Quick disclosure: I run an IT company that works with local businesses, so I look at this from the technical side. Here's what I see dealerships overlook.
Since dealers finance and lease vehicles, they're treated as financial institutions under the FTC Safeguards Rule. The common gaps:
Curious what's been the hardest piece for your store?
Since dealers finance and lease vehicles, they're treated as financial institutions under the FTC Safeguards Rule. The common gaps:
- No written risk assessment. Having security tools isn't the same as documenting the risks and revisiting them.
- No testing. The rule calls for annual pen testing plus vulnerability scans every six months, or continuous monitoring.
- MFA gaps. It's required for anyone accessing customer information, including DMS, CRM, and email.
- Vendor oversight. The vendors that touch customer data should have security expectations written into their contracts.
- Incident reporting. Since May 2024, a breach involving unencrypted info on 500+ consumers must be reported to the FTC within 30 days.
Curious what's been the hardest piece for your store?