Most dealers don’t shop for IT support until something breaks. The DMS goes down on the last Saturday of the month. A phishing email costs the store six figures. An insurance carrier asks for a written information security program and nobody has one.

By then the decision is being made under pressure, and pressure produces bad contracts.

The better approach is to evaluate managed IT services for dealerships the same way you’d evaluate any other operational partner: against a defined set of criteria, before you need them. This guide lays out the five criteria that actually separate providers in this vertical, the questions that surface real answers, and the warning signs worth walking away from.

Why Generic IT Support Fails in a Dealership

A dealership is not a 60-person professional services firm that happens to sell cars. The operating environment is genuinely different in ways that break the standard managed services playbook:

  • Revenue is concentrated in narrow windows. An hour of downtime on a Tuesday morning is an inconvenience. An hour of downtime during the last three days of the month is deals that don’t get delivered.
  • The application stack is unusual and interdependent. DMS, CRM, desking, equity mining, service scheduling, telephony, digital retailing, OEM portals, dealer management integrations — most of it vendor-hosted, much of it talking to everything else.
  • You are a high-value target. Dealerships hold NPI on thousands of consumers, move large sums of money by wire, and historically underinvest in security relative to that risk profile.
  • You are federally regulated. The FTC Safeguards Rule applies to you as a financial institution. Most generalist providers have never read it.
  • Departments have different tolerances. Service advisors, techs on tablets in the shop, F&I, BDC, and the sales floor all have distinct uptime and access requirements.

A provider whose reference accounts are law firms and medical practices can absolutely keep your workstations patched. What they typically cannot do is tell you why the DMS integration to your CRM broke, or defend your security program during an OEM audit or a carrier’s cyber underwriting review.

That gap is what the following five criteria are designed to find.

Criterion 1: Dealership-Specific Support Depth

Start here, because it’s the criterion most easily faked in a sales meeting and most quickly exposed in production.

What you’re actually evaluating: whether the provider’s technicians can resolve dealership problems without treating your store as a training exercise.

Questions that surface real answers:

  • How many franchised rooftops do you currently support, and what percentage of your total client base is automotive?
  • Which DMS platforms have your technicians worked in directly? Ask them to name the specific platforms — CDK, Reynolds and Reynolds, Tekion, Dealertrack, PBS, Auto/Mate — and describe a recent issue they resolved in each.
  • Do you hold any DMS or OEM partner certifications?
  • When a DMS vendor and a network issue point fingers at each other, who owns the resolution?
  • Walk me through how you’d handle a dealership acquisition, from due diligence through cutover.
  • What’s your understanding of how our OEM’s dealer infrastructure requirements affect our network design?

What good looks like: a provider who can describe the difference between a DMS-side problem and a network-side problem before you finish the sentence, who has documented runbooks for common dealership scenarios, and whose technicians have supported stores long enough to know that “the printer isn’t working” during month-end is a priority-one ticket.

What to be skeptical of: vertical claims backed by two or three accounts, or a provider who describes automotive as one of eight or nine “industries served.” Depth is what you’re buying. Breadth is what makes it expensive to acquire.

Criterion 2: Cybersecurity Alignment

Dealerships have moved firmly into the crosshairs. Ransomware groups have learned that stores can’t operate offline for long, which makes them likely to pay. Business email compromise targeting wire transfers is now routine. And a single compromised credential in a dealer group with shared infrastructure can expose every rooftop.

What you’re actually evaluating: whether security is an integrated part of the service or a line item that gets sold to you later.

Baseline controls a serious provider includes or requires:

  • Multi-factor authentication across email, remote access, and administrative accounts — with no permanent exceptions for executives
  • Endpoint detection and response (EDR) with 24/7 monitoring, not signature-based antivirus
  • Immutable, tested backups with documented recovery time objectives — and evidence of actual restore tests, not just successful backup jobs
  • Email security tuned for the impersonation and wire fraud patterns that hit dealerships specifically
  • Privileged access management and least-privilege administrative rights
  • Ongoing security awareness training with simulated phishing, reported by department
  • A written incident response plan naming who calls whom, including your cyber carrier and counsel
  • Vendor and third-party access controls, since a meaningful share of dealership breaches arrive through an integration partner

Questions that surface real answers:

  • Is your security operations monitoring in-house or subcontracted? If subcontracted, to whom?
  • What’s your average detection-to-containment time, and how do you measure it?
  • Have you managed a dealership through an actual incident? What happened, and what did you learn?
  • Which of these controls are included in the base agreement, and which are add-ons?

What to be skeptical of: a proposal where the monthly rate looks competitive because EDR, backup validation, email security, and awareness training are all optional modules. Price the security stack you actually need, then compare.

Criterion 3: Compliance Readiness

The FTC Safeguards Rule treats dealerships as financial institutions. That means a written information security program, a designated qualified individual, documented risk assessments, encryption of customer NPI at rest and in transit, MFA, service provider oversight, an incident response plan, and an annual written report to your board or governing body.

Enforcement is real, and the exposure isn’t limited to the FTC — carriers ask about it during underwriting, OEMs increasingly ask about it during audits, and plaintiffs’ attorneys ask about it after a breach.

