Two Compliant Cybersecurity Options Under the FTC Safeguards Rule
Key takeaways
- The FTC Safeguards Rule offers dealerships two compliant options for the cyber portion of compliance.
- Option one requires periodic pen testing and vulnerability scanning plus someone in-house capable of remediating the findings.
- Option two requires 24/7 monitoring and remediation through a security operations center, which removes the need for scheduled pen tests and vulnerability scans.
- Many dealerships use two to four separate vendors for OSHA, sales audits, cyber compliance, and antivirus or phishing simulation, which often costs more than necessary.
- Consolidating compliance services with a single provider can reduce monthly vendor costs, as shown by one dealership saving $1,200 a month after consolidating three vendors.
Summary
The FTC Safeguards Rule gives dealers two ways to satisfy its cyber security requirements. Option one allows periodic vulnerability scans and pen testing, done a few times a year, but only works if someone on staff can actually read those reports and remediate what they find. Option two replaces scheduled scanning with 24/7 monitoring and remediation through a security operations center, which the speaker says fully satisfies the FTC's requirement on its own and leaves a dealership more genuinely secure than checking the minimum boxes under option one.
Many dealerships end up spread across two to four separate vendors for OSHA physical audits, sales audits, cyber compliance, and antivirus or phishing simulation tools, often paying far more combined than necessary. The speaker describes a real example where a store paying roughly $4,000 a month across three companies consolidated with one provider and cut costs by $1,200 a month without losing coverage. For a dealer principal or GM, the takeaway is to review current vendor spending before year end, confirm which option under the Safeguards Rule is actually in place, and consider whether consolidating compliance functions could reduce cost while improving protection.
Transcript
Dealers overspending on multiple compliance vendors
Hi, my name's Terry Dortch. I'm with Automotive Risk Management Partners. I do want to talk real quick about, um, what I've done over the last probably six weeks, or six plus weeks, that I've been running around the country. I've been to several different states running with my consultants. We've been all over the South, Southeast, over in the East Coast, was down into, went to Nevada, Arizona. So I mean, I've been all over this country, really, the last probably six weeks, and it's given me an opportunity to talk to a lot of dealers. But, you know, current customers, potential customers, we've been on several sales calls, things like that. And I've reached a conclusion, um, that I kind of half thought anyway, but am now convinced, and that conclusion is that a lot of the dealers are spending way more money and way more time and effort on compliance than they need to be.
I think what happened is a couple years ago, we got this, a little over, well, a little over two years ago that the law, I guess, that the update came out, and then a year ago that it was, you know, that it was made effective. The effective date happened, and because of that a lot of dealers made some really quick decisions, I think, in order to make sure that they were protected and make sure that they were doing what they were supposed to be. And in doing that, they ended up doing business with anywhere from two to four different companies for their compliance problems. You know, there's several competitors out there, several people that do what we do. There's one of, probably three or four of us, that could, any one of us could probably do all of what you're trying to do with three or four different companies. I know we could, we could solve all your problems. Anything that you're doing with three or four companies can all be done through us.
And I guess what I want to do is I want to add some clarity to all of this, because right now you've got an opportunity, if you have an opportunity, coming up to the end of the year where you'll have a little bit of downtime maybe and some time to reflect and look at your expenses, look at where you're spending your money on your vendors and things like that. And I think when you look at it, you're going to see that you're spending a lot more on compliance than you need to be, and I think you could get it to a certain level where it's a lot more managed by a third party than something internally.
Case example: consolidating three vendors into one
And the reason I say that is because when we did this presentation, we did a presentation where we had a dealership, and that dealership was doing business with three different companies to solve their compliance problems. They had a very strong competitor of ours that they were paying monthly to handle OSHA, to handle their sales audit process. They had another company that is, again, a pretty good competitor in the marketplace, they were being billed by them to handle their cyber piece. Then they had another company that was doing their antivirus and doing any type of phishing simulations, things of that nature. When it was all said and done, they were almost $4,000 a month spending on these three companies. I'm going to tell you right now, we were able to go into that store, we were able to solve all three of those issues as one company, and we were able to save them $1,200 a month off their expenses.
