Cyber Vulnerability Scans vs Physical Compliance Audits
Key takeaways
- A cyber vulnerability scan and a physical compliance audit are separate and different processes, though both assess risk.
- A vulnerability scan only provides a brief synopsis of risks and does not help fix any cyber security issues.
- A physical audit identifies the same kind of risk information a vulnerability scan does, but a consulting company adds solutions on top of the report.
- Dealerships need to physically audit their premises in addition to whatever cyber vulnerability scanning they are already purchasing.
- ARMP positions itself as a risk management and consulting company that helps solve compliance problems rather than just delivering a report.
Summary
Both physical premises audits and the cyber vulnerability scans many dealerships already pay for are forms of risk assessment, but they are not the same thing, and neither one, on its own, fixes anything. A vulnerability scan produces a brief synopsis of cyber risks; it identifies problems without correcting them. A physical audit works the same way unless the provider goes further and actually helps resolve what it finds.
For a dealership, the practical takeaway is to check what you are actually getting from your current compliance vendor. If you are only receiving a report or a scan result with no remediation support, you are paying for information rather than a solution. Terry Dortch positions ARMP's approach as consulting rather than reporting: assessing risk through both physical audits and cyber scans, then sitting down with the dealership to solve the underlying compliance and security issues, often at a lower cost than existing arrangements.
Transcript
Introduction to audits and vulnerability scans
Hi, my name is Terry Dortch. I'm with Automotive Risk Management Partners. You know, I want to talk to you today about auditing. I want to talk to you because you need to physically audit your premises, and then most of you are currently buying some sort of cyber piece out there that does a, what I would call, an audit. It's a vulnerability scan, right? Those two pieces are totally separate and completely different, yet they have some similarities because they're assessing risk in both scenarios, and that's really what we are. We're a risk management company. We assess risk and then we try to give you some solutions to manage that risk.
What a vulnerability scan actually provides
So the whole purpose, when you're looking at your vulnerability scans that you're purchasing, all that is, is a brief synopsis of what your risks are. That's it. It doesn't tell you how to fix them. Doesn't help you fix them. Doesn't do anything to correct any of your cyber security issues. It's just information.
How physical audits differ through consulting solutions
Audits, physical audits, do the same thing. The difference is that we're a consulting company. When we do all of these things, we're going to sit down and give you solutions. We're not just going to give you a report. We're going to help you solve the issues that you have.
Call to action for compliance help
Please, if you don't have that with your current compliance company, give us a call. Information is right here on the screen. We will help you solve your compliance problems, and we'll do it for far less money than you're paying now. I guarantee it. Give us a call. Thanks.
Questions this video answers
Is a cyber vulnerability scan the same thing as a compliance audit?
No. They are totally separate and completely different, even though both are assessing risk. A vulnerability scan is just a brief synopsis of risks, while a physical audit is part of a broader consulting process that includes solutions.
What does a vulnerability scan actually give us?
A vulnerability scan only gives a brief synopsis of what your risks are. It does not tell you how to fix them, does not help you fix them, and does not do anything to correct your cyber security issues.
How is ARMP's approach different from just getting a scan report?
ARMP is a consulting company, so when it performs audits or reviews, it sits down and gives solutions rather than just handing over a report, helping dealerships actually solve the compliance issues found.
Read more on this
-
Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...
-
Dealership F&I Compliance Audit
An F&I compliance audit reviews a sample of completed deal jackets against the consumer finance rules that govern them: Truth in Lending and Regulation Z, ECOA...
Covered in this video
- vulnerability scanning
- physical compliance audits
- risk management consulting