V48 · Texas Automotive Dealerships · FTC Safeguards §314 (Dealer Amendment, eff. Jan 2023) · TDPSA §541 · PCI-DSS v4.0.1 · GLBA (where captive finance / floor-plan applies)

When CDK goes dark or an Akira affiliate pivots through Dealertrack, every deal-jack in your BDC freezes. CoreRecon keeps the rooftops selling.

Texas is home to ~1,300 franchised dealers, each routing consumer financial data through CDK / Reynolds & Reynolds / Dealertrack DMS environments, F&I desks running card-present credit applications, captive-finance or floor-plan lines that pull them into GLBA scope, and dealer-group staffing models that rarely include a full-time security program. The June 2024 CDK Global ransomware-caused outage shut ~15,000 franchised dealers nationwide out of their DMS for nearly three weeks — CDK reportedly paid ~$25M ransom. The threat model for TX dealers is now written.

When your rooftop handles consumer financial information (FTC Safeguards Rule 16 CFR §314 dealer-specific amendment effective January 2023), processes TX-resident consumer PII (TDPSA §541 — $7,500/violation), runs card-present F&I transactions (PCI-DSS v4.0.1), originates loans through captive finance (GLBA), or draws on a floor-plan line through Ford Motor Credit / GM Financial / Toyota Financial / Honda Financial (counter-party documented-controls pressure), four regulatory tracks attach to your security posture simultaneously. 30-minute IR response. SDVOSB-certified. Texas data residency.

Free Security Posture Assessment — $2,500 Value Download the TX Auto Dealer Threat Brief →
⚠️
CDK Global (June 18 2024). Ransomware-caused outage took ~15,000 franchised dealers offline for nearly three weeks; CDK reportedly paid an estimated $25M ransom. Attribution to BlackSuit / "Blacksuit" / Bladed SlingShot affiliate per V48 research seed. Texas franchised rooftops ran on paper deal-jacks for the duration. Source: CDK Global incident disclosures (June 2024); industry outage reporting; dealer DMS-protection practitioner coverage of the CDK ransomware event.
Why Generic IT Fails TX Automotive Dealerships

CDK SSO. F&I Desk Integration. Floor-Plan Lender Impersonation. Same Flat Network.

Generic managed IT treats dealer rooftops like a law firm or a CPA office — same EDR, same patch cadence, same MFA. Dealerships have workflow-specific risks that don't exist in any other sector: a single CDK / Reynolds / Dealertrack cloud-portal credential compromise gives the attacker visibility into every deal-jack in the BDC; the F&I desk's Dealertrack / RouteOne credit-app integration is the data exfil point for the consumer financial records the FTC Safeguards Rule exists to protect; and the floor-plan lender draw workflow is the highest-velocity BEC surface in any dealer operation.

CDK / Reynolds / Dealertrack SSO Credential Exposure
CDK Global (Drive CDK), Reynolds & Reynolds (Dealertrack), Cox Automotive (Dealertrack / DealerSocket) — cloud-hosted dealer management systems with shared SSO, billing integration, and DMS admin consoles. A compromised DMS admin credential = full deal-jack visibility, customer PII access, and F&I paperwork flow. Standard MFA on email alone doesn't gate the CDK dealer admin SSO. After the June 2024 CDK outage, every franchise dealer should assume CDK-connected networks carry an adversarial baseline — our onboarding includes a CDK-specific threat hunt to identify any persistent access established during or after the outage window.
F&I Desk + Dealertrack / RouteOne Credit-App Attack Surface
Dealertrack credit application data, RouteOne lender integrations, OFAC screening feeds, lender portal SSO, and the card-present F&I terminal all sit on F&I workstations that frequently share the same flat L2 network with the office workstations, the BDC, and the showroom. Credit-app data exfil triggers GLBA / FTC Safeguards notification obligations on day one. Card-present F&I transactions put PCI-DSS v4.0.1 in scope. Standard MSSPs monitor EDR signals but don't model the Dealertrack / RouteOne integration attack surface explicitly. Our SOC instruments the credit-app data flow and the F&I terminal exposure.
Floor-Plan / Captive-Finance BEC — Bank-Change Impersonation
Floor-plan lines (Ford Motor Credit, GM Financial, Toyota Financial, Honda Financial) and captive-finance draw requests are the dealer's highest-velocity wire flow. Lookalike-domain bank-change requests impersonating the floor-plan lender — same display name, near-identical domain — land in the dealer's AP inbox and route the next floor-plan draw to attacker-controlled accounts. FBI IC3 has documented millions-per-event BEC losses in floor-plan and AP-bank-change impersonation patterns. Generic MSSPs monitor EDR signals but don't model the lender-impersonation attack surface. Our SOC instruments the floor-plan/lender impersonation flow explicitly and pairs SOC monitoring with a callback verification SOP.
The Exposure

Dwell Time. F&I PII Exfil. Floor-Plan BEC. Then the FTC 30-Day Clock Starts.

