Skip Navigation
Better Together | Risk Strategies to Join Brown & Brown  Learn More
  • Careers
  • Report a Claim
  • Contact Us
Risk Strategies Logo
  • Industries

    • Agriculture
    • Architects & Engineers
    • Aviation
    • Cannabis
    • Construction
    • Dental
    • Education
    • Entertainment
    • Financial Services
    • Fine Art
    • Healthcare
    • Law Firms
    • Marine & Yacht
    • Nonprofit & Human Services
    • Private Equity
    • Public Sector
    • Real Estate
    • Relocation
    • Transportation
    • Waste & Recycling
    • Wineries
  • Solutions

      • Captives
      • Casualty
      • Cyber
      • Environmental
      • International
      • Executive Risk Solutions
      • Property
      • Surety
      • Employee Benefits Overview
      • Benefit Administration and Technology
      • Benefits Compliance Support
      • Data & Analytics
      • Human Capital Advisory Services
      • International Benefits
      • Absence Management & Ancillary Programs
      • Voluntary & Lifestyle Benefits
      • Medicare
      • Financial & Wealth Overview
      • Retirement Plan Services
      • Executive Benefits
      • Life Insurance
      • Private Client Services Overview
      • Homeowners
      • Flood
      • Collections
      • Umbrella & Excess Liability
      • Auto
      • Collector & Exotic Car
      • Boat & Yacht
      • Travel Medical & Trip Insurance
      • Family Office
      • Cyber Insurance - Family Office
      • Cyber Insurance - Individuals
      • Specialty Coverages
      • Private Client Risk Resource Center
    • Reinsurance
      • Risk Management Services Overview
      • Analytics
      • Claims Management & Advocacy
      • Loss Control
      • Safety Consulting Services
      • Pro Safety Training Courses
      • Workers’ Comp: Premium Review & Recovery
  • Consulting

    • Consulting Overview
    • Actuarial Services
    • Healthcare Claim Audit Services
    • Health and Welfare
    • Mergers and Acquisitions
    • Pharmacy Consulting
    • Retirement Benefits
  • News and Insights

    • All Insights
    • Blog
    • Emergency Resource Centers
    • Employee Benefits Compliance Center
    • Events
    • Media Coverage
    • State of the Market Reports
    • Press Releases
    • Private Client Resources
    • Webinars
  • Company

