The Case for Consolidating Dealership Compliance and Cyber Vendors

Terry Dortch President, Automotive Risk Management Partners

Key takeaways

  • Many dealerships cannot say when their compliance or cyber security contract is up, or even confirm they have one.
  • Dealerships typically rely on two to four separate vendors to cover cyber security hardware, compliance audits, and vulnerability scans or penetration testing.
  • The auto industry tends to treat compliance and cyber security as an afterthought because dealership staff see themselves primarily as salespeople focused on cars, parts, and service.
  • Consolidating these functions into a single platform allows a dealer to be confident about not being disrupted or costing money from a hack, rather than juggling multiple vendors.
  • ARMP offers to review a dealership's current compliance and cyber security setup and show where a consolidated approach would differ.

Summary

Dealerships across the country tend to treat compliance and cyber security as an afterthought, often unable to say who their vendor is, what services are covered, or even when a contract expires. The typical setup involves juggling two to four separate vendors: one for hardware, another sprinkling in some cyber security, another running periodic audits, and possibly another handling vulnerability scans or penetration testing. This fragmented, sales-first mindset leaves real gaps, since no single provider owns the full picture of risk across the store.

Dortch argues dealerships need to stop treating this as a side issue and instead put a single, properly built platform in place that covers compliance and cyber security together. Consolidating scattered vendor relationships into one coordinated approach means a dealer principal, GM, or F&I director can actually know what they're paying for and trust that gaps aren't being missed. The practical takeaway is to review current vendor contracts and coverage now, rather than assuming existing arrangements are adequate, and to consider a unified platform that removes the guesswork.

Transcript

Dealerships unaware of their compliance contracts

Hi, my name is Terry Dortch. I'm with Automotive Risk Management Partners, ARMP. I'm here to talk to you today because over the last couple of years, we've been in hundreds if not a thousand dealerships all across the country, and they all have the same thing. You go in and you talk to them about compliance or cyber security and I get the same response. Yeah, we're good. Yeah, we're okay. They haven't looked at it. They really don't know what they're getting for their money, to be honest. Most of them, if you were to ask them when their contract was up, they wouldn't even know if they had a contract.

Why the industry ignores compliance and cyber security

The bottom line is that compliance and cyber security, obviously within the auto industry, is not a concern. It's not something that we take seriously. And it's not something that... because what do we, we're really salespeople. That's the whole auto industry. We're there to sell cars, parts, and service. That's it. That's what we're there for. And when you throw these little monkey wrenches into things like compliance or cyber security, it's kind of like taking the fish out of the water thing, right? It just flops around because it's not something that we're used to. It's not something that we feel like dealing with.

The scattered multi-vendor approach

And so most of the comments when we go into these stores is, "Yeah, we're good. We're okay. We've got a company that handles that." You've probably got a company that handles and sprinkles a little bit of cyber security in there. They handle some of your hardware stuff. You've probably got another company out there that comes in and does some audits, maybe twice a year, maybe once a year. There's a few of you that are doing it three and four times a year. And then you've got someone that's maybe doing some vulnerability scans, some pen testing, that type of thing. So you're probably dealing with anywhere from two to four vendors to accomplish something that's a fish out of water.

The case for a single platform

I don't understand it. It kind of confuses me when I think about it because there's no reason for that. You need to take a minute, step back, and go, this is something serious. It's something we need to look at and address, and we need to put together a platform that once that platform's in place, if it's the right platform, then you can really sit back and think, "All right, I'm good. I don't have to worry about someone hacking into my system, disrupting my business, costing me money." It's just something that needs to be thought about and dealt with, and not shelved.

ARMP's offer to review current setup

Please give us a call. We're more than happy to come in and just sit with you and chat if you want, and just go over what you currently have and show you where the differences are and explain how things should be. So give us a buzz. Information is right here on the screen. Thanks.

Questions this video answers

How many vendors do dealerships usually use for compliance and cyber security?

Most dealerships are dealing with anywhere from two to four different vendors to accomplish their compliance and cyber security needs, including separate companies for hardware, audits, and vulnerability scans or penetration testing.

Why don't dealerships take compliance and cyber security seriously?

Dealership staff see themselves primarily as salespeople there to sell cars, parts, and service, so compliance and cyber security feel like an unfamiliar disruption, similar to a fish out of water, that they are not used to dealing with.

What does ARMP recommend dealerships do about their scattered compliance vendors?

ARMP recommends stepping back, treating compliance and cyber security as serious matters, and putting together a single platform so that once it is in place correctly, the dealer no longer has to worry about hacking or business disruption.

  • Dealership Cybersecurity Requirements

    A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...

  • How to Choose a Dealership Compliance Vendor

    Choose a dealership compliance vendor by testing four things: whether their own auditors come on site or the assessment is a questionnaire, which of the nine FT...

Covered in this video

  • Vendor consolidation
  • Cyber security
  • Compliance audits
  • Penetration testing
  • Vulnerability scans