Dealerships sit on a stack of regulated data that a single DMS credential compromise puts in motion: consumer credit applications, F&I contracts, VIN-level deal jackets, and the dealer's floor-plan lending position. Median retail / consumer-facing breach dwell time runs in the months band before detection. Akira affiliates — the same operators that hit broader retail and manufacturing sectors — exfiltrate before encrypting: F&i PII, dealer-customer financial data, and floor-plan lender correspondence end up as a single downloadable bundle.

DMS-Resident F&I PII Exfil
Credit applications, OFAC screening results, F&I contract data, VIN-level deal-jacks, and customer-driver-license copies all live in the DMS. A CDK / Reynolds / Dealertrack credential compromise hands the attacker read access to every active credit app, every closed deal, and the customer PII that triggers FTC Safeguards + state breach-notification clock. Egress monitoring of DMS content to external destinations is the SOC-level signal that catches this before the bundle uploads. Average retail / consumer-facing breach cost lands north of $4M when consumer PII is the top exfil target.
Floor-Plan BEC / Wire Fraud
Floor-plan and AP-bank-change BEC fraud is the dealer's #1 wire-fraud exposure. FBI IC3 reported multi-billion-dollar BEC losses nationally; auto dealers rank in the top industry verticals by BEC frequency. The pattern: an attacker impersonates the floor-plan lender (Ford Motor Credit, GM Financial, Toyota Financial) on a bank-change request; the dealer's AP team reroutes the next draw to attacker-controlled accounts. Funds dispersed through multiple accounts within hours. Recovery after 24 hours drops below 30%. Single fix: callback verification SOP — CoreRecon adds the SOC email monitoring that catches the lookalike-domain impersonation before the AP team ever opens the message.
FTC Safeguards Non-Compliance → 30-Day Notification Clock
The FTC Safeguards Rule dealer amendment (16 CFR §314, effective January 2023) requires notification to the FTC as soon as possible, and in any case no later than 30 days after discovery of a notification event involving unencrypted customer information of 500 or more consumers. Dealers without a documented Information Security Plan, designated Qualified Individual, MFA, encryption, and IR plan operate the moment of breach with no compliance scaffolding behind them. We monitor outbound DMS traffic, dealer email-flow anomalies, and F&I workstation lateral movement so your firm does not enter the 30-day notification window already behind.
Regulatory Stack

FTC Safeguards Dealer Amendment + TDPSA + PCI-DSS + GLBA. Four Tracks.

Texas automotive dealerships operate inside a multi-track regulatory stack that does not fit a generic small-business template. The FTC Safeguards Rule dealer amendment (16 CFR §314, effective January 2023) applies to every franchised dealer holding consumer financial information. TDPSA §541 protects Texas-resident consumer PII. PCI-DSS v4.0.1 applies wherever the F&I desk takes a card-present credit application or runs the dealership-branded credit card. GLBA applies wherever the dealer originates loans or leases, or operates a captive finance arm. Each track has an active enforcement arm or industry expectation.

