The Growing Cyber Security Requirements for Automotive Dealerships

Automotive dealerships now operate across many connected systems, including Dealer Management Systems (DMS), manufacturer portals, CRM platforms, finance systems, websites, marketing tools, NZTA and PPSR – to name a few.

If there are poor controls over these integrations and weak governance across data, the risks for cyber security exposure increase.

For many dealerships, the biggest IT risks are no longer infrastructure failures. Below are the main challenges we see happening right now in automotive.

1. Increased Cyber Security Requirements

Manufacturers, insurers and finance providers are placing greater cyber security requirements on automotive businesses. Weak cyber controls can affect insurance coverage, supplier approvals, contractual obligations and business continuity.

Requirements typically expected in large corporates are now becoming common in dealership environments:

  • Multi-factor authentication (MFA).
  • Endpoint Detection and Response (EDR).
  • Email security and phishing protection.
  • Security awareness training.
  • Patch and vulnerability management.
  • Security monitoring and audit logs.
  • Incident response planning.
  • Secure backups and recovery testing.
  • Privileged access controls.

Some organisations are also requiring evidence of security governance aligned with frameworks such as ISO/IEC 27001. This is particularly relevant for dealerships handling finance applications, customer identity documents and shared systems with external partners.

2. Customer Data Security

Automotive businesses handle large volumes of sensitive personal and financial information:

  • Driver licences and identity documents.
  • Finance and lending applications.
  • Bank account details.
  • Vehicle ownership records.
  • Customer contact and address data.
  • Warranty and service history.

This data is valuable to attackers and frequently targeted in phishing, ransomware and credential-theft attacks.

Storing documents across email, shared drives, cloud storage, desktops, USB devices and third-party portals makes access control, auditing and retention difficult.

3. System Integrations

System integration is one of the most overlooked cyber security risks in automotive today. Integrations between DMS, CRM, finance, OEM, Trade Me and website systems are necessary but can be poorly documented and rarely reviewed.

These integrations rely on:

  • API connections.
  • Service accounts.
  • Shared credentials.
  • Automated data feeds.
  • Legacy scripts or middleware.

Security risks further increase with shared credentials or over-permissioned accounts. Integration reviews need to be part of regular IT governance.

4. Governance over CRM and Connected Workflows

Customers expect to enquire online, submit finance information remotely and continue the process in the showroom without repeating information.

This creates governance challenges when data moves between multiple systems.

Common issues include:

  • Duplicate customer records.
  • Poor lead ownership.
  • Inconsistent deal information.
  • Weak access controls over customer data.
  • Limited visibility over who changed records.

Poor CRM governance affects customer experience and data security.

5. Governance over AI Adoption

AI is becoming more common in automotive for marketing, lead response, reporting and workflow automation. The main risk is uncontrolled AI usage.

Common issues include:

  • Staff entering sensitive data into public AI tools.
  • AI-generated content containing inaccurate information.
  • Poor oversight of AI vendor security.
  • Buying AI tools with limited business value.

AI should be treated as a governance issue. Businesses should define approved use cases, approved platforms and appropriate-use rules.


What automotive business owners should be reviewing:

  • Which systems are critical to daily operations.
  • How well those systems integrate.
  • Where sensitive customer data is stored.
  • Who has access to key systems and data.
  • Whether MFA is enabled everywhere possible.
  • Whether cyber controls meet insurer, OEM and finance requirements.
  • Whether AI usage is approved and governed.
  • Whether backups and recovery have been tested.
  • Whether incident response plans are current.

If these questions are difficult to answer, there is a likely governance or security risk to address.

Podcom Automotive IT and Cyber Security

How Podcom helps automotive businesses.

Podcom has extensive experience supporting automotive IT environments, including large dealership groups with complex multi-site operations and heavily integrated systems.

Our team understands the technical challenges around Autoline, OEM systems, legislative integrations (NZTA/PPSR), TradeMe Motors, and other third-party dealer tools.

Because we already understand automotive workflows and vendor dependencies, we can identify security risks and integration issues faster than a general IT provider.