Cybersecurity for Texas Auto Dealers  •  FTC Safeguards Rule • DMS Monitoring • 30-Min SLA • SDVOSB

CDK took 15,000 dealers down.
Yours is still exposed.

The June 2024 CDK Global cyberattack crippled ~15,000 franchised dealers for nearly three weeks — estimated $1B+ in industry losses. DMS vendors are your biggest third-party risk. CoreRecon delivers 24/7 SOC + 30-minute SLA for dealerships that can't afford another CDK — with FTC Safeguards Rule compliance built in. Texas has ~1,300 franchised dealers. Most are not ready.

Get your free $2,500 posture assessment → See what's hitting Texas dealers right now ↓
🚗
FTC Safeguards Rule 16 CFR 314 — Full Enforcement Active. Every franchised auto dealer that holds customer financial information is a covered financial institution under the FTC Safeguards Rule. The requirements — written ISP, designated Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight — are not optional. The FTC has pursued enforcement actions against dealers for Safeguards violations. The CDK outage exposed that most dealers had no vendor risk program for their DMS provider. That gap is a Safeguards violation.
~1,300
Texas franchised auto dealers — the largest uncovered vertical in MSSP coverage
TADA (Texas Automobile Dealers Association)
$1M+
Estimated average CDK 2024 outage cost per dealer (lost sales, financing delays, manual ops)
NADA / industry estimates, June 2024
68%
Of dealer breaches originate via DMS or third-party software integration attack vectors
CDK Global / Reynolds breach pattern analysis
100%
Of franchised dealers with customer financing are covered financial institutions under FTC Safeguards Rule
FTC 16 CFR 314 (2023 update)
Threat Reality — Texas Auto Dealers

Four vectors.
Every one hits dealerships.

Auto dealers run a uniquely target-rich environment: DMS platforms holding every customer's SSN and credit data, F&I desks processing finance apps, service bays on connected shop management systems, and floor plan wire transfers moving millions. Each layer is a separate attack surface with its own adversary profile.

💻
Supply Chain Attack · DMS Vendors
CDK, Reynolds & Reynolds, Dealertrack
The June 2024 CDK Global cyberattack — attributed to a ransomware group that breached CDK's infrastructure — took approximately 15,000 franchised dealers offline for 2–3 weeks. Dealers couldn't process deals, access customer records, or run DMS-dependent service operations. CDK paid an estimated $25M ransom. Reynolds & Reynolds and Dealertrack (Cox Automotive) face the same supply chain attack surface: any compromise of the DMS vendor propagates instantly to every connected dealer. Dealers have no control over their DMS vendor's security posture — but they can monitor the network behavior between their DMS-connected endpoints and their internal infrastructure. That's where CoreRecon operates.
🔐
PII / SSN Exfiltration · F&I Desk
Finance & Insurance Customer Data
Every F&I deal generates a credit application with SSN, DOB, income, employment, and financing terms — the full identity theft package. Dealerships with active F&I desks hold tens of thousands of complete consumer records in DMS and document management systems. Ransomware groups targeting dealers typically exfiltrate F&I data before encrypting systems — the double-extortion playbook means even a dealer who can restore from backup still faces a GLBA/FTC Safeguards breach notification obligation and potential regulatory action. FTC breach notification under Safeguards requires dealer notification within 30 days of discovering a breach affecting 500+ customers.
🔧
Ransomware · Service Operations
Shop Management & RO Systems
Service departments are the most consistent revenue generators at franchised dealerships — but they run on shop management software (CDK Service, Reynolds Service, DealerSocket) that is networked to the same DMS infrastructure handling sales and F&I. A ransomware event that hits the DMS simultaneously takes down service write-ups, RO completion, parts ordering, and tech time-tracking. For a high-volume service department doing $2–4M/month in labor, a two-week DMS outage costs $1–2M in deferred revenue. IoT-connected service bay equipment (alignment racks, tire pressure systems, EV charger management systems) adds additional OT attack surface that standard IT monitoring misses.
💸
BEC · Floor Plan & Rebate Wires
Floor Plan Financing & OEM Rebates
Dealer financial flows are large and fast-moving: floor plan curtailments to lenders (Ally, NextGear, Ford Motor Credit), manufacturer incentive and holdback payments, and deal funding wires from captive finance companies. BEC attackers target the controller and dealer principal email accounts to intercept payment instructions and redirect wires. A single diverted floor plan curtailment can exceed $500K. OEM rebate fraud — where attackers impersonate manufacturer representatives to redirect incentive payments — has been documented against Ford, GM, and Toyota dealer groups. FBI IC3 2024: automotive sector BEC losses increased 34% year-over-year.
Compliance Landscape — Auto Dealers

Four frameworks.
All active. All enforced.