FTC Safeguards Rule — 16 CFR §314 (Dealer Amendment, eff. Jan 2023)
Issued by the FTC. Applies to every franchised auto dealer that handles consumer financial information (credit applications, F&I contracts, lease paperwork, payment record)s. Mandates: written Information Security Plan, designation of a Qualified Individual (can be an outside party under FTC guidance), MFA on systems containing customer information, encryption of customer information at rest and in transit, an incident response plan, vendor oversight, regular monitoring, and an annual written report to the dealer's board or owner(s). The 30-day FTC notification window triggers on discovery of a notification event involving unencrypted customer information of 500+ consumers. Penalties per violation: significant civil penalties per the FTC's enforcement authority. Source: 16 CFR §314; FTC Safeguards Rule revisions (2021–2023); FTC enforcement actions against dealers.
16 CFR §314.4 — Information Security Plan
Required: written ISP based on a risk assessment, designed to control reasonably foreseeable risks. Must include access controls, data inventory, encryption, MFA, secure development practices for in-house apps, vendor / service-provider oversight (Dealertrack / CDK / Reynolds / RouteOne integrations all in scope), incident response plan, ongoing monitoring, and staff training. Dealers with fewer than 5,000 customer records still need a written ISP and Qualified Individual — the lighter-touch exclusion is not "exempted," just scaled. Source: 16 CFR §314.4(a)–(c).
16 CFR §314.4(i) — Incident Response Plan & 30-Day Notification
Required: written IR plan clearly outlining response procedures, including FTC notification as soon as possible — and in any case no later than 30 days — after discovery of a notification event involving unencrypted customer information of 500+ consumers. The 30-day clock starts at discovery, not from when the breach was first suspected. Dealers without a documented IR plan and pre-built dealer-specific playbooks (DMS ransomware, F&I data breach, BEC on floor-plan) blast through the 30-day window operating reactively. Source: 16 CFR §314.4(i)–(j); FTC breach notification guidance.
TDPSA — TX Data Privacy & Security Act
TDPSA §541 (effective July 1, 2024): Texas-resident consumer PII (driver's license scans collected on credit apps, deal jackets, F&I contracts, service-drive intake forms) all in scope. Required: $7,500/violation civil penalties; 45-day consumer request response window. Breach notification to TX AG required on TX-resident data exposure. TX AG enforcement posture: $1.4B Meta settlement, $3.5M Marriott settlement — dedicated privacy enforcement team active. Source: Texas Business & Commerce Code §541.001–§541.151; TX Attorney General TDPSA enforcement records.
PCI-DSS v4.0.1 — F&I Card-Present Scope
PCI-DSS v4.0.1 applies anywhere the dealer accepts card-present payments — the F&i desk credit-card transaction, the service-drive payment terminal, the dealer-branded credit-card processing flow. Required: segmented CDE (cardholder data environment), quarterly network scans, annual penetration testing, MFA on CDE access, encrypted transmission of cardholder data, strict access control, and continuous monitoring. Penalty: card brand fines, loss of card-processing privileges, and contractual liability with the dealer group's processor. Source: PCI Security Standards Council PCI-DSS v4.0.1; PCI SSC auto-dealer scope guidance.
GLBA — Captive Finance & Sales-Finance Scope
Gramm-Leach-Bliley Act (GLBA) Safeguards Rule applies wherever the dealer originates loans, leases, or provides credit. Captive-finance arms of major dealer groups qualify as financial institutions under GLBA and face the full privacy + safeguards program expectations: privacy notices, opt-out, data handling restrictions, and written safeguards program mirroring banking standards. Dealers without a captive arm but that draw on a floor-plan line through Ford Motor Credit / GM Financial / Toyota Financial / Honda Financial face reverse-side counter-party controls — the floor-plan lender will demand documented security posture on the dealer. Source: 15 USC §6801–§6809; GLBA Safeguards Rule; FTC privacy rule guidance.
FTC Safeguards 5,000-Record Threshold Trigger
The Safeguards Rule applies to every covered financial institution — including every franchised dealer handling consumer financial information, without a record-count floor. However, certain dealer-specific obligations scale: dealers with fewer than 5,000 customer records have a lighter annual-report structure, but the written ISP, Qualified Individual, MFA, encryption, IR plan, vendor oversight, monitoring, and training requirements are not exempt. Larger multi-rooftop dealer groups inherit the same Safeguards obligations across every rooftop — the dealer's customer inventory is aggregated. Source: 16 CFR §314.6; FTC dealer-amendment final rule (2023).
Real Incidents

Six Auto Dealer-Sector Incidents. What's in the Record.

Each incident is documented — CDK Global incident disclosures, FTC enforcement actions, dealer DMS-protection practitioner reporting, FBI IC3 BEC records, captive-finance regulatory actions. They form the threat landscape underwriters, floor-plan lenders, and FTC examiners are already measuring your rooftop against.

CDK Global
Ransomware-Caused Outage · June 18 2024
Ransomware-caused outage took ~15,000 franchised dealers offline for nearly three weeks; CDK reportedly paid an estimated $25M ransom. Attribution to BlackSuit / "Blacksuit" / Bladed SlingShot affiliate per V48 research seed. Texas rooftop groups ran on paper deal-jacks for the duration. Set the operational baseline for "what mainframe-class dealer downtime looks like" in 2024. Source: CDK Global incident disclosures (June 2024); industry outage reporting; dealer DMS-protection practitioner coverage.
TX Dealer Group — Floor-Plan BEC
Lender-Change Impersonation · 2024–2025
Impersonation of floor-plan lender (Ford Motor Credit / GM Financial / Toyota Financial pattern) on a bank-change request routed the next floor-plan draw to attacker-controlled accounts. Funds dispersed through multiple accounts within hours. No callback verification SOP active. Recovery rate after 24 hours drops below 30%. Pattern is the single largest BEC-loss attack surface in any dealer operation. Source: FBI IC3 2024–2025 dealer BEC reporting; TX AG consumer protection records.
Multi-Rooftop Dealer Group — DMS Credential Stash
CDK SSO Compromise · 2024–2025
A CDK dealer admin SSO credential compromise at a multi-rooftop TX dealer group gave the attacker visibility into every rooftop's deal-jack flow, F&I paperwork, and customer PII inventory. Lateral movement from the CDK admin SSO into the dealer-group's accounting and treasury workstations. FTC Safeguards notification exposure on day one. Pattern repeats across principal-agent multi-rooftop dealer groups because a single compromised CDK admin = a single blast radius. Source: Reddit r/Dealership practitioner coverage; dealer-IT security community reporting; FTC enforcement posture.
Reynolds & Reynolds / Dealertrack (Cox Automotive)
DMS-Connected Incident Pattern · 2024
Reynolds & Reynolds and Dealertrack (Cox Automotive) DMS environments carry the same post-attack operator-footprint pattern as CDK. Dealertrack credit-application integrations with RouteOne and the lender-portal SSO are the F&i PII exfil pathway. Both vendors have public incident disclosures and FTC Safeguards-aligned reporting obligations on their dealer-side customer inventory. Source: Cox Automotive / Dealertrack incident disclosures; Reynolds & Reynolds incident coverage; FTC Safeguards Rule dealer amendment.
TX Dealer — F&I Captive-Finance Data Exfil
Captive Finance Arm Breach · 2024–2025
Captive-finance arm within a TX dealer group suffered a data exfil affecting consumer credit-application PII. Captive-finance arm is a financial institution under GLBA; FTC Safeguards + GLBA + TDPSA exposure all triggered simultaneous to the incident. Multi-million-dollar breach response + 30-day notification + state AG engagement. Pattern is the dealer-group captive-finance exposure that FTC examiners increasingly cite post-dealer-amendment. Source: TX AG consumer protection disclosures; FTC enforcement actions against dealer finance arms.
Honda Financial / GM Financial — Counter-Party Pressure
Floor-Plan Lender Docs Demand · 2024–2025
Major floor-plan lenders (Ford Motor Credit, GM Financial, Toyota Financial, Honda Financial) increasingly demand documented security posture from their dealer network. The implied cost of failing the documented-controls check: floor-plan line reduction, rate increase, or onboarding rejection. Captive-finance arms of OEM dealer groups add a separate SofHIT signal — the dealer OEM expects a Safeguards-aligned SOC on the dealer side. Source: Floor-plan lender dealer onboarding disclosures; OEM captive-finance counter-party controls.
CoreRecon Delivers

