Cybersecurity for Dealerships

Cybersecurity for Dealerships, Built for What Actually Gets Targeted

Layered protection for DMS access, financial data, and dealership networks, built into the same team that runs your IT.

State of Cybersecurity · CDK Global
35%

of auto dealers experienced a cyberattack or incident in 2024

92%

said it caused a real financial or operational hit

3.4 wks

average downtime after an incident

The Short Answer

Cybersecurity for dealerships protects DMS access, F&I financial data, and multi-rooftop networks from the attacks dealerships actually face, most often phishing and ransomware. Helion Technologies builds this into the same accountable team that manages IT, cybersecurity, and compliance for automotive and heavy truck dealerships nationwide, backed by a security operations center staffed with live, US-based analysts.

The numbers on dealership cyberattacks aren't abstract.

35% of auto dealers experienced a cyberattack or incident in 2024, and 92% of those said it caused a real financial or operational hit. That's according to CDK Global's own State of Cybersecurity report, based on survey data from dealership personnel across the industry.

35 of every 100 auto dealers hit in 2024

When an attack does land, the recovery isn't quick.

The report found dealerships average 3.4 weeks of downtime after an incident, and nearly a quarter never fully recover the data that was taken. Ransomware payouts have climbed with it. Coveware's data shows the average payout jumped from $44,000 in 2019 to $740,144 in 2023.

$44,000
$740,144
2019 2023

Average ransomware payout · Coveware

None of that requires a dealership to be a specific target. It just requires having a DMS full of financing data, a busy F&I office, and a staff clicking through email all day.

Managed Cybersecurity

What's Actually Protected

The DMS and the F&I office

The DMS and the F&I office are the two highest-value targets on any dealership network. Customer financial data, deal records, credit applications, financing details, and driver's license data all flow through those two systems daily. That's exactly what the FTC Safeguards Rule exists to protect, and exactly what a ransomware attack goes after first.

Customer financial data Deal records Credit applications Financing details Driver's license data

Multi-rooftop dealer groups

Multi-rooftop dealer groups have a different exposure profile. Multiple locations mean multiple points of entry, and one weak link at one rooftop can expose the whole group if the network isn't segmented and monitored as a single system rather than a collection of independent sites.

Email

Email is where most attacks actually start. Phishing has ranked as the top reported threat in CDK's dealership cybersecurity research for several years running. It's also the cheapest attack to run, which is why volume is high even when the payoff per attempt is low.

Live · US-Based · Around the Clock

A Security Operations Center That's Actually Staffed

Helion's SOC runs on live, US-based analysts watching around the clock, not an offshore queue and not a dashboard nobody's reviewing after hours.

At a time when most providers are looking to outsource this function to cut costs, keeping it US-based and staffed by real people is a deliberate choice.

Built Into Managed IT, Not a Separate Contract

Cybersecurity here isn't a bolt-on from a second vendor. It runs inside the same Managed IT relationship, monitored by the same team that handles day-to-day support. That matters because a security incident and an IT incident are usually the same event, just described by two different vendors pointing at each other.

This page

This page is about stopping the attack.

Compliance page

That one's about proving to a regulator that you did.

The FTC Safeguards Rule side of this, the written security program, the risk assessments, the audit trail, lives on the Compliance page.

Go to Compliance →

What 30 Years in One Industry Looks Like

98% Client retention rate
82 sec Average time to reach a support agent during an incident
2,000+ Dealerships under management nationwide
35% Of dealers hit by a cyberattack or incident in 2024 (CDK Global)

The last number in that table is the industry's, not Helion's. It's there because it's the reason the other three matter.

"We're Too Small to Be a Target"

Cybercriminals don't check dealership size before running a phishing campaign. A single-rooftop dealer and a 30-store group both hold the same kind of financing data, and both show up in the same automated scans that most attacks start with. Size doesn't change the exposure. It changes how much damage spreads once something gets in.

“

"We already have a firewall and antivirus."

Those are two layers. CDK's own research shows dealers with active protection are still getting hit at rising rates year over year, because a firewall doesn't stop a staff member from clicking a convincing phishing email. Layered protection means monitoring, filtering, and training working together, not one tool covering everything.

“

"Isn't this something our internal IT person already handles?"

Sometimes, partially. Co-Managed IT adds dedicated cybersecurity monitoring alongside an existing internal hire, so security isn't one more thing squeezed into a job that's already covering five others.

“

"How do I know your SOC claim actually means something?"

Ask any provider making the claim whether the SOC is staffed by live analysts or automated alerts, and whether that staff is US-based or outsourced. Helion's answer to both is the stronger one.

How common are cyberattacks at dealerships?
35% of dealers reported experiencing a cyberattack or incident in 2024, according to CDK Global's State of Cybersecurity report.
What happens if a dealership does get breached?
Recovery averages 3.4 weeks of downtime, per CDK's 2023 report, and close to a quarter of affected dealers never fully recover the stolen data.
Is cybersecurity a separate cost from managed IT?
No. It runs as one system with managed IT rather than a second contract with a second vendor.
Is the security operations center actually staffed, or mostly automated?
Staffed. Helion's SOC runs on live, US-based analysts monitoring around the clock, not an automated alert system with no one reviewing it after hours.
Does this help with FTC Safeguards compliance?
It supports it directly, since the two are connected in practice. The compliance-specific requirements live on the Compliance page.
What's the most common way dealerships get attacked?
Phishing has ranked as the top threat in CDK's dealership research for multiple years running.
Do you work with multi-rooftop dealer groups on this?
Yes. Network segmentation and monitoring across multiple locations is part of how this is built for dealer groups specifically.

Sources cited on this page

CDK Global, "The State of Cybersecurity for Auto Dealerships 2024," cdkglobal.com

CDK Global, "2023 State of Cybersecurity in the Dealership Study," Oct. 2023, via CDK Global media center

Coveware ransomware payout data, cited within CDK Global's 2023 report

16x Ransomware payout growth since 2019

3.4 weeks of downtime and a payout that's grown 16x since 2019 isn't a risk worth leaving to a firewall alone.

Get Your Complimentary IT & Cybersecurity Assessment →