Skip to main content
Sister Publication Links
  • Automotive News Canada
  • Automotive News Europe
  • Automotive News China
  • Automobilwoche
AN-LOGO-BLUE
Subscribe
  • Subscribe
  • Account
  • login
  • HOME
  • NEWS
    • Dealers
    • Automakers & Suppliers
    • News by Brand
    • Cars & Concepts
    • Coronavirus Coverage
    • China
    • Shift
    • Mobility Report
    • Special Reports
    • Digital Edition Archive
    • This Week's Issue
    • Ford advertisement
      When will consumers have appetite for regular car ads again?
      The show would have stretched from the TCF Center along the river to the Renaissance Center.
      What Detroit show can be — in 2021
      Dealerships can protect access to customer data by having employees connect through a VPN.
      Dealerships can fight work-from-home vulnerabilities
      L.A. County, Calif. showrooms reopen under new protocols
    • Ford's 2 JVs post April sales gains
      Volvo back on growth track
      Deliveries stabilize at Kia venture
      Tesla
      Tesla abruptly suspends output at Shanghai plant, report says
    • Israeli exec plays matchmaker for mobility startups, large companies
      Nikola's journey from notion to Nasdaq
      Osram LEDs offer safety, customization
      StealthPath aims to shield connected cars
    • Uber posts first-ever quarterly decline in ride-hailing bookings
      Lime e-scooter
      Uber leads $170 million investment into Lime electric scooters
      Eliminating the human driver from a cab could cut costs by as much as 60 percent.
      Lyft narrows Q1 loss despite virus impact
      Uber app
      Uber cutting 3,700 jobs, signals more 'difficult adjustments' to come
    • 2020 NADA Show
      2020 CES
      Automotive News special report: Retail Realities
      2019 UAW-Detroit 3 negotiations: The path forward
    • The show would have stretched from the TCF Center along the river to the Renaissance Center.
      What Detroit show can be — in 2021
      Ford advertisement
      When will consumers have appetite for regular car ads again?
      Dealerships can protect access to customer data by having employees connect through a VPN.
      Dealerships can fight work-from-home vulnerabilities
      April sales plunge, but rebound is underway
    • Access F&I
    • Fixed Ops Journal
    • Marketing
    • Used Cars
    • Retail Technology
    • Sales
    • Best Practices
    • Dealership Buy/Sell
    • NADA
    • NADA Show
    • Automakers
    • Manufacturing
    • Suppliers
    • Regulations & Safety
    • Executives
    • Leading Women Network
    • Guide to Economic Development
    • PACE Awards
    • Management Briefing Seminars
    • World Congress
    • Aston Martin
    • BMW
      • Mini
      • Rolls-Royce
    • Daimler
      • Mercedes Benz
      • Smart
    • Fiat Chrysler
      • Alfa Romeo
      • Chrysler
      • Dodge
      • Ferrari
      • Fiat
      • Jeep
      • Maserati
      • Ram
    • Ford
      • Lincoln
    • General Motors
      • Buick
      • Cadillac
      • Chevrolet
      • GMC
      • Holden
    • Honda
      • Acura
    • Hyundai
      • Genesis
      • Kia
    • Mazda
    • McLaren
    • Mitsubishi
    • Nissan
      • Infiniti
    • PSA
      • Citroen
      • Opel
      • Peugeot
    • Renault
    • Subaru
    • Suzuki
    • Tata
      • Jaguar
      • Land Rover
    • Tesla
    • Toyota
      • Lexus
    • Volkswagen
      • Audi
      • Bentley
      • Bugatti
      • Lamborghini
      • Porsche
      • Seat
      • Skoda
    • Volvo
    • (Discontinued Brands)
    • Auto Shows
      • Detroit Auto Show
      • New York Auto Show
      • Los Angeles Auto Show
      • Chicago Auto Show
      • Geneva Auto Show
      • Paris Auto Show
      • Frankfurt Auto Show
      • Toronto Auto Show
      • Tokyo Auto Show
      • Shanghai Auto Show
      • Beijing Auto Show
    • Future Product Pipeline
    • Photo Galleries
    • Car Cutaways
    • Design
  • OPINION
    • Blogs
    • Cartoons
    • Keith Crain
    • Automotive Views with Jason Stein
    • Columnists
    • China Commentary
    • Editorials
    • Letters to the Editor
    • Send us a Letter
    • With EV deal, Honda plays catch up, GM polishes engineering chops
      PSA Tavares FCA Manley 2 web, FCA pic.jpg
