Buying another dealership is about much more than the building, inventory, employees, franchise agreement, and financials.
You are also inheriting a technology environment that may have been built over many years by different employees, IT companies, software vendors, internet providers, and managers. Some of it may fit the way your dealer group already operates. Some of it may need attention immediately. And some things may work perfectly well even though they are different from what you use at your other locations.
The challenge is knowing which is which.
Before and immediately after acquiring an auto dealership, the buyer should review the dealership's technology assets, DMS and business systems, vendor relationships, employee and administrator access, cybersecurity controls, backups, remote access, network and internet environment, documentation, and integration priorities.
The goal is not to replace everything on Day 1. It is to understand what you are inheriting before an overlooked account, aging piece of equipment, unknown vendor, or undocumented system becomes your problem.
Here are 10 areas I would want a dealer group to understand.
1. Inventory the Technology You're Actually Buying
Start with the basics:
What is there?
That sounds simple, but an acquisition can include technology spread throughout the showroom, offices, service department, parts department, accounting area, equipment rooms, and sometimes other buildings on the property.
The inventory may include:
- Desktop computers
- Laptops
- Servers
- Network switches
- Firewalls
- Wi-Fi access points
- Printers and scanners
- Phones
- Security cameras and recording equipment
- Door-access systems
- Backup equipment
- TVs and digital displays
- Service-related technology
- Internet connections
- Other connected devices
You also want to understand the software and services behind those physical devices.
NIST's Cybersecurity Framework 2.0 recommends maintaining inventories of hardware, software, systems, supplier-provided services, and relevant data because you cannot effectively manage technology risk without knowing what the organization has.
For an acquisition, the inventory gives you a starting point.
It can reveal equipment that is already approaching replacement, technology that is unsupported, systems nobody seems to own, or devices that may not need to move forward with the new organization.
But do not turn the inventory into an automatic replacement list.
If a switch is working properly, supported, appropriately configured, and fits the group's standards, there may be no business reason to replace it simply because another brand is used at your other locations.
Understand first. Standardize second.
2. Understand the DMS, CRM, OEM, and Other Critical Dealership Systems
The acquired dealership may depend on a different collection of business systems than your existing rooftops.
Start with the dealer management system (DMS), but do not stop there.
Review systems used for:
- CRM and lead management
- F&I
- Lender access
- OEM portals
- Inventory and pricing
- Service scheduling
- Parts
- Accounting
- Payroll and HR
- Customer communications
- Payments
- Websites and digital retailing
- Email and productivity
- Other dealership-specific workflows
For each important application, ask:
- What system are they using?
- Who owns the contract?
- When does it renew?
- Who administers user accounts?
- What integrations depend on it?
- Is it being retained after the acquisition?
- Will it eventually be consolidated with another system?
- Are there special network or hardware requirements?
- Which employees depend on it every day?
The technology decision should follow the business decision.
If the dealer group has already decided to migrate the acquired dealership to another DMS, that creates one integration plan.
If the acquired system will remain in place for several years, that creates a different one.
The biggest mistake is assuming that because a system is being replaced eventually, nobody needs to understand it today.
Employees still have to use it during the transition.
3. Identify Every Technology Vendor and Contract
An acquired dealership can come with a surprising number of outside technology relationships.
The obvious ones might include the DMS provider and internet carrier, but there may also be separate vendors for:
- Phones
- CRM
- Copiers
- Security cameras
- Door access
- Websites
- Digital retailing
- Payment systems
- Cybersecurity
- Backups
- Managed IT
- Service software
- OEM systems
- Specialty equipment
Create a vendor list and determine what each company actually provides.
Then ask:
- Who is the primary contact?
- Who has authority to make changes?
- Is there a current contract?
- When does it renew?
- Does the agreement transfer with the acquisition?
- Does the vendor have remote access?
- Is the service still needed?
- Does another company in your group already provide the same function?
Cybersecurity belongs in this conversation too. NIST's CSF 2.0 recommends knowing and prioritizing suppliers, performing due diligence around third-party relationships, and managing supplier risk throughout the relationship.
For auto dealerships subject to the FTC Safeguards Rule, certain service-provider relationships can also create specific oversight obligations when those providers receive customer information or access systems containing it. The FTC says covered financial institutions should take reasonable steps to select capable service providers, require appropriate safeguards by contract, and periodically assess them based on risk.
From a business perspective, though, the immediate question is straightforward:
Which vendors are we inheriting, and which ones do we actually want to keep?
4. Review Employee, Administrator, and Former-Employee Access
An acquisition is an excellent time to clean up access because ownership, responsibilities, and employment status may all be changing at once.
Start with current employees.
