• Stop being a LURKER - join our dealer community and get involved. Sign up and start a conversation.

Should CDK Pay the Cyber Ransom?

Too late now, but I'm talking more about in the future so that people have less reason to diversify. For instance, my appraisal tool and my inventory provider are the same. I'm thinking about switching inventory providers so that I don't have two things down at once if this happens again.
Oh I get what you are saying Bill and I agree.

Depending upon the architecture of their system, it might not be a simple process to segregate those components. It likely will NOT be a simple process.
 
Ok. That's what I thought you might have been saying. Totally get it.
Absolutely. I am in a couple of Facebook Groups that this is being discussed within. Many feel that CDK is done dealing to the degree that they will be no more. I guess we will find out. I am certain that nobody will ever tell exactly what happened here.

It's ironic that we as dealers are required to file reports per the Safeguards Rule. Within those reports, we are supposed to identify where the breach took place and what was done to fix it. It is going to be really hard to complete these reports if CDK won't tell anyone how it happened.
 
I don't know enough of CDK history but if they bought out some other applications and built out their system,
then
CDK probably patchworked together the different platforms.

I say this because it's not really easy to merge different programs.

example: I have a crm, cms, and ecommerce site all using the same coding language and framework. If all 3 were different at oen time, then the way they did user permissions and a few other things probably it was just simpler to provide bridge code that shares logins and such.

Now imagine using different versions of the language, frameworks or even different technologies like .Net and Java.

There is no way most companies will spend time to fully merge these different products. They possibly might try merging the databases but then again ... maybe not.

Undoing this work isn't that simple either unless this bridgework code is relatively recent but if you have a year of code changes depending on passing data and some features of the other code, it becomes hard too.

Let's not forget that users don't want to have 3 different logins and love the simplicity of 1 login.

TLDR;
Yes, it is doable.
But there is a cost to this.

I think CDK should have just paid the ransom and sucked up the bad luck instead of creating all this bad will and stink.
Why didn't they though? Are they having cash issues?