A guide to safeguarding your data, systems, and operations against cybercrime.
Written By: Alysha Webb
The reality is that cyberattacks (and) cybercriminals aren’t slowing down, they’re speeding up.
Erik Nachbahr, President and Founder of Helion Technologies
It’s been a year since the CDK attack, an incident that should have been a wake-up call for dealerships to get their cybersecurity in order. Yet many still lack a comprehensive strategy. Is your dealership one of them?
In our recent webinar, “The Hidden Side of Cybersecurity: Managing Risk in the Modern Dealership,” Erik Nachbahr, President and Founder of Helion Technologies, and Greg Weber, our Chief Product Officer, outlined the key questions every dealership should be asking to determine whether their cybersecurity plan is truly adequate.
If it’s not, your dealership is at risk — because cybercriminals aren’t resting. “The reality is that cyberattacks (and) cybercriminals aren’t slowing down, they’re speeding up,” Nachbahr said. “And not much has changed,” he added, referring to dealership cybersecurity strategy.
Helion Technologies works with thousands of dealerships nationwide to ensure they are protected against cyberattacks. “So, we see a lot,” Nachbahr added. “We’re also continuously talking with dealers.”
The Global Reach of Cybercrime
They’re very sophisticated… Were it a country, its GDP would rank fourth in the world behind the United States, China, and the European Union.
Erik Nachbahr, President and Founder of Helion Technologies
Cyberattacks on dealerships are ongoing. It was recently revealed that the same group behind the CDK attack had also nestled itself in another dealership’s system for eight months before successfully striking.
According to Erik, these aren’t small-time hackers. “These cybercriminals are businesses with call centers, data center infrastructure, and software developers,” he explained. Many operate openly in Eastern Europe and Asia.
“They’re very sophisticated,” he added, noting that cybercrime has become a massive global industry. “Were it a country, its GDP would rank fourth in the world behind the United States, China, and the European Union.”
The automotive industry has become an especially attractive target for cybercriminals. Dealerships have plenty of money, valuable data, and multiple points of entry to exploit. “Meanwhile, if you look at dealers’ preparedness when it comes to cybercrime, you know that there’s a lot that still needs to be done,” Nachbahr said.
The Importance of Verification
The criminals then conned him into transferring $400,000 in payroll funds. A simple voice verification step would have stopped the fraud.
As Erik explained, cybercriminals are often more motivated to attack a dealership than the dealership is to defend itself. A store may have safeguards in place, but if they aren’t consistently followed, the protections won’t hold.
For example, Helion was called in after a dealership’s CFO had his email compromised. He clicked a malicious link — still the source of most successful cyberattacks — and unknowingly handed over his Microsoft username, password, and multifactor authentication (MFA) code. The criminals then conned him into transferring $400,000 in payroll funds. A simple voice verification step would have stopped the fraud.
Nachbar also cautioned that insurance companies often use very precise language in their security checklist questionnaires, which can later be referenced during the review of a claim. For instance, a question might be, “Did you have X on 100% of your computers?” When it’s nearly impossible to always maintain complete control of every system. “What we find is that folks that fill out these checklists typically don’t know the answers or haven’t verified the answers,” Nachbar noted.
In one case, an underwriter’s breach audit revealed that although the insured party claimed MFA was enabled on 100% of its computers, it had not been fully implemented. As a result, the underwriter denied coverage for the cyberattack loss — and even sued the organization.
Building a Unified Cybersecurity Strategy
Cybersecurity is a completely different discipline from IT support… The tools are essential, but it’s the expertise in using the tools that makes you secure.
Erik Nachbahr, President and Founder of Helion Technologies
Dealerships tend to be reactive when it comes to cybersecurity, Nachbahr said. “In the automotive space, cybersecurity has traditionally been viewed as an expense to be minimized rather than a driver of revenue — the thought is that it doesn’t sell cars, increase gross, or generate service revenue. As a result, many dealerships have taken a reactive stance instead of spending on proactive measures, a mindset that really needs to change,” he explained.
Too often, instead of investing in a professional cybersecurity team, the responsibility gets handed to “the IT person, the controller, or anyone who kind of speaks fluent IT,” he noted. This leads to a fragmented approach where IT support, cybersecurity, and compliance are treated as separate silos.
The problem: IT support isn’t the same as cybersecurity. “Cybersecurity is a completely different discipline from IT support,” Nachbahr explained. IT support is about setting up, maintaining, and troubleshooting systems. Cybersecurity, on the other hand, involves tracking what cybercriminals are doing, defending against evolving attacks, and hunting down threats already in the system.
Then there is compliance, which is about verification. Not just checking off an FTC requirements checklist, he cautioned, but about ensuring all the protections you say you have in place are actually working.
“True compliance is about breach prevention,” he said. “It’s not about having some paperwork that you can hand to a regulatory agency.”
Even when dealerships have IT support, cybersecurity software, and compliance processes, the three areas often don’t work together. The result: tools may be installed, but no one knows how to use them effectively. “It’s like buying a set of mechanics tools. Just because I have a set of mechanics tools doesn’t actually make me a car mechanic, right?” Nachbahr said. “The tools are essential, but it’s the expertise in using the tools that makes you secure.”
