Can Your IT Service Provider Manage Your FTC Compliance?

Posted by

on

Here Are Our Top 10 Questions to Ask Your IT Provider

By Andy Graff Chief Operating Officer

If you are confused about the intricacies of the Gramm-Leach-Bliley Act’s revised  Safeguards Rule (Safeguards Rule) that went into enforcement on June 9, 2023, welcome to the club. For many dealerships, regulatory compliance presents a formidable challenge. As a result, many vendors are quick to claim to be experts in managing the Safeguards Rule and it’s not uncommon to hear some dealers say, “My MSP or IT company can handle everything.

Dealerships contemplating full reliance on an MSP for this specific regulation must weigh several factors because the intricacies of compliance demand expertise that extends beyond the realm of IT. If your MSP says they can manage your entire Safeguards Rule compliance program, there are a multitude of factors to consider. Here are my top 10 questions to ask your MSP or IT provider when they claim that they can completely handle all of your Safeguards Rule compliance requirements.

  1. Do they have qualified legal experience?

Whether it is your in-house or outside counsel, it is important to have legal expertise in data protection when drafting internal policies and procedures to ensure they are compliant. When policies are drafted they need to include language that speaks to both state and federal regulations depending on where you do business. Having legal expertise you can rely on is critical for both the timeliness and accuracy of your compliance in this ever-changing legal landscape.

  1. Can they help you complete all the elements of an internal Annual Risk Assessment?

I recently got a message from a dealer friend who asked, “Do I really have to answer every single one of these questions in the assessment?” Unfortunately for her, the answer was a resounding “Yes!” The rules, regulations, and possible citations that are coupled with risk assessments are extensive to say the least (if you know, you know). An MSP or IT provider may be able to complete a technical risk assessment, but they also need to be knowledgeable about how your staff manages the paperwork that is generated, moved, and stored in your dealership.

  1. Will they help you create an Annual Board Report?

Generating the required annual report for the Board of Directors is no simple task. The annual report will need to include every action taken on every requirement of the Safeguards Rule. As I am sure you’ve heard before from countless other sources, a violation of the Safeguards Rule carries the price tag of $50,120 per violation. I wouldn’t saddle your MSP or IT company with this responsibility especially if they do not have the legal knowledge to do so. If you’re suddenly feeling like they’re back in school and have to turn in a huge project for a class that you never attended, welcome to the club.

  1. Can they manage your Vendor Data Processing Agreements?

The mandatory question on this topic is, does my provider have the legal expertise to create Vendor Data Processing Agreements for my other relevant vendors? The idea of getting the contacts and signatures of all my third party vendors is enough to make me itchy. I don’t know about you, but I would very much prefer this process to be someone else’s problem as much as possible because not only is it time consuming it is also extremely confusing. For example, not all vendors will have to complete these Data Processing Agreements, only the “Service Providers.” Huh? Additionally, you have to be sure that the questionnaire provided to the vendors fulfills all legal requirements for vendors and needs to be processed annually. Good grief.

  1.  Will they train your employees?

I personally find that old saying of “those who cannot do, teach” to be wildly inaccurate. I’m an expert in my field but the process of teaching what I’ve learned to others has proved to be more difficult than I ever dreamed. Adult learners, in my experience, are just taller versions of their younger selves: easily distracted and quick to dismiss lessons that do not feel realistically applicable to their daily lives. Additionally, managing training for everyone amidst their daily responsibilities can feel like herding cats. Therefore, I value anyone who can expertly take on this task while also tracking every individual’s completion.

  1. What about data mapping?

I know a compliance officer that once spent six months mapping out how vendors collected, stored, and transmitted data because he had to do it all by hand. I don’t know anyone who has time for that kind of task. Will your MSP or IT provider be able to handle this for you? If they can, how long will it take and how much of the heavy lifting will you have to do? Most importantly, is your MSP or IT provider knowledgeable enough about your business to know where all your dealership’s data is derived from and stored?

