security Standards Council (pcisecuritystandards.org)

ECOA / Regulation B — Fair Lending

On April 22, 2026 the CFPB finalized changes to Regulation B narrowing disparate-impact liability under the Equal Credit Opportunity Act. That does not remove AI-underwriting risk: a May 5, 2026 CFPB circular confirms lenders remain fully responsible for giving specific, accurate adverse-action reasons when a machine-learning model contributes to a credit decision — “the black box told us to” is not a defense. This is an active, moving area; confirm current guidance before relying on it for a specific decision.

Source: Consumer Financial Protection Bureau, Regulation B Final Rule (Apr. 22, 2026) & CFPB Circular 2026-03 (consumerfinance.gov)

FFIEC IT Examination Guidance

The Federal Financial Institutions Examination Council coordinates IT and cybersecurity examination standards across the federal banking regulators. FFIEC guidance shapes what your examiner actually tests during a safety-and-soundness or IT exam — separate from, but closely aligned with, GLBA Safeguards Rule requirements.

Source: Federal Financial Institutions Examination Council (ffiec.gov)

NAIC Model Law — Insurers

For insurance carriers and MGAs, state insurance commissioners increasingly enforce cybersecurity requirements based on the NAIC Insurance Data Security Model Law, plus growing NAIC guidance specific to AI use in underwriting and claims. Applicability and specifics vary by state adoption.

Source: National Association of Insurance Commissioners (naic.org)
Our Approach

How Armorstack Secures Financial Institutions

One converged model, four coordinated portfolios — each mapped directly to the standards above.

SENTRY

Cardholder Data & Core-Banking Monitoring

24×7 detection tuned to cardholder-data-environment traffic and core-banking system behavior, mapped to PCI-DSS continuous monitoring requirements and GLBA Safeguards Rule technical safeguards.

CITADEL

Branch & Facility Physical Security

Access control and video surveillance for branch locations, vaults, and data centers — supporting GLBA’s physical safeguard expectations and card-brand requirements for cardholder-data-environment access control.

VERITY

GLBA Governance & Qualified Individual Support

vCISO-led risk assessment, written information security program development, and board-reportable evidence that keeps Safeguards Rule and FFIEC documentation exam-ready year-round — including governance for AI-assisted underwriting decisions under current CFPB guidance.

CORE

Resilient Core-Banking IT Backbone

Hardened, redundant infrastructure and network segmentation isolating the cardholder-data environment from the broader corporate network, per PCI-DSS segmentation requirements.

FAQ

Financial Services Security & Compliance Questions

What does the GLBA Safeguards Rule actually require?

A named Qualified Individual responsible for the information security program, a written information security program based on a risk assessment, access controls and encryption for customer information, multi-factor authentication, and a written incident response plan — all subject to periodic testing and reporting to the board or governing body.

Did the CFPB’s 2026 Regulation B change eliminate fair-lending risk around AI underwriting?

No. The April 2026 final rule narrowed disparate-impact liability theory under ECOA, but a separate May 2026 CFPB circular reaffirmed that lenders using machine-learning underwriting models must still be able to give specific, accurate reasons for adverse action — and remain accountable for understanding how their own models work. This is an evolving regulatory area; treat any specific compliance decision as needing current legal review.

Do small community banks and credit unions really need full PCI-DSS compliance?

If you store, process, or transmit cardholder data at all — including through a debit card program or merchant services offering — PCI-DSS applies, scaled by merchant level and transaction volume. Card brands and acquiring banks enforce it contractually, and non-compliance can mean fines or loss of card-processing privileges regardless of institution size.

Is FFIEC guidance a separate compliance obligation from GLBA?

They’re closely related rather than fully separate. FFIEC guidance shapes how federal banking examiners actually test for GLBA Safeguards Rule and broader cybersecurity readiness during an exam, so a program built to satisfy GLBA on paper still needs to hold up against FFIEC examination practice.

What does an Armorstack Financial Services Assessment look at?

A structured review of your GLBA Safeguards Rule program and Qualified Individual documentation, PCI-DSS scope and segmentation if you handle card data, physical security at branch and data-center locations, and governance around any AI-assisted underwriting or claims tools — benchmarked against the frameworks that actually apply to your institution.

Ready for an Exam-Ready Security Program?

Talk to Armorstack about a Financial Services Assessment — scoped to GLBA, PCI-DSS, and the examiner who’s actually coming.

Schedule a Consultation