Building a Full Cyber Security Program Under the Safeguards Rule
Key takeaways
- The Safeguards Rule cyber security requirement covers more than a pen test and a vulnerability scan; it extends to the specific software used in the dealership, such as Office 365, Google Docs, and CRM tools.
- Whether cyber security is handled internally or by a third party provider, the dealership must confirm all necessary elements of the Safeguards Rule are being satisfied.
- Every dealership has multiple third party vendors dialing into its system, including service contract providers, service department vendors, and parts department vendors, and each must be vetted correctly.
- Cyber security compliance should be treated as part of a broader umbrella of compliance regulations rather than a standalone task.
- Dealerships must make risk-reward business decisions about which cyber security gaps to address immediately and which can wait, often with outside consultative help.
Summary
The FTC Safeguards Rule's cyber security requirements go well beyond running a periodic penetration test or vulnerability scan. Whether a dealership handles this internally or through a third party provider, the coverage needs to extend down into the actual software in daily use, including platforms like Office 365, Google Docs, and CRM tools, so every piece of the information system is accounted for rather than just the obvious entry points.
Dealerships also need a plan for the many outside vendors dialing into their systems, from service contract providers to service and parts department tools, and those vendors need to be properly vetted. The speaker frames this as one piece of a broader compliance umbrella, and stresses that addressing it is ultimately a business decision: dealers weigh the risk, decide what level of mitigation makes sense, and prioritize accordingly. He describes a consultative approach where his team sits down with a dealership's management to identify strong areas, gaps needing attention, and what can reasonably wait.
Transcript
Cyber security beyond pen tests and scans
The cyber security piece of the whole compliance umbrella—you need to make sure that whoever you're going to do business with, or whoever you're gonna... and you may internalize it, if you internalize it, you know, that's great. Just make sure that your team, or the third party provider that you have coming into your store, that they're providing you with all the necessary elements to satisfy that whole Safeguards Rule cyber security piece, where it's not just, you know, you don't have to worry about just a pen test and a regular vulnerability scan. You want to make sure that whatever company you're dealing with, or if you're doing it internally, that you've drilled down all the way to the different software that you're using in the dealership, if you're using an Office 365, or a Google Docs, or if you're going into, you know, your different CRM tools.
Vetting third party vendors dialed into your system
And you got to remember that every dealership is different, but for the most part there's so many different vendors that are dialing into your system. Your service contract providers, you know, your service department has, your parts department has, different vendors dialed in. So everybody's dialing into your system, everybody's... so make sure you have a solution for your third party vendors, make sure they're vetted correctly, make sure that the whole—when you're dealing with this, look at it like I've called it a couple of times, an umbrella of compliance regulations that are out there that need to be addressed.
Making risk-reward compliance decisions
And again, it's like anything in business, we still have to make a business decision on it. It's a risk-reward kind of thing, where you analyze your risk, you decide how much it's going to take to mitigate or rectify that risk, and in that process you decide what you're going to do with it. We're here to help you make those decisions. And in some cases it may be that we decide, as a group, there are certain things that you don't need to do right now, or you're doing very well in one area and you need a little help over here.
Consultative approach to defining priorities
So part of the whole consultative environment that we live in is that we will be able to sit down with your management team and make those decisions, and define where we need to be and what we need to address.
Questions this video answers
Does satisfying the Safeguards Rule just mean running a pen test and vulnerability scan?
No. The transcript states you don't have to worry about just a pen test and a regular vulnerability scan. You need to drill down to the specific software used in the dealership, like Office 365, Google Docs, or CRM tools, to fully satisfy the cyber security piece.
How should a dealership handle the many third party vendors connecting into its systems?
Since service contract providers, service department vendors, and parts department vendors all dial into the dealership's system, you need a solution for third party vendors and must make sure they are vetted correctly as part of the overall compliance umbrella.
How do we decide which cyber security gaps to fix first?
The transcript describes it as a risk-reward decision: you analyze your risk, decide how much effort it takes to mitigate or rectify it, and then decide what to do. Sometimes a group decision is made that certain things don't need addressing right now while other areas need help.
Read more on this
-
Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...
-
FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) app...
Covered in this video
- FTC Safeguards Rule
- vendor due diligence
- penetration testing
- third party vendor risk