Who has access to:
- DMS
- CRM
- OEM portals
- Lender systems
- Accounting
- Payroll
- Shared files
- Remote access
- Administrator accounts
- Vendor portals
- Microsoft 365 or Google Workspace
Then look beyond current employees.
Are there former employees whose accounts were never removed?
Are there old administrator accounts?
Are people sharing credentials because “that's how we've always done it”?
Does the outgoing IT company still have administrative access?
What about former managers, consultants, vendors, or employees of the previous ownership group?
NIST CSF 2.0 calls for organizations to manage identities and credentials and to define, enforce, and review access permissions based on appropriate need.
For covered dealerships, the FTC Safeguards Rule also requires access controls and addresses multi-factor authentication for people accessing covered information systems.
You do not want to discover three months after closing that someone who no longer works for the dealership can still sign into an important system.
This also connects directly to having a consistent employee onboarding and offboarding process across the dealer group.
5. Establish the Cybersecurity Baseline You're Inheriting
Do not start with: “What cybersecurity products do they have?”
Start with: “What protections are actually in place?”
The acquired dealership may have several security products and still have gaps. Or it may use different products from your dealer group while still having reasonable controls.
Review areas such as:
- Multi-factor authentication
- Endpoint protection
- Email security
- Security monitoring
- Patch management
- Supported operating systems
- Administrator privileges
- Remote access
- Employee security training
- Firewall and network security
- Vendor access
- Incident response
- Backup security
The important question is whether the acquired location meets the security standard your dealer group expects, not whether every product has the same logo.
If your group requires MFA, confirm where it is enabled.
If every workstation is expected to have managed endpoint protection, confirm actual coverage.
If administrator access is supposed to be restricted, determine who currently has it.
This gives leadership a much clearer answer than:
“Their IT company says they're secure.”
An acquisition is a good time to establish what is known, what needs to be verified, and what genuinely needs attention.
6. Find Out Whether the Backups Actually Work
Acquisitions can create assumptions around backups.
The seller says everything is backed up.
The IT provider says backups run every night.
The DMS is hosted somewhere else.
Microsoft 365 is in the cloud.
Everything sounds covered.
But those statements do not necessarily tell you:
- What is being backed up
- What is not being backed up
- Who is responsible for each system
- Where the backups are stored
- Who can access them
- How long information is retained
- Whether backup failures are monitored
- Whether anyone has tested a restoration
Those questions matter because after closing, the new owner may inherit responsibility for recovering some of that information if something goes wrong.
NIST's cybersecurity guidance emphasizes managing technology and data throughout their life cycles and verifying backup integrity before relying on backups during recovery.
For the acquisition review, separate the systems into categories.
Vendor-hosted systems: What does the vendor protect, and what remains the dealership's responsibility?
Cloud business data: What happens to email, OneDrive, SharePoint, Google Drive, or other cloud information?
Local information: Are there file servers, workstations, accounting files, databases, or other information stored locally?
Specialized dealership systems: Who owns backup and recovery responsibility?
Then ask the most useful question:
When was the last time somebody actually confirmed we could recover what we're expecting to recover?
7. Determine Which Vendors Still Have Remote Access
This deserves its own review because dealerships can accumulate remote-access tools over many years.
A DMS vendor needs access.
The phone vendor needs access.
The camera company installed something.
The copier company connected remotely.
The previous IT provider used a remote-management tool.
A software vendor needed temporary access during an installation.
Nobody necessarily did anything wrong.
The problem is that temporary access can become permanent simply because nobody goes back and reviews it.
For every remote-access method you find, determine:
- Who uses it?
- What can they reach?
- Is the access still necessary?
- Is it tied to an individual account?
- Is MFA being used where required or appropriate?
- Who approves access?
- Can activity be monitored?
- How will access be removed when the relationship ends?
FTC dealership guidance specifically notes that service providers given direct access to a covered dealership's network are subject to the dealership's applicable access-control requirements, including MFA or a reasonably equivalent control.
An acquisition gives you a natural point to ask:
Do all of these outside companies still need a key to the new dealership we're buying?
If the answer is no, remove the access.
8. Review the Network, Wi-Fi, Internet, and Phones
Every dealership has accumulated some history in its network.
A switch was added when the service department expanded.
A wireless access point went in because the waiting room had poor coverage.
The internet provider changed.
Another circuit was installed.
The phone system was replaced.
A camera contractor added equipment.
Years later, everything may still work - but nobody has a clear picture of how it all fits together.
During the acquisition review, understand:
- Internet providers and circuits
- Backup/failover connectivity
- Firewall
- Network switches
- Wi-Fi
- Guest wireless access
- Network segmentation
- Phone system
- Network equipment locations
- Cabling
- Cameras and connected devices
- Remote locations or secondary buildings
- Monitoring
- Administrative access
- Available documentation
You are trying to answer two different questions.
