CDK Global reported that 90% of dealership leaders recognized the importance of cybersecurity, while fewer than half were confident in their defenses. The company also said roughly one in five dealerships had been targeted by a cyberattack.

The confidence gap is operationally plausible, but the findings come from a dealership systems and security vendor. Stores should use the survey as a prompt for testing controls, not as proof that a particular product or threat estimate applies to them.

Confidence should be replaced by evidence

A dealership can test whether multifactor authentication is enforced, former employees are removed promptly, backups restore successfully, vendors use appropriate access and staff recognize phishing. Those checks produce more useful assurance than asking whether leaders feel prepared.

The incident plan must cross departments

A cyber event can interrupt sales, service, parts, payroll, lender submissions and customer communications at once. The response plan should name decision owners, offline procedures, legal and insurance contacts, vendor escalation and the conditions for restoring access.

Dealers should also map sensitive data and minimize unnecessary retention. The smaller and better-controlled the accessible data set, the lower the impact when an account or vendor is compromised.

Methodology note

CDK sells dealership systems and security services; its survey should be treated as commercially interested research.

References

Cited references

  1. CDK dealership cybersecurity study Commercial dealership study