Technology

What Kind of Websites Are the Safest to Use When Handling Large Customer Databases?

Image by Tomasz Wrona

The Identity Theft Resource Center counted 3,322 data compromises in the United States in 2025, the highest yearly total in the two decades the nonprofit has kept a tally.

Financial services led its industry breakdown with 739. Healthcare came second with 534.

Both sectors work under federal security rules written for them, and both still topped the list. ITRC tracks public reports, so the count partly measures who is obliged to speak.

It can’t tell anyone which kind of website is safest to trust with a large customer database.

A fairer test is the rulebook a site answers to: what it must test, and whom it must tell when something fails.

No rulebook makes a site safe, and no category here is breach-proof. Some simply make a site prove more before anything goes wrong.

Seven Rulebooks Answer The Same Two Questions Differently

This comparison takes five categories that keep large customer databases under a named regime: banks and other financial firms, healthcare providers, card-accepting retailers, state-licensed online casinos and CFTC-registered event-contract platforms.

Two of them take two rows each, because the rule follows the company rather than the brand.

CategoryRulebookWhat it must test or auditBreach-notice duty
Banks (OCC, Federal Reserve, FDIC)Interagency security guidelines; 2021 incident-notification ruleKey controls, at a frequency its own risk assessment setsRegulator within 36 hours of a disruptive incident; customers as soon as possible if misuse is reasonably possible
Non-bank financial firms (Federal Trade Commission)FTC Safeguards RuleAnnual penetration test and six-monthly vulnerability assessments, unless monitored continuouslyFTC within 30 days when 500 or more consumers are affected
Healthcare providers and plans (HHS Office for Civil Rights)HIPAA Security and Breach Notification RulesRisk analysis and periodic evaluation, no fixed intervalIndividuals within 60 days; HHS at the same time for 500 or more
Card-accepting retailers (card-brand programs)PCI DSS v4.0.1, mainly through card-brand contractsVulnerability scans every three months; penetration tests at least every 12 monthsVisa within three calendar days; customers under state breach laws
Online casinos (New Jersey Division of Gaming Enforcement)New Jersey internet gaming rulesAnnual security assessment by an approved independent professionalState breach law
Event-contract exchanges (Commodity Futures Trading Commission)Core Principle 20; 17 CFR Part 38, Subpart UVulnerability, penetration, controls and incident-response testingCFTC staff, promptly, for threats to its systems
Event-contract brokers (CFTC and National Futures Association)17 CFR Parts 160 and 162; NFA Interpretive Notice 9070Security program reviewed at least every 12 monthsNFA, promptly, after a loss of funds or a required customer notice

The online casino row speaks for New Jersey alone. There, every casino licensee offering internet gaming must commission a yearly system integrity and security assessment from an independent professional of its choosing, subject to approval by the Division of Gaming Enforcement, and the report goes to the Division.

Banks Answer To A Clock, Non-Bank Firms To A Calendar

The two federal banking instruments in the table set one hard deadline between them, and it points at the supervisor.

Under the rule the OCC, the Federal Reserve and the FDIC issued in November 2021, a banking organization must notify its primary federal regulator no later than 36 hours after it determines that a notification incident has occurred.

The trigger is disruption rather than theft alone. The incident has to have materially disrupted or degraded the bank’s operations or business lines, or be reasonably likely to.

Data exposure runs through older interagency guidance, which calls for alerting the regulator as soon as possible after unauthorized access to sensitive customer information, and customers as soon as possible when misuse is reasonably possible.

Testing is left to judgment. The security guidelines ask for regular tests of key controls, at a frequency the bank’s own risk assessment sets, run or reviewed by people independent of the program.

Non-bank financial firms under the FTC’s Safeguards Rule get numbers instead: an annual penetration test and vulnerability assessments every six months, unless they monitor their systems continuously.

Since May 13, 2024, those firms have also owed the FTC a report within 30 days of discovering a notification event involving 500 or more consumers. On test cadence, the non-bank firm answers to the more specific rule.

HIPAA Still Leaves The Test Calendar To Each Provider

HIPAA’s Security Rule asks for “an accurate and thorough assessment of the potential risks and vulnerabilities” to electronic health information, then a “periodic technical and nontechnical evaluation” of the safeguards that follow.

It doesn’t define periodic. A regional hospital network and a two-doctor practice read the same sentence and set their own calendars.

HHS proposed to change that on January 6, 2025, with automated vulnerability scans at least every six months and a penetration test at least once every 12 months.

As of September 24, 2026, the Federal Register shows no final rule, and the regulation in force still carries the old evaluation wording.

The notice side is firmer. A provider must tell affected individuals without unreasonable delay and within 60 calendar days of discovering a breach, and must tell HHS at the same time when 500 or more people are affected.

A breach involving more than 500 residents of one state also goes to prominent media outlets there.

Retail Testing Runs On A Card-Brand Contract

Card-accepting retailers answer to a test calendar no legislature wrote. PCI DSS v4.0.1, the card industry’s security standard, requires internal and external vulnerability scans every three months, the external ones by an Approved Scanning Vendor whose scan solution the PCI Security Standards Council has tested and approved.