  1. Can they provide vulnerability and pen testing?

Vulnerability and Pen testing – required biannual and annual. Many service providers do not include this in your monthly service plan and will hit you with a costly bill when it is time to do it. Furthermore, some IT service providers are misguided and think this is not a requirement if you dealer has continuous monitoring. Check out this article why this is a myth. 

  1. Will they create your Incident Response Plan?

The Incident Response Plan (ISP) is a critical component of your FTC compliance. It should encompass contacts for dealership legal counsel and cybersecurity insurance.

  1. Will they provide tools to help keep NPI safe?

Gone are the days when a salesperson could simply request a pay stub through an email or SMS text message. It is becoming increasingly important that private information remain private, lest the dealership be held responsible. Be sure that the IT provider offers an encrypted messaging tool. What’s more, while your store is in possession of that information, you need a way to make sure it stays safe, and that means implementing tools such as Multi-Factor Authentication etc.

  1. Will they guarantee their products and services?

In the world of compliance, peace of mind goes a long way. I need to be sure that my provider will stand by their work, so that in the event that something beyond my control and expertise happens I am not the one left holding the metaphorical bag.

Bonus Question: Don’t Forget Website Tools Many states are implementing their own regulations regarding consumer privacy protection. So it wouldn’t hurt to also ask them about the tools available. In our family we often say, “Buy cheap, buy twice,” which essentially means that if you are going for a quick or inexpensive solution then it is probably not worth the savings in the long run. This is especially true when it comes to cookie banners and other website tools. Though there are many on the market these days, they may not entirely work the same way nor do what specific states are now requiring through their personal data laws (twelve states have adopted their own laws as of this writing), so you should consider more than just the price of the tool. Remember to assess whether or not the website tools provided will allow for online consumer consent and comply with local laws because website cookies are becoming increasingly complex. While we’re on the topic of websites, you need to make sure that your IT provider can develop a bespoke privacy policy for your website with proper state disclosures and based on how you collect consumer information, with whom you share it, and for what purpose it is collected.

Unfortunately, this list only scratches the surface of compliance, but it’s a good place to start when assessing whether or not your IT provider really can provide you with everything you need. Moving forward, cybersecurity will be a cornerstone in our industry, and it’s never been more imperative for the longevity of our success that we keep customer information safe.

Leave a Reply

The #1 Most Overlooked Rule: How DLP Tools Address the Safeguards Rule’s “Unauthorized Activity Monitoring” Requirement

Mock OSHA Assessment

FEATURES:

  • On-demand eight-hour assessment that imitates a real OSHA audit.
  • Conducted by an EHS Pro with OSHA-10 or OSHA-30 certification and 5+ years of experience. 
  • Simulated employee interviews
  • Issue tracking and task management
  • Detailed assessment reports after the assessment with images, videos, and recommended steps for remediation.

    Privacy & Cyber Compliance Suite

    FEATURES:

    • Custom legal policies with real-time updates, including the Information Security Program (ISP)
    • Customized Incident Response Plan (IRP)
    • Internal risk assessment tools and hands-on guidance
    • Biannual penetration testing (2) 
    • Biannual vulnerability scans (2)
    • Employee security awareness training and completion tracking
    • Extensive vendor management library – hundreds of vendor-completed GLBA contracts & risk assessments
    • Device & systems inventory automation and mapping tools
    • Unlimited industry-specific internal phishing simulations to train staff
    • Complete 50-state privacy compliance required by your state (CA, CO, CT, DE, IA, IN, MT, OR, TN, TX, UT, VA)
    • Website cookie consent banners and unique consumer privacy request portals
    • Annual report to the Board of Directors generated every year
    • Compliance Guarantee

      CPR/AED Certification

      FEATURES:

      • Instruction provided by Certified American Red Cross Instructors.
      • Practical, hands-on training sessions to practice CPR and AED techniques
      • Proper automated external defibrillator (AEDs) instruction and operation
      • American Red Cross exam and certification
      • Access to study materials, manuals, and resources for continued education and reference.
      • Available for organizations and groups, allowing for tailored training sessions.

