Most Divorce Financial Coach and family-law practices hold the most sensitive financial information about their clients that exists in private hands anywhere. Tax returns, complete asset inventories, full Social Security numbers, bank account numbers, brokerage account numbers, business records, mortgage applications, insurance policies, prenuptial agreements, settlement agreements, healthcare records, custody evaluations, psychological evaluations. The aggregated profile of a typical divorce client file is more valuable to a criminal than a stolen credit card by orders of magnitude, and the practices holding the data are typically operating with cybersecurity controls that would not survive a sophomore-level penetration test.
The federal government has noticed. The FTC Safeguards Rule, which has been in effect since 2003, was substantially updated in 2021 and the new requirements became enforceable in 2023. The Rule’s 2021 amendments expanded the definition of “financial institution” to include finders — companies that bring together buyers and sellers to negotiate and consummate financial transactions — which has been interpreted to sweep in many adjacent professional practices, including some Divorce Financial Coach and financial planning firms. Practices that previously believed they were outside the scope now find themselves inside it, with substantive compliance obligations they may not be meeting.
What follows is a working guide to cybersecurity and FTC Safeguards compliance for Divorce Financial Coaches, financial planners, and family-law practices. It covers the threat landscape, the real-world risks small practices face, the limits of outsourcing, the Safeguards Rule requirements, the NIST frameworks that provide the substantive content, the distinction between penetration testing and vulnerability scanning, and the operational steps a small practice can take today to materially improve its security posture and its compliance position.
The threat landscape — what the practices are actually facing.
Cybersecurity, in the CISA definition, is the art of protecting networks, devices, and data from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity, and availability of information. The categories of protection extend across the network (the connections between systems), the cloud (the third-party services holding data), endpoints (the laptops and desktops staff use), mobile devices (phones and tablets that access the same data), Internet of Things devices (printers, smart TVs, security cameras), applications (the software the practice uses), and increasingly into artificial intelligence integration.
The threat statistics put the problem in scale. Approximately thirty-three billion account breaches were reported in 2023. A hacker attack occurs on average every thirty-nine seconds, according to industry trackers. The average cost of a financial services data breach in the United States was approximately nine million dollars in 2023. Twenty million banking cyberattacks were blocked in the same period, with 79% of IT professionals identifying the banking and adjacent financial services sectors as soft targets. The average time to identify a ransomware attack runs forty-nine days from initial intrusion to detection. Ransomware attacks on financial services companies rose from 34% to 64% between 2022 and 2023.
The small-practice impact is disproportionate. Ten percent of small businesses go out of business following a data breach. Twenty-five percent file for bankruptcy. The practice that loses a meaningful portion of its client file to ransomware, with no working backups and no insurance, often does not recover. Even for practices that do recover, the cost of the response — forensic investigation, client notification, credit monitoring offerings, regulatory reporting, legal defense — can run to multiples of the practice’s annual revenue.
Real-world examples from financial services practices.
Six recent breaches affecting financial services firms with fewer than two hundred employees, drawn from the public University of Maryland breach database, illustrate the pattern.
A wealth management firm in Minnesota with roughly one thousand employees suffered a data breach in 2023 that exposed Social Security numbers among other client data. The cost included regulatory reporting, client notification, credit monitoring offerings to affected clients, internal forensic investigation, and reputation damage that produced ongoing client losses for months following.
An accounting practice with fewer than one hundred employees suffered a breach in 2022 that exposed client Social Security numbers. The practice was forced to suspend new client onboarding for months while the response was managed.
An investment management firm with fewer than two hundred employees suffered a breach in 2022 through compromised employee email accounts. The breach exposed client portfolio holdings and personal information. The attack vector — phishing-driven email account takeover — is the single most common breach vector at small professional practices.
A holding company with roughly one hundred twenty-five employees suffered a breach in 2022. An insurance practice with roughly fifty employees suffered a phishing attack in 2019 that compromised client policy information. A securities firm with fewer than two hundred employees suffered a breach in 2018 when an employee inadvertently loaded malware on a workstation that subsequently spread across the firm’s network.