Everything an Auto Dealer SOC Actually Needs. Nothing It Doesn't.

Auto dealers are not generic small businesses. CDK / Reynolds / Dealertrack DMS integrations, F&I desk credit-app flow with card-present PCI-DSS exposure, floor-plan lender draw workflows, captive-finance GLBA scope, and BDC workstation fleet security require a security architecture built for dealer workflows — not retrofitted from a CPA-firm template or a generic healthcare template.

🕐
Dealer-Aware 24/7 TX-Resident SOC
24/7/365 security operations center staffed by TX-based analysts who know that CDK, Reynolds & Reynolds, Dealertrack, RouteOne, and DealerSocket are not the same platform. Not an overseas NOC reading your CDK admin alert for the first time at 3 AM. A dealership GM at 11 PM on a Saturday during a CDK-style outage gets a live Texas analyst watching the BDC, F&I desk, and floor-plan AP flow.
30-Minute IR SLA
Contractual 30-min SLA — not "we'll get to it." Detection-to-containment within 30 minutes of confirmed breach, vs. industry 1–4 hour average. Documented in your MSA. The 30-min SLA is the difference between containing a CDK admin SSO stash and discovering six months later that your F&I PII was exfil'd by a pre-positioned operator during the original outage window.
🖥️
EDR on BDC + F&I Desk + DMS Admin Consoles
Next-gen EDR on the workstations that run CDK / Reynolds / Dealertrack dealer admin consoles, the BDC workstations running the deal-jack flow, the F&I desk credit-application terminals, and the service-writer workstations running CDK Service / Reynolds Service. Behavioral analytics catches lateral movement, credential dumping, and screen-capture of F&I credit-app data before the CDK cloud SSO is harvested.
📋
FTC Safeguards ISP + Qualified Individual Authorship
For dealers handling consumer financial information on credit applications, F&I contracts, or lease paperwork: written Information Security Plan authorship, formal Qualified Individual designation (FTC-acceptable outside-party designation under our vCISO service), 30-day notification workflow authorship, annual board/owner written report, vendor oversight program (Dealertrack / CDK / Reynolds / RouteOne integrations all in scope). Command tier deliverable.
🤝
TDPSA §541 Breach-Notification Workflow
Texas-resident consumer PII — driver's license scans on credit apps, deal-jack F&I paperwork, service-drive intake forms — handles TDPSA §541 exposure. Pre-built TDPSA breach-notification workflow that fires within hours of confirmed breach; coordinates with TX AG; assembles the consumer-notification distribution; tracks the 45-day consumer request response window. Default scope across all tiers.
💳
PCI-DSS v4.0.1 F&I Desk Monitoring
PCI-DSS v4.0.1 scope assessment and ongoing monitoring for the dealer's cardholder data environment — the F&I desk credit-card terminal, the service-drive payment terminal, the dealer-branded credit-card processing flow. EDR on the F&I workstation fleet with CDE-segmented visibility; quarterly ASV scan coordination; annual penetration testing; MFA enforcement on CDE access. Fortress tier deliverable.
SDVOSB + Dealer Group Counter-Party Wedge

SDVOSB Certified. Counter-Party Positioned for Floor-Plan Lenders & OEM Dealer Networks.

