Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of customer data at rest and in transit, access controls, asset inventory, secure disposal, activity logging, and either continuous monitoring or annual penetration testing with semiannual vulnerability assessments.
Which cybersecurity rules apply to a car dealership?
The controlling federal requirement is the FTC Safeguards Rule at 16 CFR Part 314, which applies because dealerships that arrange financing are financial institutions under the Gramm-Leach-Bliley Act. Its technical requirements have been mandatory since June 9, 2023, and its breach reporting requirement since May 13, 2024.
Three other sources stack on top. State data security and breach notification statutes apply based on where customers live, not where the store is. Manufacturer and lender agreements increasingly carry their own security attestations. And cyber insurance policies contain warranties that a dealership can breach without ever hearing from a regulator.
What technical controls does the Safeguards Rule require?
16 CFR 314.4(c) names eight controls. These are the ones a dealership is measured against.
| Control | Citation | What compliance looks like at a store |
|---|---|---|
| Access controls | 314.4(c)(1) | Authentication and least-privilege access, reviewed periodically. Terminated employees removed the same day, not at month end. |
| Data and asset inventory | 314.4(c)(2) | A current list of systems, devices, platforms, and personnel that hold or touch customer information — including the physical deal jacket room. |
| Encryption | 314.4(c)(3) | Customer information encrypted at rest and in transit over external networks, or a written determination of compensating controls. |
| Secure development | 314.4(c)(4) | Applies where the dealership or group builds its own applications or customer-facing portals. |
| Multi-factor authentication | 314.4(c)(5) | MFA for every individual accessing any system holding customer information. No exemptions by seniority. |
| Secure disposal | 314.4(c)(6) | Disposal within two years of last use unless retention is justified, plus periodic review of what is being retained. |
| Change management | 314.4(c)(7) | A documented procedure for evaluating security impact when systems change. |
| Logging and monitoring | 314.4(c)(8) | Logging authorized user activity and detecting unauthorized access to customer information. |
Continuous monitoring or penetration testing — which should a dealership choose?
16 CFR 314.4(d) offers two compliance paths and the choice has real cost consequences.
- Continuous monitoring. Ongoing detection of changes and threats across the environment. No prescribed testing interval on top.
- Scheduled testing. Annual penetration testing plus vulnerability assessments at least every six months, and additional assessments after any material change to operations or business arrangements.
For most dealerships the continuous route is cheaper over a year and produces a stronger evidence trail, because it generates a dated record continuously rather than three times annually. It is also more defensible: a penetration test proves the network was sound on one day in March.
ARMP takes the continuous path using the Ridgeback appliance, which sits on the dealership network and scans for vulnerabilities, open ports, unpatched software, and rogue devices without interrupting operations, backed by vulnerability and external IP exposure scanning with an archived report history.
Where do dealership breaches actually come from?
Four patterns account for most incidents in retail automotive:
- Third-party compromise. The dealership's own network is intact but a vendor with standing access is not. This is why 314.4(f) vendor oversight is a security control and not paperwork.
- Credential theft and phishing. A finance or accounting mailbox is taken over, then used for payoff or wire fraud against customers who trust the sender.
- Ransomware through remote access. Exposed remote desktop, unpatched VPN appliances, or a service technician's laptop.
- Physical exposure. Deal jackets in an unlocked room, workstations left signed in on the sales floor, or an unsecured server closet. These are Safeguards violations even when no computer is touched.
The fourth is the one software alone never finds, which is why an on-site walkthrough belongs in a dealership security program rather than a purely remote assessment.
Which systems count as "in scope" at a dealership?
Scope is where dealership security programs quietly fail. The Safeguards Rule attaches to customer information wherever it lives, not to the DMS. A defensible inventory usually turns up more than the store expected:
- The DMS — the obvious one, and usually the best protected.
- Email — credit applications, payoff quotes, driver's licence images and insurance cards move through dealership mailboxes constantly. Mailboxes are also retained far longer than any retention policy contemplates.
