31.6 million mortgage records exposed in 2023–2024. loanDepot, Mr. Cooper, First American, LoanCare — every name your borrowers trust has been on a breach notification letter. Texas's 27,000+ licensed MLOs process escrow instructions, SSNs, W-2s, and wire routing numbers in the same inbox as phishing attempts. GLBA Safeguards Rule §314.4 is enforced now. TDPSA private-right-of-action launched July 2024. Your next breach is a public filing.
The mortgage industry produced six of the top fifteen financial-services data breaches from 2023 to 2025. These aren't abstract statistics — they are NMLS-licensed entities, title underwriters, and servicers your borrowers compare you against. Their breach notifications land in your clients' inboxes weeks after yours would.
Healthcare gets the headlines, but mortgage brokers and IMBs are statistically more attractive to ransomware operators in 2024–2026 on three dimensions: data concentration, operational urgency, and payment capability.
Texas mortgage brokers and lenders are supervised simultaneously by the FTC (Safeguards Rule), CFPB (Reg P), NMLS/TDSML, the Texas AG (TDPSA), and — if you service federally-related loans — HUD/FHFA. A single breach event triggers concurrent reporting obligations, independent penalty calculations, and the possibility of simultaneous AG and class-action proceedings.
| Regulation | What It Requires | Effective / Enforced | Failure Consequence |
|---|---|---|---|
| GLBA Safeguards Rule §314.4 FTC |
9 documented program elements: qualified individual, risk assessment, safeguards implementation, service provider oversight, data disposal, encryption, MFA, access controls, incident response plan. Annual written report to board/leadership. | Effective June 9, 2023. Full enforcement live. FTC has pursued 3 civil actions against mortgage entities in 2024. | Civil penalties up to $51,744/violation/day. Personal liability for the designated "Qualified Individual." Exam finding triggers NMLS report. Class action standing for affected borrowers. |
| TDPSA — Texas Data Privacy & Security Act TX AG |
Consumer data rights (access, deletion, correction, portability). Data protection assessments for high-risk processing. Opt-out for sale/sharing of personal data. Privacy notice accuracy requirement. | Effective July 1, 2024. Attorney General has enforcement authority. 30-day cure period for first violations (expires Jan 1, 2025 for new violations). | Civil penalty up to $7,500/intentional violation. Private right of action for data breach victims under TDPSA + Texas Bus. & Com. Code §521. Class action exposure. |
| CFPB Regulation P CFPB |
Annual privacy notice to all active borrower relationships. Clear disclosure of data-sharing practices with nonaffiliated third parties. Right to opt out of certain sharing. | Ongoing. CFPB supervisory authority over IMBs with >$10B in originations; state-chartered entities supervised by TDSML. | CFPB supervisory action, public enforcement order, restitution to borrowers. TDSML license suspension or revocation for state-licensed entities. |
| SAFE Act / NMLS Recordkeeping TDSML / NMLS |
3-year retention of all loan origination records including electronic communications. Written cybersecurity incident disclosure to TDSML within 72 hours of material breach. MLO license renewal contingent on no open regulatory matters. | Texas Finance Code Chapter 156. TDSML exam cycle: 18–24 months. Post-2024: cyber incident questionnaire added to examination scope. | License suspension, civil money penalty, forced corrective action plan. NMLS record reflects regulatory actions — visible to all state regulators and to CFPB. |
| SAFE Act Surety Bond Exposure TDSML |
Texas mortgage brokers maintain surety bonds of $50,000–$100,000 depending on loan volume. A cybersecurity-facilitated fraud event that causes borrower loss can trigger a bond claim. | Texas Finance Code §156.205. Bond carrier may pursue subrogation against the broker entity if the loss was caused by security negligence. | Bond claim + subrogation action. Bond premium increase at renewal. Bond cancellation if carrier drops. License non-renewable without bond. Personal guaranty exposure for small entities. |
The IBM/Ponemon "average breach cost" figure ($4.88M in 2024) is a large-enterprise number. For a 25-MLO independent mortgage broker or small IMB with 1,200 annual borrowers, the cost model is different — and in several dimensions, more severe as a percentage of revenue.
FBI's Financial Crimes Unit operates a SWIFT-aligned Financial Fraud Kill Chain (FFKC) that can freeze and reverse wire transfers — but only if a Financial Institution (FI) submits a Priority Funds Return Request within approximately 72 hours of wire initiation. In practice, the window to stop a wire before it reaches a foreign correspondent bank or is converted to cryptocurrency is under 4 hours. CoreRecon's 30-minute SLA is designed to trigger that chain.
The mortgage industry's data residency and regulatory requirements create a real problem with offshore SOC providers: GLBA Safeguards Rule §314.4(f) requires documented vendor oversight, and sending borrower PII to offshore analysts triggers additional cross-border transfer considerations under CFPB guidance. CoreRecon resolves this categorically.
Mortgage is a volume-sensitive, rate-cycle business. Your overhead must flex with origination volume. CoreRecon pricing is per-endpoint, month-to-month, with no long-term contract required. Scale up during refi booms, right-size during rate contractions.