    • About Us
    • Annual Report
    • Careers
    • Culture and Values
    • Diversity, Equity & Inclusion
    • Environmental, Social, & Governance
    • General Terms of Business
    • Leaders
    • Local Expertise
    • Mergers & Acquisitions
    • Recognition & Awards
    • Risk Strategies Foundation
    • Transparency and Disclosures
  • Join Us
    • Careers
    • Mergers & Acquisitions
  • Industries
    • Agriculture
    • Architects & Engineers
    • Aviation
      • Aviation Business Insurance - Manned Risk
      • Non-Owned Aviation
      • Unmanned Aerial System and Drones
    • Cannabis
    • Construction
      • Alternative Solutions
      • Financing & Pre-Construction
      • Insurance Solutions
      • Risk Management
      • Surety
    • Dental
      • Insurance for Dental Professionals
      • Dental Malpractice Insurance
      • BOP Insurance - Dental Practices & DSOs
      • Dental School Graduates
      • Dental Associates & Hygienists
      • Dental Practice Owners
      • Dental Service Organizations (DSOs)
    • Education
      • Employee Benefits for Education
      • Property, Casualty & Liability for Education
      • Student Health & Wellness
        • Student Health Brokerage and Consulting
        • Student Health Plan Administration
        • Student Health Insurance Plans
        • Solutions for Student Athletes
        • Student Health & Wellness Tools
        • Special Risk Insurance
    • Entertainment
      • Film & Television
      • Advertising Production Wrap Ups
      • Advertising/PR
      • Event Cancellation & Non-Appearance
      • Music & Touring
      • Theatrical Production & Live Performance 
      • Venue Insurance
    • Financial Services
      • Asset Managers
      • Banks & Non-Bank Lending
      • Collections
      • Consumer Financial Services
      • Financial Tech
      • Insurance Companies
    • Fine Art
      • Dealers and Auction Houses
        • Galleries
        • Private Art Dealers
      • Collections
        • Private Collectors
        • Coins, Paper Money & Numismatics Collections
        • Gold, Bullion & Precious Metal Collections
      • Artists
      • Museums and Foundations
        • Museums
      • Fine Art Packers / Shippers / Warehouses
    • Healthcare
      • Employee Benefits - Healthcare
      • Managed Care / Stop Loss
      • Medical Malpractice
      • Property & Casualty - Healthcare
      • Reinsurance
    • Law Firms
    • Marine & Yacht
      • Yacht Insurance For Individuals
        • Mega Yachts
        • Cruiser Insurance - Jackline
        • One-Design Insurance Program
        • Sailors Health Insurance Program
        • US Sailing Insurance Solutions
      • Commercial Marine Insurance
        • Aquaculture
        • Cargo & Transit Insurance Solutions
        • Crew Medical Insurance
        • Hull & Machinery
        • Marine Claims Service
        • Marine Construction
        • Marine Liability
        • Ports & Terminals
        • Protection & Indemnity
        • Recreational Marine Businesses
        • Sailing Organizations – Burgee Program
    • Nonprofit & Human Services
    • Private Equity
      • Crypto Companies
    • Public Sector
      • Public Safety Organizations & Municipalities
    • Real Estate
      • Commercial
      • Community Associations
      • Hospitality
      • Residential / Habitational
      • REITs
      • Retail
      • Specialty Programs
    • Relocation
      • Domestic Household Goods
      • Expat Renters & Living Insurance
      • Relocation Claims Service
      • International Household Goods
      • Supplemental Movers Coverage
      • Temporary Living Insurance
      • Vacant Home
    • Transportation
      • Business Auto Insurance
      • Last Mile Delivery
      • While Under Dispatch Insurance
      • Forwarding & Brokering
      • Workers' Compensation
    • Waste & Recycling
    • Wineries
  • Solutions
    • Commercial Insurance
      • Captives
      • Casualty
        • Analytics
        • Auto Liability & Physical Damage
        • Captives & Alternative Risk Financing
        • Claims Advocacy & Loss Control
        • Excess Liability
        • General Liability
        • Product Recall
        • Workers' Compensation
      • Cyber
        • Cyber Resolute
        • Cyber Risk Assessment and Analytics
        • Cyber Risk Response & Claims Advocacy
        • Cyber Insurance - Family Office
        • Cyber Insurance - Individuals
      • Environmental
        • Contractors Pollution Liability
        • Environmental Excess
        • Environmental Liability Transfer
        • Environmental Liability - Healthcare
        • Environmental Liability - Higher Education
        • Pollution Legal Liability
        • Environmental Liability - Private Equity
        • Professional Environmental Liability Insurance
        • Real Estate Development
        • Remediation Cost Cap
        • Secured Creditor Protection for Lenders
        • Underground Storage Tanks
      • International
      • Executive Risk Solutions
        • Executive Risk Solutions - Entertainment
        • Executive Risk Solutions - Financial Institutions
        • Executive Risk Solutions - Healthcare
        • Executive Risk Solutions - Real Estate
      • Property
        • Builder's Risk
        • Property Claims Services
        • Inland Transit and Ocean Cargo
        • Natural Hazard Catastrophe Modeling
        • Political Violence and Terrorism
        • Property Damage & Business Interruptions Valuations
        • Property Loss Prevention and Control
      • Surety
    • Employee Benefits
      • Employee Benefits Overview
      • Benefit Administration and Technology
      • Benefits Compliance Support
      • Data & Analytics
      • Human Capital Advisory Services
      • International Benefits
      • Absence Management & Ancillary Programs
      • Voluntary & Lifestyle Benefits
      • Medicare
    • Financial & Wealth
      • Financial & Wealth Overview
      • Retirement Plan Services
      • Executive Benefits
      • Life Insurance
    • Private Client Services
      • Private Client Services Overview
      • Homeowners
      • Flood
      • Collections
      • Umbrella & Excess Liability
      • Auto
      • Collector & Exotic Car
      • Boat & Yacht
      • Travel Medical & Trip Insurance
      • Family Office
      • Cyber Insurance - Family Office
      • Cyber Insurance - Individuals
      • Specialty Coverages
      • Private Client Risk Resource Center
    • Reinsurance
    • Risk Management Services
      • Risk Management Services Overview
      • Analytics
      • Claims Management & Advocacy
      • Loss Control
      • Safety Consulting Services
      • Pro Safety Training Courses
      • Workers’ Comp: Premium Review & Recovery
  • Consulting
    • Consulting Overview
    • Actuarial Services
    • Healthcare Claim Audit Services
    • Health and Welfare
    • Mergers and Acquisitions
    • Pharmacy Consulting
    • Retirement Benefits
  • News and Insights
    • All Insights
    • Blog
    • Emergency Resource Centers
      • Cybersecurity
      • Earthquake
      • Hurricane
      • Pandemic
      • Riot & Civil Unrest
      • Severe Storms
      • Violence & Active Shooter
      • Wildfire
      • Winter Weather
    • Employee Benefits Compliance Center
    • Events
    • Media Coverage
    • State of the Market Reports
    • Press Releases
    • Private Client Resources
    • Webinars
  • Company
    • About Us
    • Annual Report
    • Careers
    • Culture and Values
    • Diversity, Equity & Inclusion
      • BeHEARD Series
      • DE&I Structure
      • Employee Resource Groups
    • Environmental, Social, & Governance
    • General Terms of Business
    • Leaders
    • Local Expertise
    • Mergers & Acquisitions
    • Recognition & Awards
    • Risk Strategies Foundation
    • Transparency and Disclosures
      • General Terms of Business
      • Conflict of Interest Policy
      • Compensation Disclosure
      • Enterprise Risk Management
  • Join Us
    • Careers
      • Benefits & Wellness
      • Investing in Growth & Leadership
      • Life at Risk Strategies
      • Next Steps
    • Mergers & Acquisitions
      • Partnership Benefits
      • Why Join Us?
      • Onboarding & Integration
  • Careers
  • Report a Claim
  • Contact Us