      This is the wrong time to revise PSA-FCA merger financial terms
      Hyundai Kona EV web.jpg
      The good, the bad and the pricey of driving electric
      Welcome to the Bailout Club, everybody
    • view gallery
      1 photos
      Transmission Protection
      view gallery
      1 photos
      COVID-19 Hygiene
      Cleaning up the dealership
      view gallery
      1 photos
      Coronavirus Clearing
      view gallery
      1 photos
      Global Pandemic System
    • Shifting gears away from the stick shift
      SEMA still a wonderful circus
      Penske still has plenty of races to win
      Ford's turn in the hot seat
    • May 4, 2020 | Normalcy slowly returning to the auto industry
      April 28, 2020 | Signs of recovery
      April 21, 2020 | A glimmer of hope for automotive retailers
      April 7, 2020 | Helpers emerge across the industry
    • Andy MacLeay
      Dealers, get your online houses in order
      Dave Versical
      Crack the online retail code — now
      Rory Gamble
      Crisis proves need for U.S. manufacturing
      Jamie Butters
      Room for hydrogen after crisis
    • Beijing pins hope of popularizing EVs on battery swaps
      Extending subsidies may not reverse EV decline
      Don't let a billion-dollar bailout fool you
      Tax cut a big boon to underdeveloped used-vehicle market
    • Industry must address worker, shopper fear
      Shutdown a chance to map supplier networks
      Dealers help communities in crisis
      Manufacturing will need cash after crisis
    • Cleaner air a glimpse of what could be
      Auto shows ready to get back into action
      Tesla well positioned for COVID-19 recovery
      Nissan needs to fix image problem
  • DATA CENTER
  • VIDEO
    • AutoNews Now
    • First Shift
    • Special Video Reports
    • Weekend Drive
    • AutoNews Now: Shoppers to steer clear of showrooms?
      AutoNews Now: Lincoln wasn't 'right' fit for Ford-Rivian EV
      AutoNews Now: GM to 'prioritize' trucks when production resumes
      AutoNews Now: FCA aims for May 18 N.A. restart
    • First Shift: Ford to restart most N.A. factories May 18
      First Shift: Lawmakers begin push for auto aid
      First Shift: GM posts Q1 profit, plans for May 18 restart
      First Shift: FCA posts $1.84B loss in Q1 amid pandemic
    • 'When you feel helpless, help': How dealers are springing into action amid the coronavirus crisis
      Show-and-tell: How video boosts repair approvals in service bays and driveways
      Staying ahead of the EV service curve
      Creativity amid the coronavirus: How two dealers are navigating the crisis
    • Why the pickup is the auto industry's 'battleground'
      Carlos Ghosn's quest to restore his reputation
      Why Ford must execute to avoid 'deep trouble'
      Why Honda is 'locked and loaded' for 2020
  • EVENTS & AWARDS
    • Events
    • Awards
    • PACEpilot
    • Congress Conversations
    • Retail Forum: NADA
    • Canada Congress
    • Europe Congress
    • Retail Forum: Chicago
    • Leading Women Conference
    • Retail Forum: Toronto
    • Fixed Ops Journal Forum
    • 100 Leading Women
      • Submit a nomination for 2020
    • 40 Under 40 Retail
    • All-Stars
    • Best Dealerships To Work For
    • PACE Awards
    • PACEpilot
    • Rising Stars
    • Europe Rising Stars
  • JOBS
  • Content Studio
  • +MORE
    • Leading Women Network
    • Podcasts
    • Webinars
    • Publishing Partners
    • Classifieds
    • People on the Move
    • Newsletters
    • Contact Us
    • Media Kit
    • RSS Feeds
    • Shift: A Podcast About Mobility
    • Special Reports Podcasts
    • Weekend Drive Podcasts
    • IHS Markit: Autonomous vehicles: Automotive and transportation disruption
    • IHS Markit: The battery electric vehicle (BEV)
    • Wells Fargo Auto: Switching gears from LIBOR to SOFR
    • Ally: Do It Right
    • DealerSocket
    • Deloitte: Cyber everywhere: Preparing for automotive safety in the face of cyber threats
    • Facebook: The road to a zero-friction future
    • Guide To Economic Development
    • PayPal Credit: How consumer financing helps drive sales for online auto parts retailers
MENU
Breadcrumb
  1. Home
  2. Retail
May 09, 2020 12:00 AM