Penetration tests, internal and external, follow at least once every 12 months and after any significant change.

That is more specific about timing than HIPAA’s current rule or the banks’ guidelines, but the standard binds mainly through contracts.

The council says so plainly: “We do not monitor the implementation of standards.” Payment brands and acquirers decide who must comply and who must prove it, though at least one state has also written compliance into statute for businesses that take cards there.

The contract carries a breach clock of its own, and it points at the card brand. Visa’s compromise rules, in their June 2026 version, require any entity that suspects unauthorized access to Visa account data to make sure the event reaches Visa within three calendar days of the suspicion.

The clock for telling customers comes from somewhere else. Every state has a breach-notification law, as do the District of Columbia, Guam, Puerto Rico and the US Virgin Islands, according to National Conference of State Legislatures figures GovTech reported in January 2026.

A retailer can be held to quarterly scans by its acquirer and still owe customers nothing faster than its state’s statute demands.

Event-Contract Exchanges Test Against A Federal Checklist

Event-contract platforms, the apps usually marketed as prediction markets, come in two layers borrowed from futures markets.

The exchange is a designated contract market, Kalshi’s among them, and it answers to the CFTC’s Core Principle 20 and the system safeguards rules in Part 38, Subpart U.

Registration settles which agency examines those systems. Where the contracts may be offered is a separate fight: judges have split over whether a sports contract is a derivative under federal law or betting under state law, so the position still differs from one state to the next.

Since the CFTC’s September 2016 testing rule, Subpart U has named the work: vulnerability testing, external and internal penetration testing, controls testing, incident response plan testing and an enterprise technology risk assessment, mostly by independent contractors or by staff who neither build nor run the systems under test.

A covered exchange, one carrying at least 5% of all contract volume across designated contract markets, also gets floors, including quarterly vulnerability testing and yearly penetration tests.

Senior management and the board receive the results, and the exchange must document every weakness its testing finds, with a decision to fix it or accept the risk.

A cyber incident that threatens the systems goes to CFTC staff, and the rule’s word for the timing is promptly.

Several apps aren’t the exchange, though. They’re futures commission merchants that hold the customer’s account and route orders to one.

Part 160 makes their policies cover administrative, technical and physical safeguards for customer records, and Part 162 can require a board-approved Identity Theft Prevention Program where a broker keeps covered consumer accounts.

NFA’s Interpretive Notice 9070 adds a written security program, approved by a senior officer and reviewed at least once every 12 months, plus a prompt notice to the NFA when an incident costs funds or forces customer notices.

The CFTC withdrew its January 2024 proposal for an operational resilience framework at futures commission merchants, testing and incident notices included, in September 2025.

Two layers means two rulebooks, and which one guards a customer’s identity file depends on which company holds the prediction-market account.

So the first fact to establish about any of these apps is its registration, because an offshore venue with no CFTC registration sits outside both.

A comparison of the top prediction markets at GamingToday records a regulation status for every platform it lists, beside each platform’s market focus and payment methods, and several listings name the registered company behind the app.

Customers Get The General Version Of A Breach

Several notice duties in the table run only to regulators, among them the exchange’s word to CFTC staff and the broker’s summary to the NFA.

None of the rules creating them requires the regulator to publish what it receives. HITECH is the exception among these federal rules: it orders HHS to post a public list naming each covered entity with a breach affecting more than 500 people, which gives a patient a provider-by-provider record to check.

The FTC went partway. It said it intended to put its non-bank reports in a publicly available database, because the report “requires only the most general information and cannot provide a meaningful roadmap for attackers.”

That’s a defensible call for a regulator, and it still leaves the public side of a breach general by design.

The letters customers receive have thinned out as well: the Identity Theft Resource Center found that 70% of 2025’s notices carried no attack information, against 45% in 2023.

The report’s own verdict, quoted in Insurance Journal’s write-up, is that “transparency is on life support.”

The regulator can ask for more. An exchange must hand over every system safeguards test report it holds, promptly, when a Commission representative requests it. A customer, as a rule, gets the letter and the public lists rather than the reports.

Registration Is The Part A Customer Can Look Up

The registration behind an event-contract app is a different matter, because it sits in public records.

The CFTC lists the exchanges it has designated, and the NFA offers its free BASIC search to investors thinking about opening a futures account.

Registration records change, and courts in several states have ruled on sports event contracts during 2026, not always the same way. Anyone tracking those changes can add GamingToday on Facebook to a news feed.

What’s left is a decision about which rulebook you’d rather have behind your records. A site that tests against a regulator’s checklist and owes a supervisor a prompt account of any incident has committed to more than one that sets its own calendar, even if neither can promise it won’t be breached.

Look up the legal entity named in the disclosures, then decide whether its rulebook is enough for what you’re about to hand over.

Kavichselvan

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

5 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

5 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

6 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

7 hours ago