A Buyer’s Guide for Multi-Rooftop Auto and Truck Groups

Helion Technologies

Every managed IT provider you talk to will tell you they work with dealerships. Some of them mean they have one rooftop as a client. A few mean they understand what happens when the service drive goes down at 8:15 on a Saturday morning.

The gap between those two things is the entire evaluation.

This guide is for groups running multiple rooftops who need to compare dealership cybersecurity compliance services against each other on something more substantial than a capabilities deck. It assumes you already know you need help. The harder question is how to tell the providers apart.

First: separate the three things you’re actually buying

Most proposals bundle these together, which makes apples-to-apples comparison nearly impossible. Force them apart before you compare pricing.

  1. Managed IT. Help desk, endpoint management, network, servers, connectivity, hardware lifecycle, user provisioning. The stuff that keeps people working.
  2. Security operations. Endpoint detection and response, 24/7 monitoring, log collection and retention, vulnerability management, penetration testing, incident response. The stuff that catches and contains attacks.
  3. Compliance program management. The written information security program, risk assessments, Qualified Individual support, service provider oversight, employee training, evidence documentation, and the annual reporting your Safeguards Rule obligations require. The stuff that proves you did the other two.

A provider can be excellent at one and thin on the others. Many managed IT providers sell security as a checkbox and treat compliance as documentation they’ll hand you a template for. Ask each vendor to price and describe all three separately. What they can’t itemize tells you where they’re weak.

The compliance floor, and why “we handle that” isn’t an answer

Auto dealers are financial institutions under the Gramm-Leach-Bliley Act because they arrange consumer financing, which puts them squarely under the FTC Safeguards Rule. The 2021 overhaul took effect for most requirements in June 2023, and a further amendment requiring covered institutions to report certain data breaches and security incidents to the FTC took effect in May 2024.

What changed since isn’t the rule — it’s the posture. Federal attention on dealers is visibly back: in March 2026 the FTC sent warning letters to 97 dealerships, publicly naming them in May 2026. Those letters concerned advertising and pricing practices rather than data security, but they establish that dealers are a priority target. The practical read for 2026 is that “we’re working on it” has stopped being a defensible position.

So when a vendor says they handle FTC compliance, make them show the mapping. Every requirement below should trace to a named service, a named deliverable, and a named owner.

Requirement What to make them show you
Qualified Individual designated Will they serve as it, support your internal QI, or neither? Get this in writing — it’s a named accountability role, not a service line.
Written information security program A sample ISP from a comparable dealer group, not a generic template.
Written risk assessment Their methodology, cadence, and who performs it.
Access controls and MFA Coverage for all remote access and privileged accounts, including DMS and vendor portals.
Encryption in transit and at rest Including what happens to data on service drive tablets and in shared folders.
Continuous monitoring, or annual pen test plus biannual vulnerability assessment Which one they’re providing, by whom, and whether the report comes to you.
Service provider oversight Their process for assessing your DMS, CRM, and F&I vendors — not just themselves.
Incident response plan Whether it’s been tested, and how often they run tabletop exercises.
Employee security awareness training Delivery method, phishing simulation cadence, and how completion is tracked across rooftops.
Annual written report to the board or dealer principal Ask to see a redacted example.
Secure disposal of customer information Practical process, including paper deal jackets and retired hardware.

Note the threshold: groups serving fewer than 5,000 consumers get relief from several of these requirements. No multi-rooftop group qualifies. Assume every line applies to you.

The deliverable that matters most is evidence. Regulators examining a dealership after an incident are looking for documented proof that controls existed and operated — not policies in a binder. Ask each vendor directly: when we get asked to demonstrate compliance, what exactly do you hand us, and how fast? A vendor who can produce a current evidence package on demand is doing something structurally different from one who assembles it in a panic.

Dealership-specific coverage

Generic security assessments miss the dealership attack surface, because most of it doesn’t look like a corporate office. Ask how they handle:

  • DMS access and integration security. Who has DMS credentials, how third-party integrations authenticate, how vendor data pulls are inventoried, and what happens to access when an employee leaves on a Friday.
  • The third-party sprawl. A typical rooftop connects dozens of vendors to customer data — CRM, digital retailing, texting, reputation, service scheduling, inventory syndication, payroll. Ask how they inventory it and how often. Most groups cannot produce this list. That’s the finding.
  • F&I and credit applications. Where credit app data lands, who can see it, how long it persists, and whether it’s encrypted at every step.
  • The service drive and parts counter. Shared workstations, tablets, and logins used by multiple advisors and technicians. This is where “one shared password” lives.
  • Deal jackets and paper. Physical document security is in scope and is routinely ignored.
  • Guest and shop Wi-Fi segmentation. Customer lounge traffic should have no path to the DMS network. Ask them to describe the segmentation, not just confirm it exists.
  • OEM program requirements. Manufacturer data and portal access requirements vary by brand and can carry their own security terms.
  • Phishing aimed at your finance office. Wire fraud and payoff-check redirection are the losses dealers actually experience. Ask what controls they’d put around payment changes, not just email filtering.

