Last Updated: July 2026

Disclaimer: This article is intended to help auto dealerships better understand the FTC Safeguards Rule and its cybersecurity requirements. It is provided for educational purposes only and should not be considered legal advice. Dealerships should consult qualified legal or compliance professionals regarding their specific obligations.

FTC Safeguards Rule compliance checklist for auto dealerships

Introduction

If your auto dealership collects customer financial information, the FTC Safeguards Rule likely applies to your business.

The Rule requires financial institutions, including many auto dealerships, to develop, implement, and maintain a comprehensive information security program that protects customer information from unauthorized access, misuse, or disclosure.

For many dealership owners and managers, the regulation can seem overwhelming. The Rule includes administrative, technical, and physical safeguards, ongoing risk assessments, employee training, vendor oversight, and continuous monitoring. Fortunately, the goal is much simpler than the regulation itself.

The objective is to build and maintain a cybersecurity program that helps protect your dealership, your employees, and your customers' information.

This guide explains the FTC Safeguards Rule in plain English and provides a practical checklist you can use to evaluate your dealership's cybersecurity program. You'll also learn where a managed IT provider can assist and which responsibilities remain with your dealership.

FTC Safeguards Rule at a Glance

Requirement Summary
Who it applies to Many auto dealerships that handle customer financial information
Primary goal Protect customer information through a written information security program
What it requires Risk assessments, administrative safeguards, technical safeguards, employee training, vendor oversight, ongoing monitoring, and regular reviews
One-time project? No. Compliance requires ongoing maintenance and periodic review.
Can a managed IT provider help? Yes. A managed IT provider can help implement and maintain many technical safeguards, support documentation, assist with risk assessments, and help maintain your Written Information Security Program (WISP). Your dealership remains responsible for compliance.

Why This Matters

The FTC Safeguards Rule is not simply an IT requirement.

It is a business requirement.

Protecting customer information requires participation from dealership leadership, finance, human resources, and IT. While technology plays an important role, compliance also depends on documented policies, employee training, vendor management, and ongoing oversight.

Many dealerships already have some of the required security measures in place. The challenge is ensuring those safeguards are documented, maintained, reviewed regularly, and work together as part of a comprehensive security program.

That is exactly what this guide is designed to help you understand.

Does the FTC Safeguards Rule Apply to My Dealership?

For most auto dealerships, the answer is yes.

The FTC Safeguards Rule applies to financial institutions that collect, process, or maintain customer financial information. Because many dealerships assist customers with financing, lease transactions, or credit applications, they are generally considered financial institutions under the Rule.

If your dealership:

  • Accepts credit applications
  • Arranges vehicle financing or leasing
  • Collects or stores customer financial information
  • Shares financial information with lenders

the FTC Safeguards Rule likely applies to your business.

The Rule is not limited to large dealership groups. Smaller dealerships that handle customer financial information are also expected to develop and maintain an information security program appropriate for the size and complexity of their business.

Rather than requiring every dealership to implement the exact same security measures, the Rule takes a risk-based approach. That means your security program should reflect your dealership's operations, the sensitivity of the information you handle, and the risks facing your organization.

For example, a single-rooftop dealership with 35 employees will likely have different cybersecurity needs than a multi-location dealership with hundreds of employees. Both are expected to protect customer information, but the safeguards they implement should be appropriate for their environment.

The important takeaway is that compliance is not about checking boxes or purchasing a specific security product. It is about developing and maintaining a security program that helps protect customer information while supporting the way your dealership operates.

What Is Customer Information?

One area that often causes confusion is the term customer information.

In general, customer information includes nonpublic personal information that your dealership collects in connection with providing a financial product or service.

Examples may include information contained in:

  • Credit applications
  • Financing documents
  • Lease applications
  • Income and employment information
  • Driver's license information
  • Social Security numbers
  • Bank account information
  • Other financial records collected during the sales or financing process

Because this information is valuable to cybercriminals, protecting it is one of the primary goals of the FTC Safeguards Rule.

Compliance Is an Ongoing Process

One of the biggest misconceptions about the FTC Safeguards Rule is that compliance is a one-time project.

It isn't.

Your dealership's technology, employees, vendors, and cybersecurity risks change over time. New computers are deployed, employees join and leave the organization, software is updated, and cyber threats continue to evolve.

For that reason, your information security program should also evolve.

Compliance involves regularly reviewing your security program, documenting changes, evaluating risks, training employees, and updating safeguards as your business and technology change.

The goal is continuous improvement, not simply completing a checklist once and assuming the work is finished.