- The CRM and desking tools — full applicant records, often with looser access controls than the DMS and more third-party integrations.
- Credit bureau and lender portals — accessed with shared credentials more often than anyone admits.
- Scanners, copiers and the shared drive — the scan-to-folder destination for deal documents is frequently a network share with no access control at all.
- Personal phones — salespeople photographing licences and insurance cards, then keeping them in a camera roll that syncs to a personal cloud account.
- Physical deal jackets — the rule covers information, not just data. An unlocked jacket room is an access-control failure under 314.4(c)(1) exactly as an open share is.
The camera-roll problem is worth naming directly because it is nearly universal and almost never in a written program. It creates customer NPI on a device the dealership does not control, cannot inventory, cannot encrypt, cannot log, and cannot wipe when the employee leaves. The fix is procedural rather than technical — a capture path inside a controlled application, and a rule that is actually enforced — but it has to be written down and trained on to count.
What does a dealership need to log, and why?
16 CFR 314.4(c)(8) requires monitoring and logging of authorised users' activity and detection of unauthorised access to or use of customer information. Dealerships tend to treat this as the least interesting safeguard. It is in fact the one that determines the cost of everything that goes wrong later.
The reason is the presumption in the notification provision. Where customer information was accessed without authorisation, unauthorised acquisition is presumed unless the dealership holds reliable evidence showing no acquisition occurred. Logs are that evidence. A store that cannot show which records an account touched has no way to rebut the presumption, so an incident that affected a handful of customers gets reported as though it affected everyone reachable from the compromised account.
What that means in practice: retain authentication and access logs for long enough to investigate an incident discovered months after the fact, log at the record level in systems that support it, alert on the patterns that matter at a dealership — bulk export from the DMS, logins outside business hours, access to records unrelated to the user's department — and confirm that a departed employee's access actually ended on their last day rather than at the next licence audit.
What has to happen after an incident?
Two clocks start at discovery. The federal clock under 16 CFR 314.4(j) runs 30 days for notification events affecting the unencrypted customer information of at least 500 consumers, filed on a form on the FTC's website and published in a public database. State clocks run separately and several are shorter.
The written incident response plan required by 314.4(h) must cover the goals of the plan, internal processes for responding, roles and responsibilities and levels of decision-making authority, internal and external communications and information sharing, remediation of identified weaknesses, documentation and reporting of incidents, and post-incident evaluation and revision of the plan itself. Writing that plan after an incident begins is too late; the plan is the thing that tells a general manager who to call at 6pm on a Friday.
Does a dealership have to encrypt everything?
16 CFR 314.4(c)(3) requires customer information to be encrypted both in transit over external networks and at rest. Where encryption of information at rest is infeasible, the dealership may instead secure it using effective alternative compensating controls — but only where the Qualified Individual has reviewed and approved those controls in writing.
Two things follow. The infeasibility route is real and legitimate: legacy DMS modules and some manufacturer systems genuinely cannot encrypt at rest, and the rule anticipates that. But it is a documented determination, not an assumption. A dealership relying on it without the Qualified Individual's written approval has not used the exception; it has simply not encrypted.
The other point is scope again. "In transit over external networks" covers the everyday traffic dealerships forget: a deal packet emailed to a lender, a spreadsheet of prospects sent to a marketing agency, a scanned licence texted from a salesperson's phone. Encrypting the DMS while credit applications leave the building as plain email attachments satisfies the letter of nothing. It is also the failure mode most likely to be discovered by someone outside the dealership, because the recipient can see it.
Encryption is worth more than its line in the checklist because of how it interacts with 314.4(j). A notification event is the unauthorised acquisition of unencrypted customer information. Information that was encrypted falls outside the definition unless the key was taken too. Encryption at rest is therefore not only a control — it is the thing that decides whether an incident becomes a filing the FTC publishes.
What must the written incident response plan contain?
