LEVELFOURINFORMATIONSECURITY

Research

Assessed on Faith

What the technology vendors serving automotive retail publish about their own security — measured only from what any dealer’s procurement team could look up unaided.

Findings publish after every assessed brand has received its scorecard

The study

101 brands, 87 independent companies

In August 2026 we assessed 101 vendor brands, operated by 87 independent companies serving automotive retail, against two layers of entirely public signal: email authentication published in DNS, and security documentation published on the web. Every automated positive was verified by hand before it was counted.

Population
101 vendor brands, 87 independent companies, across DMS, inventory and data, F&I and titling, fixed operations, marketing and web, and lending
Collection window
August 2026; the exact window is recorded in the report
Layer one
SPF, DKIM and DMARC records, queried in public DNS
Layer two
Security and trust documentation published on the vendor’s own website, including whether a route exists for reporting a vulnerability
Verification
Every automated positive reviewed by hand; an adversarial review of the first dataset produced a corrected release
Author
Andrew Tubbs, CISSP, CISM, C|CISO — formerly Director, Information Security at Cox Automotive

Method

What the study does not do

The constraint is the point. A study that tested vendor systems would be a different document with a different set of legal problems, and it would not answer the question a dealer actually faces.

  • Nothing was scanned, tested or probed. DNS records were queried and public web pages were read. Every signal in the dataset is one a customer could look up for themselves.
  • It measures assessability, not security. A vendor that publishes nothing may run an excellent program. The study measures whether a customer can tell — and a customer who cannot tell has to take it on faith.
  • It is not a compliance finding about anyone. The finding is that vendors publish nothing a dealer could use to complete the assessment the Rule requires of the dealer. That is a statement about published evidence, not about any company’s compliance.
  • Only vendors that publish are named. In the public release, a company appears by name only where it published something. The aggregate names no one else.

Why it matters

Eighteen elements, and the one that points outward

The FTC Safeguards Rule sets out eighteen discrete requirements for the information security program of every dealership that finances or leases vehicles. Almost all of them look inward, at the dealer’s own program. FTC Safeguards § 314.4(f) looks outward: select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider.

That last obligation is what generates the questionnaire traffic in this market. It is also, if a vendor publishes nothing, an obligation the dealer has no public means of discharging. This study is a measurement of that gap.

Sequence

Vendors first, publication second

No company learns about its own result from a press release.

  1. 1

    Each brand receives its own scorecard

    Its result, the evidence behind it, and what would change it — sent privately, with no commercial ask attached.

  2. 2

    Roughly two weeks pass

    Time to correct a finding, or to fix the underlying gap before anything is published. Several already have.

  3. 3

    The aggregate publishes

    Figures at the level of the market and of each category. Companies that publish security documentation are named and credited. No one else is named.

If you operate a brand serving automotive retail and want to know whether you are in the sample, write and ask. We will send your scorecard.

Request your scorecard

Disclosure

The author was Director, Information Security at Cox Automotive, which operates brands appearing in the sample; some of the controls assessed at those brands were built during his tenure. Cox Automotive brands are treated in the study exactly as every other brand is, and the relationship is disclosed wherever they appear.

The study is self-funded. The author’s consultancy has commercial relationships with companies in this market, which may include companies in the sample. No vendor paid for, commissioned, reviewed or influenced this study, and the dataset was collected before any such engagement was discussed.