According to Nachbahr, the key is for dealerships to move toward a single, unified cybersecurity strategy.
Patch & Upgrade: Low-Hanging Cybersecurity Wins
If you’re not patching and replacing outdated technology, you’re vulnerable to cyber attackers.
Erik Nachbahr, President and Founder of Helion Technologies
If a dealership considers all the defensive steps it can take to protect itself against cyberattacks, patching and the use of obsolete technology is “one that really is a low-hanging fruit” Nachbar said. “If you’re not patching and replacing outdated technology, you’re vulnerable to cyber attackers.”
But patching involves more than simply clicking “yes” on a software update. It also should include a check of the entire system to ensure the patches are tested and properly implemented — something that often isn’t happening at dealerships.
“What we typically see in dealerships when we look at their systems, is that patching is way, way, way, way, way far behind,” Nachbahr said. He added that many stores also still run old, outdated hardware, which creates “a gaping hole for the cybercriminal to walk through.”
Why the hesitation? Often it comes down to fear that an update will disrupt operations. “It’s Saturday morning and the sales tower can’t work deals because some update happened and now they can’t log into the bank right and pull credit,” Nachbahr explained. “So, there’s this historical feeling that patches could take me down.”
Helion manages patching by taking a strategic approach. Their team reviews computers, networks, printers, and all other connected devices to ensure patches are up to date. Updates are researched, tested, and released in small, controlled chunks — so that critical patches are rolled out quickly while less urgent ones are scheduled over time. “It’s a strategy that involves some pretty sophisticated technology,” Nachbahr said.
Protect Your Keys to the Kingdom
Once you have the administrative account, you've got the keys to the Kingdom.
Erik Nachbahr, President and Founder of Helion Technologies
“The number one thing that cyber criminals want to get is privileged account access,” Nachbar said. Privileged accounts can access a dealership’s administrative accounts. “Once you have the administrative account, you’ve got the keys to the Kingdom,” he explained.”
Helion often finds multiple administrative accounts on just one computer network—and usually many more exist within the DMS and other systems.
Those with administrative account access are generally C-suite employees, Nachbar said, and they remain logged in all day performing general tasks that don’t require this level of access. This creates a significant vulnerability. Another issue is that users rarely change their administrative passwords because they don’t want to forget them and be prompted to enter them repeatedly. “This is a huge, huge problem in dealerships,” he emphasized.
Dealerships also need to understand the difference between a vulnerability scan and a penetration test, Nachbar noted. A vulnerability scan simply checks whether software is running as it should. A penetration test, however, is conducted by a human assessor using tools to attempt access to various servers. It evaluates how easily a cybercriminal could launch an attack. Dealers are often told they are receiving a pen test when, in reality, they are only getting a vulnerability scan, he warned.
Best practices typically recommend conducting vulnerability scans twice a year and penetration tests once a year. “You can certainly do them more frequently, but that’s the minimum,” Nachbar added. However, he emphasized that pen tests and vulnerability scans are of little value unless the results are properly understood, vulnerabilities are prioritized, and corrective actions are taken to address the identified issues.
Ask the Right Questions
While it might feel like you’re drinking from a firehose with all the cybersecurity information coming at you, just start asking questions.
Greg Weber, Chief Product Officer, Rosenfield and Co.
Rosenfield & Co. went through a cybersecurity evaluation and, last August, began tightening up its network, Weber said. “It’s taken a year, and we feel a lot better about our network,” he added.
While it might feel like you’re drinking from a firehose with all the cybersecurity information coming at you, Weber advised just to start asking questions. Be curious about your dealership’s cybersecurity status.
Some questions to consider:
- Have we upgraded all our computers and devices to Windows 11?
- Have we appropriately deployed MFA?
- Do we have outdated or unsupported technology on our network?
- If we’re attacked, who will save us and how?
- What’s the process for applying security patches?
Cybersecurity isn’t a one-time fix; it’s an ongoing process that requires curiosity, vigilance, and a unified approach. Dealerships must move beyond reactive measures, outdated systems, and fragmented strategies to stay ahead of increasingly sophisticated cybercriminals. Start by asking the right questions, patching systems, securing privileged accounts, and conducting regular vulnerability and penetration assessments. The goal isn’t just compliance — it’s true protection. By investing in a comprehensive, proactive cybersecurity plan, your dealership can safeguard its data, its finances, and its reputation in an era where threats are constant and evolving.
Did you miss the webinar?
Catch the full recording of “The Hidden Side of Cybersecurity: Managing Risk in the Modern Dealership” and download the slide deck to review key insights and actionable steps for strengthening your dealership’s cybersecurity.
🎥 Watch the replay
📊 Download the slides
Have questions or want to talk it through? Connect with us or contact a member of our team directly for questions and expert guidance.
Explore our full library of past webinar recordings and recaps by visiting our Webinar Hub.