The common features across these incidents: the practices were small, the attack vectors were unsophisticated (phishing emails, password reuse, lateral movement from a single compromised workstation), the response was expensive, and several of the firms did not survive in their previous form. None of these were targeted attacks from nation-state actors. They were the typical pattern of opportunistic attacks against under-defended targets.
The real-world risks beyond financial cost.
The financial cost of a breach is substantial but it is only one dimension of the risk. The ransomware demand itself, typically denominated in cryptocurrency and running from low five figures to high seven figures depending on the target. The fines from regulatory action, including FTC enforcement, state attorney general actions, and where applicable HIPAA penalties when health-related information is involved. The loss of market trust, which produces client departures (existing) and reduced acquisition rates (new). The reputation damage that extends through professional referral networks, since referrers are reluctant to refer to a practice with a public breach history. And the revenue loss during the disruption period — practices that lose access to client files for weeks during a recovery cannot deliver client work, cannot bill, and have no operating cash flow.
The non-financial costs include the time the practice’s principals must commit to managing the response (typically hundreds of hours over multiple months), the strain on staff who carry the practical impact of compromised systems, and the personal exposure of principals if the breach implicates them in negligent oversight.
What outsourcing does not actually accomplish.
A common pattern at small practices is to outsource cybersecurity to a managed IT provider and consider the matter closed. The pattern is incomplete. Outsourcing does important things — it provides expertise the practice cannot afford to retain in-house, it provides ongoing monitoring, it provides a first-line response capability when incidents occur — but it does not, by itself, accomplish three things the practice still needs.
Outsourcing does not guarantee protection. Managed providers have widely varying levels of competence, and even strong providers cannot prevent every attack. A managed provider’s role is to reduce risk to a manageable level, not to eliminate it. The practice retains the residual risk.
Outsourcing does not ensure fiduciary or legal responsibilities are met. The FTC Safeguards Rule, state data-breach notification laws, professional licensing board requirements, and any contractual obligations to clients all remain the practice’s responsibility regardless of which third party is providing technical services. The principal of the practice cannot delegate compliance away.
Outsourcing does not replace the need for penetration testing, risk assessments, or response plan reviews. The managed provider is a service vendor; their work needs to be independently validated through periodic testing by an independent party, just as a Divorce Financial Coach’s work should be independently reviewable. A practice that has not had its security tested by a party other than the managed provider is operating on assertion rather than evidence.
FTC Safeguards Compliance — what the rule actually requires.
The FTC Safeguards Rule was issued under the Gramm-Leach-Bliley Act and applies to non-bank financial institutions. Section 314.2(h) provides examples of entities the FTC considers financial institutions for Safeguards purposes — thirteen examples spanning mortgage brokers, payday lenders, investment advisors, real estate appraisers, finance companies, financial planners, and others. The 2021 amendments added “finders” to the list: companies that bring together buyers and sellers to negotiate and consummate financial transactions. The finder category has been interpreted broadly enough to include many practices that previously believed they were outside the scope, including some Divorce Financial Coach practices that engage substantively in financial transactions for clients.
Practices that fall within scope must implement a written information security program. The program must include nine specific elements under the 2023 enforceable requirements.
First, designate a qualified individual to oversee and implement the information security program. The qualified individual must have substantive security expertise and must report periodically to the practice’s board of directors or equivalent governing body. For a small practice without a formal board, the qualified individual must report to senior management with appropriate documentation of the reporting.
Second, conduct a written risk assessment. The risk assessment must identify foreseeable internal and external risks to the security, confidentiality, and integrity of customer information, and must assess the sufficiency of any safeguards in place to control those risks. The assessment must be in writing and must be updated periodically.
Third, develop and implement safeguards designed to control the risks identified in the risk assessment. The Rule specifies several categories of safeguards that must be addressed: access controls, data inventory and classification, encryption of customer information in transit and at rest, secure development practices for any internally developed applications, multi-factor authentication for access to information systems, secure disposal of customer information, change management procedures, and monitoring and logging of authorized users.