TX dealer groups have a counter-party edge that generic MSSPs don't service. SDVOSB positioning on OEM financed franchise purchases (Ford, GM, Stellantis, Honda, Toyota, Hyundai, Subaru, BMW, Mercedes-Benz, Volkswagen, Mazda, Mitsubishi, Nissan). Floor-plan lender (Ford Motor Credit, GM Financial, Toyota Financial, Honda Financial) documented-controls pressure on dealer onboarding. Captive-finance arms of major dealer groups add a separate SofHIT signal. TX Auto Dealers Association procurement channel.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's Center for Verification and Evaluation (CVE). USMC veteran-led team. TX franchised dealer groups and dealer-group captive finance arms can source SOC, ISP authorship, and Qualified Individual service from an SDVOSB without a separate RFP. DIR cooperative contract eligible (TIPS / BuyBoard).
OEM Financed Franchise Vendor Positioning
Major OEM financed franchise programs (Ford, GM, Stellantis, Honda, Toyota dealer network) increasingly require SOC-documented cybersecurity posture from dealership vendors. CoreRecon's CVE-verified SDVOSB certification streams vendor approval for cybersecurity services on franchise dealer groups. We produce the documentation an OEM dealer-network reviewer requires without a separate bid cycle.
Floor-Plan Lender Counter-Party Controls
Ford Motor Credit, GM Financial, Toyota Financial, Honda Financial increasingly require documented security posture from the dealer network at onboarding. The dealer group that can present an FTC-Safeguards-aligned ISP, a designated Qualified Individual, and a SOC-engaged endpoint/credential posture gets faster floor-plan line renewals and a documented-controls audit pass. The dealer group that cannot loses a floor-plan option at renewal — a credit-line shock to a multi-rooftop group.
Captive Finance SofHIT — Direct Arm Coverage
Dealer-group captive-finance arms (the credit arm of a major dealer group) operate as financial institutions under GLBA. Captive-finance IT is the Safeguards + GLBA envelope on the back half of the dealer-group's customer PII inventory — credit applications, lease contracts, loan tapes, payment records. CoreRecon services that envelope with the same SOC and vCISO framework as a community-bank or credit-union target.
Transparent Pricing — No "Contact Sales"

Published Rates. Month-to-Month. No 3-Year Lock-In.

CoreRecon publishes pricing because dealership GMs shouldn't need to spend 90 minutes on a sales call to learn whether a cybersecurity provider is in-bounds. Three tiers. Per-endpoint. All include 24/7 SOC coverage and 30-minute IR SLA.

Sentinel
$89/endpoint/mo
min. 10 endpoints
  • 24/7 SOC monitoring — TX-resident analysts
  • Endpoint detection & response (EDR)
  • BDC + F&I workstation telemetry
  • Floor-plan lender impersonation monitoring
  • Callback verification SOP template
Command
$2,500+/mo
flat-fee retainer
  • Everything in Fortress, plus:
  • Dedicated vCISO — designated FTC Qualified Individual
  • Full FTC Safeguards Rule ISP authorship
  • 30-day FTC notification workflow authorship
  • Annual board / owner written report
  • On-site incident response capability
  • Direct line to 24/7 IR team — no queue
30-minute IR SLA is contractual across all tiers — documented in your Master Service Agreement. Industry average response time: 1–4 hours (SANS 2024 IR Survey). We measure against that standard every month and report it to you.
SLA Proof

30 Minutes vs. Industry Standard: The Gap Is the Risk.

The 30-minute SLA isn't marketing — it's the difference between containment and dwell time. Ransomware operators complete the full attack chain (initial access → lateral movement → DMS credential harvesting → F&I PII exfil → encryption) in 45–90 minutes on average. Most MSSPs detect and respond within 1–4 hours. The window between what they offer and what ransomware actually does is where dealer groups lose everything — DMS credentials, F&I PII, floor-plan lender trust, FTC Safeguards compliance posture.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to you in your service review.
Median Dwell Time: Months
Median dwell time for retail / consumer-facing midsize breaches runs in the months band before detection. Dealer groups sit in this band because the F&I desk, BDC, and DMS environment rarely have a SOC engaged across the full workstation fleet. A 30-min SLA means we kill the chain in the active phase, not months later when the pre-positioned operator has already exfil'd the F&I PII and the credit-app data inventory.
Industry Average: 1–4 Hours
SANS 2024 IR Survey: median time from detection to containment is 1–4 hours for MSSP-monitored environments. By that time, DMS-side operators have usually completed F&I PII exfil, Dealertrack / RouteOne credit-app data staging, and lateral movement into the floor-plan AP terminal. Containment is still necessary — but the exfil bundle is already uploaded.
Ransomware Kill Chain: 45–90 Min
CrowdStrike 2024 Global Threat Report: average time from initial access to encryption is 45–90 minutes for human-operated ransomware. The dealers-targeted Akira / BlackSuit affiliates documented kill chains at the lower end of this range. A 30-min SLA puts us inside the kill chain. Anything slower means we're responding to a fully-executing attack, not containing one.
Compliance Mapping

Framework-to-Control Crosswalk for Texas Auto Dealerships

CoreRecon maps every SOC function to the specific regulation or framework that requires it. When your floor-plan lender, captive-finance counter-party reviewer, FTC examiner, TX AG breach examiner, or PCI-DSS QSA asks "what does your security program actually cover?", this is the answer.

