Dealership Cybersecurity Requirements

A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of customer data at rest and in transit, access controls, asset inventory, secure disposal, activity logging, and either continuous monitoring or annual penetration testing with semiannual vulnerability assessments.

By Terry Dortch President, Automotive Risk Management Partners Last reviewed

Which cybersecurity rules apply to a car dealership?

The controlling federal requirement is the FTC Safeguards Rule at 16 CFR Part 314, which applies because dealerships that arrange financing are financial institutions under the Gramm-Leach-Bliley Act. Its technical requirements have been mandatory since June 9, 2023, and its breach reporting requirement since May 13, 2024.

Three other sources stack on top. State data security and breach notification statutes apply based on where customers live, not where the store is. Manufacturer and lender agreements increasingly carry their own security attestations. And cyber insurance policies contain warranties that a dealership can breach without ever hearing from a regulator.

What technical controls does the Safeguards Rule require?

16 CFR 314.4(c) names eight controls. These are the ones a dealership is measured against.

ControlCitationWhat compliance looks like at a store
Access controls314.4(c)(1)Authentication and least-privilege access, reviewed periodically. Terminated employees removed the same day, not at month end.
Data and asset inventory314.4(c)(2)A current list of systems, devices, platforms, and personnel that hold or touch customer information — including the physical deal jacket room.
Encryption314.4(c)(3)Customer information encrypted at rest and in transit over external networks, or a written determination of compensating controls.
Secure development314.4(c)(4)Applies where the dealership or group builds its own applications or customer-facing portals.
Multi-factor authentication314.4(c)(5)MFA for every individual accessing any system holding customer information. No exemptions by seniority.
Secure disposal314.4(c)(6)Disposal within two years of last use unless retention is justified, plus periodic review of what is being retained.
Change management314.4(c)(7)A documented procedure for evaluating security impact when systems change.
Logging and monitoring314.4(c)(8)Logging authorized user activity and detecting unauthorized access to customer information.

Continuous monitoring or penetration testing — which should a dealership choose?

16 CFR 314.4(d) offers two compliance paths and the choice has real cost consequences.

  • Continuous monitoring. Ongoing detection of changes and threats across the environment. No prescribed testing interval on top.
  • Scheduled testing. Annual penetration testing plus vulnerability assessments at least every six months, and additional assessments after any material change to operations or business arrangements.

For most dealerships the continuous route is cheaper over a year and produces a stronger evidence trail, because it generates a dated record continuously rather than three times annually. It is also more defensible: a penetration test proves the network was sound on one day in March.

ARMP takes the continuous path using the Ridgeback appliance, which sits on the dealership network and scans for vulnerabilities, open ports, unpatched software, and rogue devices without interrupting operations, backed by vulnerability and external IP exposure scanning with an archived report history.

Where do dealership breaches actually come from?

Four patterns account for most incidents in retail automotive:

  1. Third-party compromise. The dealership's own network is intact but a vendor with standing access is not. This is why 314.4(f) vendor oversight is a security control and not paperwork.
  2. Credential theft and phishing. A finance or accounting mailbox is taken over, then used for payoff or wire fraud against customers who trust the sender.
  3. Ransomware through remote access. Exposed remote desktop, unpatched VPN appliances, or a service technician's laptop.
  4. Physical exposure. Deal jackets in an unlocked room, workstations left signed in on the sales floor, or an unsecured server closet. These are Safeguards violations even when no computer is touched.

The fourth is the one software alone never finds, which is why an on-site walkthrough belongs in a dealership security program rather than a purely remote assessment.

What has to happen after an incident?

Two clocks start at discovery. The federal clock under 16 CFR 314.5 runs 30 days for notification events affecting the unencrypted customer information of 500 or more consumers, filed through the FTC's online form and published in a public database. State clocks run separately and several are shorter.

The written incident response plan required by 314.4(h) must cover the goals of the plan, internal processes for responding, roles and responsibilities and levels of decision-making authority, internal and external communications and information sharing, remediation of identified weaknesses, documentation and reporting of incidents, and post-incident evaluation and revision of the plan itself. Writing that plan after an incident begins is too late; the plan is the thing that tells a general manager who to call at 6pm on a Friday.

A practical dealership cybersecurity checklist

  1. Enable MFA on the DMS, CRM, email, VPN, and any remote access — no exemptions by seniority.
  2. Inventory every system and device holding customer information, including physical storage.
  3. Confirm encryption at rest and in transit, or document the compensating controls in writing.
  4. Remove access the day an employee leaves, and review access rights on a set schedule.
  5. Choose the 314.4(d) path and put the resulting cadence on a calendar.
  6. Enable logging of authorized user activity on systems holding customer information.
  7. Write and test the incident response plan, including who is called and in what order.
  8. Set the retention and disposal schedule and actually run the disposal.
  9. Collect current security attestations from every vendor with system access.
  10. Assign security awareness training to every employee and track expiry.
  11. Verify your cyber policy's warranties match what you can actually evidence.

Primary sources

Related guides

Frequently asked questions

Is multi-factor authentication actually mandatory for dealerships?

Yes. 16 CFR 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system holding customer information. The only permitted alternative is a written determination by the Qualified Individual that a reasonably equivalent or more secure access control is in use. Verbal agreement that a manager finds MFA inconvenient is not that determination, and exempting managers is the most common way dealerships fail this element.

Does a dealership need to encrypt data at rest as well as in transit?

Both. 16 CFR 314.4(c)(3) requires encryption of all customer information held or transmitted, at rest and in transit over external networks. Where encryption is infeasible, the Qualified Individual may approve effective alternative compensating controls in writing. Legacy DMS installations are the usual sticking point, which makes a written determination and a migration plan the practical route.

What cybersecurity training do dealership employees need?

The rule requires security awareness training for all personnel, updated to reflect current risks, plus qualified information security personnel whose skills are kept current. For a dealership the practical shape is annual awareness training for every employee, phishing recognition emphasised for anyone handling credit applications or wire instructions, and role-specific coverage for F&I and accounting. Tracking expiry matters as much as tracking completion.

How long can a dealership keep customer data?

Under 16 CFR 314.4(c)(6), customer information must be securely disposed of no later than two years after the last date it was used in connection with providing a product or service, unless retention is necessary for business operations, another legitimate business purpose, or required by law. State record retention rules and lender agreements often require longer, so the workable approach is a written retention schedule that names the legal basis for each category rather than keeping everything forever by default.

What is the biggest cybersecurity risk specific to dealerships?

The combination of high-value data and broad third-party access. A dealership holds full credit applications with Social Security numbers, dates of birth, and income, while granting standing access to its systems to a DMS provider, a CRM, lenders, marketing vendors, and service contractors. Attackers target the dealership because the data is dense, and they frequently arrive through a third party rather than the front door.