Report Dealership cybersecurity

The State of Dealership Cybersecurity

Published By Helion Technologies · 7 min read

Key takeaways

Automotive and heavy-truck dealerships are prime targets for cyberattacks because they keep customer, financing and employee data in one place. This February 2020 report from Helion Technologies explains why attackers go after dealers, what a breach can cost and how to prepare.

A dealership’s CRM, F&I records and staff logins make it a valuable target, and one phishing email can open the door.
A breach costs time and money to fix, and it can damage the reputation customers rely on when they choose a dealer.
Under state privacy laws, a breach can also lead to fines or lawsuits, and baseline security controls help a dealership prepare.

Many dealers still underestimate how exposed their stores are.

Some still treat cybersecurity as one more expense to control, and that is a costly mistake. Cybersecurity is a core business practice, and it matters more for dealerships each year as attacks become more common.

Cybercrime at a Glance

The figures below come from studies published between 2016 and 2019. Each one names its source and year, and together they describe the threat picture when this report was published in February 2020.

11 secA 2019 forecast predicted that ransomware would attack a business every 11 seconds by the end of 2021.
Source: Cybersecurity Ventures, Official Annual Cybercrime Report (sponsored by Herjavec Group), 2019
91%of cyberattacks start with a phishing email.
Source: Dark Reading, reporting PhishMe research, 2016
71%of ransomware attacks in 2018 targeted small and medium-size businesses.
Source: Beazley, Beazley Breach Briefing, 2019
$3.92Mwas the average cost of a data breach.
Source: IBM Security and Ponemon Institute, Cost of a Data Breach Report, 2019
25,575records were involved in the average data breach.
Source: IBM Security and Ponemon Institute, Cost of a Data Breach Report, 2019
2ndTransportation was the second-most targeted industry in 2018.
Source: IBM X-Force Threat Intelligence Index, 2019

Why Do Cybercriminals Target Dealerships?

Think about the data a dealership collects and stores every day: customer names, addresses, email addresses and phone numbers in the CRM; bank details and Social Security numbers gathered in F&I; and employees’ usernames and passwords.

Daily operations require a dealership to hold private information for thousands, often tens of thousands, of customers and employees. That makes it a data goldmine for criminals, and sometimes a single phishing email is all it takes to get in. Helion’s post on the anatomy of a phishing attack walks through two real incidents at dealerships.

Who Is Behind the Attacks?

Picture a cyberattack and you may imagine a bored teenager breaking into a server for fun. That picture badly underestimates the people dealerships are up against.

Most of today’s attackers work for large multinational crime organizations, and some of those groups are state-sponsored. The work pays well enough to draw smart, technically skilled people from around the world, and the pay grows with experience. Helion’s post on who cybercriminals are looks at the people behind the attacks and what drives them.

Many dealerships are still not doing nearly enough to protect themselves. Rather than investing in stronger security controls and policies, some ignore the problem and hope for the best. As long as cybersecurity is treated only as an expense to control, the business stays exposed.

How Can a Breach Affect a Dealer’s Reputation?

A breach costs time and money, because it takes real resources to respond to an attack and recover from it. It also puts something harder to rebuild at risk: the dealership’s reputation.

Most dealerships sell the same vehicles at similar prices, so reputation is one of the few things that sets one store apart from another. Customers notice when their data is exposed.

84%

of consumers said they would not buy another car from a dealership after their data had been compromised.

Source: Total Dealer Compliance survey, via Auto Remarketing, 2016

News of a breach travels fast. Between online reviews and social media, customers talk to each other more quickly than ever, and a dealer’s reputation can take a lasting hit. Helion’s post on how a data breach could sink a dealership looks at that risk in more detail.

An attack is not a crisis that ends once the systems are restored. Its effect on a dealership’s bottom line can last for years.

How Do Privacy Laws Raise the Stakes?

Time, money and reputation are not the only things a breach puts at stake. Under new consumer data privacy laws, a breach can also bring legal trouble, including fines or lawsuits.

California’s CCPA, New York’s SHIELD Act and Ohio’s Data Protection Act had already passed when this report was published, and a federal consumer privacy law was under discussion.

25+

states, plus Puerto Rico, saw consumer data privacy bills introduced in 2019.