Requirement FTC Safeguards / GLBA / PCI-DSS TDPSA / Counter-Party CoreRecon Control
Access Controls (AC) FTC §314.4(c)(1); PCI-DSS 7 TDPSA §541.062 MFA on Dealertrack SSO + F&I desk; RBAC on deal-jack access
Audit & Accountability (AU) FTC §314.4(c)(2); PCI-DSS 10 Floor-plan lender audit demands EDR + DMS audit log ingest; 6-year retention; dealer admin SSO monitoring
Configuration Management (CM) FTC §314.4(c)(3); PCI-DSS 11 OEM dealer-network baseline checks BDC + F&I workstation baseline configs; weekly drift detection
Identification & Authentication (IA) FTC §314.4(c)(4); PCI-DSS 8 Floor-plan lender MFA expectations MFA on CDK / Reynolds / Dealertrack portal; conditional access on dealer admin SSO
Incident Response (IR) FTC §314.4(i) 30-day notification TX AG TDPSA breach notice 30-min SLA + 30-day FTC notification workflow; pre-built dealer IR playbooks
Media Protection (MP) FTC §314.4(c)(5); PCI-DSS 9 TDPSA §541 media sanitization Encrypted DMS backups; media disposal documentation
Risk Assessment (RA) FTC §314.4(a)–(b); PCI-DSS 12 Annual dealer risk-assessment expectation Annual third-party risk assessment; dealer-group / multi-rooftop scope
Security Assessment (CA) FTC §314.4(c)(8); PCI-DSS 11.3 Floor-plan lender penetration-test demands Annual penetration test against F&I desk + DMS environment
System & Communications (SC) FTC §314.4(c)(6); PCI-DSS 1, 4 Counter-party network-segmentation asks DMS environment segmentation; encrypted in-transit credit-app data
System & Information Integrity (SI) FTC §314.4(c)(7); PCI-DSS 11.5 GLBA ongoing monitoring expectation EDR behavioral analytics on DMS-connected workstations; vulnerability patching
How We Compare

Built for Auto Dealers. Not a Generic Enterprise Package.

Cybriant, Arctic Wolf, and Huntress are real products with real strengths — Cybriant brings healthcare-adjacent MDR experience, Arctic Wolf has strong compliance reporting, and Huntress has excellent SMB-focused EDR. CoreRecon is built for dealer-group workflows from day one, with TX-resident analysts, CDK / Reynolds / Dealertrack-aware EDR, FTC Safeguards Rule ISP + Qualified Individual authorship, PCI-DSS v4.0.1 F&I desk scope assessment, and SDVOSB contracting at a published price.

Capability CoreRecon Cybriant Arctic Wolf Huntress
Pricing transparency Published: $89–$129/ep Annual contract (sales-led) Annual contract (sales-led) Per-deployment
TX-resident analyst Yes, USMC veteran-led SOC Distributed US-based Centralized SOC (US + offshore) Distributed US-based
CDK / Reynolds / Dealertrack aware EDR Yes — workstation telemetry + dealer admin SSO monitoring Generic EDR; no DMS model Aurora EDR; generic Huntress EDR; generic
FTC Safeguards Qualified Individual authorship Yes — designated QI on vCISO Not offered as standard Add-on via partner network Not offered
SDVOSB-certified Yes — CVE-verified No No No
30-min contractual IR SLA Yes — guaranteed in MSA Best-effort 1–4 hour response Best-effort
Pricing under $100/endpoint $89 Sentinel; min 10 endpoints Custom pricing (typically 4-figure floors) Custom pricing (~$200+/yr pricing) ~$110+/endpoint (per public docs)
DIR cooperative contracting Yes — TIPS / BuyBoard eligible Not directly listed Not directly listed Not directly listed
Captive finance GLBA exposure GLBA-mapped vCISO + ISP authorship Healthcare-SOC 2 angle Strong compliance reporting mature Limited reporting
Month-to-month Yes — Sentinel & Fortress Annual contract Annual contract Yes

Where we lose. Huntress is best-in-class at SMB EDR detection fundamentals; if your dealership prioritizes EDR signal alone over DMS-aware 24/7 SOC + FTC Safeguards ISP / Qualified Individual authorship, Huntress is a credible choice. Arctic Wolf's compliance reporting is more mature; if compliance dashboards are your priority and budget isn't, Arctic Wolf is solid. Cybriant's healthcare-adjacent positioning is a legitimate alternative if your dealership's IT is shared with a hospital-affiliated auto leasing or transport-medical operation.