Dealerships can fight work-from-home vulnerabilities

Lindsay VanHulle
  • Tweet
  • Share
  • Share
  • Email
  • More
    Print
    Dealerships can protect access to customer data by having employees connect through a VPN.
    AUTOMOTIVE NEWS ILLUSTRATION

    Dealerships can protect access to customer data by having employees connect through a VPN.

    For Canadian auto retailer HGreg.com, setting up a cloud-based computer system was necessary to connect its dealerships across two nations. That initiative started around 2014, and it turned out to be a beneficial strategy during the current coronavirus pandemic.

    The company uses a cloud-based phone system and Google technology for email and file-sharing across its 32 rooftops, including two Nissan stores and six used-car dealerships in Florida, CEO John Hairabedian said. When the coronavirus swept across North America in March and HGreg shifted non-customer-facing employees to work remotely, "we were pretty well prepared already," he said.

    Best practices

    Dealerships with employees working remotely should consider these strategies to protect their networks and customer data from cyberthreats:

    • Set up a virtual private network, or VPN, to enable employees to remotely access their work computers.
    • Limit the number of people who have VPN access. Document who receives it so it can be disabled should the employee leave.
    • Provide work computers to prevent employees from connecting on personal devices. If that’s not possible, verify that an employee’s device is running anti-virus software.
    • Train employees to spot phishing attempts or malicious email and on the protocol if a suspicious link is clicked.
    • Enable multifactor authentication to require additional verification of an employee’s identity.
    • Create a plan to transition to remote work and then back to the office.

    Companies have expanded remote work arrangements in recent weeks as governments have ordered nonessential businesses closed to keep people from congregating at offices, dealerships included.

    Yet dealership consultants who specialize in information technology say retailers generally aren't familiar with having employees work remotely — and neither are their computer systems, which routinely handle customers' personal information. Home offices may keep the work pipeline from being entirely halted, but they pose new cybersecurity risks.

    Perhaps the biggest risk to a dealership is allowing employees to use their home computers for work. That's because employees would not have corporate anti-virus protection, and that could create an unsecured opening for a cyberattacker to infiltrate the network and access data, according to Helion Technologies and Proton Technologies Inc., two IT consultants that work with dealerships. Dealerships have no way to monitor the activity on an employee's personal computer.

    "Home PCs are inherently not secure," said Erik Nachbahr, president of Helion Technologies. "You could count on that they're compromised."

    Layers of security

    In April, Proton Technologies received an estimated 1,000 service ticket requests in the course of a week from dealerships needing access to a virtual private network, or VPN, CEO Brad Holton said. The networks allow employees to connect to the dealership's system through a virtual "tunnel" that is secure and encrypted.

    Holton: Phishing attempts are up.

    An alternative is to use cloud software so an employee can use a personal device to remotely operate a work computer as if he or she were at the office, Holton said. Neither option eliminates risk, but they add a layer of security to dealership operations. Cloud-based software, such as that used by HGreg, reduces risk because it sidesteps the need to access the business network.

