“There is quite a lot that dealers must do between now and December, and the time for dealers to act is now in order to ensure compliance by the deadline.” – NADA

 

Barcom Has Your Back

The revised FTC Safeguards Rule has many dealerships across the country scrambling to meeting compliance by the June 9th deadline. Dealers who fail to meet compliance may face penalties of up to $43,792 per violation.

The Barcom Technology Solutions team have provided extensive cybersecurity and IT services to dealerships across the country, with compliance being a large part of our focus.

If you would like to schedule a private consultation reach out to Ava Mattei.

(210) 870-1948

 

Webinar link will be sent to this email

 

 

 

 

 

barcom technology solutions team working together at computer in modern office

 

 

What does the revised Safeguards Rule require?

Barcom has gone through every page to find the rules that will impact dealers the most

1. Submit a periodic written report to the dealership’s board of director or senior officer on compliance with these new requirements and overall status and results of the Information Security Program (ISP).

2. Implement a written “Incident Response Plan”.

3. Perform periodic written risk assessments that adhere to certain requirements.

4. Encrypt all data in transit over external networks and at rest.

5. Require Multi-Factor Authentication (MFA), such as an SMS/text verification code, for all systems containing customer nonpublic personal information (NPI). 

6. Implement a data retention policy and dispose of customer information within two years after the end of a customer relationship, unless doing so conflicts with state or federal law.

7. Adopt procedures for IT “change management”.

8. Appoint a single “Qualified Individual” to oversee the dealership’s ISP.

9. Monitor and log the activity of authorized users and detect unauthorized use or access of customer information.

10.  Implement a system or software for continuous monitoring of cybersecurity threats, including annual penetration tests and bi-annual vulnerability tests.

11.  Perform “security awareness” training for all employees.

12.  Periodically assess service providers for their adequacy of physical and technical safeguards. 

 

 

In light of the FTC’s impending regulation compliance deadline, we are reaching out to offer a free webinar to answer any questions you may have regarding the FTC’s Revised Safeguards Rule and how Barcom can help your business achieve and maintain compliance.

 

 

FTC Safeguards Rule: What Your Business Needs to Know

For a full description of the Safeguards Rule, we have included the FTC Website for your convenience.

 

 

Webinar link will be sent to this email