TSLA364.085-2.11501%
GM82.610-4.01%
F13.145-0.465%
RIVN15.090-0.31%
CYD35.4300.91%
HMC32.225-0.305%
TM191.710-2.2%
CVNA65.160-0.68%
PAG212.220-2.53%
LAD315.900-5.78%
AN168.705-6.175%
GPI248.170-6.78%
ABG183.340-4.57%
SAH63.600-2.35%
TSLA364.085-2.11501%
GM82.610-4.01%
F13.145-0.465%
RIVN15.090-0.31%
CYD35.4300.91%
HMC32.225-0.305%
TM191.710-2.2%
CVNA65.160-0.68%
PAG212.220-2.53%
LAD315.900-5.78%
AN168.705-6.175%
GPI248.170-6.78%
ABG183.340-4.57%
SAH63.600-2.35%
TSLA364.085-2.11501%
GM82.610-4.01%
F13.145-0.465%
RIVN15.090-0.31%
CYD35.4300.91%
HMC32.225-0.305%
TM191.710-2.2%
CVNA65.160-0.68%
PAG212.220-2.53%
LAD315.900-5.78%
AN168.705-6.175%
GPI248.170-6.78%
ABG183.340-4.57%
SAH63.600-2.35%


Why dealership compliance can’t be a one-time check-the-box exercise

We’ve talked about the vulnerabilities dealers are facing, and why being secure doesn’t necessarily mean being compliant. Now, let’s talk about what happens next. In our final segment of this three-part series on Inside Automotive, Hunter Giambra and Andy Graff join us to break down what an ongoing compliance partnership actually looks like and why this can’t just be a one-time check-the-box exercise.

Sign up for CBT News’ daily newsletter and get the latest industry stories delivered straight to your inbox.

Giambra, Founder and President of Hurricane IT Solutions, said the partnership between Hurricane and ComplyAuto is designed to bridge the gap between dealership cybersecurity and compliance. While the companies remain separate, they can work together to give dealers a more comprehensive view of everything from network security and hardware to employee training and regulatory requirements.

Compliance requires ongoing attention

One of the biggest issues, Giambra said, is that dealerships sometimes consider themselves compliant because they conducted training or established policies years ago. But with employee turnover and changing requirements, that approach can quickly become outdated. Recurring training and annual reviews can help dealers stay on top of requirements such as multifactor authentication and data backups. Therefore, recurring training and annual reviews can help dealers stay on top of requirements such as multifactor authentication and data backups.

“So we're gonna... go on the offensive and get that product on the dealer's website to protect them. And so we do that with Hurricane.” – Andy Graff

According to Graff, the complexity of the dealership environment makes specialized support increasingly important. Dealers are experts at selling and servicing vehicles, but IT, cybersecurity and compliance have become specialized areas that can be difficult to manage internally. 

Vendor access creates risks

The conversation then turned to California privacy requirements, with Graff discussing the California Invasion of Privacy Act, or CIPA, and the demand notices being sent to businesses over how website conversations with consumers are captured and potentially shared with third parties. Since California consumers can shop on dealership websites anywhere in the country, he said the issue is not necessarily confined to California dealers.

Vendor oversight is another potential source of exposure, as dealerships routinely give marketing companies, website providers, DMS-related vendors and other third parties access to customer information. Graff said dealers should understand how those companies protect the data and have the appropriate agreements and assessments in place before granting access.

That includes a data processing agreement, or DPA, which establishes expectations for how a vendor handles dealership data, and a vendor risk assessment, or VRA, to evaluate how that vendor protects the information it receives. If a third-party vendor experiences a breach, dealers may still face questions about how they conducted their own due diligence.

Giambra also emphasized the everyday employee activity that can create cybersecurity risk. Personal email, social media, unauthorized websites and other activity on dealership systems can expose information or create openings for threats. Establishing controls around what employees can access and how dealership data moves through the network is increasingly important.

How dealers can prepare 

For dealers that want to see where vulnerabilities exist, Giambra is offering a 60-day trial of Hurricane’s services at no cost, with no long-term contract. The assessment is designed to give dealers a closer look at their current environment and provide a report detailing what the team finds.

“No strings attached. I mean, it's just 60 days. You know, if you like us, great, we hope you move forward with us. If you don't, we understand.” – Hunter Giambra

For larger dealer groups, the evaluation can start with just a few rooftops. The broader takeaway from today’s conversation is that cybersecurity and compliance are moving targets. Dealers need to continually review their systems, train employees, evaluate vendors and stay current with changing requirements rather than assuming a policy or training session from years ago is still enough.


More from Safety & Compliance
NADA welcomes FTC pricing FAQs as dealers gain clearer guidance

NADA welcomes FTC pricing FAQs as dealers gain clearer guidance

- September 16, 2026
On the Dash: Dealer-required fees must be included in the advertised price, with only government-required charges generally excluded. MSRP, discounts, rebates and financing offers can appear in ads, but the...
dealers

The hidden security gaps putting dealers at risk 

- September 15, 2026
Dealers face growing pressure to protect customer information while keeping up with an increasingly complex web of compliance requirements. But according to Hunter Giambra, Founder and President of Hurricane IT...
NHTSA urges dealers to strengthen airbag inspections after latest safety finding

NHTSA urges dealers to strengthen airbag inspections after latest safety finding

- September 10, 2026
On the Dash: Dealers should inspect vehicles that received replacement driver airbag inflators after crashes, especially used vehicles. Vehicles equipped with defective DTN60DB inflators should not be driven until the...
FTC warns car buyers about fake dealership websites and payment scams

FTC warns car buyers about fake dealership websites and payment scams

- September 2, 2026
On the Dash: Scammers can copy dealership branding, vehicle listings, photos and even customer testimonials. Shoppers should confirm a vehicle and dealership exist before sending money. Buyers purchasing remotely...
CBT News
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.