My point in all of this is that a lot of times what happens is we pick a company that does a little bit of this, another company does a little bit of this, when in reality, if you were really to sit down and work with the companies, and this is where we differ from our competitors, if you were to sit with us and say, look, here's who we're doing business with, we're going to sit down and analyze all of that for you. We're going to sit with you and go, okay, do you really need to spend this X number of dollars over here on this guy? Maybe you do, maybe it's something we can't provide for you, or maybe they do a better job of it than we do. And we're going to tell you that, because we're really a consulting company. We're going to sit down with you, we're trying to do what's best for the dealership. Our ultimate goal in all of this is to make sure the dealer keeps the money that he's made the last year, right? That's really what we're trying to do, is set up an affirmative defense within your dealership so that you can keep the money you've made. And the best way to do that is to really analyze who you're doing business with and how much you're spending on that.
Two FTC Safeguards Rule options for cyber compliance
What I want to do is I want to define what the FTC is looking for in their Safeguards Rule real quick, and I think there was some confusion when this came out. So really the FTC, you have two options to solve, especially, let's just concentrate on the cyber aspects of it right now. I think the physical part of all of this, doing the physical audits, the OSHA piece, those have been, we've been doing those for years. It's something that I think everybody understands, everybody knows that the audit that occurs and how in-depth it is. But when you look at the cyber part of all of this, it's a little more difficult because there's so much more involved in it.
Option one: periodic scanning and pen testing
And when I look at the cyber piece of the FTC's requirements and what they're looking for, you as a dealer have two options. One of them, which is what most of our competitors provide you, or can provide you at this point, provides you the ability to run a pen test a couple times a year, they can run a vulnerability scan two to four or five times a year, I'm not sure exactly, everyone's a little different, and they give you the scanning that they do. And sometimes it's scheduled, so they'll schedule it to where it scans every six months, or it's scheduled to scan maybe some guys are doing it quarterly, and they'll provide these reports to you. That's one option the FTC says. But then in that option, you have to have someone that can be able...
To look at those reports and act on those reports. And what I mean by that, they need to be able to remediate. They need to be able to do what they need, you know, whatever those reports are telling them, they need to be able to take action on them. So if you don't have anyone in your store that's capable of doing that, or anyone to pass that off to, option number one is not really a solution for you, unless you're just trying to check some boxes and get by on the very, very, very bare minimum. That's option one.
Option two: 24/7 SOC monitoring and remediation
Now option two, the FTC points out that says, listen, you don't need to do vulnerability scans, you don't need to do pen testing, as long as you're doing a 24/7 monitoring and remediation afterwards. So that second option, which would require accessing a SOC, a security operations center, having 24/7 engineer monitoring it, eliminates the need for option one and allows you to progress and go to a point where there's a 24/7 monitoring service being done. Yeah, we can still produce reports at that level, and those reports can tell you what action was taken. But the bottom line is, at option two, there's nothing more you need to do. You're completely, completely compliant with anything the FTC requires. Not to mention that you've even gone to the extent of remediating those, you as an organization would be completely secure, as secure as you can be in today's world, at that point.
Closing recommendation to review vendors before year end
So I guess what I'm trying to tell you is this: make sure before you make any decisions going into the new year that you take a look at all of this. And if you want help with it, call us. We're here to sit down and analyze it, give you the best scenario for you, and really sit down and try to figure out what's going to work best for your organization at this time. So give us a call, and again, have a great Christmas. I hope everybody enjoys the holidays. We'll see you again next year. And if you have any questions or anything, our number's here on the screen, just give us a call. Thanks.
Questions this video answers
What does the FTC Safeguards Rule require for the cyber part of compliance?
The FTC gives dealers two options: run periodic pen tests and vulnerability scans (a couple times a year and two to four or five times a year respectively) with someone able to act on the reports, or implement 24/7 monitoring and remediation through a security operations center, which eliminates the need for scheduled pen testing and vulnerability scans.
Is option one, periodic scanning and pen testing, enough to be compliant?
It can satisfy the FTC requirement, but only if someone at the dealership is capable of reviewing those reports and remediating the issues found. If no one in the store can act on the reports, this option is only checking a box at the bare minimum level.
Why are dealerships spending too much on compliance vendors?
Many dealers made quick decisions when the Safeguards Rule update took effect and ended up hiring two to four different companies to cover OSHA audits, sales audit processes, cyber compliance, and antivirus or phishing simulations separately, when one company could typically handle all of it together.
Can using one compliance vendor instead of several actually save money?
Yes, in one example a dealership was paying almost $4,000 a month across three different companies for OSHA, sales audits, cyber, and antivirus, and consolidating those services with one company saved them $1,200 a month.
Read more on this
-
Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...
-
FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) app...
Covered in this video
- FTC Safeguards Rule
- penetration testing
- vulnerability scanning
- security operations center (SOC) monitoring
- vendor consolidation