Part 1: Build Your Information Security Program

The FTC Safeguards Rule requires dealerships to develop and maintain a comprehensive information security program. While the Rule contains many detailed requirements, they can be organized into practical steps that make compliance easier to understand.

Use the checklist below as a starting point to evaluate your dealership's security program. Every dealership is different, so your specific requirements may vary based on your operations, technology environment, and risk profile.

□ Designate a Qualified Individual

One of the first requirements of the FTC Safeguards Rule is to designate a Qualified Individual responsible for overseeing your information security program.

This person is responsible for coordinating your dealership's security program, helping ensure safeguards are implemented, and reporting on the effectiveness of the program to management.

Depending on your dealership, the Qualified Individual may be an employee or an outside resource with the appropriate knowledge and experience.

Questions to Ask Yourself

  • Has our dealership formally designated a Qualified Individual?
  • Is that person actively overseeing our information security program?
  • Does leadership receive regular updates on cybersecurity and risk?

How a Managed IT Provider Can Help

A managed IT provider can support the Qualified Individual by implementing technical safeguards, providing documentation, monitoring systems, and helping maintain the security program. Some providers may also serve as the Qualified Individual if that responsibility is formally assigned.

□ Conduct a Risk Assessment

Every dealership should understand the risks facing its business.

A risk assessment helps identify where customer information is stored, how it is protected, and where vulnerabilities may exist. It also helps determine whether existing safeguards are appropriate for your dealership's environment.

A risk assessment is not something you perform once and forget. It should be reviewed periodically as your business, technology, and cybersecurity risks change.

Questions to Ask Yourself

  • Do we know where customer information is stored?
  • Have we identified the systems that present the greatest risk?
  • Have we documented the results of our risk assessment?
  • When was the last time it was reviewed?

How a Managed IT Provider Can Help

A managed IT provider can assist by identifying technical risks, performing vulnerability assessments, reviewing security controls, documenting findings, and helping prioritize remediation efforts.

□ Create and Maintain a Written Information Security Program (WISP)

The FTC Safeguards Rule requires dealerships to maintain a Written Information Security Program (WISP).

A WISP documents how your dealership protects customer information, identifies risks, assigns responsibilities, and describes the safeguards your organization has implemented.

It should not be viewed as a document that sits on a shelf. As your business changes, your WISP should be reviewed and updated to reflect new technologies, changing risks, and operational changes.

Questions to Ask Yourself

  • Do we have a documented WISP?
  • Does it accurately reflect how our dealership operates today?
  • Has it been reviewed and updated recently?
  • Are employees following the documented procedures?

How a Managed IT Provider Can Help

A managed IT provider can help develop and maintain your WISP, provide templates, document technical safeguards, create standard operating procedures (SOPs), and help ensure the documentation reflects your current technology environment.

□ Implement Administrative, Technical, and Physical Safeguards

The FTC Safeguards Rule requires dealerships to implement safeguards that are appropriate for their business and the risks they face.

These safeguards generally fall into three categories:

  • Administrative safeguards, such as policies, procedures, employee training, and vendor management.
  • Technical safeguards, such as multi-factor authentication, endpoint protection, vulnerability management, encryption, and system monitoring.
  • Physical safeguards, such as securing areas where customer information is stored, restricting access to sensitive systems, and protecting equipment from unauthorized access.

No single safeguard is enough on its own. The goal is to build multiple layers of protection that work together to reduce risk.

Questions to Ask Yourself

  • Are our policies documented and followed?
  • Have we implemented appropriate technical security controls?
  • Is physical access to sensitive systems restricted?
  • Do our safeguards reflect today's cybersecurity risks?

How a Managed IT Provider Can Help

A managed IT provider can implement and maintain many of the technical safeguards required to support your information security program while helping document and monitor those controls over time.

Part 2: Protect Your Dealership's Environment

Once your dealership has established its information security program, the next step is implementing the technical safeguards that help protect customer information and reduce cyber risk.

The FTC Safeguards Rule does not prescribe a one-size-fits-all security solution. Instead, it expects dealerships to implement safeguards that are appropriate for their size, complexity, and risk profile.

The following controls are commonly included in a comprehensive cybersecurity program.

□ Implement Strong Access Controls

Employees should have access only to the systems and information they need to perform their job responsibilities.

Limiting access reduces the risk of unauthorized disclosure, accidental changes, and compromised accounts.

Access permissions should also be reviewed regularly to ensure employees who change roles or leave the dealership no longer have unnecessary access.

Questions to Ask Yourself

  • Does every employee have a unique user account?
  • Do employees only have access to the systems they need?
  • Are former employees removed promptly?
  • Are privileged accounts limited to authorized personnel?