Auto dealers face a tighter compliance stack than most SMBs realize. The FTC Safeguards Rule alone has eight operational requirements that most dealers are not meeting. Add state breach notification, PCI DSS for F&I credit card processing, and GLBA for finance arms — and the compliance picture is genuinely complex.

Framework Applies To Enforcement / Deadline CoreRecon Coverage
FTC Safeguards Rule
16 CFR Part 314 — written ISP, Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight, penetration testing
All franchised dealers and independent dealers holding customer financial information — defined broadly to include any credit application, financing record, or insurance data. Applies to every auto dealer with F&I operations regardless of size Full requirements effective June 2023; FTC has pursued enforcement actions; no size exemption below 5,000 customer records for the written ISP and Qualified Individual requirements; 30-day breach notification trigger at 500+ affected customers Sentinel MFA deployment, encryption verification, IR plan template, basic ISP framework. Fortress Vendor oversight program for DMS/F&I vendors, annual penetration testing, encrypted backup. Command Qualified Individual service, written ISP authorship, annual board report, full Safeguards program ownership
TX Bus & Com Code §521
Texas breach notification law — covers SSN, driver's license, financial account numbers
All Texas dealers holding customer PII — virtually every franchised dealer in Texas given F&I credit applications, motor vehicle title records, and service records containing driver's license numbers Must notify affected individuals within a "reasonable time" after discovery; AG notification required for breaches affecting 250+ Texas residents; civil penalty up to $100/day per individual up to $250K; AG may seek injunctive relief Sentinel Breach detection and documentation. Fortress Forensic investigation support, breach scope determination. Command Full breach notification management, AG reporting coordination, legal notification letter support
PCI DSS 4.0.1
Payment card security for F&I credit card processing and service department payments
Dealerships accepting credit cards for vehicle deposits, service payments, or parts purchases — which includes virtually every dealership with a service department or that accepts any credit card at point of sale PCI DSS 4.0.1 requirements in full effect 2025; non-compliance can result in card brand fines ($5K–$100K/month), loss of card acceptance, and mandatory forensic investigation costs after a breach; most dealers process under SAQ A or SAQ B-IP Sentinel Network segmentation to isolate cardholder data environment, log monitoring for payment system anomalies. Fortress Annual SAQ completion support, quarterly vulnerability scanning, penetration testing for PCI scope systems
GLBA — Finance Arms
Gramm-Leach-Bliley Act for dealers with captive finance or in-house financing operations
Dealers with in-house financing, buy-here-pay-here operations, or captive finance subsidiaries — treated as financial institutions under GLBA with full privacy notice, data handling, and safeguards obligations beyond the FTC Safeguards Rule GLBA requirements continuous — no sunset; state AG enforcement in Texas; dealers with BHPH portfolios face additional CFPB oversight under fair lending requirements that intersect with data security obligations Command GLBA compliance mapping for captive finance operations, data handling controls for consumer financial records, privacy notice accuracy review, integration with CFPB-relevant data governance requirements
Industry Incidents — The Reference Cases Every Dealer Needs to Know

CDK. Arnold Clark.
The playbook is written.

Ransomware groups that target dealers now have documented playbooks built from multiple real-world dealer attacks. The CDK outage gave them their first look at how much leverage a DMS compromise provides. Arnold Clark showed what F&I data exfiltration looks like at scale.

June 2024 — DMS Vendor Compromise
CDK Global Ransomware Outage

In June 2024, CDK Global — the DMS platform used by approximately 15,000 franchised auto dealers across North America — suffered two consecutive cyberattacks within days of each other. The BlackSuit ransomware group is attributed. CDK shut down all systems to contain the breach, taking every CDK-dependent dealer offline simultaneously.


The outage lasted approximately 2–3 weeks for most dealers. Dealers were forced to manual paper-based processes for deals, financing, and service. Industry estimates placed total dealer losses at $1B+. CDK reportedly paid approximately $25M in ransom to accelerate recovery. The attack demonstrated the catastrophic supply chain risk of DMS dependency — a single vendor compromise affects every connected dealer simultaneously, regardless of the individual dealer's own security posture.


