Evaluating Cyber Security Compliance Vendors During Year-End Reviews

Terry Dortch President, Automotive Risk Management Partners

Key takeaways

  • Dealerships typically hold year-end manager meetings to evaluate vendors and set plans for the following year, and cyber security compliance should be part of that discussion.
  • Many cyber security compliance vendors charge dealerships money while only delivering partial coverage of what is needed.
  • Dealerships often end up paying two or three different vendors to accomplish what could be handled through a single superior platform.
  • ARMP offers to review a dealership's current cyber security vendor setup and provide a platform that can lower costs while better protecting dealership assets.

Summary

Year-end planning season is when most dealerships review expenses, hold manager meetings, and decide which vendors to keep for the coming year. Cyber security compliance should be part of that discussion, even though it often gets left out. As those budget and vendor conversations come up, dealership leadership has an opportunity to take a hard look at whether current cyber security spending is actually delivering full compliance coverage or just a partial solution dressed up as one.

The speaker's view is that a large share of the vendors dealerships currently pay for cyber security compliance are charging for only part of what's needed, and that many stores end up paying two or three different vendors to cover ground that one properly built platform could handle. His recommendation is straightforward: during end-of-year vendor reviews, evaluate whether you're getting full value, and if not, bring ARMP into the conversation. He states that ARMP can offer a more complete compliance platform at a lower overall cost while better protecting the dealership's assets.

Transcript

Year-end vendor review season approaches

Hi, my name is Terry Dortch. I'm with Automotive Risk Management Partners, ARMP. You know, we're getting close to the end of the year. Here it is, middle of September. Before long, you guys are going to, we're going to have holiday schedules going on. We're going to have all kinds of, the weather's going to change. Everything's going to, we're getting towards the end of the year. Most of you are going to start looking at your expenses. You're going to have your manager meetings. You're going to evaluate your year, how everything went. You're going to take a look at what you want to do going forward, what your vendors are going to be, that whole bit. At least when I was in retail, that's what we would do towards the end of the year. Every year, like clockwork, we had a manager's meeting. Everybody grabbed their doc sheets, came in, had their notes on it, and we would sit down and figure out, all right, who are we going to do business with, and what were we looking to accomplish going forward in the following year, you know, in the following year.

Cyber security compliance often overlooked or overpaid

So, I know that's coming up with a lot of you. I don't know if cyber security compliance is anywhere in that mix, in that discussion. If it's not, it should be. And I'm telling you, it should be for several reasons. You've got a lot of choices right now when it comes to the whole cyber security compliance realm. Ninety percent of them are charging you money for half a job.

ARMP's offer to consolidate and save money

So, what I'm telling you right now is you really need to look, in these meetings when you get together, look at your vendors, figure out if you're getting what you're paying for out of it. And if you're not, I mean, give us a call. Bring us, at least bring us to the table, and let us show you how we can take and provide you with a platform that is far superior to anything you've got right now, and do it for less money. I guarantee you it will save you money, because you're probably doing business with two or three different vendors to accomplish the same end.

Give us a call. Our information is right here on the screen. I guarantee you we can help you save some money and make sure that you're protecting the assets that your dealership has. Thanks a lot. Talk to you later. Take care.

Questions this video answers

Why should we discuss cyber security compliance at our year-end manager meeting?

Year-end is when dealerships typically evaluate vendors and plan for the following year, and cyber security compliance should be part of that evaluation because many current vendors charge for incomplete coverage, leaving dealerships underprotected or overpaying.

How do we know if we're getting our money's worth from our current cyber security vendor?

Look at your vendors during your year-end meetings and figure out if you're getting what you're paying for. If not, bring ARMP to the table to compare their platform, which is described as superior and less costly than dealing with multiple vendors.

Is it common for dealerships to use multiple vendors for cyber security compliance?

Yes, according to the transcript, dealerships are often doing business with two or three different vendors to accomplish the same end, which ARMP says can be consolidated to save money.

  • Dealership Cybersecurity Requirements

    A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...

  • How to Choose a Dealership Compliance Vendor

    Choose a dealership compliance vendor by testing four things: whether their own auditors come on site or the assessment is a questionnaire, which of the nine FT...

Covered in this video

  • Cyber security compliance vendor evaluation
  • Year-end vendor review
  • ARMP compliance platform