Is the environment reliable and secure today?
And: How difficult will this be to integrate and support as part of the larger dealer group?
A network does not need to look identical to your other dealerships on closing day.
But your IT team should understand it well enough to support it.
9. Find the Documentation - or Find Out What Isn't Documented
Good documentation makes an acquisition easier.
Poor documentation usually reveals itself when someone asks:
“What's the administrator password?”
or:
“Who manages this system?”
or:
“Why does this device have remote access?”
and the answer is:
“You need to ask Bob.”
Bob may be helpful.
Bob may also have left six months ago.
The acquisition review should gather documentation for:
- Technology assets
- Network diagrams
- Internet services
- Vendor contacts
- Administrative accounts
- Licensing
- Domain names
- DNS
- Websites
- Microsoft 365 or Google Workspace
- Backup systems
- Cybersecurity tools
- Phone systems
- Important applications
- Service accounts
- Warranty information
- Contracts
- Support procedures
NIST's CSF explicitly treats hardware, software, systems, supplier services, network flows, and data inventories as part of understanding and managing cybersecurity risk.
From an operational standpoint, documentation also reduces dependence on one employee, one vendor, or the previous owner knowing how everything works.
Do not expect perfect documentation.
The useful outcome is knowing what you have and what you still need to figure out.
10. Separate Day-One Problems From Long-Term Standardization
This is where a lot of acquisition projects can go wrong.
You discover that the acquired dealership has different computers, a different firewall, a different phone provider, different security tools, and a different way of doing almost everything.
The temptation is: Replace it all.
Sometimes that is appropriate.
Often it is not.
Put findings into three buckets.
Fix Before or Immediately After Closing
These are issues that create an unacceptable security, reliability, access, or business-continuity concern.
Examples might include unauthorized administrator access, unsupported critical systems, an important backup problem, or access belonging to people who should no longer have it.
Standardize During the Integration
These are things you want aligned with the dealer group's normal operating model but that do not need emergency action.
That might include endpoint standards, support processes, documentation, equipment configurations, Wi-Fi standards, user-management processes, or vendor consolidation.
Leave Alone Until There Is a Business Reason to Change
Some technology may work perfectly well.
If it is secure, reliable, supported, and does not create unnecessary complexity, replacing it immediately may accomplish little beyond spending money.
This is where your existing 9 IT Standards Every Multi-Location Auto Dealership Should Have becomes useful.
The acquisition review tells you what the new dealership has.
Your group standards tell you where you ultimately want it to go.
The integration plan connects the two.
What Should Be Reviewed Before Closing vs. After Closing?
Not every technology question has to be answered at the same point in the transaction.
Before Closing
Try to understand the items that could materially affect the integration, cost, security, or ability to operate:
- Critical dealership systems
- Key technology contracts
- Internet connectivity
- Major equipment
- Cybersecurity environment
- Important backups
- Key vendors
- Administrative ownership
- Known technology problems
- Systems that will need to change immediately
The purpose is not to conduct a destructive technical investigation into systems you do not yet own. The scope and access available before closing will depend on the transaction and agreements involved.
The goal is to avoid going into closing completely blind.
Immediately Around Closing
Pay particular attention to control.
Confirm:
- Administrative credentials
- Microsoft 365 or Google Workspace ownership
- Domain and DNS control
- Vendor contacts
- Remote-access tools
- Former-owner access
- Former IT-provider access
- Employee accounts
- Backup administration
- Firewall/network administration
- Key software administrators
The business may look exactly the same to employees on Friday and Monday.
Behind the scenes, however, control of the technology environment needs to transfer too.
During the First 30-90 Days
Once the dealership is operating under the new ownership, move from discovery into improvement.
Prioritize the gaps.
Standardize what makes sense.
Develop the equipment plan.
Clean up vendors.
Improve documentation.
Bring onboarding and offboarding into the group process.
Align cybersecurity controls.
Review backups and business continuity.
Do not try to complete a three-year technology strategy during the first week.
Get control first. Then improve deliberately.
Who Should Be Involved in the Technology Side of a Dealership Acquisition?
Technology due diligence should not live entirely with the IT company.
Different people see different parts of the environment.
Dealer group leadership should establish the business goals and integration priorities.
The dealership's IT provider or internal IT team should review the technical environment, security, infrastructure, access, documentation, and integration requirements.
Department leaders can identify critical workflows and systems that may not be obvious from an IT inventory.
Legal and financial advisors should handle contractual, transaction, regulatory, and legal due diligence within their areas of responsibility.
The insurance broker or carrier may need to be involved when cybersecurity changes affect coverage or when the acquisition changes the organization's risk profile.