Where we win. Published dealer pricing. CDK / Reynolds / Dealertrack DMS-aware EDR. FTC Safeguards ISP authorship with designated Qualified Individual at vCISO tier. 30-day FTC notification workflow authorship. PCI-DSS v4.0.1 F&I desk scope assessment. Floor-plan lender counter-party documented-controls readout. TX-resident analysts on dealer-DMS workflows. SDVOSB positioning for OEM-financed franchises and dealer-group captive-finance arms. 30-min contractual SLA in your MSA at $89–$129/endpoint.

See full competitor comparison →
Free Assessment — $2,500 Value

Find Out Where Your Dealership Actually Stands.

CoreRecon's Security Posture Assessment covers endpoint coverage across your BDC, F&I desk, and DMS admin workstations, CKD / Reynolds / Dealertrack attack surface, F&i credit-app data exposure, FTC Safeguards Rule §314 readiness, PCI-DSS v4.0.1 F&i desk scope, TDPSA breach-notification exposure, and a callback verification SOP on your floor-plan AP flow. It's free. Takes 20 minutes to complete. Written report with prioritized findings — not a sales deck.

What the Assessment Covers
Endpoint coverage audit — which BDC, F&I desk, accounting, and DMS admin workstations are actually monitored.
CDK / Reynolds / Dealertrack attack surface — dealer admin SSO credential posture + lateral movement baseline.
FTC Safeguards Rule §314 readiness — ISP authorship, Qualified Individual designation, MFA, encryption, IR plan, vendor oversight.
PCI-DSS v4.0.1 scope review — F&i desk card-present environment + service-drive payment terminal.
TDPSA + floor-plan lender counter-party exposure — TX-resident PII handling + wire-flow controls.
What You Get
Written security posture report — prioritized findings, not a risk matrix.
30-min debrief call with a TX-based analyst (not a sales rep).
Remediation roadmap — what to fix first, what can wait.
No obligation — if you're not a fit, we'll tell you.
Start Your Free Security Posture Assessment →
Client Voices

What Texas Dealer Group Owners Are Saying.

Social proof — quotes from TX dealer-group dealers, dealer-group IT directors, and GM principals who have onboarded with CoreRecon. PLACEHOLDER block (John to fill). Three short testimonials, each tied to a different outcome: CDK outage handled within SLA, floor-plan lender impersonation caught by SOC, FTC Safeguards ISP authorship leading to OEM dealer-network approval.

PLACEHOLDER — Quote 1
“PLACEHOLDER — quote from a TX dealer-group principal about how CoreRecon's 30-min SLA contained a CDK credential exfiltration during the June 2024 outage window. Name + dealer group + city.”
PLACEHOLDER — Quote 2
“PLACEHOLDER — quote from a TX dealer-group IT director about SOC email monitoring catching a Ford Motor Credit-impersonation bank-change request before the next floor-plan draw. Name + dealer group + city.”
PLACEHOLDER — Quote 3
“PLACEHOLDER — quote from a TX multi-rooftop dealer-group GM about Command tier's FTC Safeguards ISP authorship + Qualified Individual service clearing the OEM dealer-network review. Name + dealer group + city.”
Research Brief — July 2026

Download the TX Automotive Dealerships Threat Brief.

6 documented incidents. CDK Global (June 18 2024, ~15,000 dealers, ~$25M ransom). TX dealer group floor-plan BEC. Multi-rooftop DMS credential stash. Reynolds / Dealertrack DMS pattern. TX captive-finance breach. OEM counter-party pressure. Threat actor profile (Akira / BlackSuit / Blacksuit) and 30 verified sources. Print-ready PDF.

What's in the Brief
Named incidents: CDK Global (June 18 2024, ~15,000 dealers, ~$25M ransom), TX dealer-group floor-plan BEC impersonation, multi-rooftop DMS credential stash, Reynolds & Reynolds / Dealertrack (Cox Automotive) DMS pattern, TX captive-finance arm breach, OEM captive-finance counter-party pressure — 6 anchors with confirmed dates and vectors.

TX dealer regulatory stack: FTC Safeguards Rule 16 CFR §314 dealer amendment (eff. January 2023): written ISP, Qualified Individual, MFA, encryption, IR plan, 30-day notification, annual board / owner report; TDPSA §541 (consumer PII); PCI-DSS v4.0.1 (F&i desk card-present); GLBA (captive finance arm); floor-plan lender documented-controls counter-party pressure.
How to Get It
Gate: Name + firm email + phone. Takes 30 seconds.

Delivery: Instant access to the PDF. Confirmation email with link. No drip sequence.

Source tag: v48_automotive_dealerships_brief

30 sources including CDK Global incident disclosures (June 2024), FTC Safeguards Rule dealer amendment final rule (2023), 16 CFR §314 full text, FBI IC3 dealer BEC reporting, Reynolds / Dealertrack / Cox Automotive incident coverage, PCI SSC v4.0.1 auto-dealer scope guidance, GLBA 15 USC §6801–§6809, TX AG TDPSA enforcement records, Akamai / Corvus Insurance 2024–2025 auto retail breach analyses.
Download the V48 TX Automotive Dealerships Threat Brief →
FAQ

Questions Texas Auto Dealer Groups Ask Before Signing.

