Written By: Ken Rosenfield, CPA and Greg Weber

The cyberattack on CDK last June and the even more recent CrowdStrike incident, which caused a massive Microsoft Windows outage, underscores a critical truth: no organization is invulnerable, regardless of its size or security budget. From an accounting standpoint, it showed us that it is still best for auto dealers to stick to the basics.

Going forward, consider having a daily backup to an additional source outside of your DMS provider. In addition, rather than making assumptions and relying solely on the assurance of your current provider, it is advisable to enlist an outside provider to audit your IT infrastructure to ensure that resources and networks are properly hardened.

It’s important to review the basics and the mechanics of the files needed to keep your business running, such as how to handle prepared sales invoices, dealer trades, repair orders, and parts tickets all while keeping track of your inventory. We have seen that simply knowing where to input figures on a menu screen does not mean that the manner of getting to the outcome is correct. It is important to train the appropriate staff on the actual mechanics of their system. Consider practicing this on occasion in the event of system failures in the future.

Now that the DMS can start inputting the activity, there is no need to rush the process to get caught up. Take it slow and steady so you are not prone to errors. Make sure that the dates are accurate and that the balances tie out to the documentation. Understanding that the date to input repair orders is restricted on the system to the actual date the RO is input, double check the accuracy of the dates when making the correction adjustments. This is important to ensure that the in-service dates of vehicles will not expire. We were made aware of some vehicles that the in-service date passed during the outage.

We recommend running “mini audits” of your schedules, sales journals, work in process, open repair orders, and cash transactions. Look for accuracy of dates and amounts as well as any adjustments.

We have compiled a list of areas to consider when conducting an audit of your IT infrastructure. Below is a breakdown of key areas for audit consideration.

Network Security

  • Firewall Configuration: Ensure firewalls are properly configured and updated.
  • Intrusion Detection and Prevention Systems (IDPS): Verify the effectiveness of IDPS in identifying and mitigating threats.
  • Segmentation: Assess network segmentation to limit access to sensitive data.
Access Controls
  • User Authentication: Evaluate the strength of user authentication methods, including multi-factor authentication.
  • Privileges: Review user access levels to ensure the principle of least privilege is followed.
  • Access Logs: Check for regular monitoring and analysis of access logs.
Data Protection
  • Encryption: Ensure that data is encrypted both at rest and in transit.
  • Backup Systems: Verify the integrity and reliability of data backup and recovery procedures.
Vulnerability Management
  • Patch Management: Confirm that all systems are up to date with the latest security patches.
  • Penetration Testing: Perform regular penetration tests to identify and address vulnerabilities.
  • Vulnerability Scanning: Utilize automated tools to continuously scan for and remediate vulnerabilities.
Endpoint Security
  • Anti-malware: Ensure that robust anti-malware solutions are in place and regularly updated.
  • MDR (Manage, Detect and Response): consider replacing traditional Anti-Malware piece with an MDR that remotely monitors, detects, and responds to Malware and Ransomware threats.
  • Device Management: Assess policies for managing and securing devices, including BYOD (Bring Your Own Device).
Incident Response
  • Plan Evaluation: Review the incident response plan to ensure it is comprehensive and up to date.
  • Training and Drills: Confirm that staff are trained on incident response procedures and conduct regular drills.

Physical Security

  • Access Controls: Evaluate the physical access controls to critical IT infrastructure.
  • Surveillance: Ensure that surveillance and monitoring systems are in place and functional.

Compliance and Policy Review

  • Regulatory Compliance: Assess compliance with relevant regulations and standards.
  • Policy Updates: Review and update IT security policies regularly.

Attacks can come from many directions and in many forms. It is crucial to be aware that cybercriminals may capitalize on a recent attack. For instance, a current phishing scam aimed at auto dealers is taking advantage of the recent CrowdStrike outage. The scam involves fake emails prompting employees to click a link for an “immediate patch update.” It is essential for everyone to stay informed, protected, and ready against such threats.

If you have any questions or seek further insights on this subject, join us for an upcoming live Q&A webinar taking place this August. Our panel of industry experts will provide diverse perspectives, covering technical, accounting, and legal aspects. Sign up for our emails to stay updated on the webinar registration information and receive the latest R&Co news.