• This thread is just the tip of the iceberg.The people ahead of the curve aren't Googling for answers — they're already in here, having the conversations you haven't found yet. DealerRefresh is free.Get the full picture →

FTC Safeguards Rules are here and I wanted to share some advice to stay complaint.

Oct 2, 2026
1
0
First Name
Justin
Quick disclosure: I run an IT company that works with local businesses, so I look at this from the technical side. Here's what I see dealerships overlook.

Since dealers finance and lease vehicles, they're treated as financial institutions under the FTC Safeguards Rule. The common gaps:
  • No written risk assessment. Having security tools isn't the same as documenting the risks and revisiting them.
  • No testing. The rule calls for annual pen testing plus vulnerability scans every six months, or continuous monitoring.
  • MFA gaps. It's required for anyone accessing customer information, including DMS, CRM, and email.
  • Vendor oversight. The vendors that touch customer data should have security expectations written into their contracts.
  • Incident reporting. Since May 2024, a breach involving unencrypted info on 500+ consumers must be reported to the FTC within 30 days.
The FTC's guide, "What Your Business Needs to Know," is plain English and worth a read.
Curious what's been the hardest piece for your store?
 

✨ AI Highlights

An IT professional outlines the most common FTC Safeguards Rule compliance gaps he sees at dealerships, including missing written risk assessments, lack of penetration testing, incomplete MFA deployment, and insufficient vendor contract language. The key insight is that having security tools in place is not the same as meeting the rule's documentation and testing requirements, and dealers classified as financial institutions face specific, auditable obligations. The post serves as a practical checklist for dealerships trying to avoid regulatory exposure.

Replies Views 0 27 Started Last Reply