Direct answers. Not legal advice. Not a substitute for your breach counsel — but enough to know whether we're a fit.

Beacon EDR on every DMS-connected workstation (BDC, F&I desk, service writer, accounting, dealer admin); Conditional Access enforcement on the cloud DMS portal SSO; network-segmented visibility into the traffic between DMS-connected workstations and DMS infrastructure; authentication anomaly detection on DMS admin accounts. We do not replace the DMS platform itself — we add the SOC layer the DMS vendor's infrastructure cannot provide. Onboarding includes a CDK-specific threat hunt to identify any persistent access established during or after the June 2024 outage window.
Yes — at Command tier. Our vCISO can fulfill the FTC Safeguards Rule 16 CFR 314.4(a) requirement for a "qualified individual" responsible for the dealer's information security program, including the annual board / owner written report. The Qualified Individual must have relevant experience and can be an outside party under FTC guidance. Command tier delivers: ISP authorship and maintenance, annual risk assessment documentation, annual written report to dealer-group board / owners, vendor oversight program (Dealertrack / CDK / Reynolds / RouteOne integrations all in scope), and incident response plan. This satisfies the operational requirements under 16 CFR 314.4 for dealers with fewer than 5,000 customer records as well as larger multi-rooftop dealer groups.
Endpoints (BDC + F&I desk + service writer + accounting + DMS admin workstations) are counted under the per-endpoint pricing model, then aggregated into a single engagement so the SOC sees the entire dealer group. The CDK / Reynolds / Dealertrack administrative credential posture is included in the aggregate coverage; per-rooftop branch PCs are priced individually under the same per-endpoint framework. Field laptops and dealer-group captive-finance arm workstations roll into the same SOC dashboard view.
We'd argue the floor-plan line itself does not — but the fact that you carry it triggers the floor-plan lender's documented-controls check at renewal, and the lender will demand an FTC Safeguards-aligned posture. If your dealer group also operates a captive-finance arm that originates loans or leases, that arm is a financial institution under GLBA and faces the full privacy + Safeguards program expectations. Command tier includes GLBA compliance mapping for captive-finance arms and coordinates with your DMS vendor on data handling controls for financing records.
Pre-built dealer IR playbook: the moment the SOC sees lookalike-domain impersonation of Ford Motor Credit / GM Financial / Toyota Financial / Honda Financial on a bank-change request, we (1) freeze outbound wire flow on the AP workstation, (2) trigger the callback verification SOP (out-of-band callback to the lender's known number, not the contact info on the impersonation email), (3) preserve the impersonation email + headers for FBI IC3 reporting, (4) notify the dealer GM and the lender's AP fraud team. If a wire did go out, our IR team activates FBI IC3 reporting within hours. Recovery rate after 24 hours drops below 30% — the callback step is the single fix that stops 90%+ of floor-plan BEC.
Our monitoring runs on your endpoint and network infrastructure independently of CDK — we don't lose visibility when your DMS goes offline. During a CDK-style outage, our SOC continues watching your BDC workstations, F&I desk, and accounting terminals; identifies the social engineering and BEC risks that spike during paper-based manual fallback workflows; and stays inside the 30-minute detection-to-containment SLA against in-progress lateral movement, DMS-credential stuffing, or impersonation of your floor-plan lender. Fortress tier includes specific monitoring for the manual fallback workflows that activate during DMS outages.
Yes. Our standard agreement is month-to-month for Sentinel and Fortress. Command tier (dedicated vCISO + FTC Qualified Individual service + ISP authorship continuity) is a 12-month retainer for compliance continuity. There are no hidden termination fees for early exit on month-to-month tiers. We win on retention results at the dealer-group level — not contract lock-in. Rooftop closure transitions are scoped individually: we can remove endpoints and stop SOC coverage within 5 business days of notification.
📍 Texas-Based SOC
🎖️ SDVOSB-Certified (CVE)
🇺🇸 USMC Veteran-Led Team
🛡️ 24/7 SOC — 30-Min IR SLA
📋 FTC Safeguards §314 Mapped
🤝 Month-to-Month

CDK SSO. F&I PII. Floor-Plan Wire.
CoreRecon Protects All Three.

CDK Global went dark for ~15,000 dealers in June 2024. The 2024–2025 wave targets Texas dealer groups through CDK / Reynolds / Dealertrack credential theft, F&I credit-app data exfil, and floor-plan bank-change BEC fraud. FTC examiners are watching dealer-groups post-Safeguards-amendment enforcement. The only question is whether your rooftop has a documented FTC Safeguards ISP with a designated Qualified Individual — or a hope and a default cyber insurance carve-out.

Start the free assessment. Takes 20 minutes. Written report with prioritized findings. No sales deck.

Start Your Free Security Posture Assessment →