16 CFR 314.4(h) requires a written plan designed to promptly respond to and recover from any security event materially affecting the confidentiality, integrity or availability of customer information. It names seven things the plan must address, and a dealership plan is judged against that list rather than against its length:
- The goals of the plan.
- The internal processes for responding to a security event.
- Clear roles, responsibilities and levels of decision-making authority.
- External and internal communications and information sharing.
- Requirements for remediating any identified weaknesses in information systems and associated controls.
- Documentation and reporting of security events and the response activities.
- Evaluation and revision of the plan following a security event.
Item three is where dealership plans fail in practice. The question a plan has to answer is who decides to take the DMS offline at 6pm on a Friday when the general manager is unreachable and the decision costs a weekend of selling. If the plan does not name that person and their alternate, the decision defaults to whoever is present, which is how ransomware gets a further twelve hours to run.
Item four has to include the 30-day federal notification clock under 314.4(j), the notification duties in the states where the affected consumers live, and the contractual notice obligations owed to lenders and the manufacturer. Those deadlines run from discovery, not from the end of the investigation, and several state deadlines are shorter than the federal one.
A dealership maintaining customer information on fewer than 5,000 consumers is excepted from 314.4(h) by 16 CFR 314.6. That exception removes the requirement to write the plan; it does not remove the 30-day notification duty, which is not among the four provisions 314.6 excepts.
A practical dealership cybersecurity checklist
- Enable MFA on the DMS, CRM, email, VPN, and any remote access — no exemptions by seniority.
- Inventory every system and device holding customer information, including physical storage.
- Confirm encryption at rest and in transit, or document the compensating controls in writing.
- Remove access the day an employee leaves, and review access rights on a set schedule.
- Choose the 314.4(d) path and put the resulting cadence on a calendar.
- Enable logging of authorized user activity on systems holding customer information.
- Write and test the incident response plan, including who is called and in what order.
- Set the retention and disposal schedule and actually run the disposal.
- Collect current security attestations from every vendor with system access.
- Assign security awareness training to every employee and track expiry.
- Verify your cyber policy's warranties match what you can actually evidence.
Primary sources
- 16 CFR Part 314 — Standards for Safeguarding Customer Information
- FTC — Safeguards Rule: What Your Business Needs to Know
Related guides
Frequently asked questions
Is multi-factor authentication actually mandatory for dealerships?
Yes. 16 CFR 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system holding customer information. The only permitted alternative is a written determination by the Qualified Individual that a reasonably equivalent or more secure access control is in use. Verbal agreement that a manager finds MFA inconvenient is not that determination, and exempting managers is the most common way dealerships fail this element.
Does a dealership need to encrypt data at rest as well as in transit?
Both. 16 CFR 314.4(c)(3) requires encryption of all customer information held or transmitted, at rest and in transit over external networks. Where encryption is infeasible, the Qualified Individual may approve effective alternative compensating controls in writing. Legacy DMS installations are the usual sticking point, which makes a written determination and a migration plan the practical route.
What cybersecurity training do dealership employees need?
The rule requires security awareness training for all personnel, updated to reflect current risks, plus qualified information security personnel whose skills are kept current. For a dealership the practical shape is annual awareness training for every employee, phishing recognition emphasised for anyone handling credit applications or wire instructions, and role-specific coverage for F&I and accounting. Tracking expiry matters as much as tracking completion.
How long can a dealership keep customer data?
Under 16 CFR 314.4(c)(6), customer information must be securely disposed of no later than two years after the last date it was used in connection with providing a product or service, unless retention is necessary for business operations, another legitimate business purpose, or required by law. State record retention rules and lender agreements often require longer, so the workable approach is a written retention schedule that names the legal basis for each category rather than keeping everything forever by default.
What is the biggest cybersecurity risk specific to dealerships?
The combination of high-value data and broad third-party access. A dealership holds full credit applications with Social Security numbers, dates of birth, and income, while granting standing access to its systems to a DMS provider, a CRM, lenders, marketing vendors, and service contractors. Attackers target the dealership because the data is dense, and they frequently arrive through a third party rather than the front door.