Car dealerships handle a significant volume of highly sensitive customer information, often more than many other small businesses, including Social Security numbers, credit histories, income details, and financing records. This type of data is extremely valuable to cybercriminals, making dealerships a prime target for attackers who actively seek to exploit vulnerabilities and gain unauthorized access to personal and financial information.
The FTC Safeguards Rule now requires dealerships to implement and maintain a formal, written information security program that protects customer data and reduces risk. Thought Streams helps dealerships design, manage, and strengthen these programs while actively defending against real-world threats, ensuring compliance is met and security measures are effective without disrupting daily operations.
Secures the customer financial data your F&I department handles every day.
Protects your DMS and dealer systems from ransomware and unauthorized access.
Builds the written security program the FTC Safeguards rule now requires.
Keeps your service lane, parts systems, and manufacturer portals locked down.
A car dealership runs on systems that have to stay up: the DMS, the service drive, the F&I desks, the manufacturer portal. We protect the environment those systems run in and make sure the security program the FTC requires is actually functional.
The F&I desk manages the most sensitive customer data in the dealership. Credit applications, SSNs, and financial records are limited to staff who need them, with audit trails maintained.
Your DMS is the center of dealership operations. If it goes down, the whole business stops. We protect the network it runs on and keep a single compromise from spreading.
The FTC Safeguards Rule requires a written security program, a designated coordinator, and a risk assessment. We help you build and document the program so it holds up under scrutiny.
Dealership staff turnover is frequent. Unremoved access credentials create recurring vulnerabilities. We manage user access to ensure former staff can’t access dealership systems.





Car dealerships are a targeted industry. The financial data your F&I department handles, the systems that can't afford downtime, and the multiple vendor connections into your network create exactly the profile that ransomware groups and data thieves look for.
The FTC Safeguards Rule added a compliance obligation on top of an already complex threat environment. Dealerships that treat it as a paperwork exercise rather than a real security program are exposed on both fronts: to the attackers and to the regulators.
Dealership environments have moving parts most IT services companies aren't familiar with: DMS integrations, manufacturer portal access, service lane technology, and F&I processes. We know what a dealership's systems look like and what protecting them requires.
We help dealerships satisfy the FTC Safeguards Rule without making it a months-long project. The documentation gets built, the risk assessment gets done, and the security controls get maintained so the program stays current rather than becoming outdated.

The FTC Safeguards Rule requires auto dealers to have a written information security program, a qualified individual overseeing it, and regular risk assessments kept on file. It is not a suggestion and there is no size exemption. We help dealerships build a program that actually satisfies what the Rule requires: documented controls, assigned accountability, tested processes, and a written plan that reflects what's really in place at your dealership.
Building an FTC Safeguards program means more than drafting a policy document. The Rule requires a risk assessment, a designated coordinator, vendor oversight documentation, employee training, and a written incident response plan. We work through each component with you, document the controls already in place, and close the gaps so your program is genuinely compliant rather than just technically assembled.
Written security program built and kept current as your dealership evolves.
Risk assessment completed and documented to satisfy FTC review requirements.
Designated coordinator assigned and accountability for the program formalized.
Your dealer management system touches every department in the dealership: sales, F&I, service, and parts. It also connects to manufacturer portals, third-party integrations, and potentially remote access points for staff working off-site. Each of those connections is a potential entry vector if not properly managed. We secure the network the DMS runs on, control who has access to it, and watch for the kind of activity that suggests something has gone wrong.
DMS security starts with understanding what connects to it. Most dealerships have more integrations than they realize, and not all of them have been assessed for risk. We map what has access to your DMS environment, apply appropriate controls, and make sure that vendor connections and remote access points aren't creating exposure that nobody is managing. The DMS is too critical to leave partially unprotected.
Network the DMS runs on secured and monitored for unauthorized access attempts.
Vendor and integration connections mapped and assessed for unmanaged exposure.
Remote access points controlled so staff access doesn't become a security gap.
The F&I office handles the most sensitive customer data in the dealership. Every customer who finances or leases a vehicle hands over a Social Security number, income documentation, and financial history. That data has real value on criminal markets and stays in your systems long after the sale closes. Protecting the F&I environment means controlling who can access it, encrypting where appropriate, and monitoring for signs of unauthorized activity.
F&I data protection starts with access management and extends to how that data is stored, transmitted, and retained. We restrict F&I record access to staff who need it, set up encryption for sensitive fields, and establish retention policies that limit how long high-risk data sits in systems that don't require it. We also make sure the F&I environment is covered in your FTC Safeguards documentation.
Access to F&I records restricted to staff with a job requirement for them.
Encryption applied to sensitive financial data fields in storage and transit.
Retention policies set so high-risk customer data isn't kept longer than needed.
Dealerships hold large amounts of sensitive customer data, run on systems that can't afford to go down, and now operate under a formal federal compliance requirement. These are the reasons a car dealership needs more than a generic IT services provider.
Customer Data Is High Value
SSNs, credit applications, and income data from every vehicle buyer sit in your systems. Attackers know what's there. Securing it is a legal obligation and a basic responsibility to the people who trusted you with it.
Ransomware Hits Hard and Fast
A ransomware attack on a dealership's DMS shuts down sales, service, and F&I. The pressure to restore access is real. A tested backup and recovery plan is what keeps the ransom from being the only option.
The FTC Safeguards Rule Is Law
The FTC Safeguards Rule requires auto dealerships to implement a formal written security program or face enforcement action. Having the program in place, documented, and maintained is the baseline expectation for every dealer in the country.
Vendor Access Creates Real Risk
DMS providers, manufacturer portals, and third-party integrations all create access points into a dealership's network. Each is a potential entry vector if not controlled. Managing vendor access is part of what the FTC Safeguards Rule addresses.
Yes. The FTC Safeguards Rule applies to all auto dealers regardless of whether they're franchised or independent. The Rule defines a financial institution broadly, and the FTC has confirmed that auto dealerships fall within that definition. Both franchise and independent dealers are required to have a written information security program in place. The size of the dealership does not create an exemption.
Finance and insurance transactions generate some of the most sensitive personal data collected anywhere: Social Security numbers, income documentation, employment history, credit reports, and bank account details. This data sits in dealer management systems, sometimes for years. It's exactly what identity thieves and ransomware groups look for when targeting a business, and it makes dealerships a specific and deliberate target.
A ransomware attack that hits the DMS effectively shuts down the dealership. Sales can't be processed, service records can't be accessed, F&I can't run deals, and parts ordering stops. The pressure to pay and restore access is immediate and intense because every hour offline costs revenue. Dealerships with tested backups and a documented recovery process have an option that dealerships without them don't.
The Rule requires a designated qualified individual to oversee the information security program. That person is responsible for the program and reports to ownership or senior management at least annually. In smaller dealerships, this is often the dealer principal or general manager. We help identify who should own the role, document their responsibilities, and make sure the program they're overseeing is one they can actually stand behind.