A vendor with real dealership depth will start volunteering these before you finish the list. One without will answer each in generic IT terms.

Multi-location fit

Running five rooftops is not running one rooftop five times.

  • Standardization vs. autonomy. How do they handle a group where stores were acquired with different equipment, different vendors, and different habits? What’s their standardization roadmap and what does it cost?
  • Acquisition onboarding. If you buy a store in March, what’s the process and timeline to bring it into the security program? Get a defined playbook, not an assurance.
  • Segmentation between rooftops. A compromise at one store should not reach the others. Ask how.
  • Centralized identity and offboarding. One directory, one offboarding process, verifiable across all locations. Ask how they prove a terminated employee lost every access path, including DMS and third-party portals.
  • Consolidated visibility. A single view of posture and open issues across all stores, or five separate reports you have to reconcile?
  • Coverage hours across time zones. Dealership hours are not business hours. Saturdays are revenue days.
  • Per-store escalation. Who does a GM in your smallest store call, and what happens if they’re unhappy with the answer?

Operational fit — where most relationships actually fail

Security programs rarely fail on technology. They fail because the provider’s operating rhythm doesn’t match the dealership’s. Ask for specifics, and ask for the numbers behind them:

  • Response and resolution SLAs by severity, with actual performance data from the last 12 months — not the targets in the contract
  • What happens when the DMS is down: do they own the vendor escalation, or hand you a ticket number?
  • On-site presence — how often, and is it the same technician who knows your stores?
  • Named account team, or a rotating queue?
  • Their process during a business-hours outage in a revenue department, specifically
  • Whether their help desk staff know what an RO is

Contract terms worth reading before you’re excited about the demo

  • Term length, auto-renewal window, and notice requirements. Diary the notice date the day you sign.
  • Price escalators and what triggers them.
  • Pricing unit — per user, per device, per rooftop — and how it changes when you acquire or close a store.
  • What’s out of scope. Project work, after-hours, on-site visits, incident response hours. Incident response billed at time and materials during an active breach is a bad position to discover.
  • Documentation, configurations, credentials, and log data returned in usable form, at a defined cost. Negotiate this at signing.
  • Cyber insurance interaction. Your carrier’s application asks specific control questions. Ask the vendor to confirm in writing which of those controls they deliver — a misstatement on that application is a coverage problem, not a paperwork problem.
  • Their own security posture. They’ll have privileged access to everything you own. Ask for their SOC 2 report, their MFA and privileged access practices, and their incident history.

Red flags

  • Compliance sold as a document package with no ongoing program
  • No ability to name comparable dealer group references at your size
  • “We’ll be your Qualified Individual” offered casually, without discussing what that accountability entails
  • Security described entirely as products (a brand-name EDR, a firewall) with no operational process behind them
  • No mention of your third-party vendor ecosystem in their assessment scope
  • Unwillingness to share 12-month SLA performance data
  • A proposal that can’t be separated into managed IT, security operations, and compliance line items

Heavy truck groups: a few additions

Truck dealer environments carry considerations auto-focused providers routinely miss: mobile service technicians operating on cellular connections outside the perimeter; shop-floor and diagnostic systems that can’t be patched on a normal cadence; fleet and national account customers whose own security requirements flow down to you contractually; multi-OEM portal access, each with distinct requirements; and parts operations running on integrations built years ago that nobody has reviewed since. Ask any prospective provider to describe how they’ve handled each. Vague answers here mean they haven’t.

Run the process properly

Three practices materially improve outcomes:

  1. Send the same written question set to every vendor and compare answers side by side. Verbal capability claims are not comparable; written ones are.
  2. Take reference calls with groups of similar size and structure — and ask specifically about year two, after the onboarding team moved on.
  3. Require a paid discovery or assessment before a long-term commitment. A provider who finds real, specific issues in your environment during discovery has demonstrated something no proposal can. One who returns a generic report has also told you something.

The vendor you want is the one whose assessment makes you slightly uncomfortable, because it found things nobody else did.

In fairness: Helion is a provider in this category, so treat this as a framework rather than a neutral referee. Every question above is one we’d expect to answer — and we’d rather compete against a rigorous evaluation than a vague one.

Helion works exclusively with franchised auto and heavy truck dealerships across the US. If you’re running a vendor evaluation, or you’re not confident your current provider could produce evidence of compliance on demand, we’ll walk your environment and tell you what we find.

Sources

FTC Safeguards Rule applicability to auto dealers; breach reporting amendment effective May 2024 — ftc.gov/business-guidance/resources/automobile-dealers-ftcs-safeguards-rule-frequently-asked-questions

June 9, 2023 compliance deadline and extension history — nada.org/safeguardsrule

FTC warning letters to 97 dealerships (March 2026, disclosed May 2026) — crowell.com, “Auto Dealers: The FTC Is Back in the Driver’s Seat”

Qualified Individual role and evidence documentation expectations — forvismazars.us, “Dealerships to Comply With FTC Data Breach Safeguards”