Fourth, regularly conduct penetration tests and vulnerability scans on the information system, with frequencies specified in the Rule (annually for penetration tests, semi-annually for vulnerability scans, in addition to event-driven testing after material system changes).
Fifth, develop information security policies and procedures that document how the safeguards will be maintained and applied.
Sixth, conduct service provider risk assessments. Vendors with access to customer information must be evaluated for their security posture before engagement and periodically thereafter. Service provider contracts must require the service provider to implement appropriate safeguards.
Seventh, adjust the information security program as needed based on the results of risk assessments, testing, monitoring, and material changes to operations.
Eighth, establish a written incident response plan that addresses identification, containment, eradication, recovery, and post-incident review of security events.
Ninth, the qualified individual must report to the board of directors (or equivalent) annually on the overall status of the information security program.
Small practices below a defined customer threshold are exempt from some of these requirements but not from others. The threshold and exemption structure should be reviewed with cyber-focused counsel before assuming the practice is below scope. The 2023 enforcement window has demonstrated that the FTC takes the Rule seriously and that practices believing themselves to be below scope have been challenged on that interpretation.
NIST 800-53 and the substantive risk assessment content.
The FTC Rule requires a written risk assessment but does not prescribe the methodology. The mainstream methodology adopted by competent compliance practices is NIST 800-53, the National Institute of Standards and Technology’s catalog of security and privacy controls for federal information systems and adapted broadly for private use.
A NIST 800-53-based risk assessment evaluates the practice against twenty control areas: access control, awareness and training, audit and accountability, security assessment and authorization, configuration management, contingency planning, identification and authentication, incident response, maintenance, media protection, physical and environmental protection, planning, personnel security, risk assessment, system and services acquisition, system and communications protection, system and information integrity, program management, supply chain risk management, and PII processing and transparency.
For each control area, the assessment identifies the controls relevant to the practice’s environment, evaluates whether the controls are implemented, evaluates the effectiveness of the implemented controls, and produces a risk score for each control based on the probability of compromise and the impact of compromise. The output is a detailed report with findings and recommendations. The report becomes the practice’s working baseline for security improvement and the documentation that supports the FTC compliance requirement.
The NIST Ransomware Readiness Assessment — and why ransomware deserves its own treatment.
NIST Internal Report 8374 provides a Ransomware Risk Management framework as a specific application of the broader NIST Cybersecurity Framework. Ransomware deserves its own framework because the attack pattern is sufficiently distinct from generic data breach to warrant dedicated controls.
The Ransomware framework organizes around the same five Cybersecurity Framework functions used for general security: Identify (six categories, fifteen subcategories — knowing what assets are at risk and how they connect to the practice’s mission), Protect (six categories, sixteen subcategories — putting safeguards in place), Detect (three categories, thirteen subcategories — recognizing ransomware activity quickly), Respond (five categories, fifteen subcategories — taking action when ransomware is detected), and Recover (three categories, six subcategories — restoring operations after a ransomware event).
The ransomware-specific controls focus particularly on backup posture (offline, air-gapped, periodically tested backups that cannot be encrypted by ransomware), email security (since most ransomware enters through phishing), endpoint detection and response, network segmentation (limiting the lateral movement that turns a single compromised system into a practice-wide encryption event), and tested incident response plans that include the specific decisions ransomware events require (whether to pay, how to engage law enforcement, how to communicate with clients).
Penetration testing versus vulnerability scanning — the difference matters.
Both penetration testing and vulnerability scanning are required by the FTC Safeguards Rule. The two are often conflated but they are distinct activities producing distinct outputs.
A vulnerability scan is an automated software-driven scan that identifies known vulnerabilities by comparing the practice’s systems against databases of published security weaknesses. Vulnerability scans are quick, relatively inexpensive (low four figures for a typical small practice), and should be conducted quarterly or after any significant software installation. They produce a list of identified vulnerabilities with severity ratings and remediation recommendations. Vulnerability scans can produce false positives (vulnerabilities flagged that are not actually exploitable in the practice’s specific configuration) and they cannot identify novel vulnerabilities (those not yet in the published databases).
