We’ve talked about the vulnerabilities dealers are facing, and why being secure doesn’t necessarily mean being compliant. Now, let’s talk about what happens next. In our final segment of this three-part series on Inside Automotive, Hunter Giambra and Andy Graff join us to break down what an ongoing compliance partnership actually looks like and why this can’t just be a one-time check-the-box exercise.
Giambra, Founder and President of Hurricane IT Solutions, said the partnership between Hurricane and ComplyAuto is designed to bridge the gap between dealership cybersecurity and compliance. While the companies remain separate, they can work together to give dealers a more comprehensive view of everything from network security and hardware to employee training and regulatory requirements.
Compliance requires ongoing attention
One of the biggest issues, Giambra said, is that dealerships sometimes consider themselves compliant because they conducted training or established policies years ago. But with employee turnover and changing requirements, that approach can quickly become outdated. Recurring training and annual reviews can help dealers stay on top of requirements such as multifactor authentication and data backups. Therefore, recurring training and annual reviews can help dealers stay on top of requirements such as multifactor authentication and data backups.
“So we're gonna... go on the offensive and get that product on the dealer's website to protect them. And so we do that with Hurricane.” – Andy Graff
According to Graff, the complexity of the dealership environment makes specialized support increasingly important. Dealers are experts at selling and servicing vehicles, but IT, cybersecurity and compliance have become specialized areas that can be difficult to manage internally.
Vendor access creates risks
The conversation then turned to California privacy requirements, with Graff discussing the California Invasion of Privacy Act, or CIPA, and the demand notices being sent to businesses over how website conversations with consumers are captured and potentially shared with third parties. Since California consumers can shop on dealership websites anywhere in the country, he said the issue is not necessarily confined to California dealers.
Vendor oversight is another potential source of exposure, as dealerships routinely give marketing companies, website providers, DMS-related vendors and other third parties access to customer information. Graff said dealers should understand how those companies protect the data and have the appropriate agreements and assessments in place before granting access.
That includes a data processing agreement, or DPA, which establishes expectations for how a vendor handles dealership data, and a vendor risk assessment, or VRA, to evaluate how that vendor protects the information it receives. If a third-party vendor experiences a breach, dealers may still face questions about how they conducted their own due diligence.
Giambra also emphasized the everyday employee activity that can create cybersecurity risk. Personal email, social media, unauthorized websites and other activity on dealership systems can expose information or create openings for threats. Establishing controls around what employees can access and how dealership data moves through the network is increasingly important.
How dealers can prepare
For dealers that want to see where vulnerabilities exist, Giambra is offering a 60-day trial of Hurricane’s services at no cost, with no long-term contract. The assessment is designed to give dealers a closer look at their current environment and provide a report detailing what the team finds.
“No strings attached. I mean, it's just 60 days. You know, if you like us, great, we hope you move forward with us. If you don't, we understand.” – Hunter Giambra
For larger dealer groups, the evaluation can start with just a few rooftops. The broader takeaway from today’s conversation is that cybersecurity and compliance are moving targets. Dealers need to continually review their systems, train employees, evaluate vendors and stay current with changing requirements rather than assuming a policy or training session from years ago is still enough.



