Running an independent auto dealership means wearing a lot of hats.
You are selling vehicles, managing inventory, working with lenders, dealing with customers, managing employees, negotiating with vendors, watching cash flow, and trying to keep the business moving.
Cybersecurity and regulatory compliance can easily end up somewhere near the bottom of the list.
Until something happens.
- A phishing attack.
- A former employee still has access to the system.
- A laptop goes missing.
- A vendor has a security problem.
- Someone asks to see your Written Information Security Program.
Suddenly, the question changes from:
"Are we doing enough?"
to:
"Can we prove what we're doing?"
The FTC's Safeguards Rule generally applies to most automobile dealers that finance or lease automobiles. Covered dealers are expected to develop, implement, and maintain a comprehensive written information security program designed to protect customer information.
The good news is that compliance doesn't have to be complicated.
But there are some mistakes that independent dealers should avoid. Here are seven of the most common ones.
Mistake #1: Thinking "Our IT Company Handles It"
This is probably one of the easiest mistakes to make.
A dealership has an MSP. They manage the firewall, install antivirus software, maintain backups, set up MFA, and monitor computers. So the dealer assumes: "We're covered."
Not necessarily.
Your IT provider may be doing a very good job protecting your technology, but the FTC Safeguards Rule is broader than technology alone. A covered dealership needs a comprehensive information security program that addresses administrative, technical, and physical safeguards — one that's maintained and updated as the dealership's risks and circumstances change.
That means someone needs to understand what customer information the dealership has, where it's stored, who can access it, what the risks are, what safeguards are being used, how employees are trained, how vendors are managed, how incidents are handled, and how compliance activities are documented.
Your IT company may be an important part of that program. But having an IT company isn't the same thing as having an FTC compliance program.
What to do instead: Make sure your dealership has a clearly defined information security program and a designated person responsible for overseeing it. The FTC calls this person the Qualified Individual.
Mistake #2: Creating a WISP and Then Forgetting About It
A dealership finally creates a Written Information Security Program. Everyone is relieved. The document gets signed. Someone saves it to a folder. And then nobody looks at it again.
A year passes. Then another year. Meanwhile: the dealership changed its CRM, a new DMS was introduced, three employees left, six new employees were hired, the dealership started using a new cloud application, a new MSP was brought in, and the dealership added another location.
But the WISP still describes the business as it existed two years ago. That's a problem.
The FTC says covered financial institutions need to maintain their information security programs and make adjustments based on monitoring, testing, risk assessments, vulnerabilities, and material changes to the business.
A WISP shouldn't be a static document. It should be a living program.
What to do instead: Review the WISP regularly and update it when something meaningful changes in your dealership. A change in technology, personnel, vendors, locations, or risk can be a reason to revisit the program.
Mistake #3: Doing a Risk Assessment Once — or Not at All
Some dealerships have never completed a formal risk assessment. Others completed one several years ago and assume they're finished. Neither approach is ideal.
Your dealership's risk environment changes constantly. A new employee can introduce a new risk. A new vendor can introduce a new risk. A new software platform can introduce a new risk. A new cyber threat can introduce a new risk.
The FTC says the information security program should be based on a written risk assessment identifying reasonably foreseeable internal and external risks to customer information and evaluating the safeguards already in place. The risks and safeguards should also be periodically reassessed.
A useful risk assessment should answer questions such as: What could go wrong? How likely is it? What would happen if it did? What controls do we have? Where are the gaps? Who is responsible for fixing them?
That's much more useful than simply checking a box that says "Risk Assessment: Complete."
What to do instead: Treat your risk assessment as a management tool. Identify the risks, rank them, assign responsibility, establish remediation steps, and revisit the assessment as your dealership changes.
Mistake #4: Focusing on Technology but Ignoring Employees
You can have excellent cybersecurity technology and still have a security problem. Why? Because your employees interact with customer information every day.
An employee can click a phishing link, send a document to the wrong person, leave a laptop unattended, use a weak password, share credentials, download sensitive information to an unsecured device, fall for social engineering, or accidentally expose customer information.
That's why employee security awareness matters. The FTC's Safeguards Rule specifically addresses security awareness training for personnel and specialized training for individuals responsible for implementing the information security program.
And here's another common problem: the dealership provides training but doesn't keep good records. If you can't demonstrate who completed training, when they completed it, and what they were trained on, your program becomes harder to demonstrate.
What to do instead: Make security awareness training part of your dealership's regular operations. And keep the evidence. Training records should be easy to retrieve when management, an auditor, or a compliance reviewer needs them.
Mistake #5: Assuming Your Vendors Are Someone Else's Problem
Your dealership doesn't operate alone. You probably depend on a long list of technology and service providers — your DMS, your CRM, your MSP, your cloud provider, your payment processor, your marketing platforms, your document management provider.
Other companies may have access to your systems or customer information. That creates another layer of risk.
The FTC says covered institutions should take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, require appropriate safeguards through contracts, and periodically assess service providers based on the risk they present.
The mistake is thinking: "They're a reputable company, so we're fine." Reputation isn't a vendor risk assessment.
What to do instead: Know which vendors have access to customer information, what information they can access, what security controls they have, what contractual protections exist, when contracts expire, when vendors should be reassessed, and whether their level of access is still necessary. Vendor management should be part of your compliance program — not an afterthought.
Mistake #6: Having Policies but No Evidence
This one is extremely common.
