Employees are increasingly bypassing cybersecurity measures at hand in pursuit of convenience and speed. A recent new survey indicates that this phenomenon poses a direct challenge to the increasingly severe cyber risks facing enterprises, and the situation has not been alleviated even though employees and consumers have a higher awareness of the risk of cyberattacks and the costs they bring to businesses.

In the automotive dealership industry, human eyes, hands, and experience remain the primary strategy for preventing identity theft crimes. Even though computer systems monitor digital networks, no dealership can be 100% immune to compliance lapses and data breaches.

We have previously written to emphasize that employees need to raise their awareness of their role in preventing cyber "fires." A December 2024 Forbes article focusing on "efficiency" noted that 65% of employees admitted to bypassing their employer's security policies. Earlier Verizon data breach research showed that 68% of breaches in the past year were caused by human error—for example, employees failing to properly protect confidential information due to falling for social engineering fraud.

The Forbes article concluded: How can dealerships enforce compliance without hindering workflow? When rushing to meet performance goals, employees sometimes skip security steps to close deals.

I must emphasize that dealership leaders must confront the human factor in data security and implement it at all levels of the store. One or two managers should be assigned to implement and supervise data security training and compliance across all departments. Employees must be explained and enforced: as the first line of defense against cyberattacks, any reduction of protective measures, skipping of processes, steps, or training is intolerable, even at the expense of sales.

What reasonable alternatives exist for this dilemma? I offer three suggestions:

  • First, robust cybersecurity technology must be deployed.The more proactively this solution can counter cyberattacks (i.e., offensive security), the more protection the dealership obtains. Cybersecurity investment should be prioritized; today, insurance companies rigorously scrutinize how dealerships guard against penetration of internal data flows and those with vendors.
  • Second, focus on your own vulnerabilities.Do not let security concerns lapse; do not fall into a "all clear" mindset just because current defenses have not detected signs of attack. We have seen networks that were penetrated years ago, continuously stealing financial or personal data, or lying dormant until triggers in their code activated an attack. Appropriate security software and processes should not leave you exposed to such risks.
  • Third, continuously reinforce employee awareness of the importance of cyber compliance.Under today's rules, a quarterly refresher is not too frequent. No dealership can be 100% immune to compliance lapses and data breaches, even with computer systems monitoring digital networks. However, in my 25 years of protecting dealerships from compliance and security lapses, lax information hygiene remains the greatest information theft risk dealerships face. For over a decade, I have argued that lax audit and paper-handling practices expose dealerships to unnecessary risk and reputational damage.

However, employee compliance cooperation does not have to be a choice between security and sales. This focus should apply not only to network-related risks, but also to the everyday information theft opportunities and careless paper document handling we find when visiting nearly every dealership.

I am surprised that many dealerships still manage deal jackets loosely: leaving them exposed in the F&I office, or piling them in customer waiting areas without proper storage. Paper documents—from complete deal jackets to service records and transaction worksheets—are rich in personal and financial data. Anyone with malicious intent and a camera phone wandering the store can quickly capture this information, often without being noticed.

Your compliance and security vendor will provide video training on these topics and audit network and manual compliance practices and processes at least quarterly. Dealerships often request more frequent reviews of these vulnerabilities so they can sleep soundly.

Compliance and cybersecurity solutions in this industry offer a variety of service options and costs. Do not equate price with value, or assume that low price means no value.

The passion and commitment shown by the people running the company, and the same enthusiasm, rigor, and integrity they bring to your dealership, along with the technology and strategies they use to ensure the integrity of data platforms, will yield rich long-term returns. Determine whether they passively provide cyber protection or actively pursue criminals attempting to defraud you and your customers.

About the Author

Terry Dortch
Terry Dortch, Founding Partner of Automotive Risk Management Partners (ARMP)

Terry Dortch, Founding Partner of Automotive Risk Management Partners (ARMP), has over 40 years of experience in retail dealership operations and compliance consulting. Dortch created the first Gramm-Leach-Bliley Act (GLBA) audit process for dealership sales and finance centers in North America.