How a Managed IT Provider Can Help

A managed IT provider can help establish role-based access, manage employee onboarding and offboarding, review user permissions, and periodically audit privileged accounts.

□ Use Multi-Factor Authentication (MFA)

Passwords remain one of the most common ways attackers gain access to business systems.

Multi-factor authentication adds an additional layer of security by requiring users to verify their identity using something beyond a password, such as an authentication application or security key.

When implemented properly, MFA significantly reduces the likelihood of unauthorized access caused by stolen or compromised credentials.

Questions to Ask Yourself

  • Is MFA enabled for Microsoft 365 and other cloud services?
  • Is MFA required for remote access?
  • Are administrator accounts protected with MFA?
  • Are employees using modern authentication methods instead of text message codes where practical?

How a Managed IT Provider Can Help

A managed IT provider can deploy and manage MFA, assist employees during enrollment, monitor authentication issues, and review MFA policies as part of an ongoing cybersecurity program.

□ Encrypt Sensitive Information

Encryption helps protect sensitive information by making it unreadable to unauthorized individuals.

Depending on your environment, encryption may apply to data stored on computers and servers, portable devices, cloud services, and information transmitted across networks.

Encryption is one component of a layered security strategy and should be combined with strong access controls, backups, and ongoing monitoring.

Questions to Ask Yourself

  • Are laptops encrypted?
  • Is sensitive information encrypted when appropriate?
  • Are encryption keys managed securely?
  • Do we understand where sensitive information is stored?

How a Managed IT Provider Can Help

A managed IT provider can help configure encryption technologies, verify encryption status, monitor compliance, and document encryption practices within your information security program.

□ Perform Vulnerability Scanning

New software vulnerabilities are discovered every day.

Regular vulnerability scanning helps identify systems that may require security updates, configuration changes, or other corrective actions before they are exploited.

Scanning should be performed regularly and reviewed as part of your ongoing cybersecurity program.

Questions to Ask Yourself

  • When was our last vulnerability scan?
  • Are identified vulnerabilities reviewed and prioritized?
  • Are critical vulnerabilities addressed promptly?
  • Are scan results documented?

How a Managed IT Provider Can Help

A managed IT provider can perform scheduled vulnerability scans, review findings with your dealership, prioritize remediation efforts, and document corrective actions.

Note: Vulnerability scanning is designed to identify known weaknesses. Penetration testing is a separate service that actively evaluates how those weaknesses might be exploited and is often performed periodically or when required by your organization's risk management strategy.

□ Monitor Your Systems Continuously

Cybersecurity is not something that can be reviewed once each year.

Networks, computers, and cloud services should be monitored continuously to help identify unusual activity, system failures, and potential security incidents.

Early detection often allows organizations to respond more quickly and reduce the impact of an incident.

Questions to Ask Yourself

  • Are our critical systems monitored around the clock?
  • Who reviews security alerts?
  • Do we have a documented process for responding to incidents?
  • Are monitoring tools tested regularly?

How a Managed IT Provider Can Help

A managed IT provider can monitor endpoints, servers, firewalls, and cloud services, investigate security alerts, assist with incident response, and help maintain documentation of security events.

□ Train Employees Regularly

Even with strong technical safeguards, employees remain an important part of your dealership's cybersecurity program.

Regular security awareness training helps employees recognize phishing emails, social engineering attempts, password-related risks, and other common cyber threats.

Training should be ongoing and reinforced as new threats emerge.

Questions to Ask Yourself

  • Do employees receive cybersecurity awareness training?
  • Are phishing simulations conducted periodically?
  • Is training documented?
  • Are new employees trained during onboarding?

How a Managed IT Provider Can Help

A managed IT provider can deliver security awareness training, conduct phishing simulations, provide reporting, and help your dealership document participation as part of its overall security program.

Part 3: Maintain and Improve Your Security Program

Implementing security controls is an important milestone, but it's not the finish line.

Technology changes. Employees join and leave the organization. Software is updated. New cyber threats emerge every day. A security program that isn't reviewed and maintained will become less effective over time.

The FTC Safeguards Rule recognizes this by requiring dealerships to regularly evaluate and improve their information security program.

The following practices help ensure your program continues to evolve as your business and technology change.

□ Review Third-Party Service Providers

Many dealerships rely on outside companies to provide technology services, cloud applications, payment processing, website hosting, payroll, marketing, and other business functions.

These vendors may have access to sensitive customer information or systems that support your dealership's operations.

As part of your information security program, you should understand what information your vendors can access and evaluate whether they have appropriate safeguards in place.

