For Auto Dealerships | Educational Resource

What Every Dealership Should Know About Customer Data, the Safeguards Rule, and Downtime

Every credit application is a complete identity, every payoff is a wire someone can redirect, and the whole store runs on the DMS. Here’s what the FTC actually requires of dealers, how dealerships really get hit, and what well run dealership IT looks like, in plain English.

The Safeguards Rule for dealers, translated
Why credit applications make dealers identity goldmines
What the industry learned when dealer software went down
A baseline checklist to review with whoever runs your IT

Get the Free Dealership Technology Guide

Six plain English pages: your Safeguards obligations, the attacks, the dealership security baseline, and the questions dealer principals should ask. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.

Covered
dealers arranging financing fall under the Safeguards Rule
Every Deal
includes a full identity in the credit application
The DMS
runs sales, service, and parts all at once
Payoffs
and floorplan payments are wires attackers watch

Your Obligations, In Plain English

Because dealerships arrange financing, federal regulators treat them like financial institutions. The requirements reduce to three themes.

You're a Financial Institution

The FTC Safeguards Rule covers dealers that arrange financing or leasing. That means a written information security program: a qualified individual responsible for it, risk assessment, access controls, encryption, MFA, vendor oversight, and incident response, documented and maintained.

Customer Data Has Rules

Credit applications hold Social Security numbers, income, and everything else identity theft needs. Privacy notices, safeguarding, and proper disposal of financing paperwork are regulatory duties, and the paper in the F and I office counts as much as the data in the DMS.

Your Vendors Are Your Risk

The DMS, CRM, financing portals, and marketing tools all touch customer data, and the Safeguards Rule expects documented oversight of every one. The industry learned the hard way that a vendor outage or breach becomes every dealer’s problem at once.

How Dealerships Actually Get Hit

Dealership incidents follow the money and the systems. Four patterns cover most of the damage.

01

The Redirected Payoff

Attackers compromise or impersonate an inbox in the deal flow, then send updated banking details for a lien payoff, an auction payment, or a floorplan transaction. Amounts are large, timing is predictable, and the defense is procedural: banking changes verified by phone at a known number, every time.

02

Ransomware Meets the DMS

When the DMS goes down, sales, F and I, service, and parts stop together, and the industry saw exactly what that looks like when a major dealer software provider was taken down and thousands of stores wrote deals on paper for weeks. Your own systems and backups deserve the same scrutiny as your vendor’s.

03

The Phished F and I Office

Finance staff live in email and portals all day, handling the most sensitive data in the store under time pressure. One convincing email harvests a login that reads every credit application in reach. MFA and training turn the most targeted office into the strongest one.

04

The Disposal Pile

Printed credit applications, dead hard drives, and traded devices hold customer identities long after the deal. Documented shredding and drive destruction is a Safeguards requirement, and the cheapest one on the list.

What Well Run Dealership IT Looks Like

Whoever manages your store’s technology, this is the baseline worth reviewing together. Every item maps to a rule or an attack above.

A Safeguards Program That's Real

A written program with a named qualified individual, current risk assessment, and evidence behind every claim, ready for an FTC question or a customer’s lawyer.

MFA on Everything

Email, the DMS, CRM, financing portals, and remote access, every employee, no exceptions and no shared logins at the sales desk.

Payment Verification Procedure

Payoffs, auction payments, and any banking change confirmed by phone at a known number before funds move, written and trained.

Backups Beyond the Vendor

Daily backups of the data your store depends on, with one copy ransomware can’t reach, plus a written plan for operating when the DMS or a vendor is down.

Segmented Networks

Customer WiFi, the shop, and the business network separated, so a device in the waiting room can’t reach the F and I office.

Training, Disposal, and Monitoring

Staff phishing trained, documents and drives destroyed with documentation, and systems watched around the clock, because stores are open late and attackers are open later.

Common Questions

Yes. Dealers that arrange or extend financing or leasing are treated as financial institutions under the Safeguards Rule. That requires a written information security program with a designated qualified individual, risk assessment, access controls, encryption, multifactor authentication, vendor oversight, employee training, and incident response, and the FTC has shown it will enforce against dealers.

Every deal file contains a complete identity: Social Security number, income, address, and banking details. Dealerships also move large predictable payments like lien payoffs and auction settlements, and the entire operation depends on a handful of systems, which makes ransomware pressure immediate. Attackers get identities, payment flows, and leverage in one target.

When a major DMS provider was taken down by attackers, thousands of dealerships lost sales, F and I, service, and parts systems at once, many for weeks. The lessons: vendor risk is your risk, a written plan for operating without the DMS is not optional, and your own local systems and backups need the scrutiny you now apply to vendors.

State breach notification laws apply to customer data, the Safeguards Rule expects an incident response plan and, for larger incidents, FTC notification, and customers whose identities are exposed tend to remember where they bought the car. Dealers with a written plan and documented safeguards navigate it in days. Dealers without one improvise in public.

A six page plain English guide covering your Safeguards Rule obligations, the four attack patterns that hit dealerships, a dealership security baseline checklist, vendor and DMS risk, and the questions dealer principals should ask about their IT.

Start With the Guide. Decide From There.

Download the Dealership Technology Guide and review the baseline with whoever runs your IT. If you’d rather have the answers verified for you, a free confidential security assessment for your store is available too.

Fill the information below to download a PDF with everything you need to know about Penetration Test: