By Ron Conti, Owner and Founder of Tech Marvel
Your collision center can have endpoint protection, multi-factor authentication, backups, employee training, and several technology vendors - and still leave you with important unanswered questions. That doesn't mean you made bad decisions. More often, the business grew faster than the security process around it.
Think about what a normal workday now depends on. Your estimators may move among CCC ONE, Mitchell, Audatex, and insurer portals. ADAS work can require scan tools, calibration software, OEM repair information, current procedures, and dependable access to outside systems. Accounting handles banking and payroll, while your managers rely on email, phones, cameras, vendor platforms, and information shared across locations.
One compromised account or unavailable system can disrupt much more than one computer. An estimate stalls. A calibration waits. A technician can't reach OEM information. Another location sits idle while you try to coordinate several vendors.
The practical question is whether you can verify what is protected, where the exceptions are, what has been tested, and who takes charge when several vendors are involved.
These six assumptions are a good place to start.
Assumption 1: “We Are Too Small for Cybercriminals to Notice”
Automated attacks do not care how many locations or employees you have.
A single-location shop may look unimportant next to a national company. But an attacker doesn't have to research your business before trying a stolen Microsoft 365 password, sending a convincing invoice, or scanning an internet-facing system for a known weakness. Many attacks simply look for exposed systems, reusable passwords, vulnerable accounts, and people who can be pressured into acting.
Your shop also has a useful mix of information and access. Estimators communicate with insurers and customers. Accounting handles payments and payroll. Managers approve vendors and may work across locations. Ask a more useful question: if someone gets into one account, what could they reach next?
Assumption 2: “Our Employees Will Recognize a Phishing Email”
Training helps, but employees cannot be your only phishing control.
A suspicious request may look like a supplement, parts invoice, insurer notice, Microsoft 365 sign-in, payroll change, shared estimate, or message from you. Put it in front of someone juggling customers, carriers, parts, technicians, and cycle time, and the urgency may feel completely normal.
CISA recommends recognizing and reporting phishing, but recognition is only one layer. Give employees a simple way to verify payment changes, unexpected login requests, requests for sensitive information, and any message that tries to bypass your normal approval process.
Assumption 3: “MFA Means Our Accounts Are Protected”
MFA protects only the accounts and systems where it is actually enabled.
Your email may require MFA while an estimating platform, OEM information system, ADAS calibration application, remote-access tool, vendor account, camera system, or older administrator login does not. If you operate more than one location, accounts created at different times may follow different standards.
You should be able to see where MFA is required, which important systems remain outside that standard, and what an employee should do after an unexpected approval prompt. MFA strengthens the plan; it doesn't finish it.
Assumption 4: “Our Backups Have Us Covered”
A successful backup job does not prove that your shop can recover.
Some systems may be protected directly by your shop or IT provider. Other information lives inside vendor-managed platforms. You need to know what is backed up, what isn't, who starts recovery, and which systems must return first so estimating, accounting, parts, and production can work.
Tech Marvel's guide to the four most expensive backup assumptions collision centers make explains why backup and recovery are different questions. A tested restore tells you far more than a green status screen.
Assumption 5: “Cybersecurity Is IT's Responsibility”
IT can protect the environment, but your team still owns business decisions and undisclosed access.
When an employee leaves, IT may disable email and the computer account. Your manager may still need to identify access to estimating systems, insurer portals, OEM information, calibration applications, payroll, parts vendors, shared credentials, and location-specific services. The same shared responsibility applies when a vendor needs remote access or accounting receives new payment instructions.
You see the ownership gap most clearly when systems cross vendor boundaries. The software vendor blames the network. The internet provider says the circuit is fine. The IT provider points back to the application. Meanwhile, you're coordinating three companies while an estimator, technician, or calibration process waits.
One accountable technology partner should organize that conversation, keep you informed, and stay with the issue until there's a clear answer. Everyone doesn't own everything; each person and vendor needs a defined role, with one party responsible for coordinating the gaps.