Questions to Ask Yourself

  • Have we identified vendors that access customer information?
  • Do we understand how those vendors protect sensitive data?
  • Are vendor security expectations documented where appropriate?
  • Do we periodically review our critical service providers?

How a Managed IT Provider Can Help

A managed IT provider can help identify technology vendors, document system access, review security practices, and coordinate with vendors when security issues arise.

□ Test and Monitor Your Security Controls

Security controls should not simply be implemented and forgotten.

Regular testing helps verify that your safeguards continue to function as expected and identifies opportunities for improvement before problems occur.

Examples include:

  • Reviewing vulnerability scan results
  • Testing backup restoration
  • Reviewing security alerts
  • Verifying endpoint protection
  • Evaluating user access permissions

Regular testing helps ensure your security program continues to support your dealership's changing environment.

Questions to Ask Yourself

  • When were our backups last tested?
  • Are vulnerability scan findings being addressed?
  • Are security alerts reviewed regularly?
  • Are our security controls functioning as intended?

How a Managed IT Provider Can Help

A managed IT provider can perform ongoing vulnerability scanning, review security events, validate backup operations, monitor critical systems, and help document testing activities.

□ Prepare for Security Incidents

No organization can eliminate every cybersecurity risk.

Having a documented process for responding to security incidents helps your dealership react more effectively if an event occurs.

An incident response process should identify key responsibilities, communication procedures, escalation steps, and recovery priorities before they are needed.

Planning ahead often reduces confusion during stressful situations and helps restore normal operations more efficiently.

Questions to Ask Yourself

  • Do we have a documented incident response process?
  • Does everyone know who to contact during a security incident?
  • Have we identified our critical business systems?
  • Have we discussed recovery priorities?

How a Managed IT Provider Can Help

A managed IT provider can assist with incident response planning, monitor systems for suspicious activity, coordinate technical recovery efforts, and help document lessons learned following an incident.

□ Review and Update Your Information Security Program

Your Written Information Security Program (WISP) should be a living document.

As your dealership grows, adopts new technology, changes vendors, or responds to emerging cyber threats, your documentation should evolve as well.

Regular reviews help ensure your security program continues to reflect how your dealership actually operates.

A program that is reviewed, maintained, and improved over time is far more valuable than one that is created once and never revisited.

Questions to Ask Yourself

  • When was our WISP last reviewed?
  • Does it accurately reflect our current technology environment?
  • Have policies and procedures been updated as our business has changed?
  • Are changes documented?

How a Managed IT Provider Can Help

A managed IT provider can help review your WISP, update technical documentation, maintain standard operating procedures, document security changes, and support ongoing compliance efforts throughout the year.

Compliance Is a Continuous Process

It's easy to think of compliance as a project with a clear finish line.

In reality, effective cybersecurity requires continuous attention.

As technology evolves, new employees are hired, software is updated, and cyber threats change, your security program should evolve as well.

Rather than asking, "Are we compliant?", a better question is:

"Are we continuously improving our ability to protect customer information?"

That mindset aligns with both the intent of the FTC Safeguards Rule and the practical realities of operating a modern dealership.

FTC Safeguards Rule compliance framework for auto dealerships

Lessons Learned from a Cybersecurity Incident

Cybersecurity incidents rarely happen because of a single failure.

More often, they occur when several small issues accumulate over time. An outdated computer isn't replaced. A user account has more access than it needs. Multi-factor authentication isn't enabled everywhere. Security policies haven't been reviewed in years.

Individually, these issues may not seem significant.

Together, they create opportunities for attackers.

We experienced this firsthand while helping a dealership recover from a cybersecurity incident.

Although the dealership was ultimately able to recover, the process required far more than restoring files or replacing equipment. Management spent countless hours coordinating with vendors, evaluating systems, strengthening security controls, and restoring normal business operations.

The financial cost of recovery was only part of the impact.

Employees experienced disruptions to their daily work, leadership devoted valuable time to managing the incident, and security improvements that had been deferred suddenly became urgent priorities.

The experience reinforced an important lesson.

Cybersecurity is far less expensive -- and far less disruptive -- when it is approached proactively rather than reactively.

Compliance Is More Than Passing an Audit

One of the biggest misconceptions about the FTC Safeguards Rule is that compliance is simply about satisfying a regulatory requirement.

In reality, the FTC Safeguards Rule promotes many of the same security practices that help businesses reduce cyber risk every day.

A documented information security program, regular risk assessments, employee training, vulnerability management, and ongoing monitoring are not just compliance activities. They are practical business practices that help protect your dealership, your employees, and your customers.

Viewed this way, compliance becomes more than a checklist.

It becomes part of a long-term strategy for managing technology responsibly.

