One weak password exposed personal information from 12.5 million consumers in a breach tied to 130 dealerships.
FTC penalties for violating an existing order reach $53,088 per violation. The often-repeated $43,792 figure dates from 2021 and is no longer current.
Use these seven checks to find your biggest FTC Safeguards Rule gaps in ten minutes.
#1 Written Information Security Program, WISP
Fine risk: An auditor asks for your written information security program. Your team produces an insurance questionnaire, an old policy binder, or nothing.
None of those meets the requirement.
The FTC Safeguards Rule requires a written program built around your dealership’s size, operations, systems, and customer information. A downloaded template with another dealer’s name removed will fall apart once an auditor asks how the policy works inside your store.
What FTC auditors ask for:
• Who is your Qualified Individual?
• Where is your written risk assessment?
• When did senior management receive the last written security report?
Your WISP should identify where customer information enters the dealership, where staff stores customer records, who receives access, and when records get deleted. Include paper deal jackets, shared drives, desktops, cloud storage, email, CRM records, DMS records, and vendor portals.
List the person responsible for every control. “IT department” is not a person.
The FTC requires periodic risk reassessments and a written report to the board or senior officer at least once each year. Keep signed copies, meeting notes, and proof of follow-up work.
ACTION: Ask your Qualified Individual for the current WISP, risk assessment, and last management report by Friday.
#2 Multi-Factor Authentication on DMS, CRM, and Email
Fine risk: One stolen password gives a criminal access to credit applications, driver’s licenses, Social Security numbers, payroll records, and customer email.
The FTC requires multi-factor authentication for anyone accessing customer information, unless the Qualified Individual approves an equivalent control in writing.
Check every login path. Dealers often protect Microsoft 365 or Google Workspace, then leave a CRM mobile app, remote desktop account, vendor portal, or former employee login outside MFA.
Force MFA on DealerSocket, VinSolutions, DealerLeads.com, your DMS, dealership email, remote access tools, cloud storage, and every system holding customer information.
Do not accept a vendor’s statement saying MFA is “available.” Ask whether MFA is mandatory for every dealership user, administrator, support technician, and third-party integration.
A Florida Honda dealership fine of $125,000 tied to this check does not appear in FTC public enforcement records. Do not publish the claim without a case number or order. The documented dealer-sector example is DealerBuilt. The FTC alleged weak authentication, missing access controls, and unencrypted data contributed to exposure of information belonging to about 12.5 million consumers.
ACTION: Pull an MFA status report for every user and disable unprotected access by Friday.
#3 Role-Based Access Controls
Fine risk: A salesperson, former employee, temporary worker, or vendor account sees records unrelated to the job.
Auditors look beyond whether a login exists. They look at what each login opens.
Map access by role. Sales staff rarely need full access to funded credit files. BDC staff rarely need Social Security numbers. Vendors should receive only the records required for contracted work.
Review:
• Customer Social Security numbers
• Driver’s license images
• Credit applications and bureau reports
• Bank and payment details
• Employee payroll and tax files
Remove shared accounts. Disable former employee access on the employee’s last day. Review administrator privileges each quarter and preserve the review record.
The FTC also expects monitoring of authorized-user activity. Turn on access logs for systems holding customer information. Decide who reviews alerts and how fast the owner must respond.
ACTION: Export all active users from your DMS, CRM, email, and file systems. Remove stale and excessive access by Friday.
#4 Employee Training and Phishing Tests
Fine risk: Your training vendor marks every employee “complete,” but nobody knows how to report a fake DocuSign request.
FTC guidance requires security awareness training and regular refreshers. The rule does not prescribe quarterly training, though quarterly sessions create a stronger record and address turnover common inside dealerships.
Run one short lesson and one phishing test every quarter. Cover fake password resets, fraudulent wire instructions, MFA approval bombing, malicious QR codes, customer-data downloads, and lost devices.
Document each session. Keep the date, topic, attendee list, completion report, test result, retraining record, and manager sign-off.
Training without records gives an auditor no proof. A completion spreadsheet without follow-up also looks weak when the same employee fails several tests.
Set a clear reporting route. Every employee should know one email address or phone number for suspected incidents. Speed matters more than certainty.
ACTION: Schedule the next phishing test and export the last four training reports by Friday.
#5 Data Encryption at Rest and in Transit, Plus Vendor Audits
Fine risk: A stolen laptop, exposed backup, or open vendor portal reveals readable customer information.
The rule calls for encryption on your systems and during transmission. Where encryption is infeasible, the Qualified Individual must approve effective alternative controls in writing.
Check databases, laptops, backups, file transfers, email attachments, shared drives, website forms, and vendor portals. Confirm encryption status with evidence, not a checkbox on a questionnaire.