Key vendors may need to explain contracts, migration requirements, integrations, or access.
The point is not to put 15 people into every meeting.
It is to avoid assuming one person knows everything about the dealership you are buying.
What Are the Biggest Technology Red Flags When Buying an Auto Dealership?
A red flag does not necessarily mean “walk away.”
It means: We need to understand this before we decide what to do next.
Examples include:
- Nobody can produce a current technology inventory
- Important administrator credentials are missing
- Former employees still have accounts
- The outgoing IT company is the only party with administrative control
- Shared administrator passwords are widely used
- MFA is inconsistent or missing from important accounts
- Unsupported critical equipment or software remains in use
- Nobody can explain the backup process
- Backups have never been tested
- Several unknown remote-access tools are installed
- Vendors have undocumented access
- Internet or network problems regularly affect employees
- Important contracts are about to renew
- One employee is the only person who understands a critical system
- There is little or no useful documentation
The presence of one of these does not tell you what the solution should be.
It tells you where to ask more questions.
Frequently Asked Questions About IT Due Diligence for Auto Dealership Acquisitions
Should IT be reviewed before buying an auto dealership?
Yes. The technology environment can affect operating continuity, cybersecurity, integration costs, vendor obligations, employee productivity, and the effort required to bring the acquired dealership into the buyer's existing standards.
The depth of the pre-closing review will depend on what access and information the transaction permits.
What technology should a dealer group review during an acquisition?
At minimum, review technology assets, DMS and business applications, vendors and contracts, employee and administrator access, cybersecurity controls, backups, remote access, networks and internet, documentation, and the plan for integrating the rooftop into the dealer group's standards.
Should a dealer group replace the acquired dealership's IT immediately?
Not automatically.
Address urgent security, reliability, and business-continuity problems first. Other systems can be standardized as contracts expire, equipment reaches replacement, projects are planned, or there is another legitimate business reason for changing them.
Should the acquired dealership keep its current IT provider?
That depends on the quality of the relationship, capabilities of the provider, existing contracts, the dealer group's support model, and how the location will ultimately be integrated.
The immediate priority should be ensuring continuity and obtaining the documentation, credentials, and access needed to manage the environment. The long-term provider decision can then be made with better information.
What happens to vendor access when ownership changes?
Do not assume vendor access automatically needs to stay exactly as it is.
Identify each vendor with remote or administrative access, confirm that the relationship is continuing, determine what access is still needed, and update or remove access accordingly.
For dealerships covered by the FTC Safeguards Rule, applicable service-provider and access-control requirements should also be considered.
How soon should an acquired dealership be brought into the dealer group's IT standards?
Start immediately with anything that presents an unacceptable business or security risk.
For everything else, build a prioritized integration plan. Some changes may make sense during the first 30-90 days, while others can happen during planned replacements, contract renewals, renovations, or future projects.
Does a dealership acquisition require an IT risk assessment?
There is no universal rule requiring every acquisition to have a particular type of IT assessment.
But an IT risk review can help the buyer understand assets, systems, access, vendors, backups, cybersecurity, documentation, and infrastructure before deciding which issues need immediate attention and which can be addressed later.
Does the FTC Safeguards Rule matter during a dealership acquisition?
For dealerships covered by the Rule, it can.
The FTC's current dealership guidance addresses access controls, MFA, protection of customer information, and oversight of service providers. If ownership, vendors, administrators, systems, or access are changing during an acquisition, those responsibilities should be considered as part of the transition.
This is not legal advice; the buyer should confirm its specific legal obligations with qualified counsel.
Don't Wait Until After Closing to Ask Who Has the Password
A dealership acquisition already has enough moving parts.
Technology does not need to become another source of surprises.
The objective is not to conduct a technical investigation for the sake of producing a long report. It is to answer practical business questions before they become operational problems:
What are we buying?
Who has access to it?
Which vendors are involved?
What are we responsible for protecting?
Can we recover the information we depend on?
What needs attention immediately?
What can wait?
How do we bring this rooftop into the way our dealer group operates?
An acquisition transfers more than employees, inventory, and a building. You inherit years of technology decisions along with them.
Understanding those decisions gives you the opportunity to keep what works, correct what needs attention, and build a sensible integration plan rather than starting with assumptions.
For dealer groups in Morris County and Northern New Jersey, Tech Marvel can help review the technology behind an acquisition, identify areas that need attention, coordinate existing vendors, and develop a practical plan for integrating the new dealership into the rest of the organization.
Planning an acquisition? Let's talk about your dealership.
Schedule a free 20-minute Dealership IT Review to talk through the location, systems, vendors, integration plans, and technology questions you want answered before or after closing.


