Research

Assessed on Faith

What the technology vendors serving automotive retail publish about their own security — measured only from what any dealer’s procurement team could look up unaided.

No vendor is named alongside its own results

One finding

Anyone can send email that appears to come from your vendor

One of the costliest frauds against a dealership involves breaking into nothing at all. Someone emails the finance office from a supplier the dealership already trusts: a change of bank details on an invoice, an attachment, a request that looks routine because it looks familiar. No system is compromised. The message is simply forged, and it is delivered because nothing told the receiving mail server to refuse it.

Only the vendor can stop mail that forges its exact domain. A domain owner publishes one public instruction — it is called a DMARC policy — asking every mail server that checks it to refuse those messages, and most large mail providers do check. It costs nothing, it requires no software, and the dealership cannot publish it on the vendor’s behalf. Until the vendor does, mail forging that vendor’s domain is not refused on the vendor’s instruction.

What we found

Of the 101 brands assessed, 32 — about a third — do not have it switched on. Twenty-seven publish a policy set only to watch, which leaves forged mail to be delivered rather than refused; five publish no policy at all. Counted by company rather than by brand, 28 of 83 — treating a company as unprotected if any one of its brands is.

The more useful number is the next one. Of those 32, 28 already publish both SPF and DKIM — the two mechanisms a DMARC policy relies on — and 25 of those already publish the record that carries the policy. For most of this market the remaining step is a policy change rather than a build.

If you buy from these vendors

Ask your three most critical suppliers one question: is your DMARC policy set to quarantine or reject? It is free to check, free for them to fix, and it tells you something a forty-page questionnaire will not.

The study

101 brands, 83 independent companies

In August 2026 we assessed 101 vendor brands, operated by 83 independent companies serving automotive retail, against two layers of entirely public signal: email authentication published in DNS, and security documentation published on the web. Every automated positive was verified by hand before it was counted.

Population
101 vendor brands, 83 independent companies, across nine categories: DMS and operations, dealer CRM, digital retail, inventory and data, F&I and titling, fixed operations, marketing and web, marketplace and leads, and lending and payments
Collection window
August 2026; the exact window is recorded in the report
Layer one
SPF, DKIM and DMARC records, queried in public DNS
Layer two
Security and trust documentation published on the vendor’s own website, including whether a route exists for reporting a vulnerability
Verification
Every automated positive reviewed by hand, and every negative treated as a floor rather than a census
Author
Andrew Tubbs, CISSP, CISM, C|CISO — formerly Director, Information Security at Cox Automotive

Method

What the study does not do

The constraint is the point. A study that tested vendor systems would be a different document with a different set of legal problems, and it would not answer the question a dealer actually faces.

  • Nothing was scanned, tested or probed. DNS records were queried and public web pages were read. Every signal in the dataset is one a customer could look up for themselves.
  • It measures assessability, not security. A vendor that publishes nothing may run an excellent program. The study measures whether a customer can tell — and a customer who cannot tell has to take it on faith.
  • It is not a compliance finding about anyone. The finding is that vendors publish nothing a dealer could use to complete the assessment the Rule requires of the dealer. That is a statement about published evidence, not about any company’s compliance.
  • Only vendors that publish are named. In the public release, a company appears by name only where it published something. The aggregate names no one else.

Why it matters

Eighteen elements, and the one that points outward

The FTC Safeguards Rule sets out eighteen discrete requirements for the information security program of every dealership that finances or leases vehicles. Almost all of them look inward, at the dealer’s own program. FTC Safeguards § 314.4(f) looks outward: select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider.

That last obligation is what generates the questionnaire traffic in this market. It is also, if a vendor publishes nothing, an obligation the dealer has no public means of discharging. This study is a measurement of that gap.

Publication

No company is named with its own results

The published study reports figures at the level of the market and of each category. A company appears in it by name only where that company published something itself — a trust page, a disclosure route, a sub-processor list — and then it appears as credit, not as a score. Nothing in the published study identifies who scored badly.

  • Scorecards go to the vendor, never to the market. Every assessed brand has one: its result, the evidence behind it, and what would change it. Any brand in the sample can ask for its own at any time, free, with no commercial ask attached.
  • Corrections are accepted from anyone, at any point. If a finding is wrong, or the page the method missed exists, say so and the dataset is corrected.
  • It is not a compliance finding about anyone. The study measures what a customer can look up unaided. A vendor that publishes nothing may run an excellent program.

What is published today

The email-authentication figures above are the only ones published so far. The web layer — security pages, disclosure routes, sub-processor lists — is complete and publishes with the full study.

If you operate a brand serving automotive retail and want to know whether you are in the sample, write and ask. We will send your scorecard.

Request your scorecard

Disclosure

The author was Director, Information Security at Cox Automotive, which operates brands appearing in the sample; some of the controls assessed at those brands were built during his tenure. Cox Automotive brands are treated in the study exactly as every other brand is, and the relationship is disclosed wherever they appear.

The study is self-funded. The author’s consultancy has commercial relationships with companies in this market, which may include companies in the sample. No vendor paid for, commissioned or influenced this study's design, method or findings; each vendor sees only its own result before publication. The dataset was collected before any such engagement was discussed.