GLBA enforcement status. FTC enforcement actions (recent): (a) DRIZLY (2022) - alcohol delivery; security failures including no Information Security Program + no MFA + no audit + no vendor-management; consent order; (b) TaxSlayer (2017) - tax preparation; no Safeguards Rule + privacy notices issues; consent order; (c) Wyze Labs (2024) - smart devices; consumer fraud + security issues; (d) Equifax (2019 + ongoing) - credit-reporting agency; massive 2017 breach; settlements with FTC + CFPB + state AGs USD 575M+; (e) RingCentral + others. CFPB ENFORCEMENT: under Dodd-Frank Title X for non-bank financial institutions + UDAAP + Reg E + Reg P + including Section 1033 compliance once effective 2026-2030 phased; Section 1071 small-business lending data. SEC ENFORCEMENT: Regulation S-P enforcement actions (e.g. PIPL Securities + Cetera + JP Morgan + Voya + Morgan Stanley + others) + Item 1.05 Form 8-K cybersecurity disclosure (SolarWinds + others). NAIC + STATE INSURANCE ENFORCEMENT: NY DFS 23 NYCRR 500 enforcement actions (RingCentral USD 100K + Excellus USD 1M + Genworth + others) + state insurance commissioners examinations. BANKING-AGENCY ENFORCEMENT: OCC + Federal Reserve + FDIC + NCUA examination program + bank cyber-incident notification rule (12 CFR Part 53) effective 2022-05-01 requires 36-hour incident notification to primary federal regulator + 36-hour notification to bank service providers under bank-service-provider relationships. FSA HIGHER ED ENFORCEMENT: 2024 Department of Education increased scrutiny of Title IV institutions GLBA Safeguards compliance + FSA Audit Guide updates + Cybersecurity Program Bulletins.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.