How Your Dealership Can Strengthen Cybersecurity and Support Compliance
If your dealership collects customer financial information—and virtually every dealership does, the FTC Safeguards Rule requires you to implement a written information security program designed to protect that data. While the regulation applies nationwide, Illinois dealerships face the same cybersecurity threats, compliance expectations, and cyber insurance requirements as dealerships across the country.
The good news is that compliance isn’t about purchasing one piece of software. It’s about implementing a layered approach to cybersecurity, employee training, access controls, monitoring, and ongoing risk management.
At ACS, we help Illinois dealerships strengthen the technology and security practices that support compliance with the FTC Safeguards Rule. In this guide, we’ll explain what the rule is, why it matters, and the key cybersecurity safeguards every dealership should evaluate.
What Is the FTC Safeguards Rule?
The FTC Safeguards Rule is part of the Gramm-Leach-Bliley Act (GLBA) and requires businesses that handle customer financial information to develop, implement, and maintain a comprehensive information security program.
For automotive dealerships, that includes protecting sensitive customer information collected during activities such as:
- Vehicle financing
- Credit applications
- Lease agreements
- Customer Financial Records
- Personally identifiable information (PII)
The goal is simple: reduce the risk of unauthorized access, data breaches, and identity theft by implementing reasonable administrative, technical, and physical safeguards.
While the rule establishes security requirements, every dealership’s environment is different. Your technology, staffing, and business operations will influence how those safeguards are implemented.
Why the FTC Safeguards Rule Matters
Cybersecurity has become a business issue—not just an IT issue.
Dealerships process large amounts of sensitive customer information every day, making them attractive targets for cybercriminals.
A security incident can lead to:
- Business disruption
- Lost productivity
- Customer notification requirements
- Reputational damage
- Increased cyber insurance costs
- Regulatory scrutiny
Strong cybersecurity practices not only help support compliance but also improve operational resilience and customer trust.
FTC Safeguards Rule Cybersecurity Checklist
While every dealership’s security program should be tailored to its environment, the following safeguards are commonly considered part of a strong cybersecurity strategy.
✔ Designate Someone to Oversee Information Security
Every dealership should have an individual responsible for overseeing the information security program.
This doesn’t necessarily mean hiring a full-time security officer. Many dealerships work with internal leadership and their managed IT provider to help implement and maintain technical safeguards.
✔ Perform Regular Risk Assessments
Understanding your risks is the foundation of cybersecurity.
A risk assessment should be evaluated:
- Hardware
- Software
- User accounts
- Network security
- Remote access
- Backup systems
- Third-party vendors
Identifying vulnerabilities allows your dealership to prioritize improvements before problems occur.
✔ Implement Multi-Factor Authentication (MFA)
Passwords alone are no longer enough.
Multi-Factor Authentication adds an additional layer of protection by requiring users to verify their identity using another method, such as an authentication app or security code.
MFA is one of the most effective ways to reduce unauthorized access to business systems.
✔ Protect Endpoints
Every workstation, laptop, and server connected to your dealership network should be protected with modern endpoint security.
This typically includes:
- Endpoint Detection & Response (EDR)
- Antivirus
- Threat monitoring
- Automated response capabilities
✔ Secure Microsoft 365
Many dealerships rely on Microsoft 365 for email, file storage, and collaboration.
Protecting this environment includes:
- Multi-Factor Authentication
- Conditional Access
- Secure email filtering
- User access reviews
- Ongoing monitoring
Because Microsoft 365 often contains sensitive customer and business information, securing it should be a priority.
✔ Keep Systems Updated
Cybercriminals frequently target known software vulnerabilities.
A proactive patch management process helps ensure operating systems, applications, and security devices receive important updates in a timely manner.
✔ Backup Critical Data
Backups remain one of the most important protections against ransomware and other disasters.
Dealerships should regularly review:
- Server backups
- Microsoft 365 backups
- Recovery testing
- Disaster recovery planning
A backup is only valuable if it can be restored successfully.
✔ Train Employees
Technology alone cannot stop every cyberattack.
Employees should receive ongoing security awareness training covering topics such as:
- Phishing emails
- Password security
- Social engineering
- Safe browsing
- Suspicious attachments
Well-trained employees become an important part of your cybersecurity strategy.