    Multifactor authentication, a process that requires users to provide extra verification of their identity, also is a good idea, said John Rondini, an attorney and co-chairman of the cybersecurity and data privacy practice at Brooks Kushman law firm in Southfield, Mich. That could include an email or text message containing a code to enter when logging in.

    The most secure action dealerships can take is to supply employees with individual work computers, consultants said. Yet that's rarely done.

    Nachbahr said that historically, it has been difficult to get dealerships to spend money on technology. And that was before the cash crunch brought on by COVID-19.

    But VPN access is "the kind of thing that costs thousands of dollars, not tens of thousands of dollars," Nachbahr said.

    Employee risks

    Consultants say dealerships should pay attention to another potential security risk: their employees.

    Even before the coronavirus outbreak, cybercriminals exposed vulnerabilities in networks by using email phishing attempts and ransomware. Those attempts have increased during the pandemic, Holton said, as scammers prey on people's anxiety. Dealerships should keep up employee training to spot malicious email.

    Dealerships also should disable network access for employees who have been furloughed or laid off, consultants said. That includes access to email and the dealership management and customer relationship management systems.

    "A terminated employee who has access to the system is our most dangerous security threat," Nachbahr said.

    Those who are out of work could be tempted to extract customer data from the DMS or CRM and take it to another dealership, consultants said. To combat that, their accounts could be suspended until they return to work.

    Holton said he advises dealerships to limit employees' ability to run reports and build data sets.

    Hairabedian, of HGreg.com, said his group disabled functions that allow employees to download customer lists for all but C-suite administrators. The system also logs records of large downloads.

    "We've taken proper precautions to make sure that those things don't happen," he said.

    Letter
    to the
    Editor

    Send us a letter

    Have an opinion about this story? Click here to submit a Letter to the Editor, and we may publish it in print.

    Recommended for You
    Digital Edition
    Automotive News 5-4-20
    THIS WEEK'S EDITION
    See our archive
    Fixed Ops Journal
    Fixed Ops Journal 4-20-20
    Read the issue
    See our archive
    Sign up for free newsletters
    EMAIL ADDRESS

    Please enter a valid email address.

    Please enter your email address.

    Please select at least one newsletter to subscribe.

    You can unsubscribe at any time through links in these emails. For more information, see our Privacy Policy.

    Get Free Newsletters

    Sign up and get the best of Automotive News delivered straight to your email inbox, free of charge. Choose your news – we will deliver.

    Subscribe Today

    Get 24/7 access to in-depth, authoritative coverage of the auto industry from a global team of reporters and editors covering the news that’s vital to your business.

    Subscribe Now
    Connect With Us
    • Facebook
    • Instagram
    • LinkedIn
    • Twitter

    Our mission

    The Automotive News mission is to be the primary source of industry news, data and understanding for the industry's decision-makers interested in North America.

    AN-LOGO-BLUE
    Contact Us

    1155 Gratiot Avenue
    Detroit, Michigan
    48207-2997

    (877) 812-1584

    Email us

    Automotive News
    ISSN 0005-1551 (print)
    ISSN 1557-7686 (online)

    Fixed Ops Journal
    ISSN 2576-1064 (print)
    ISSN 2576-1072 (online)