All tiers: month-to-month, no long-term contract, no setup fee. Minimum: 10 endpoints. Typical 25-MLO shop deployment: 75–90 endpoints.
The FTC Safeguards Rule §314.4 requires nine specific documented program elements. Your TDSML examiner and your warehouse lender cyber questionnaire both reference these. Here is how CoreRecon maps to each element, with the specific deliverable your compliance file receives.
| §314.4 Element | What the Rule Requires | CoreRecon Control / Deliverable | Tier |
|---|---|---|---|
| §314.4(a) — Qualified Individual | Designate a qualified individual responsible for overseeing and implementing the information security program. Report to board/senior management annually. | Command: CoreRecon vCISO serves as your documented Qualified Individual. Sentinel/Fortress: CoreRecon provides written program support; you designate an internal QI. | Mapped |
| §314.4(b) — Risk Assessment | Periodic risk assessment identifying internal and external threats to customer information, assessing adequacy of controls, and evaluating likelihood and potential damage of threats. | CoreRecon delivers an annual written risk assessment covering LOS, POS, email, borrower portal, and third-party integrations. Updated quarterly for material changes. | Mapped |
| §314.4(c) — Safeguards Design | Design and implement safeguards to control risks identified in the risk assessment, including access controls, encryption, and data management practices. | CoreRecon manages EDR, email security, MFA enforcement, access review, and encryption-at-rest monitoring. Written safeguards design document provided annually. | Mapped |
| §314.4(d) — Service Providers | Oversee service providers by selecting and retaining only those with appropriate safeguards and requiring them by contract to implement and maintain appropriate safeguards. | CoreRecon provides a vendor risk assessment template and conducts annual security reviews of your LOS (Encompass, BytePro, Calyx), POS (Floify, SimpleNexus), and title software vendors. | Mapped |
| §314.4(e) — Program Evaluation | Evaluate and adjust the information security program in light of results of testing and monitoring, changes in operations, or material changes in business arrangements. | CoreRecon delivers quarterly written posture evaluations and notifies you within 48 hours of any material change in your risk posture requiring program adjustment. | Mapped |
| §314.4(f)(1) — Encryption | Encrypt customer information in transit and at rest, unless the Qualified Individual approves alternative compensating controls in writing. | CoreRecon enforces TLS 1.2+ for all in-transit communications and monitors for unencrypted customer data stores. Exceptions documented and approved by QI in writing. | Mapped |
| §314.4(f)(2) — MFA | Implement multi-factor authentication for any individual accessing information systems containing customer information, unless approved alternative controls are documented. | CoreRecon enforces MFA across all MLO workstations, LOS access, email, and remote access VPN. MFA coverage report delivered monthly. | Mapped |
| §314.4(h)(2) — Incident Response | Establish a written incident response plan to respond to a security event affecting the confidentiality, integrity, or availability of customer information. | CoreRecon provides a written IRP tailored to mortgage operations including wire fraud scenarios, LOS ransomware, and email compromise — with CoreRecon's direct-contact escalation path and the FFKC activation procedure. | Mapped |
| §314.4(i) — Annual Reporting | Qualified Individual must report to board or senior management, in writing, on the overall status of the information security program and the company's compliance with the Safeguards Rule. | CoreRecon drafts the annual §314.4(i) written report for your QI/leadership review and signature. Delivered 60 days before your fiscal year-end to allow review. | Mapped |
In 90 minutes, CoreRecon delivers a written GLBA §314.4 gap analysis, an email security review covering BEC exposure, an endpoint inventory check, and a prioritized remediation roadmap — at no cost, no obligation. You get the same output a Big 4 firm charges $2,500 for, because we want your business, not your consulting budget.
Arctic Wolf, Huntress, and Critical Start are credible MDR providers. They have real technology, real customers, and real capabilities. Here is where CoreRecon wins on the dimensions that matter most to a Texas mortgage broker.
| Capability / Wedge | CoreRecon | Arctic Wolf | Huntress | Critical Start |
|---|---|---|---|---|
| TX-Resident Analysts (No Offshore) | ✓ | ✗ | ✗ | ✗ |
| SDVOSB Certification | ✓ | ✗ | ✗ | ✗ |
| Published Pricing (No Sales Call Required) | ✓ | ✗ | ≈ | ✗ |
| 30-Minute IR SLA (Wire Fraud Specific) | ✓ | ≈ | ✗ | ≈ |
| GLBA §314.4 Written Program Included | ✓ | ≈ | ✗ | ≈ |
| NMLS Exam Prep Documentation | ✓ | ✗ | ✗ | ✗ |
| Mortgage-Specific BEC Detection Rules | ✓ | ≈ | ≈ | ≈ |
| Month-to-Month (No Annual Contract) | ✓ | ✗ | ≈ | ✗ |
| Minimum Endpoint Count ≤ 25 | ✓ (10 min) | ✗ (50+) | ✓ | ✗ (100+) |
| Technology Depth (EDR + SIEM + Network) | ✓ | ✓ | ≈ | ✓ |
| Brand Recognition / Enterprise References | ≈ | ✓ | ✓ | ≈ |
✓ = full capability / clearly available. ≈ = partial or requires add-on. ✗ = not available or not documented. Arctic Wolf and Critical Start are enterprise-focused and typically require 100+ endpoint minimums and 12-month contracts. Huntress is strong on SMB/MSP channel but lacks mortgage-specific compliance deliverables and TX SOC residency.
