Drowning
Resources / Blog

Dealerships Are Drowning In Security Debt

By Erik NachbahrApril 28, 2023 · 2 min read

Auto dealers – like many other businesses – are facing a serious problem when it comes to cybersecurity. They’re drowning in “security debt,” which means they have a multitude of unaddressed technical vulnerabilities that need to be addressed to protect their dealership from a cyberattack.  These unaddressed security vulnerabilities include things like unpatched software, unmanaged devices, obsolete hardware, and insecure network protocols.

The issue of security debt is becoming more and more prevalent due to the lack of qualified technical resources, and the speed at which technology changes and cyber threats evolve.  Dealers simply don’t have the resources they need to proactively stay on top of their dealership’s technical vulnerabilities.   In fact, according to the 2023 Global Cyber Confidence Index, 77% of IT decision-makers say that outdated cybersecurity practices were to blame for at least half of the incidents they experienced.  Virtually all (98%) of those surveyed believe that they’re running at least one insecure network protocol.

Businesses find that they are overburdened with the lack of qualified technical cybersecurity and IT expertise.  This is why the FTC pushed the deadline for complying with the new Safeguards Rule from December 2022 to June 2023.  Because of the lack of experienced technical resources, dealerships often deprioritize basic cybersecurity necessities.

The risk of a ransomware attack is inversely proportional to a dealership’s level of cybersecurity debt.  The inability of a dealership to effectively manage their security debt will result in downtime, financial losses, reputational damage, and legal liabilities.  These costs significantly outweigh the costs associated with securing the resources needed to proactively address security debt.  Taking a reactive approach and waiting for an attack and then addressing the technical vulnerabilities your dealership has is a mistake.

About the author

Erik Nachbahr

Founder & President, Helion Technologies

Erik Nachbahr founded Helion Technologies in 1997 and has spent nearly 30 years working exclusively with automotive and heavy truck dealerships. Helion now supports more than 2,000 dealerships and 35,000 end users with managed IT, cybersecurity, FTC Safeguards compliance, Tekion enablement, and managed AI, all under one team. A CISSP, Erik writes and speaks about the parts of dealership technology most operators inherit rather than choose: vendor sprawl, AI governance, and cyber risk. His goal is simple: make the technology work so dealerships can focus on what they do best, selling and servicing cars and heavy trucks.

Confidence in your current setup and actual protection aren't always the same thing. The only way to know which one you have is to look.

Get Your Complimentary IT & Cybersecurity Assessment →