ARMP Offers Combined Cybersecurity and Compliance for Dealers

Terry Dortch President, Automotive Risk Management Partners

Key takeaways

  • Many dealership compliance companies originated around OSHA and EPA audit work rather than cyber security.
  • Comply Auto emerged in response to the FTC Safeguards Rule requirement for cyber security measures such as vulnerability scans and annual penetration tests.
  • ARMP states its cyber security platform can see a dealership's network in real time and monitor every device attempting to connect, not just endpoints.
  • ARMP describes using an offensive cyber security approach involving decoys called phantoms placed within the network.
  • ARMP says it has provided compliance and auditing services since 2003.

Summary

Dealership compliance vendors tend to be fragmented, each built around a narrow niche. Some grew out of OSHA and EPA work, offering audits and engineering support but treating cyber security as an afterthought. Others, like Comply Auto, emerged specifically to address the Safeguards Rule requirement for a cyber security program, such as ongoing monitoring, regular vulnerability scans, and an annual penetration test, then later tried to expand into deal jacket audits remotely without the staff to do it well. The result is that most stores end up stitching together separate vendors for OSHA-style compliance, deal audits, and cyber security.

Automotive Risk Management Partners positions itself as a single provider covering all three areas. Terry Dortch describes ARMP's cyber security platform as offering real-time visibility into every device attempting to connect to the network, not just endpoints, plus an offensive tactic using decoy "phantoms" placed throughout the network to detect intrusions. On the compliance side, he says ARMP originated dealership compliance auditing back in 2003. For a dealership principal, GM, or F&I director evaluating vendors, the message is that combining compliance and cyber security under one provider, priced to be cost-effective, avoids the gaps left by piecing together specialized outside companies.

Transcript

Introducing ARMP and typical compliance vendors

Hi, my name is Terry Dortch. I'm with Automotive Risk Management Partners, ARMP, the cyber security. We're a compliance company, and we differ from the compliance companies that you're used to dealing with. Their niche really is probably OSHA. Yeah, they provide some stuff along the front end and they help you with audits and things like that, but that's really not what their forte is. They were designed and created around the whole OSHA concept, OSHA, EPA, they had engineers, the whole bit.

Comply Auto's origin from Safeguards Rule fears

Comply Auto, they came into existence when we had the fear that was thrown out from the Safeguards Rule regarding cyber security. You had to have some sort of a cyber security platform in place, either 24/7 monitoring or, you know, you had to have regular vulnerability scans with an annual pen test, that type of thing. So Comply Auto came in and tried to fill that gap a little bit. After a while they tried to pick up and do a little bit of the OSHA part of it. They were doing some deal jacket audits, but they had to do them remote because they didn't have a lot of people.

ARMP's real-time cyber security platform and phantoms

My point is that everybody else out there is fragmented. ARMP is a solution that provides it all. We have a cyber security platform that I'm telling you right now, there's nobody in the world has anything close to it. Not anything close. It's the only platform that can see your network real time, see every device that's trying to connect to it, not just your endpoints. And we're the only platform that takes an offensive approach that creates a series of cyber security, man, this virtual minefield within your network. They're called phantoms. We're the only platform that does that.

ARMP's history and value in compliance auditing

And when it comes to the compliance end of it and the auditing, we're the originators of it. We started it 20 years ago, back in 2003. That is our bailiwick. We have the best compliance platform out there. I'm telling you right now, if compliance, cyber security is even a thought, you need to give us a call, because there's nobody out there that can hold a candle to what we can do. And not for the money. We're not expensive by any stretch. We've designed and created this platform to where it is cost-effective for anyone.

Closing contact information

So, please, our information is here on the screen. Give us a buzz. Talk to you later.

Questions this video answers

How is ARMP different from other dealership compliance providers?

Other compliance companies are fragmented, often built around OSHA or EPA work, with cyber security added later. ARMP provides both compliance and cyber security in one platform, rather than splitting the services across multiple vendors.

Why did companies like Comply Auto start offering cyber security services?

The FTC Safeguards Rule created a requirement for dealerships to have a cyber security platform in place, such as 24/7 monitoring or regular vulnerability scans with an annual penetration test, and companies like Comply Auto came in to try to fill that gap.

What makes ARMP's cyber security platform different?

ARMP says it is the only platform that can see a dealership's network in real time, monitor every device trying to connect rather than just endpoints, and that it uses an offensive approach creating decoys called phantoms throughout the network.

How long has ARMP been doing compliance and auditing work?

Terry Dortch states that ARMP are the originators of dealership compliance auditing, having started the work back in 2003.

  • Dealership Compliance Software

    Dealership compliance software tracks a store's obligations under the FTC Safeguards Rule, OSHA, EPA, and F&I regulations in one system, with audit findings, em...

  • Dealership Cybersecurity Requirements

    A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...

Covered in this video

  • FTC Safeguards Rule
  • OSHA
  • EPA
  • penetration testing
  • vulnerability scanning