Source: Reuters, Wall Street Journal reporting June–July 2024; SEC 8-K filings. CoreRecon had no involvement in this incident.

December 2022 — UK Dealer Group — Largest Automotive Data Breach in UK History
Arnold Clark: 1M+ Customer Records Exfiltrated

Arnold Clark — the UK's largest privately-owned car dealer group with 200+ outlets — was breached in December 2022 by the Play ransomware group. The attackers exfiltrated data on over 1 million customers before Arnold Clark detected the intrusion in January 2023. Exfiltrated data included names, dates of birth, addresses, contact details, National Insurance numbers (UK equivalent of SSN), passport information, and driver's license data.


The breach demonstrated what F&I data exfiltration looks like at scale: a single dealer group's customer database contains enough PII to enable identity theft for every customer who ever financed a vehicle with them. Texas dealer groups with 50,000–500,000 customer records face identical data concentration risk. The Arnold Clark attackers used data exfiltration as leverage — threatening to publish records publicly if ransom was not paid.


Source: Arnold Clark official statements; ICO (UK data protection authority) investigation 2023. CoreRecon had no involvement in this incident.

What the Texas Breach Tracker shows: Texas dealership breach notifications filed with the Texas AG's office include incidents at single-point dealerships and regional groups — F&I data exposure, DMS-related system compromises, and service records breaches. Texas dealers are required to notify the AG for breaches affecting 250+ Texas residents. Most dealer breaches meet that threshold before the dealer realizes the breach has occurred. See Texas Breach Tracker →
CoreRecon Dealer Coverage — Purpose-Built for the DMS Stack

Built for CDK, Reynolds,
Dealertrack, and Dominion.

Most MSSPs treat a dealership like any other SMB. CoreRecon maps the specific attack surfaces of the dealer technology stack — DMS, F&I document platforms, OEM portals, and service management systems — and monitors the integration points that CDK proved are the real risk.

DMS Monitoring
CDK · Reynolds · Dealertrack · Dominion
We monitor the network behavior between your DMS-connected workstations and your internal infrastructure — credential anomalies, unusual data access patterns, and lateral movement from DMS-connected endpoints. We instrument the API tap-points that CDK, Reynolds, Dealertrack, and Dominion use to connect to your network. When CDK goes offline again, we have visibility into what was happening on your network in the hours before. We also conduct CDK-specific threat hunts during onboarding to look for persistent access established during or after the June 2024 outage period.
F&I Database DLP
SSN & Consumer Financial Record Protection
F&I desks are the highest-value data concentration in any dealership. We deploy DLP (data loss prevention) controls on the systems and network segments that hold credit application data, deal jackets, and consumer financing records. Anomalous bulk access of F&I data — consistent with pre-exfiltration staging — triggers immediate SOC alert. Every franchised dealer with active F&I operations should have DLP coverage on consumer financial records under FTC Safeguards Rule vendor oversight requirements.
OT / IoT — Service Bays
EV Chargers · Alignment Racks · Shop Equipment
Modern service bays have meaningful IoT attack surface: EV charging management systems (networked to charge metering and billing), connected alignment and diagnostic equipment, tire pressure monitoring systems, and shop management platforms integrated with DMS. Fortress tier extends monitoring to your service bay network segment. For EV-focused dealerships (Ford Pro, GM EV portfolio, Toyota BEV), EV charger network security is an emerging OEM audit requirement — we provide the monitoring documentation that franchise agreements increasingly require.
Vendor Risk — OEM Portals
Ford DealerConnection · GM GlobalConnect · Toyota TMS · Stellantis
Every franchise dealer accesses OEM portals for warranty claims, incentive programs, parts ordering, and technical service bulletins. These portals are authenticated access points into OEM systems that carry financial transaction authority (warranty reimbursements, holdback payments, volume incentives). Credential compromise on OEM portal accounts is an active threat vector — attackers redirect incentive payments and warranty reimbursements by taking over dealer portal accounts. Command tier includes OEM portal access monitoring and MFA enforcement for all accounts with payment redirect authority.
Multi-Rooftop Groups
Consolidated Coverage Across Locations
Dealer groups with 3–20 rooftops get a single consolidated ISP, centralized SIEM with per-location visibility, and one vCISO who understands the full group's DMS and F&I technology stack. Multi-rooftop groups are higher-value targets — an attacker who compromises the group's shared DMS infrastructure affects every rooftop simultaneously. Pricing scales by total endpoint count across all locations; no per-rooftop overhead. We've onboarded mixed-make groups with CDK at some rooftops and Reynolds at others — our monitoring handles heterogeneous DMS environments.
FTC Safeguards — Qualified Individual
vCISO as Your 16 CFR 314.4(a) Designee
The FTC Safeguards Rule requires every covered dealer to designate a Qualified Individual responsible for the information security program — someone with relevant experience who oversees it, coordinates implementation, and reports to the owner/board annually. Command tier's vCISO service fulfills this role: ISP authorship, annual risk assessment, annual board report, vendor oversight coordination, and IR plan maintenance. The FTC's guidance explicitly permits an outside party to serve as Qualified Individual. This is the most cost-effective path to Safeguards compliance for single-point and small-group dealers who can't justify a full-time security hire.
Transparent Pricing — Auto Dealer Edition