Source: National Conference of State Legislatures, 2019

Many of these laws ask for similar things, including baseline security controls. Putting those controls in place now helps a dealership prepare for new and changing rules.

How Should a Dealership Prepare?

Lowering the risk of a breach and protecting a dealership’s reputation both start with sound security practices. A dealership can begin with the basics on its own:

1.Train your people. Staff who can spot a phishing email close off one of the most common ways in.
2.Secure your network. Review hardware and software, limit administrative access and watch for vulnerabilities. Helion’s tips for preventing a data breach cover these steps.
3.Market with care. Follow sound practices for the customer data that digital marketing collects.

Those steps lower the risk, but they are only a start. Defining and running dealership security well takes people trained and certified in cybersecurity, and in many dealerships IT security falls to someone who is neither.

30%of dealers employed a network engineer with computer security certifications or training.
25%of dealers had hired an outside firm to test their networks for vulnerabilities.
70%+of dealers were not up to date on their antivirus software.
Source: Total Dealer Compliance survey, via Auto Remarketing, 2016

One breach could sink a dealership, so trusting its systems and data to someone without that expertise is a risk it does not need to take. Putting IT security best practices in place takes a team that knows both data security and the business of selling and servicing cars and trucks.

Many dealerships keep their own IT staff for on-site and hardware work and add Helion for depth, such as advanced cybersecurity monitoring and extra technical resources. The dealership cybersecurity page has more.

Common Questions

What dealership data do cybercriminals want?
Helion Technologies points to three kinds of data that make dealerships attractive to attackers: customer contact details in the CRM, bank and Social Security information collected in F&I, and employees’ usernames and passwords. A dealership holds this data for thousands of customers and staff, so a single successful phishing email can expose a great deal. That is why dealership security has to cover people and email as well as systems.
Are small dealerships at risk, or only large dealer groups?
Helion Technologies treats every dealership as a potential target, whatever its size. Attackers look for valuable data and weak defenses, and in 2018 small and medium-size businesses drew a large share of ransomware attacks. A single-rooftop store holds the same kinds of customer and financing data as a large dealer group, and it may have fewer people watching its systems, which can make it easier to break into.
How does a data breach hurt a dealership beyond the cost of recovery?
Helion Technologies points to reputation as a cost that lasts well beyond the recovery. Most dealerships sell the same vehicles at similar prices, so reputation is one of the few things that sets a store apart, and customers who learn their data was exposed may take their business elsewhere. Word spreads quickly through online reviews and social media, and the effect on sales can last for years.
Do state privacy laws apply to car dealerships?
They can. Dealerships collect personal and financial information from consumers, and state laws such as California’s CCPA and New York’s SHIELD Act set rules for protecting that kind of information and for what happens after a breach. Depending on the law, a breach can lead to fines or lawsuits. Many of these laws expect similar baseline security controls, and legal counsel can confirm which laws apply to a given dealership.
What security basics should every dealership have in place?
Helion Technologies recommends starting with three basics: training staff to recognize phishing, securing the network by reviewing hardware and software and limiting administrative access, and handling customer data carefully in digital marketing. These steps lower the risk but do not replace cybersecurity expertise. Many dealerships keep their own IT staff for on-site and hardware work and add Helion for depth, such as advanced cybersecurity monitoring.
Are the statistics in this report still current?
Helion Technologies published this report in February 2020, and its figures come from studies released between 2016 and 2019. Each figure on the page names its source and year so it can be read in context. The figures describe the threat picture at that time, and more recent studies may report different numbers. The report’s main points do not depend on any single figure.

About Helion

Helion Technologies

Helion Technologies has worked exclusively with automotive and heavy-truck dealerships for nearly 30 years. Founded in 1997 and based in Baltimore, Maryland, it supports more than 2,000 dealerships and 35,000 end users with managed IT, cybersecurity, Tekion enablement, DMS transition support and managed AI. Its founder, Erik Nachbahr, is a CISSP.

Complimentary assessment

Is Your Dealership Secure?

Helion’s complimentary IT and cybersecurity assessment gives better insight into your dealership’s cybersecurity posture and information on how to strengthen its defenses. Request one and a Helion representative contacts you to schedule it.

Prefer to talk first? Call (443) 541-1500.