Get FTC Compliant

This SubRosa guide explains that the FTC Safeguards Rule now reaches car dealerships that offer leasing or financing, treating them as financial services providers, and that penalties for noncompliance can top $42,000 a day. It then sets out the services SubRosa offers dealers to meet the rule, from the responsible person role and a written security program to attack readiness and incident response.

JP
John Price
  • Reviewed by Kevin Schewe and Ratan Gupta
  • 5 min read
  • Download PDF
Share

Key Highlights

  • Dealers that offer leases or financing fall under the FTC Safeguards Rule and are classed as financial services providers or advisors.
  • Penalties for failing to comply can run above $42,000 for every day.
  • SubRosa can take on the responsible person designation and deliver a formal infosec program that is refreshed at least once a year.
  • Support spans proactive work such as penetration testing, social engineering and a managed SOC, plus reactive incident response and computer forensics.

Get access to industry-leading compliance, information security and strategic knowledge to stay compliant, and one step ahead of your attackers, competitors and industry changes.

What you need to know

Changes to the FTC's safeguards ruling now includes certain car dealerships among organization's covered by the rule, and categorizes them as financial services providers or financial advisors.

The FTC’s rule requires detailed procedures and specific criteria that auto dealers must implement to provide better protection and to curb data breaches and cyberattacks that could jeopardize sensitive customer data.

If you offer lease or financing agreements, you must abide by the ruling.

Noncompliance fines can exceed $42,000 per day

Meet SubRosa

Prepare for cyber incidents. Train your workforce. Respond to threats.

SubRosa delivers unified FTC compliance, cyber risk solutions and services to help you achieve and maintain compliance with the FTC's ruling

We provide solutions to help you manage your entire risk and vulnerability landscape, from small dealerships to large enterprises.

FTC Compliance Solutions.

  • Responsible person: Hassle-free compliance — We save you on resources by handling the responsible person designation.
  • Documented infosec program: Proactively prepare. A formally written information security program, updated at least annually.
  • Cyber attack readiness: Proactively prepare. A suite of services to help you prepare for cyber attacks.
  • Risk and compliance: Know your organization. Services to help you manage risk, and maintain regulatory compliance.
  • Incident response: Respond to attacks. Detect and prepare for incidents in real time.
  • Integrated solutions: Leverage smart technology. Leverage intelligent technology to gain full insights into your network and applications.

Powerful expertise. Practical costs.

Proactive Security.

  • Cyber Attack Readiness: Prepare for a cyber attack with a range of proactive services.
  • Social Engineering: Identify vulnerabilities in your procedures and personnel.
  • Managed SOC: Gain unparalleled visibility into who is attacking your infrastructure.
  • Risk & Compliance: Enhance confidence that your processes address current risks.

Reactive Security.

  • Incident Response: SubRosa’s incident response team leverage real-world expertise, industry-leading technology and extensive threat intelligence to analyze and respond to a multitude of incidents, regardless of your organization’s size.
  • Computer Forensics Services: SubRosa’s computer forensics experts can assist you with the most difficult and sensitive investigative or litigation issues requiring electronic evidence or data preservation.

Cyber Attack Readiness

Proactively prepare for cyber attacks

Prepare for a cyber attack with a range of services from simulated attacks, vulnerability management to social engineering.

Identify avenues of attack.

Cyber attack readiness is a fundamental cybersecurity service set for organizations of all sizes. Cyber criminals are attacking your networks, applications and people on a daily basis. Statistically speaking, almost every organization will have an attempted attack made against them, whether they realize it or not.

  • Social engineering: Social Engineering will identify vulnerabilities in your personnel and test the effectiveness of your security awareness training.
  • Physical penetration testing: Physical penetration testing assesses the physical security controls of your locations, data centers and critical infrastructure.
  • Network penetration testing: Identify & Exploit Vulnerabilities. Simulate Attacks. Remediate and Protect Your Critical Network Assets with Network Penetration Testing.
  • Application security testing: Static and dynamic app testing will identify vulnerabilities in your web applications that could lead to unauthorized data exposure.
  • Red team assessments: Red team assessments test your organization’s already established cybersecurity program and your team’s response and cyber attack readiness state.
  • Vulnerability assessments: Vulnerability assessments will enable you to manage your vulnerability landscape with automated and manual vulnerability scanning and verification.

Governance, Risk and Compliance

Manage risk and maintain regulatory and contractural compliance

Eliminate holes in your company cyber security defenses to maintain the robustness of your essential information systems, and enhance confidence that your systems and processes address the current risks and industry standards.

As you manage the pressures of digitalization, new technologies, legislation, and the shifting risk and threat landscape at an accelerated pace, unique risks and cyber vulnerabilities that were previously unthinkable have become the commonplace. The good news: we can plan to fast adjust to these changes and take steps to guard against the risks.

  • Compliance assessments: Achieve and maintain compliance with a wide range of industry frameworks and regulations.
  • Cybersecurity maturity assessments: Assess your cyber program maturity level and pave the way for program improvements.
  • Cyber audit preparation: Plan and prepare for audit and certification with audit preparation services.
  • Third party assurance: Assess and manage enterprise and cyber risks associated with your supply chain and third parties.

Incident Response

Timely, cost effective response to cyber incidents

Security incidents can cripple an organization’s operations in a matter of minutes. If an incident is not responded to in a timely, professional manner, costs can spiral and irreparable damage can occur.

Failure to properly and efficiently manage a cyber incident can be drastically more costly for an organization than the actual incident itself. This presents resource-strapped IT executives with an increasingly burdensome challenge.

Incident response services.

  • Compromise assessment: Identify past and present attacker activity in your environment. Use the results to drive improvements to your incident response program.
  • Readiness assessment: Test your ability to respond to, manage and mitigate an incident from a wide array of attackers and attack types.
  • Incident response training: Train stakeholders and incident response personnel to better prepare them for live incident response requirements.
  • Managed incident response: Bolster your incident response capabilities with a team on standby, ready to assist with incident response at a moments notice.

Engagement models.

  • Proactive incident response: Detect incidents in real time. Prepare for incident response through training and workshops.
  • Emergency incident response: Respond to incidents post-discovery and engage SubRosa’s cyber incident response and forensics team to assist.
  • Threat research and development: Research and analysis of emerging and existing threats to help proactively counter new threats, as they emerge.
  • Incident response retainer: Retain industry-leading incident response experts, reducing the impact of incidents and enable quick, cost-effective response.
Get help meeting the FTC Safeguards RuleWork with SubRosa on compliance assessments, audit preparation and a documented security program for your dealership.Explore compliance services

Frequently asked questions

What does the FTC Safeguards Rule require of car dealers?

Covered dealers have to put detailed procedures and specific criteria in place so that customer data is better protected against breaches and cyberattacks.

Does the FTC Safeguards Rule apply to my dealership?

It does if your dealership offers lease or financing agreements. Under the updated rule, such dealers are treated as financial services providers or financial advisors.

What are the penalties for violating the FTC Safeguards Rule?

According to SubRosa, fines for noncompliance can go beyond $42,000 for each day a dealer is out of compliance.

How can SubRosa help a dealership become FTC compliant?

SubRosa can handle the responsible person designation, provide a written information security program that is reviewed every year, and support dealers with attack readiness testing, risk and compliance services, and incident response.

Ready to strengthen your security posture?

Have questions about this article or need expert cybersecurity guidance? Connect with our team to discuss your security needs.