Three tiers. Published pricing.
Built for 50–150 endpoint dealers.

Average franchised dealership runs 50–150 endpoints: sales writers, F&I desks, service advisors, parts counter, management, and admin. Month-to-month. No long-term contracts. 10-endpoint minimum.

Sentinel
$89 / endpoint / month
10-endpoint minimum • ~$4,450–$13,350/mo for typical dealer • Month-to-month
  • 24/7 SOC monitoring across all dealership endpoints
  • DMS-connected workstation anomaly detection
  • Email security with BEC pattern detection for floor plan and OEM payment flows
  • MFA deployment on DMS, email, and OEM portal accounts
  • FTC Safeguards Rule ISP framework and basic documentation package
  • Monthly threat report with automotive sector intel
  • TX Bus & Com §521 breach detection and notification trigger
Command
$2,500+ / month
Custom scope • Dedicated vCISO • Qualified Individual service available
  • Everything in Fortress
  • 30-minute SLA — analyst on call with dealer principal within 30 minutes of major alert
  • FTC Safeguards Qualified Individual — vCISO designated as your 16 CFR 314.4(a) designee
  • Written ISP authorship, maintenance, and annual board/owner report
  • OEM portal access monitoring — Ford, GM, Toyota, Stellantis dealer portal accounts
  • Multi-rooftop group coverage with consolidated ISP and per-location SIEM views
  • GLBA compliance mapping for captive finance operations
  • CDK-specific threat hunt during onboarding; quarterly re-assessment

Endpoint guidance for Texas dealers: Single-point franchised dealer (new vehicles only): 50–80 endpoints. Full-line dealer with service and parts: 80–120 endpoints. High-volume group store: 100–150+ endpoints. Multiply by $89 (Sentinel) or $129 (Fortress) for your monthly estimate. Command tier is fixed-fee custom scope — typical single-rooftop dealer starts at $2,500/mo.

Free Security Assessment — $2,500 Value

Find out if your DMS network has persistent access from the CDK breach window.

We map your DMS-connected endpoints, identify FTC Safeguards compliance gaps, check BEC vulnerability on your floor plan and OEM payment flows, and deliver a dealer-specific remediation roadmap. No credit card. No commitment. Delivered in 14 days.

Request your free $2,500 assessment →

Delivered within 14 days  •  No credit card  •  SDVOSB-certified team

Free Interactive Tool
What Does a Floor Plan BEC Event Cost Your Dealership?
Model your BEC loss exposure on floor plan curtailments, OEM rebate payments, and F&I deal funding. Get your unrecoverable loss estimate in 60 seconds.
Calculate BEC Exposure →
Free Tool — Vendor Risk Scorecard
Score CDK, Reynolds & Your F&I Vendors Before They Score You
DMS vendors are your #1 third-party risk — CDK proved it. Score your vendor exposure in 5 minutes. FTC Safeguards requires documented vendor oversight. Start here.
Score My DMS Vendors →
Free Quiz — FTC Safeguards Rule · 16 CFR Part 314
Are You Actually FTC Safeguards Compliant?
20 questions. All 9 required elements — Qualified Individual, MFA, encryption, vendor oversight, board report, 30-day breach notification. Get your score + enforcement exposure in 10 minutes.
Take the FTC Safeguards Quiz → Texas TDPSA Quiz →
Frequently Asked Questions

What Texas dealer principals actually ask.

Yes. CoreRecon monitors the network layer around CDK-connected environments — endpoint telemetry, authentication anomalies, and network behavior between CDK-connected workstations and your internal infrastructure. We don't replace CDK; we provide the security monitoring layer that CDK's own infrastructure cannot provide. Critically, we conduct CDK-specific threat hunts during onboarding to identify any persistent access that may have been established during the June 2024 outage window. The BlackSuit ransomware group that hit CDK maintained access inside CDK's network for weeks before executing — your dealer network may have been exposed during that period. Our onboarding hunt addresses that specific risk.

