Why Dealerships Need Tailored, Ongoing Phishing Campaigns

Terry Dortch President, Automotive Risk Management Partners

Key takeaways

  • Dealerships should confirm that their compliance vendor runs an official, regular phishing campaign rather than a one-time or generic test.
  • Many cybersecurity incidents, including the Equifax case, originate from phishing, which makes it a key risk area for dealerships to address.
  • A phishing campaign should not be a canned, off-the-shelf product but should be tailored to the specific dealership.
  • ARMP tailors phishing campaigns to a dealership's brand and systems, such as Chrysler branding or the DMS used, like CDK or Tekion, based on information gathered during physical audits.
  • The goal of a tailored phishing test is to make it believable enough that it creates a teaching moment for employees about being cautious with incoming emails.

Summary

Phishing remains one of the leading causes of cyber security breaches, including well-known cases like Equifax, and dealerships need an ongoing, official phishing campaign as part of their compliance program rather than a one-time check-the-box exercise. Whatever compliance provider a store uses, that vendor should be running regular phishing tests, not a generic, off-the-shelf product that employees will quickly learn to recognize and ignore.

Effective phishing campaigns should be tailored to the specific dealership, reflecting its manufacturer brand, its DMS provider such as CDK or Tekion, and details learned through an on-site audit, since personalization makes fake emails more believable and better tests whether employees will click. The goal is not to punish staff but to create teaching moments that build awareness of suspicious emails. Dortch notes ARMP built its own phishing program in-house so it runs efficiently and stays closely tied to each store's actual systems and vendors.

Transcript

Importance of a regular phishing campaign

Hi, my name is Terry Dortch. I'm with Automotive Risk Management Partners. I want to talk to you today about phishing. Whatever compliance company you're doing business with, make sure that you have some sort of official phishing campaign being implemented. And the reason I say that, you know, I can go — Equifax was an organization that was caught up in a phishing situation. A majority of the cases out there, not necessarily auto related, but just overall cyber security issues, stem from phishing. So make sure that whoever you've got out there, that they're doing a phishing campaign for you, and that they're doing it on a regular basis. And make sure too that it's not some canned thing that they've bought off the shelf that they're throwing at you.

Tailoring phishing tests to the dealership

Our phishing campaign, what we do, we're going to tailor it to your store. If you're a Chrysler store, we're going to tailor it to a Chrysler store. If you're using CDK, we're going to tailor your phishing campaigns towards things that'll come from a CDK. If you're Tekion, if you're — you know, when we come in and do our audits, we're going to learn about your store. So this comes back to two things: one, the physical audit. The fact, the mere fact that we're there and that we're present and analyzing everything, allows us then to come in and personalize a lot of this stuff. It's going to make it more believable to the employees when they see these things, and that's what you're really trying to do. You're trying to make this thing as believable as possible to see if they're going to click on it, to follow that. Not that you're trying to bang on anybody, but you're just trying to create a teaching situation where you can come in and say, "Listen guys, you got to be more cognizant of the emails that come into your inbox."

Closing recommendation on phishing

I can't stress this enough: make sure whoever you're doing business with, that you got a phishing campaign in place. We have our own, we've developed it, our guy has done everything with it, so that now it works and it works efficiently, and it's going to do things that are very, very tied to your store. Thanks. If you have any questions, give us a call.

Questions this video answers

Why does my dealership need a phishing campaign as part of cybersecurity compliance?

Most cybersecurity incidents, not just in the auto industry, stem from phishing. Equifax is one example of an organization caught up in a phishing situation. Because of this widespread risk, dealerships should ensure their compliance provider runs an official, regular phishing campaign.

What makes ARMP's phishing campaign different from other providers?

ARMP tailors its phishing campaigns to each specific store rather than using a canned, off-the-shelf product. For example, campaigns are customized based on whether the dealership is a Chrysler store or uses a system like CDK or Tekion, learned during the physical audit.

How does a tailored phishing test benefit dealership employees?

Making the phishing test as believable as possible helps determine if employees will click on suspicious content. This is not meant to punish anyone but to create a teaching situation where staff can be reminded to be more cognizant of the emails coming into their inbox.

Covered in this video

  • Phishing campaigns
  • Cybersecurity risk assessment
  • Employee security awareness training
  • Dealership compliance audits