Why You Must Scrutinize Vendors’ Cyber Security

By Terry Dortch Originally published in Digital Dealer
Why You Must Scrutinize Vendors’ Cyber Security

Third-party vendors can create a direct path into a dealership’s customer, sales and financial data. Assuming a vendor has adequate security—or relying only on its privacy notice or contract—is not enough. Dealerships can remain responsible for vendor-related breaches under the GLBA Safeguards Rule, while cyber insurance may provide limited coverage or deny losses when required due diligence was not performed.

Dealerships should identify every vendor with physical or digital access, determine what information each can reach and verify that access is limited to a legitimate purpose. Vendor reviews should examine privacy practices, data retention and destruction, employee controls, incident-response plans, system recovery capabilities and regulatory history. Strong contracts, recurring risk assessments and employee training can reduce exposure and demonstrate that the dealership has taken meaningful steps to protect customer information.