What you’re actually evaluating: whether the provider can produce evidence, not just controls.

Questions that surface real answers:

  • Can you serve as, or directly support, our qualified individual under the Safeguards Rule?
  • What documentation do you produce and maintain — risk assessments, WISP, policies, annual reports?
  • How do you handle the service provider oversight requirement for our other vendors?
  • If our OEM or cyber carrier requests evidence of our security program next week, what can you hand us?
  • How do you keep us current as state privacy laws expand?

What good looks like: a provider who treats compliance as a deliverable with artifacts and review cycles, not as a byproduct of good hygiene. Good technical controls with no documentation still fail an audit.

What to be skeptical of: “We’ll make you compliant.” Compliance is an ongoing program that you own; the right provider operates and documents it with you.

Criterion 4: Multi-Rooftop Scalability

Even single-store dealers should evaluate this criterion. Groups acquire. If you’re the store being acquired, or the store doing the acquiring, the provider’s ability to scale determines whether integration takes six weeks or six months.

What you’re actually evaluating: whether the provider has an operating model for groups or just more technicians.

Questions that surface real answers:

  • How many multi-rooftop groups do you support, and what’s the largest?
  • How do you standardize across stores that joined with different DMS platforms, different vendors, and different network gear?
  • Can you support centralized identity and access management across rooftops while keeping appropriate separation?
  • What does your acquisition playbook look like? How fast can you onboard a newly acquired store?
  • How do you handle consolidated reporting and per-rooftop cost allocation?
  • What’s your approach to inter-rooftop connectivity and network segmentation?

What good looks like: documented standards, a repeatable onboarding process, and reporting that lets a group CFO see cost and risk by store. Segmentation matters here — a group where every rooftop sits on flat, shared infrastructure has converted a single-store incident into a group-wide one.

What to be skeptical of: a provider whose scale story is entirely about headcount. Standardization is what makes groups efficient.

Criterion 5: Service Accountability

Every provider promises responsiveness. Very few will put meaningful numbers in the contract.

What you’re actually evaluating: whether performance is measurable and whether there are consequences.

Contract terms worth negotiating:

  • Response versus resolution. A one-hour response SLA means someone acknowledges your ticket. Ask for resolution targets by severity, and ask how severity is assigned — and by whom.
  • Month-end and Saturday coverage. Dealership hours are not business hours. Confirm coverage windows explicitly, including holidays and your busiest selling days.
  • Onsite response. For a store, remote-only support has limits. What’s the committed onsite timeframe, and from where?
  • Escalation path. Who do you call when the ticket stalls? Name and number, in the agreement.
  • Reporting cadence. Monthly metrics on tickets, response times, patch compliance, backup success, and security events. Quarterly business reviews with your leadership, not just your controller.
  • Staffing ratios. Ask how many endpoints and how many stores each technician supports.
  • Term and exit. How long is the initial term? What are the termination provisions? Most importantly: at termination, do you get full documentation, credentials, and configuration data — and is that spelled out?

What to be skeptical of: a provider unwilling to put SLAs in writing, or one whose contract makes your documentation and administrative credentials their property.

Warning Signs Worth Walking Away From

  • No named dealership references you can call directly
  • Security presented as an upsell rather than a baseline
  • No familiarity with the Safeguards Rule’s specific requirements
  • Unwillingness to commit to written SLAs or provide historical performance data
  • Contract language that restricts your access to your own documentation or credentials
  • Pricing well below market for the described scope — it usually means the scope is narrower than it appears
  • A discovery process that never asks about your DMS, your OEM requirements, or your month-end workflow

How to Run the Evaluation

  1. Document your current state. Rooftops, endpoints, users, DMS and core applications, existing vendors and contract end dates, known pain points.
  2. Define requirements against the five criteria above before you take sales meetings. Write them down.
  3. Shortlist three providers with genuine automotive depth. More than three and the comparison gets noisy.
  4. Score each on all five criteria, weighted for your situation — a 12-rooftop group should weight scalability heavily; a single store facing a carrier renewal should weight compliance.
  5. Call the references, and call the ones they didn’t give you. Ask other dealers in your 20 Group.
  6. Negotiate the SLA and exit terms before signing, not at renewal.
  7. Plan the transition. Ask each finalist for a written 90-day onboarding plan, and evaluate it as part of the decision.

The Bottom Line

The right IT partner for a dealership is not the one with the lowest monthly rate or the most impressive certifications on the wall. It’s the one whose technicians have solved your specific problems before, whose security program stands up to a carrier’s questions, whose compliance documentation survives an audit, whose operating model scales with your acquisitions, and whose contract makes performance measurable.

Evaluate on those five criteria and the field narrows quickly — which is exactly the point.


Helion Technologies has supported franchised automotive and heavy truck dealerships exclusively since 1997, with managed IT, cybersecurity, and FTC Safeguards compliance services delivered from operations in Baltimore and Dallas–Fort Worth. If you’re evaluating providers, we’re happy to walk through the framework above against your current environment.