TDPSA (Texas Business & Commerce Code Chapter 541) creates an individual private right of action for Texas residents whose sensitive personal data is exposed due to a controller's failure to implement reasonable security measures. Mortgage borrower data — SSNs, financial account numbers, income data, credit information — qualifies as sensitive personal data under TDPSA §541.001(23).
Unlike CCPA (California) or CPA (Colorado), TDPSA does not limit the AG's right to pursue cases where the controller had a cure period but failed to remediate. And unlike most state privacy laws, TDPSA private plaintiffs can file directly in Texas district court without a class certification requirement for individual claims. For a 25-MLO broker with 1,200 borrowers, each borrower is an independent potential plaintiff.
What this means operationally: You need to be able to demonstrate, in writing, that you implemented reasonable security measures for borrower data. "We had antivirus" is not a reasonable security measure under TDPSA in 2026. "We have a GLBA §314.4 program managed by a TX-resident MSSP with documented controls, monitoring, and incident response" is. CoreRecon provides the documentation trail that makes "reasonable security" a defensible legal position.
Ten (10) endpoints. This covers a small independent broker with 3–5 MLOs and shared infrastructure. For context, a typical 5-MLO broker shop has 5 MLO laptops, 1–2 servers (LOS, file share), 1 network appliance, and 1–2 admin machines = 9–10 endpoints. The minimum means you're not locked out because you're not "enterprise-sized." There is no enterprise contract requirement, no minimum term, and no setup fee.
Standard onboarding completes in 5–7 business days for a 10–75 endpoint environment. EDR agent deployment is silent and non-disruptive — no reboots required for most endpoints, no application conflicts with Encompass, BytePro, Calyx, or Floify LOS/POS platforms. Email security integration (BEC detection layer) goes live within 24 hours via MX record change or connector configuration — takes approximately 20 minutes with your IT contact or email admin. We have never caused a closing delay due to onboarding.
Yes — under the Command tier, CoreRecon's vCISO can formally serve as your designated Qualified Individual. The Safeguards Rule allows the QI to be an employee or a qualified outside service provider. We will accept the QI designation in writing, maintain the required documentation, deliver the annual §314.4(i) board/management report, and be available for TDSML examination questioning. Sentinel and Fortress tiers provide all QI support documentation — you designate an internal individual who relies on our program infrastructure.
Yes. TDSML added a cybersecurity questionnaire to its examination scope starting in 2024. CoreRecon provides a pre-examination preparation packet that addresses every question on the current TDSML cybersecurity examination guide, including incident history, program documentation, vendor oversight records, and risk assessment currency. For NMLS bond reporting: if a cybersecurity-related fraud event occurs that requires bond notification, CoreRecon prepares the written incident summary for your bond carrier and provides documentation supporting any subrogation defense.
Yes. CoreRecon's EDR and SIEM have pre-built integration profiles for Encompass 360 and Encompass SmartClient. We monitor for unusual Encompass API access patterns, credential sharing across LO accounts, bulk loan file export events, and privilege escalation on the Encompass administrator account. We also conduct annual security configuration reviews against ICE Mortgage Technology's recommended Encompass security hardening guide. Calyx Point, BytePro Express, Floify, and SimpleNexus are also in our integration library.
The exact sequence: (1) CoreRecon's email security layer flags a suspicious outbound message from an MLO account that matches BEC wire instruction patterns; (2) an analyst reviews within minutes and escalates if confirmed; (3) within 30 minutes, you receive a direct phone call (not just an email) from a CoreRecon analyst with specifics on which account was compromised and which transactions are at risk; (4) we provide a written incident summary within 2 hours for your bank's fraud team, which is the document your bank needs to initiate an FBI FFKC Priority Funds Return Request. We maintain a direct line to FBI Houston's Financial Crimes Unit for urgent FFKC escalations.
Yes. Warehouse lenders (Texas Capital Bank, Western Alliance, Flagstar, etc.) increasingly include cybersecurity questionnaires in their annual IMB due diligence process. CoreRecon provides a completed warehouse lender cybersecurity questionnaire response package under the Command tier, covering: security program documentation, incident history, penetration testing recency, encryption standards, access control evidence, and third-party audit status. Fortress tier clients receive a template and guidance. Most questionnaires take 2–3 hours to complete with CoreRecon support vs. 2–3 weeks without.
Upon contract termination, CoreRecon removes all EDR agents from your endpoints within 48 hours of your request. We provide you with a complete export of all security event logs, incident reports, and compliance documentation generated during your service period — this is your property, required for TDSML examination records, and you receive it in a format compatible with standard SIEM and document management systems. We retain no customer data beyond the retention period in our data processing agreement. You own all your compliance documentation.