A dealership says: "Yes, we have a policy." Great. Then someone asks: "Can you show me that employees received the training?" Nothing. "Can you show me the last risk assessment?" Maybe. "Can you show me your vendor review?" It's somewhere in someone's email. "Can you show me when that security issue was resolved?" Nobody knows.
This is where compliance becomes frustrating. A policy tells people what they are supposed to do. Evidence demonstrates what actually happened.
Your compliance program may generate evidence such as risk assessments, WISP versions, training records, training certificates, vendor assessments, vendor contracts, security testing reports, vulnerability assessments, incident records, remediation records, access reviews, and management reports.
The FTC's Safeguards Rule requires the information security program to be maintained and includes ongoing monitoring, testing, and reporting responsibilities. That makes documentation more than paperwork — it becomes part of your ability to demonstrate that the program is actually operating.
What to do instead: Create a centralized evidence process. When something important happens, document it. When a control is tested, retain the evidence. When an issue is fixed, document the remediation. Don't wait until somebody asks for it.
Mistake #7: Waiting Until Something Goes Wrong
This is probably the biggest mistake of all.
Nobody wants to think about a cyber incident. But hoping you won't have one isn't a security strategy.
Imagine this scenario. It's Monday morning. An employee tells the general manager that they clicked a suspicious link. A few computers are behaving strangely. Then someone discovers that customer files may have been accessed.
What happens next? Who takes charge? Who contacts the IT provider? Who determines what happened? Who decides whether systems should be disconnected? Who documents the incident? Who contacts legal counsel? Who determines whether notification requirements apply? Does anyone know where the incident response plan is?
The FTC requires covered financial institutions to maintain a written incident response plan describing how they will respond to and recover from security events affecting customer information.
There are also FTC notification requirements for certain security incidents involving at least 500 consumers' unencrypted information. Covered institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event.
You don't want to start figuring all of this out while you're dealing with an active incident.
What to do instead: Build your incident response process before you need it. Know the people involved. Know their responsibilities. Document escalation procedures. Keep the plan accessible. And periodically review it.
So, how does your dealership compare?
Take a moment and ask yourself:
- Do we have a current written information security program?
- Have we completed a current written risk assessment?
- Do we have someone clearly responsible for overseeing our security program?
- Can we demonstrate that employees have received security awareness training?
- Do we know which vendors have access to customer information?
- Can we quickly produce evidence of our compliance activities?
- Do we have a written incident response plan?
If you answered "no" or "I'm not sure" to several of these questions, you're not alone. But it's worth doing something about it.
The bigger problem isn't one missing document
When dealers think about compliance, they sometimes think in terms of individual documents. "We need a WISP." "We need a risk assessment." "We need a vendor policy." "We need training records." "We need an incident response plan."
But these things are connected. Your risk assessment should influence your WISP. Your risk assessment should influence your safeguards. Your safeguards should influence employee training. Your vendors should be evaluated based on risk. Security testing should identify weaknesses. Weaknesses should generate remediation activities. Remediation should be documented. And management should have visibility into the overall program.
That's a compliance system. Not a pile of documents.
How Sterling Safeguard helps
This is exactly the problem Sterling Safeguard was built to solve. Independent dealerships shouldn't have to manage their FTC compliance program through spreadsheets, Word documents, email reminders, shared folders, and disconnected systems. Sterling Safeguard brings the major components together in one platform designed specifically for independent auto dealerships.
Start with your risk. The Risk Assessment Engine helps your dealership identify risks, evaluate safeguards, uncover gaps, and establish a measurable compliance posture.
Build a living WISP. The Living WISP Generator helps create a dealership-specific Written Information Security Program that can evolve as your business changes.
Keep your evidence together. The Evidence Vault provides a central location for policies, assessments, training records, vendor documentation, security reports, and other compliance evidence.
Know your vendors. The Vendor Management tools help you track vendors, risk levels, contracts, renewal dates, and access to customer information.
Stay on top of training. The Employee Training Tracker helps you know who has completed required training and keeps the supporting records organized.
Be ready for an incident. The Incident Response Center provides a structured place to manage and document security incidents.
Don't miss important activities. The Compliance Calendar helps keep recurring compliance activities on schedule.
See where you stand. The FTC Audit Readiness Score™ gives dealership leadership a simple way to understand the current state of the compliance program and where attention is needed.
Because these pieces are connected, your dealership can move from simply having compliance documents to actually managing a compliance program.
Compliance doesn't have to be complicated
The FTC Safeguards Rule can feel intimidating. But compliance becomes much easier when you break it into manageable pieces.
Know your information. Understand your risks. Protect the information. Train your people. Manage your vendors. Test your safeguards. Prepare for incidents. Document your work. Keep the program current. And make sure someone is accountable.
That's the foundation. The goal isn't to create a mountain of paperwork. The goal is to build a dealership that knows how it protects customer information — and can demonstrate it.
Don't wait until someone asks for your compliance records
The best time to discover a gap in your compliance program is before an incident, review, or regulatory inquiry forces you to find it.
Sterling Safeguard helps independent auto dealerships identify their risks, organize their compliance program, maintain evidence, and stay prepared.
Know your risks. Close your gaps. Protect your customers.
Sterling Safeguard — FTC Safeguards Rule Compliance Built for Independent Auto Dealerships.
Take the free FTC risk assessment here.
This publication is for educational and informational purposes only and does not constitute legal advice. The FTC Safeguards Rule may apply differently depending on a dealership's specific activities and circumstances. Dealerships should consult qualified legal or compliance professionals regarding their specific obligations.