CoreRecon monitoring runs on your endpoint and network infrastructure independently of CDK availability. We don't lose visibility when your DMS goes offline. In fact, DMS outage scenarios require more monitoring attention — not less. Manual fallback processes (paper deals, offline service write-ups) introduce social engineering opportunities and manual override risks that digital workflows prevent. Fortress tier includes specific detection for the manual workflow patterns that activate during DMS outages, such as unusual export activity as staff try to pull data offline, and BEC attempts targeting staff who are managing deals manually and are more susceptible to phone-based fraud.

Command tier's vCISO service fulfills the 16 CFR 314.4(a) Qualified Individual requirement. The FTC Safeguards Rule requires a designated Qualified Individual to oversee your ISP — someone with relevant experience who coordinates implementation, reports to ownership annually, and maintains the program. The FTC's own guidance explicitly permits an outside party to serve in this role. Command tier includes: ISP authorship and maintenance, annual risk assessment, annual written report to owner or board, vendor oversight program coordination (CDK, Reynolds, Dealertrack), and IR plan maintenance. This covers all eight operational requirements under 16 CFR 314.4 for a single-point dealer. Multi-rooftop groups are covered under the same engagement at consolidated pricing.

Multi-rooftop groups get a single consolidated security program under Command tier — one ISP covering all rooftops, centralized SIEM with per-location visibility, and one vCISO who understands the full group's DMS and F&I stack. Pricing scales by total endpoint count across all rooftops; you don't pay per-location overhead. A 5-rooftop group averaging 80 endpoints per location (400 total endpoints) is a standard Command engagement. We've handled mixed-make groups with CDK at some rooftops and Reynolds at others — heterogeneous DMS environments are not a problem. The consolidated ISP satisfies FTC Safeguards requirements for the entire group under one Qualified Individual designation.

Yes — significantly. Dealers with captive finance operations, BHPH portfolios, or in-house financing subsidiaries are treated as financial institutions under both GLBA and the FTC Safeguards Rule, with the full set of obligations that entails — including annual privacy notices, consumer data handling restrictions, and safeguards program requirements that are more stringent than those applied to dealers that only accept third-party financing. BHPH dealers with large consumer loan portfolios also have CFPB oversight exposure that intersects with data security obligations. Command tier includes GLBA compliance mapping for captive finance operations and coordinates data handling controls for consumer financing records with your DMS configuration.

Command tier at $2,500+/month includes IR retainer services with pre-authorized containment authority and 30-minute SLA. Pre-built playbooks cover the specific scenarios dealers face: DMS ransomware and offline isolation, F&I data breach with FTC breach notification workflow, BEC on floor plan or OEM rebate payment flows, and OEM portal credential compromise. A ransomware event on a CDK-connected dealership environment typically requires 2–4 weeks of IR engagement to fully contain, remediate, document, and satisfy FTC Safeguards breach notification obligations (30-day clock from discovery for incidents affecting 500+ customers). The monthly retainer cost is a fraction of what an unretained emergency IR engagement costs — market rates for forensic IR firms responding to dealer ransomware events run $25K–$150K+ for the full engagement, plus legal and notification costs.

DMS Down? Active Breach? 24/7 Emergency Response
CDK offline again? Ransomware on the DMS? We respond in 30 minutes.
No retainer required for emergency response. SDVOSB-certified. No voicemail.
📞 (800) 955-2596 Or submit emergency intake form →
Free Security Assessment — $2,500 Value

Find out what your DMS network looks like to an attacker.

Texas dealers are the most financially exposed sector in the SMB market — SSN and credit data on every customer, floor plan wires moving daily, and DMS vendors that proved they can take you down for weeks. Our free assessment maps your DMS attack surface, checks FTC Safeguards compliance gaps, and delivers a dealer-specific remediation roadmap. No credit card. No commitment.

Request your free $2,500 assessment →

Delivered within 14 days  •  No credit card  •  SDVOSB-certified team

Free Tool — vCISO ROI Calculator
Fractional vCISO vs. Full-Time Hire — Calculate the Real 3-Year Cost
IBM CODB breach model + compliance penalty exposure + tier recommendation. Know the math before your board asks the question.
Calculate vCISO ROI →