The FTC’s DealerBuilt complaint provides a concrete warning. The agency alleged personal data sat and traveled in clear text. An insecure backup connection remained exposed for 18 months, and the breach affected dealer customer records.
Audit high-risk vendors yearly. Run quarterly exposure scans where contracts and systems permit. Request encryption standards, penetration-test summaries, breach history, access controls, subcontractor lists, cyber insurance, and incident-notification terms.
ACTION: Get written encryption confirmation from your five highest-risk vendors by Friday.
#6 Vendor Risk Assessment
Fine risk: Your CRM, DMS, website provider, call-recording platform, lead vendor, or document processor loses customer data. Your dealership still owns the compliance problem.
FTC guidance says dealerships must select capable service providers, place security duties in contracts, monitor vendor work, and reassess vendor suitability.
Build one vendor register. Record the data each company receives, the system connection, the business owner, contract date, renewal date, last security review, and termination process.
Every vendor touching customer information should sign an agreement covering safeguards, access limits, breach notice, subcontractors, record return or deletion, audit rights, and cooperation after an incident.
A generic confidentiality clause is too thin. Your agreement needs measurable security duties.
Start with vendors holding Social Security numbers, credit applications, driver’s licenses, payment details, or large customer lists. Review those vendors first.
ACTION: List every vendor with customer-data access and flag missing security agreements by Friday.
#7 Incident Response Plan
Fine risk: A breach starts Friday night. The GM calls the MSP, the MSP calls the software vendor, and nobody preserves logs or contacts counsel.
The Safeguards Rule requires a written incident response plan. The plan should name decision-makers, internal steps, communication routes, documentation procedures, system-recovery work, and post-incident review.
Build a contact sheet for the Dealer Principal, GM, Qualified Individual, IT provider, cyber insurer, breach counsel, forensic firm, OEM contact, and affected vendors.
The often-used “72-hour FTC deadline” is inaccurate. Under the Safeguards Rule, a financial institution must notify the FTC as soon as possible and no later than 30 days after discovering unauthorized acquisition involving at least 500 consumers’ unencrypted information. State laws, contracts, and insurance policies often impose different or shorter deadlines.
Your first 72 hours still matter. Isolate affected systems, preserve logs, stop unauthorized access, notify counsel and insurance, record every decision, and avoid wiping evidence.
Run a tabletop exercise twice each year. Use a realistic event, such as a compromised CRM administrator account.
ACTION: Print the response plan, verify every phone number, and run a 30-minute tabletop by Friday.
The Compliance Table
| Check | Risk Level | Time to Fix | Who Owns It |
| Written WISP | Critical | 1 to 3 days | Qualified Individual |
| MFA | Critical | 2 to 8 hours | IT lead and system owners |
| Role-based access | High | 4 to 8 hours | Department managers |
| Training and phishing tests | High | 1 day | HR and Qualified Individual |
| Encryption and vendor audits | Critical | 1 to 5 days | IT lead and vendor owners |
| Vendor risk assessment | High | 2 to 5 days | Compliance and legal |
| Incident response plan | Critical | 1 day | GM and Qualified Individual |
ACTION: Print this table, write one name beside every owner, and review open items Friday morning.
The 3 Biggest Mistakes Dealers Make
- Thinking IT handles compliance
Your MSP manages systems. Management owns the Safeguards Rule. The FTC expects a Qualified Individual, written risk decisions, vendor oversight, and senior-level reporting.
- Keeping no evidence
Screenshots, signed reports, access reviews, training logs, contracts, test results, and meeting notes prove work happened. Verbal assurances disappear during an audit.
- Running one annual compliance push
Dealership staff, vendors, systems, and threats change throughout the year. Review access and vendors quarterly. Update the risk assessment after major system or business changes.
ACTION: Put quarterly WISP, access, training, vendor, and incident-response reviews on the management calendar by Friday.
The Bottom Line
Start with the WISP and MFA this week. Those checks establish ownership and block a common route into customer systems.
Do not claim they cover 70% of fines. No public FTC dataset supports that percentage. The stronger statement is simpler. Missing documentation leaves no defense, and missing MFA leaves an open door.
For the FTC Safeguards Rule dealership 2026 review, keep one evidence folder with the WISP, risk assessment, user-access reports, training records, encryption proof, vendor agreements, test results, incident plan, and annual management report.
ACTION: Assign one executive owner and hold a 20-minute compliance review by Friday.
Related: 8 CRM Automations That Recover Cold Leads
Sponsored by Gas.net — powering dealership growth through intelligent data.
Alt text: “Gas.net connects franchise dealers with integrated analytics and marketing tools.”