Cyberattack risk increases annually, but regular security measures and reviews can help protect your dealership now and in the future.
Fremont, CA: Cyberattack risk increases annually, but regular security measures and reviews can help protect your dealership now and in the future. Here are the key actions that will enhance cybersecurity:
1. Identify a Qualified Leader
A security leader should guide a dealership safely, adhering to the FTC Safeguards Rule. They should restrict administrative access, create an incident response plan, conduct risk assessments, and conduct regular online stability assessments to ensure compliance with regulations.
2. Update Your Software and Secure Your Files
Ensure your apps, web browsers, operating systems, and software is updated regularly. Back up essential files in the cloud, external hard drive, or offline, and ensure secure storage of paper files.
3. Require Strong Passwords
Strong passwords on laptops, tablets, and smartphones should be at least 12 characters long, combine numbers, symbols, letters, and punctuation, and be limited to prevent password-guessing attacks.
4. Encrypt Data
Encrypt sensitive or personal data on devices like laptops, tablets, smartphones, removable drives, and cloud storage solutions at the source to protect against potential breaches.
5. Use Multifactor Authentication (MFA)
Access to sensitive network areas requires MFA, which involves additional steps beyond passwords, such as a temporary code on a smartphone or a key inserted into a computer, as per the FTC Safeguards Rule.
6. Secure Routers, Endpoints and Remote Connectivity
To ensure network security, configure your router, change default settings, turn off remote management, and log out as the administrator. Enable WPA2 or WPA3 encryption for secure data transmission. Include security provisions in vendor contracts, follow the FTC Safeguards Rule for personal information protection, prioritize endpoints like laptops and tablets, and perform system monitoring or penetration tests to assess infrastructure vulnerabilities.
7. Provide Security Awareness Training
Implement regular and mandatory employee training to foster a security culture. Keep employees informed about new risks and vulnerabilities. If training isn't attended, consider blocking network access to protect against phishing attacks.
8. Assess Vendor Security Measures
The FTC Safeguards Rule mandates vendors and service providers to regularly assess their security measures and include a clause addressing proper security standards in all contracts.
9. Have a Plan
The FTC Safeguards Rule mandates dealerships to develop a robust cybersecurity plan, which can be aided by resources like NIST Planning Tools and Workbooks, which offer guides, online resources, cyber insurance, and workbooks for cybersecurity improvement.
10. Get Answers
Consider hiring a managed service provider or security provider to supplement your team or manage your security posture. These vendors can assess your infrastructure and develop an action plan for your dealership, ensuring a smooth transition.