Assumption 6: “We Know What to Do If Something Happens”
An incident plan must tell people what to do before the pressure starts.
If a workstation shows a ransom note or a mailbox begins sending fraudulent messages, employees need to know whom to contact and which actions could make things worse. You need current contact information, another way to communicate, and clarity about the roles of your cyber insurer, vendors, legal counsel, and affected systems.
The harder questions surface quickly: Who can authorize emergency work? Does a location need to be isolated? Who contacts the estimating platform, phone provider, or insurance carrier? A short tabletop exercise can expose those gaps while you still have time to fix them.
The Bigger Myth: Buying Security Means You Have a Security Program
A security program connects products to coverage, monitoring, response, and recovery.
Security products matter. They also need someone to keep them aligned with a changing business. Accounts change, employees move between locations, vendors gain access, and new applications appear. A control that fit last year's operation may no longer cover today's.
The NIST Cybersecurity Framework organizes cybersecurity around governing, identifying, protecting, detecting, responding, and recovering. You don't need to turn that framework into a technical project. Use the same logic to check whether you have a coordinated process instead of a collection of tools.
Multi-Location Growth Makes Inconsistency Easier to Miss
Every location can use different equipment and still meet one defined security standard.
One shop may have current Wi-Fi equipment and documented vendor access, while another still relies on an older network and a shared password. Backup practices can vary too. Managers may follow different rules for adding employees, removing access, approving remote support, or protecting estimating, OEM, and ADAS calibration systems.
Those differences usually accumulate quietly. You acquire a shop. A vendor installs what it needs. Someone solves a local problem quickly, and the temporary answer becomes permanent. That's a sign the business has outgrown the informal decisions that once worked - not that you were careless.
Standardization doesn't require identical hardware everywhere. It means you can explain the minimum standard for Wi-Fi, backups, MFA, administrator access, vendor connections, documentation, monitoring, and recovery across all of your shops. Any exception should be visible and intentional.
Three Steps From Assumptions to Clear Answers
Move from assumptions to evidence in three practical steps.
1. Review What the Business Depends On
List the accounts, applications, vendors, locations, remote access, backups, and employee processes that keep estimates, communications, payments, parts, and production moving.
2. Verify the Important Claims
Confirm where MFA is enabled, what is monitored, when recovery was last tested, how vendor access is controlled, and what employees should do when a request feels wrong.
3. Assign Ownership Across the Gaps
Each vendor can support its own platform. You still need one accountable technology partner to coordinate issues, keep you informed, and stay with the problem until the business has a clear answer.
Six Questions to Ask Your IT Provider
Your IT provider should be able to answer six questions in plain English.
- Which important accounts and systems have MFA, and which do not?
- How should an employee report a suspicious email, call, login prompt, or payment request?
- What information is backed up, what is handled by outside vendors, and when was recovery last tested?
- How are employee and vendor accounts reviewed when access changes?
- Who coordinates an incident involving several locations or technology vendors?
- What happens during the first hour after the shop suspects an account or system has been compromised?
The answers should make sense to you and your operations team. “We think it's covered” doesn't prove there's a failure, but it does give you a good reason to verify.
Get a Clearer Picture of Your Collision Center's Cybersecurity
Start by verifying what you already have before buying something new.
Tech Marvel helps growing New Jersey collision centers replace informal IT support with one accountable technology partner for every location. We review the systems, accounts, vendors, backups, and response processes that keep your shops productive, protected, and able to move cars.
If you operate in Morris County or elsewhere in Northern New Jersey, the goal is straightforward: identify what's working, what needs verification, and who owns the next step.
Schedule Your Free IT Roadmap Meeting. Talk with Tech Marvel about your shops and current technology environment.
Not ready for a meeting? Start with 10 Signs You've Outgrown “The IT Guy”, a practical guide for owners deciding whether informal support still fits the business.