A Strong Security Program Supports the Entire Dealership

An effective information security program benefits more than your IT department.

It helps:

  • Protect customer information
  • Reduce business disruption
  • Support cyber insurance requirements
  • Improve consistency across locations and departments
  • Strengthen employee cybersecurity awareness
  • Provide leadership with greater visibility into technology risks
  • Create documentation that supports audits and regulatory reviews

Most importantly, it helps your dealership continue serving customers with confidence.

Technology should support your dealership, not become a source of unnecessary risk or disruption.

Frequently Asked Questions About the FTC Safeguards Rule

Does the FTC Safeguards Rule apply to every auto dealership?

Many auto dealerships are subject to the FTC Safeguards Rule because they collect, process, or maintain customer financial information in connection with financing or leasing vehicles. If your dealership handles credit applications or works with lenders, the FTC Safeguards Rule likely applies.

Is the FTC Safeguards Rule only an IT responsibility?

No.

While technology plays a significant role, compliance requires participation from dealership leadership, finance, human resources, and IT. Policies, employee training, vendor management, documentation, and ongoing oversight are all important parts of an effective information security program.

What is a Written Information Security Program (WISP)?

A Written Information Security Program (WISP) is a documented plan that describes how your dealership protects customer information. It identifies risks, defines responsibilities, documents security safeguards, and establishes procedures for maintaining and improving your information security program.

Your WISP should be reviewed and updated regularly as your dealership, technology, and cybersecurity risks change.

Does having antivirus software make my dealership compliant?

No.

Antivirus software is only one component of a comprehensive cybersecurity program. The FTC Safeguards Rule expects dealerships to implement a combination of administrative, technical, and physical safeguards that work together to protect customer information.

Do I need vulnerability scanning or penetration testing?

Most dealerships should perform regular vulnerability scanning as part of their cybersecurity program.

Penetration testing serves a different purpose. It is a more in-depth evaluation designed to identify how an attacker might exploit weaknesses in your environment. Depending on your dealership's size, complexity, and risk profile, penetration testing may also be appropriate.

Can a managed IT provider make my dealership compliant?

A managed IT provider can help implement many of the technical safeguards that support compliance, including vulnerability scanning, system monitoring, multi-factor authentication, endpoint protection, employee security awareness training, documentation, and maintaining your Written Information Security Program.

However, your dealership remains responsible for its compliance program and meeting the requirements of the FTC Safeguards Rule.

How often should we review our security program?

Your security program should be reviewed regularly and whenever significant changes occur, such as implementing new technology, opening another location, changing vendors, or responding to a security incident.

Compliance is an ongoing process, not a one-time project.

What happens if we experience a cybersecurity incident?

Even organizations with strong security programs can experience cybersecurity incidents.

The goal of the FTC Safeguards Rule is not to eliminate every risk. It is to reduce risk, strengthen your security posture, and improve your ability to detect, respond to, and recover from security events.

Having a documented information security program, tested backups, an incident response plan, and ongoing monitoring can significantly improve your dealership's ability to respond effectively.

Conclusion

The FTC Safeguards Rule is about more than meeting a regulatory requirement. It provides a framework for protecting customer information and reducing cybersecurity risk through thoughtful planning, documented processes, and ongoing improvement.

For many dealerships, the biggest challenge isn't understanding that cybersecurity is important. It's knowing where to begin and how to maintain a security program as technology, regulations, and business needs continue to evolve.

By developing a Written Information Security Program, implementing appropriate safeguards, training employees, documenting procedures, and reviewing your program regularly, your dealership can build a stronger security foundation while supporting its compliance efforts.

The goal isn't to check a box once and move on.

The goal is to create a security program that helps protect your customers, supports your employees, and strengthens your dealership for the long term.

Ready to Evaluate Your Dealership's Security Program?

If you're unsure whether your dealership's cybersecurity program aligns with the FTC Safeguards Rule, the best place to start is with a structured assessment of your current environment.

At Tech-Marvel, we help dealerships develop practical, security-focused compliance programs by assisting with:

  • Risk assessments
  • Written Information Security Programs (WISPs)
  • Standard Operating Procedures (SOPs)
  • Vulnerability scanning
  • Technical safeguard implementation
  • Security awareness training
  • Ongoing documentation and compliance support

Whether you're building a security program from the ground up or strengthening an existing one, our goal is to help you create a program that is practical, well documented, and aligned with the way your dealership operates.

Schedule a Complimentary IT Assessment to review your current environment, identify opportunities for improvement, and discuss how your dealership can strengthen its cybersecurity and support its FTC Safeguards Rule compliance.