✔ Limit Access to Sensitive Information
Not every employee needs access to every system.
User permissions should follow the principle of least privilege, giving employees access only to the information necessary to perform their jobs.
Regular reviews help ensure former employees and outdated accounts are removed promptly.
✔ Develop an Incident Response Plan
No organization can eliminate every risk.
Having a documented plan helps your dealership respond more effectively if a cybersecurity incident occurs.
An incident response plan should outline:
- Who to contact
- Steps to contain the incident
- Communication procedures
- Recovery priorities
How ACS Helps Dealerships Strengthen Security
The FTC Safeguards Rule isn’t about installing one product—it’s about maintaining an ongoing security program.
ACS helps dealerships support these efforts by providing:
- Managed IT Services
- Cybersecurity Solutions
- Microsoft 365 Management
- Endpoint Protection
- Multi-Factor Authentication
- Backup & Disaster Recovery
- Security Awareness Training
- Patch Management
- Technology Vendor Management
Our team works proactively to reduce risk while helping dealerships maintain reliable technology environments that support day-to-day operations.
Common Cybersecurity Mistakes We See
Over the years, we’ve observed several recurring challenges that increase risk for dealerships:
- Weak or reused passwords
- Missing Multi-Factor Authentication
- Outdated operating systems
- Inconsistent patch management
- Lack of employee security training
- Inadequate backup testing
- Too many users with administrative privileges
- Assuming software vendors are responsible for overall cybersecurity
Addressing these issues proactively can significantly improve your dealership’s security posture.
ACS Insight: Compliance is not a one-time project. Cybersecurity requires continuous monitoring, regular updates, employee education, and periodic reviews to keep pace with evolving threats and changing business needs.
Customer Success Story
For Deborah Blake, Owner of Tyson Motor Chrysler Jeep Dodge Ram, partnering with ACS provided confidence that the dealership’s technology was helping protect its business while supporting compliance requirements.
“Signing up for your managed IT services has given us peace of mind by protecting our cyber weaknesses. Your expert services keep us compliant with federal and state rules, which is crucial for us. Plus, your support helps us easily meet insurance requirements.
Your fast response and personalized care set you apart from other IT firms we’ve used. The attention to detail and custom approach boosts our IT efficiency.
You provide great customer service with a team that’s honest and trustworthy. Your dedication makes you the best choice for dependable IT services.”
— Deborah Blake, Owner, Tyson Motor Chrysler Jeep Dodge Ram
This testimonial reflects the outcomes many dealerships are looking for: stronger cybersecurity, responsive support, assistance meeting compliance expectations, and a trusted technology partner.
Frequently Asked Questions
Does every dealership have to comply with the FTC Safeguards Rule?
Many dealerships that collect customer financial information are subject to the FTC Safeguards Rule. Because every business is different, it’s important to understand how the regulation applies to your dealership and seek legal or compliance guidance when necessary.
Does Microsoft 365 make my dealership compliant?
No. Microsoft 365 is a powerful platform, but compliance depends on how it’s configured, managed, and integrated into your overall information security program.
Is Multi-Factor Authentication required?
Multi-Factor Authentication is widely recognized as an important security control and can significantly reduce the risk of unauthorized access. It should be part of a broader cybersecurity strategy.
Can a Managed IT provider help with compliance?
Yes. While an MSP does not provide legal advice, an experienced provider can implement and manage many of the technical safeguards that support your dealership’s information security program.
What happens if my dealership experiences a cyberattack?
The impact depends on the nature of the incident. A documented incident response plan, tested backups, and proactive security measures can help reduce downtime and support recovery.
Final Thoughts
The FTC Safeguards Rule is about protecting your customers, your employees, and your dealership. Compliance isn’t achieved through a single technology purchase—it’s built through a comprehensive information security program supported by strong cybersecurity practices and ongoing management.
At ACS, we help Illinois dealerships strengthen the technology that supports these efforts through proactive managed IT services, cybersecurity, Microsoft 365 management, backup and disaster recovery, and technology vendor management.
If you’re unsure whether your current technology environment is supporting your dealership’s security goals, contact ACS to schedule a technology assessment. We’ll help you identify opportunities to strengthen your cybersecurity posture and build a more resilient IT environment.
