Cybersecurity for Dealerships, Built for What Actually Gets Targeted
Layered protection for DMS access, financial data, and dealership networks, built into the same team that runs your IT.
of auto dealers experienced a cyberattack or incident in 2024
said it caused a real financial or operational hit
average downtime after an incident
The Short Answer
Cybersecurity for dealerships protects DMS access, F&I financial data, and multi-rooftop networks from the attacks dealerships actually face, most often phishing and ransomware. Helion Technologies builds this into the same accountable team that manages IT, cybersecurity, and compliance for automotive and heavy truck dealerships nationwide, backed by a security operations center staffed with live, US-based analysts.
The numbers on dealership cyberattacks aren't abstract.
35% of auto dealers experienced a cyberattack or incident in 2024, and 92% of those said it caused a real financial or operational hit. That's according to CDK Global's own State of Cybersecurity report, based on survey data from dealership personnel across the industry.
When an attack does land, the recovery isn't quick.
The report found dealerships average 3.4 weeks of downtime after an incident, and nearly a quarter never fully recover the data that was taken. Ransomware payouts have climbed with it. Coveware's data shows the average payout jumped from $44,000 in 2019 to $740,144 in 2023.
Average ransomware payout · Coveware
None of that requires a dealership to be a specific target. It just requires having a DMS full of financing data, a busy F&I office, and a staff clicking through email all day.
Managed Cybersecurity
What's Actually Protected
The DMS and the F&I office
The DMS and the F&I office are the two highest-value targets on any dealership network. Customer financial data, deal records, credit applications, financing details, and driver's license data all flow through those two systems daily. That's exactly what the FTC Safeguards Rule exists to protect, and exactly what a ransomware attack goes after first.
Multi-rooftop dealer groups
Multi-rooftop dealer groups have a different exposure profile. Multiple locations mean multiple points of entry, and one weak link at one rooftop can expose the whole group if the network isn't segmented and monitored as a single system rather than a collection of independent sites.
Email is where most attacks actually start. Phishing has ranked as the top reported threat in CDK's dealership cybersecurity research for several years running. It's also the cheapest attack to run, which is why volume is high even when the payoff per attempt is low.
A Security Operations Center That's Actually Staffed
Helion's SOC runs on live, US-based analysts watching around the clock, not an offshore queue and not a dashboard nobody's reviewing after hours.
At a time when most providers are looking to outsource this function to cut costs, keeping it US-based and staffed by real people is a deliberate choice.
Built Into Managed IT, Not a Separate Contract
Cybersecurity here isn't a bolt-on from a second vendor. It runs inside the same Managed IT relationship, monitored by the same team that handles day-to-day support. That matters because a security incident and an IT incident are usually the same event, just described by two different vendors pointing at each other.
This page is about stopping the attack.
That one's about proving to a regulator that you did.
The FTC Safeguards Rule side of this, the written security program, the risk assessments, the audit trail, lives on the Compliance page.
Go to Compliance →What 30 Years in One Industry Looks Like
The last number in that table is the industry's, not Helion's. It's there because it's the reason the other three matter.
"We're Too Small to Be a Target"
Cybercriminals don't check dealership size before running a phishing campaign. A single-rooftop dealer and a 30-store group both hold the same kind of financing data, and both show up in the same automated scans that most attacks start with. Size doesn't change the exposure. It changes how much damage spreads once something gets in.
"We already have a firewall and antivirus."
Those are two layers. CDK's own research shows dealers with active protection are still getting hit at rising rates year over year, because a firewall doesn't stop a staff member from clicking a convincing phishing email. Layered protection means monitoring, filtering, and training working together, not one tool covering everything.
"Isn't this something our internal IT person already handles?"
Sometimes, partially. Co-Managed IT adds dedicated cybersecurity monitoring alongside an existing internal hire, so security isn't one more thing squeezed into a job that's already covering five others.
"How do I know your SOC claim actually means something?"
Ask any provider making the claim whether the SOC is staffed by live analysts or automated alerts, and whether that staff is US-based or outsourced. Helion's answer to both is the stronger one.
Common Questions
Get Your Complimentary IT & Cybersecurity Assessment →How common are cyberattacks at dealerships?
What happens if a dealership does get breached?
Is cybersecurity a separate cost from managed IT?
Is the security operations center actually staffed, or mostly automated?
Does this help with FTC Safeguards compliance?
What's the most common way dealerships get attacked?
Do you work with multi-rooftop dealer groups on this?
Sources cited on this page
CDK Global, "The State of Cybersecurity for Auto Dealerships 2024," cdkglobal.com
CDK Global, "2023 State of Cybersecurity in the Dealership Study," Oct. 2023, via CDK Global media center
Coveware ransomware payout data, cited within CDK Global's 2023 report
3.4 weeks of downtime and a payout that's grown 16x since 2019 isn't a risk worth leaving to a firewall alone.
Get Your Complimentary IT & Cybersecurity Assessment →