You are about to leave Risk Strategies website and view the content of an external website.

You are leaving risk-strategies.com

By accessing this link, you will be leaving Risk Strategies website and entering a website hosted by another party. Please be advised that you will no longer be subject to, or under the protection of, the privacy and security policies of Risk Strategies website. We encourage you to read and evaluate the privacy and security policies of the site you are entering, which may be different than those of Risk Strategies.

OK
  • News and Insights
  • Blog
Subscribe

Subscribe via Email

  • News and Insights
  • Blog
July 02, 2024

Strengthening Cybersecurity in Car Dealerships: Lessons from the CDK Global Hack

Cyber
5 min read
Luke Shipp, Managing Director, and Allen Blount, National Cyber & Technology Product Leader
  • Facebook
  • X (Twitter)
  • LinkedIn
  • Email
Lessons from the CDK Global Cyberattack: Auto Dealer Cybersecurity
  • Facebook
  • X (Twitter)
  • LinkedIn
  • Email

The recent cyberattack on CDK Global, which affected thousands of car dealerships nationwide, underscored significant vulnerabilities within industries in which a single vendor hack can disrupt entire swaths of the market, such as healthcare and fine arts. The incident disrupted daily operations and revealed critical weaknesses in the systems many dealerships rely on.

As cyber threats continue to evolve, reassessing cybersecurity strategies becomes crucial for car dealerships, with a particular focus on vendor management as well as comprehensive cyber insurance.

Lessons from CDK cyberattack: addressing outdated systems

Naturally, car dealerships are primarily focused on selling and servicing vehicles, with owners and managers dedicated to engaging with customers and running successful businesses. Business leaders in this space, may not be all that tech-savvy, and dealerships, in general, are not on the forefront of cyber best practices. While larger dealerships might have CIOs, many operate without any full-time IT staff and still use outdated, pre-Windows, DOS-based systems. Security limitations in these systems abound including:

  • Lack of advanced security features like encryption.
  • No multi-user support, making it vulnerable to unauthorized access and malware.
  • Higher vulnerability to cyberattacks as cybercriminals view them as easy targets.

Managing vendor cybersecurity risks

The CDK breach, originating from a vulnerability in a specific vendor's technology, affected the Dealer Management System (DMS) used by thousands of dealerships across the country. This system is crucial for managing sales, ordering (vehicles and parts), and maintenance (scheduling, quoting, invoicing). The breach allowed malicious actors to launch a ransomware attack on CDK. Ransomware attackers infiltrate IT systems, silently moving through devices and stealing corporate data. After taking all data and gaining control, they encrypt every device and leave ransom notes. They demand payment to decrypt devices and promise not to leak stolen data, using it as leverage.

The impact of the breach was multifaceted:

  • Sales Operations: Dealerships faced significant delays in processing vehicle and parts orders, resulting in customer dissatisfaction and lost sales opportunities.
  • Maintenance Scheduling: The disruption of maintenance scheduling systems led to confusion and delays in service appointments, affecting customer trust and revenue.
  • Quoting and Invoicing: The inability to generate accurate quotes and invoices in a timely manner hindered financial operations and strained dealer-customer relationships.

Most dealerships are heavily dependent on their DMS vendors and lack the IT resources to easily switch to alternative solutions. The "switching cost"—the financial, time, and resource investment required to transition to a new vendor—is prohibitively high. This includes not only the direct expenses of purchasing new software but also the indirect costs of training staff, migrating data, and adjusting business processes. In addition, given manufacturer vendor mandates, they have a limited universe from which to choose. Consequently, dealerships remain tied to their current vendors despite the risks exposed by the breach, underlining the critical need for robust cybersecurity measures and comprehensive contingency plans.

