Dealers face growing pressure to protect customer information while keeping up with an increasingly complex web of compliance requirements. But according to Hunter Giambra, Founder and President of Hurricane IT Solutions, and Andy Graff, Chief Operating Officer of ComplyAuto, many dealerships still have significant gaps between what they believe is protected and what is actually happening inside their stores.
In part two of a three-part series on Inside Automotive, we welcome back Giambra and welcome Graff, to explore the dangerous gap between IT security and regulatory compliance. They also break down why U.S. auto dealers are increasingly landing in the crosshairs of federal regulators and cybercriminals.
Dealer Vulnerability
While many dealers believe their existing IT staff or “legacy” operational habits have them covered, Giambra and Graff point out that physical and digital security practices on the ground often tell a different story.
“We wanna make sure that they're compliant, but also that they're secure. And that's where the compliance side comes in from ComplyAuto, and we come in on the security side.” – Hunter Giambra
According to Giambra, common ground-level violations include sales staff leaving deal jackets, driver’s licenses, and credit applications on desks or in unattended drop boxes. Staff often share login details, neglect to lock terminals, or use personal emails to send sensitive customer information.
Whereas cybercriminals, Graff says, target dealerships because they are lucrative ransomware targets, with financial resources, essential operational systems that cannot afford interruptions, such as writing repair orders or processing deals, and a strong desire to protect their local reputation.
Hardware security
To solve these challenges without forcing dealers to juggle multiple finger-pointing vendors, Hurricane IT Solutions and ComplyAuto have formed a unified partnership:
- Hurricane IT Solutions handles the technical, hands-on infrastructure, managing networks, hardware, and cybersecurity perimeter defense.
- ComplyAuto provides the regulatory oversight, backed by a team of 10 attorneys specializing in automotive retail compliance across FTC Safeguards, state privacy laws, advertising, sales, and HR.
Together, they offer integrated security scanning, annual required board-reporting tools, incident response planning, and a complete Learning Management System (LMS) to train dealership personnel annually, as mandated by the FTC.
“I would think that that happens in just general compliance and privacy and the way I think that there's a disconnect from the upper management in many cases and what's really happening on the sales floor.” – Andy Graff
Instead of forcing dealers into long-term vendor lock-in, the duo emphasizes a single-point-of-contact approach (“one throat to choke”) for emergency incidents, eliminating vendor deflection and reducing operational friction. To help dealers evaluate their posture without upfront risk, Hurricane IT offers an exclusive 60-day trial for viewers, paired with free compliance and network security assessments from ComplyAuto.