A penetration test is a thorough, expert-driven examination conducted by a human security professional who attempts to gain unauthorized access to the practice’s systems using techniques actual attackers would use. Penetration tests are exhaustive in their examination, identify both vulnerabilities and root causes, have a meaningfully lower false-positive rate, and produce a detailed narrative of how an attacker could have compromised the practice’s systems. Penetration tests are more expensive (low to mid five figures for a typical small practice) and should be conducted one to two times per year.
The two are complementary rather than substitutable. Vulnerability scans provide ongoing surveillance of the known threat landscape. Penetration tests provide periodic deep-dive evaluation by a human attacker simulating real attacks. A compliance program that includes only one of the two is not satisfying the Safeguards Rule’s intent.
What a small practice can start doing today.
The full compliance program described above can take months to stand up and can cost tens of thousands of dollars to implement. Small practices need an actionable starting point. Four steps move a practice from no posture to a defensible initial posture.
First, conduct an initial risk assessment. This can be a self-assessment using the NIST 800-53 framework, ideally with external consultation to validate the findings. The assessment identifies the practice’s most significant exposures and provides the working baseline against which improvement is measured.
Second, conduct an initial penetration test. The test produces concrete evidence of where the practice’s defenses fail and what an attacker could actually do. The test is also the single most credible thing the practice can show clients, insurance carriers, and regulators if the question of security posture is raised.
Third, develop a written incident response plan. The plan identifies who is responsible for what when an incident occurs, what the practice’s communication obligations are (to clients, to regulators, to law enforcement, to insurance), and what the decision tree looks like for the high-stakes choices a ransomware event requires. Even a basic plan is enormously better than no plan at all.
Fourth, evaluate cyber insurance and third-party validation. Cyber insurance has become a standard component of small-practice risk management. Coverage limits, deductibles, and exclusions vary substantially across carriers, and an insurance application process itself surfaces gaps in the practice’s security posture (the application is essentially a risk assessment). Third-party validation — a certification from an external assessor that the practice meets a defined security standard — provides external assurance, internal assurance and risk mitigation, and competitive differentiation when clients evaluate the practice.
How VennBoard reduces the security surface for small practices.
Most security incidents at small practices begin with documents stored in places they should not be — files in personal cloud storage, attachments in email inboxes, copies on staff laptops, screenshots in personal phone galleries. The proliferation of locations is the security surface, and the surface is what an attacker has to find and compromise.
VennBoard reduces the security surface by consolidating sensitive client information into a single matter workspace with enterprise-grade access controls, encryption in transit and at rest, audit logging of every document access and download, role-based permissions that limit which staff can see which files, and the ability to enforce multi-factor authentication on practitioner access. The data is held centrally rather than scattered across email and personal cloud accounts.
The structural security benefits compound across the practice’s compliance posture. The audit log captures who accessed what and when, which is the documentation required for both incident investigation and routine compliance reporting. The encryption of data at rest and in transit satisfies a specific safeguard required by the FTC Rule. The access controls implement the data inventory and classification requirements. The multi-factor authentication satisfies the explicit FTC requirement for MFA on access to information systems. Each of these is a control that the practice would otherwise have to implement separately and document separately.
Two further features matter beyond the security architecture. The immutable messaging log between staff, between staff and clients, and between the practice and opposing counsel produces an evidentiary record that survives security incidents and supports both incident investigation and compliance reporting. And the consolidated billing layer with Stripe Connect and PayPal Commerce payment links reduces the practice’s exposure to handling payment card data directly — the payment processing happens in the integrated processor’s PCI-compliant environment rather than in the practice’s systems.
Cybersecurity is not the same as cybersecurity compliance, and neither is the same as cybersecurity for a typical Divorce Financial Coach or family-law practice. VennBoard exists to make all three more tractable for practices that need a workable starting point. Professional walkthrough at VennBoard.com, product detail at VennBoard.com.
