Compliance for Dealerships
FTC Safeguards Compliance for Dealerships, Built Into IT and Cybersecurity
Continuous compliance monitoring instead of a once-a-year audit scramble.
FTC notification clock
FTC Safeguards compliance for dealerships means meeting the nine required elements of the FTC's Safeguards Rule, which treats dealerships as financial institutions under the Gramm-Leach-Bliley Act. Helion Technologies builds this into the same team that manages IT and cybersecurity, using proprietary tools and annual human-led penetration testing, so compliance runs continuously instead of getting handled once a year.
Dealerships that have a compliance vendor aren't always getting compliance. They're getting a product.
Nobody does.
A line item on an invoice, maybe a checklist, maybe a portal with a score in it, and the expectation that someone on their team is going to do something with it.
The dealership doesn't have a compliance team. That's the whole reason they bought the product in the first place. So the checklist sits there, the portal goes unlogged, and the monthly fee keeps clearing, while the actual work of identifying gaps, testing systems, rating vendors, and closing vulnerabilities never gets done.
That's not a knock on any specific vendor. It's how compliance products in this space are typically built, because doing the actual work is hard, requires real people, and costs more than a $650 monthly line item can cover.
Helion's approach is different. The compliance program is fully managed, which means Helion's team does the work, not yours.
Continuous Compliance
The Difference Between a Binder and a System
Compliance handled once a year is a snapshot. A risk assessment done in January says nothing about a vendor added in March or a new employee with access in July. Continuous compliance means the same team running Managed IT and Cybersecurity keeps the compliance posture current as things change, rather than reconstructing it from scratch every twelve months.
Here's what that system actually does.
A proprietary tool runs directly against a dealership's own PCs and servers, scanning for:
That data feeds directly to Helion's compliance team, who run it against checklists built from the actual regulatory requirements.
A report with real action items, not a generic list of what's missing.
Human penetration testing
Performed by people, not an automated scan mislabeled as a pen test.
Vulnerability monitoring
Semi-annual vulnerability monitoring in between annual pen tests.
Vendor risk rating
Evaluating the security posture of every third-party vendor already connected to a dealership's systems, a step most compliance offerings in this space skip entirely.
It's completely managed, and built on Helion's own custom software, custom reporting, and API connections into the systems it monitors, not a resold third-party tool with Helion's logo on it.
Pen Test Finding
What That Actually Looks Like in Practice
That's the difference between a report that flags a risk and a team that actually closes it.
The Nine Required Elements
The FTC's amended Safeguards Rule (16 CFR Part 314) requires every covered dealership's information security program to include:
Qualified Individual
A designated person overseeing the entire program, accountable to leadership
Written risk assessment
Documented inventory of where customer data lives and what threatens it
Safeguards design
Controls built to address the risks identified
Access controls
Limits on who can reach customer data and systems
Encryption
Data protected at rest and in transit
Multi-factor authentication
Required on systems accessing customer information
Monitoring and testing
Ongoing verification that safeguards are actually working
Vendor oversight
Ensuring service providers meet the same security standard
Incident response plan
A documented plan for responding to and recovering from a security event
Source: Federal Trade Commission, Safeguards Rule FAQ for Automobile Dealers
New Compliance Surface
AI Governance & Compliance
Dealerships adopting AI tools — for service scheduling, F&I workflows, lead follow-up, or internal drafting — are creating a new compliance surface the original Safeguards Rule didn't anticipate. California's ADMT regulations, effective January 2026, add another layer for any dealership using automated decision-making in financing or credit decisions.
Helion extends its Continuous Compliance model to cover AI tool adoption as part of the same program. That means:
Not a separate AI compliance vendor. The same team, the same program.
Learn more about Managed AI for Dealerships →What 2,000+ Dealerships and 30 Years Looks Like
"We Already Did a Compliance Audit Last Year"
An audit is a moment in time. The Rule requires ongoing monitoring and testing, not a once-a-year checkbox. If nothing has been reviewed since that audit, whatever passed then may not reflect what's actually running today.
"We already have a compliance vendor."
Worth asking what that vendor actually does day to day. A lot of compliance products generate documentation without connecting to the IT and cybersecurity systems the documentation is supposed to describe, and a vague monthly line item on an invoice doesn't tell you which one you're paying for. If the vendor isn't the same team running monitoring and security, there's a gap between what's on paper and what's actually protected.
"Isn't this mostly a fine risk we can manage if it happens?"
The bigger cost usually isn't the fine. It's the downtime and recovery that come with an actual security event, which is a cybersecurity problem before it's ever a compliance one.
Common Questions
Does the FTC Safeguards Rule actually apply to my dealership?
What happens if we have a breach?
Who can serve as our Qualified Individual?
Is compliance a separate service from managed IT and cybersecurity?
Does compliance work include real penetration testing?
Does this include rating the security of our third-party vendors?
Does this cover AI tools we're starting to use?
We already have a WISP. What does Helion add?
The FTC's 30-day breach notification clock doesn't wait for the next scheduled audit.
Get Your Complimentary IT & Cybersecurity Assessment →