    Resources
    • About us
    • Contact Us
    • Media Kit
    • Subscribe
    • Manage your account
    • Reprints
    • Ad Choices Ad Choices
    • Sitemap
    Legal
    • Terms and Conditions
    • Privacy Policy
    • Privacy Request
    Automotive News
    Copyright © 1996-2020. Crain Communications, Inc. All Rights Reserved.
    • HOME
    • NEWS
      • Dealers
        • Access F&I
        • Fixed Ops Journal
        • Marketing
        • Used Cars
        • Retail Technology
        • Sales
        • Best Practices
        • Dealership Buy/Sell
        • NADA
        • NADA Show
      • Automakers & Suppliers
        • Automakers
        • Manufacturing
        • Suppliers
        • Regulations & Safety
        • Executives
        • Leading Women Network
        • Guide to Economic Development
        • PACE Awards
        • Management Briefing Seminars
        • World Congress
      • News by Brand
        • Aston Martin
        • BMW
          • Mini
          • Rolls-Royce
        • Daimler
          • Mercedes Benz
          • Smart
        • Fiat Chrysler
          • Alfa Romeo
          • Chrysler
          • Dodge
          • Ferrari
          • Fiat
          • Jeep
          • Maserati
          • Ram
        • Ford
          • Lincoln
        • General Motors
          • Buick
          • Cadillac
          • Chevrolet
          • GMC
          • Holden
        • Honda
          • Acura
        • Hyundai
          • Genesis
          • Kia
        • Mazda
        • McLaren
        • Mitsubishi
        • Nissan
          • Infiniti
        • PSA
          • Citroen
          • Opel
          • Peugeot
        • Renault
        • Subaru
        • Suzuki
        • Tata
          • Jaguar
          • Land Rover
        • Tesla
        • Toyota
          • Lexus
        • Volkswagen
          • Audi
          • Bentley
          • Bugatti
          • Lamborghini
          • Porsche
          • Seat
          • Skoda
        • Volvo
        • (Discontinued Brands)
      • Cars & Concepts
        • Auto Shows
          • Detroit Auto Show
          • New York Auto Show
          • Los Angeles Auto Show
          • Chicago Auto Show
          • Geneva Auto Show
          • Paris Auto Show
          • Frankfurt Auto Show
          • Toronto Auto Show
          • Tokyo Auto Show
          • Shanghai Auto Show
          • Beijing Auto Show
        • Future Product Pipeline
        • Photo Galleries
        • Car Cutaways
        • Design
      • Coronavirus Coverage
      • China
      • Shift
      • Mobility Report
      • Special Reports
      • Digital Edition Archive
      • This Week's Issue
    • OPINION
      • Blogs
      • Cartoons
      • Keith Crain
      • Automotive Views with Jason Stein
      • Columnists
      • China Commentary
      • Editorials
      • Letters to the Editor
      • Send us a Letter
    • DATA CENTER
    • VIDEO
      • AutoNews Now
      • First Shift
      • Special Video Reports
      • Weekend Drive
    • EVENTS & AWARDS
      • Events
        • PACEpilot
        • Congress Conversations
        • Retail Forum: NADA
        • Canada Congress
        • Europe Congress
        • Retail Forum: Chicago
        • Leading Women Conference
        • Retail Forum: Toronto
        • Fixed Ops Journal Forum
      • Awards
        • 100 Leading Women
          • Submit a nomination for 2020
        • 40 Under 40 Retail
        • All-Stars
        • Best Dealerships To Work For
        • PACE Awards
        • PACEpilot
        • Rising Stars
        • Europe Rising Stars
    • JOBS
    • Content Studio
    • +MORE
      • Leading Women Network
      • Podcasts
        • Shift: A Podcast About Mobility
        • Special Reports Podcasts
        • Weekend Drive Podcasts
      • Webinars
      • Publishing Partners
        • IHS Markit: Autonomous vehicles: Automotive and transportation disruption
        • IHS Markit: The battery electric vehicle (BEV)
        • Wells Fargo Auto: Switching gears from LIBOR to SOFR
        • Ally: Do It Right
        • DealerSocket
        • Deloitte: Cyber everywhere: Preparing for automotive safety in the face of cyber threats
        • Facebook: The road to a zero-friction future
        • Guide To Economic Development
        • PayPal Credit: How consumer financing helps drive sales for online auto parts retailers
      • Classifieds
      • People on the Move
      • Newsletters
      • Contact Us
      • Media Kit
      • RSS Feeds