Leveraging comprehensive cyber insurance policies

A comprehensive cyber insurance policy should cover both direct and contingent business interruption. In cybersecurity insurance, "direct disruption" refers to immediate, tangible losses caused by a cyber incident, such as system damage, supply chain disruption, and negative publicity. "Business disruption," on the other hand, involves the broader impact on business operations, including:

  • Lost revenue
  • Downtime
  • The cost of restoring normal operations

Cyber insurance policies also address costs related to business continuity measures, such as overtime payments for staff and finding alternative vendors.

A well-structured cyber insurance policy can also provide:

  • Financial support
  • Coverage for costs associated with switching to alternative vendors
  • Mitigation of operational disruptions

Developing backup systems and alternative vendor arrangements are also key components of a resilient cybersecurity strategy. This type of planning can come into play before a breach occurs as part of a comprehensive proactive risk management plan, which may also include steps like business continuity planning and customer response planning.

Proactive risk management

Companies can stay vigilant to thwart potential attacks by implementing risk management best practices into their systems and culture. Here are a few examples.

Conduct business continuity planning

Dealerships would benefit from detailed business continuity planning, preparing for worst-case scenarios, and rehearsing the steps to bring their business back online. Planning for the absence of technology—such as reverting to manual processes—helps maintain operations during a cyber incident.

As mentioned, cyber insurance coverage allows businesses that may not be as focused on tech to build in a safety net should unforeseen events occur.

Identify and correct single points of failure

Addressing single points of failure is a vital part of business continuity efforts. Evaluating whether a supplier, specific equipment, a key staff member, or other resource could bottleneck the business if they become unavailable can guide backup plan development. In the case of the CDK Global breach, for example, many dealerships did not have a digital backup plan and thus resorted to pen-and-paper methods for selling and managing inventory.

Develop a breach response plan

When a breach happens, multiple response plans are put into action. Beyond the technical response, leaders need to think about the communications of the breach to employees and customers. Developing best practices and policies for transparently communicating breaches when they happen will allow you to act quickly and communicate transparently. These initial communications touchpoints will be important for restoring trust with key stakeholders.

Carefully vet and oversee vendors

Careful vendor vetting and oversight prevent vulnerabilities from being exploited. Review contracts to understand who is responsible for patch management and other cybersecurity activities. Regularly update and verify vendor compliance to strengthen security.

Review insurance policies regularly

Thoroughly reviewing insurance policies ensures proper protection. Verify the coverage is relevant to how the dealership operates. This will help you better understand the fine print, especially during policy renewals, which can prevent gaps in coverage.

Exercise vigilance

  • Assume cyber criminals are targeting your business
  • Bring in specialists to evaluate cyber vulnerabilities
  • Conduct regular cyber training for all employees since over 80% of cyber breaches trace back to human error

Looking ahead

The CDK Global hack serves as a stark reminder of the cybersecurity challenges faced by car dealerships. To protect against future cyber threats, proactively manage vendor relationships, invest in comprehensive cyber insurance, and develop robust contingency plans. Businesses can also partner with a cybersecurity insurance broker to ensure they are adequately protected against potential hacks. By addressing these challenges head-on, you can ensure business continuity and build resilience in the face of evolving cyber threats.

Want to learn more

Find Luke Shipp on LinkedIn.

Find Allen Blount on LinkedIn.

Connect with Risk Strategies Cyber Risk team at cyber@risk-strategies.com. 

 

The contents of this article are for general informational purposes only and Risk Strategies Company makes no representation or warranty of any kind, express or implied, regarding the accuracy or completeness of any information contained herein. Any recommendations contained herein are intended to provide insight based on currently available information for consideration and should be vetted against applicable legal and business needs before application to a specific client. 

Related Posts

See all posts

Cyber Dental
4 min read
June 03, 2025

Understanding Cyber Liability Risks for Dental Practices

Your dental practice handles sensitive patient information, making it a target for cyberattacks. …
Read article
Transportation Cyber
4 min read
May 14, 2025

How Cybercrime is Hijacking the Supply Chain: Cargo Theft, Fraud, and Insurance Gaps

Cyber risk is no longer just the IT department's problem in today's fast-moving transportation …
Read article
Cyber Risk
5 min read
April 02, 2025

The Future of Risk: Cyber Threats Affecting Businesses in 2025

Editor’s note: The way businesses approach risk is undergoing a fundamental shift. This article is …
Read article
Risk Strategies Logo
  • Report a Claim
  • Contact
  • Terms of Use
  • Cookie Policy
  • Privacy Policy
  • Consumer Health Data Privacy Notice
  • Accessibility
  • Health Plan Transparency Compliance
  • Accessibility
  • Cookie Policy
  • Health Plan Transparency Disclosure
  • Privacy Policy
  • Terms of Use
©2025 Risk Strategies. All rights reserved.

Connect with Us

  • LinkedIn
  • X
  • Instagram
  • Facebook