      HR Fundamentals

      FEATURES:

      • Customized policy builder with real-time updates
      • E-sign functionality for required employee policies 
      • Online HR training with employee completion tracking
      • State-specific policies and training
      • Employee management tool
      • Training and policies include Workplace Violence, Active Shooter, IT and Electronic Device Use, Biometric Data Privacy, Sexual Harassment, and more 
      • HR Fundamentals access is included with any other ComplyAuto product

        Encrypted Messaging

        FEATURES:

        • Encrypt SMS text and email messaging among staff, clients, and customers when sending and receiving files
        • Track usage and detect violations in real-time
        • Advanced security features include auto-deletion of files, Multi-Factor Authentication protection, IP safelisting, and domain blocklisting
        • Supports compliance with various state and federal regulations and recognized industry standards: GLBA, HIPAA, SOC 2, ISO 27001, NIST, CIS Controls, SEC

          Safety Compliance Suite

          FEATURES:

          • Concierge on-site onboarding 
          • On-demand safety walkthroughs conducted by experienced EHS Pros at various intervals – once, twice, or four times per year
          • Comprehensive Online Training Library and employee progress tracking
          • Automated 50-State Legal Injury & Illness Reporting
          • Policy Builders with Automatic Updates
          • Simplified SDS Creation and Management
          • Guided risk mitigation
          • Signage builder & tracking
          • Efficient equipment inspections with QR Codes
          • Tier 1 Spill Prevention Control and Countermeasure Plan 
          • Automated Tier 2 environmental reporting for all 50 states 
          • Unlimited one-on-one support from our dedicated team
          • Workplace Violence and Active Shooter Policy and Training
          • Unlimited one-on-one support from our dedicated team
          • Automated Tier II environmental reporting for all 50 states.

            EduTech Course 3

            Program to Fulfill AG Disciplinary Order - $299/student

            The California AG routinely penalizes facilities that violate these laws and requires them to perform specific remedies while on probation. One of these remedies requires the ARD to take a course that outlines the laws and regulations of the Automotive Repair Act. This program fulfills the requirement.

            FEATURES:  

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            EduTech Course 2

            Program to Fulfill BAR Remedial Training - $299/student

            As part of their authority to levy fines and corrective actions against repair facilities, the Bureau of Automotive Repair may direct them to take a remedial training program. This program is intended for facilities who have already been identified by the BAR as needing corrective action and have committed to taking a remedial training course in lieu of specific penalties.The California Attorney General (AG) has required violating automotive repair dealers to take a course that instructs students on the laws and regulations of the Automotive Repair Act as part of the disciplinary order.

            FEATURES:

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            • Automated notification to the Bureau of Automotive Repair

             

            EduTech Course 1

            Automotive Repair Act Certification Training - $49/month per rooftop

            Provide advisors and technicians with the knowledge and tools necessary to comply with California laws and regulations and be viewed favorably by the Bureau of Automotive Repair.

            FEATURES:

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            F&I Compliance Suite

              • Precise Deal Jacket Audits to identify and address real-world F&I compliance issues accurately.
              • Focused Compliance on specific F&I compliance concerns such as Fair Lending Compliance Solutions, California Litigation, Vehicle Safety Recalls, Used Vehicle History, FTC Buyers Guide & Federal Warranty Disclosures, 
              • Automated EZ Cash Reporting & Anti-Money Laundering with IRS Reporting 
              • Spot Delivery & Unwind Management
              • Real-Time Issue Identification Quickly detect compliance gaps and issues, enabling swift corrective action and risk mitigation.
              • Online F&I Compliance Training 
              • Compliance Guarantee

                Device & Email Security

                FEATURES:

                The combined features create a dynamic defense system that adapts to evolving cybersecurity threats and secures the organization's digital ecosystem.

                • Continuous threat detection and response powered by Coro:
                  • EDR (Endpoint Detection and Response) 
                  • MDR (Managed Detection and Response) 
                  • 24/7 Security Operations Center team
                  • Swift response and alert to potential security breaches
                • Enhanced authentication and access control via Multi-factor Authentication (MFA) powered by Duo Security™
                • Advanced email security to shield e-threats such as phishing, malware, spam, and scams – integrates with Google Workspace & Microsoft Office 365.
                • Data governance and Data Loss Prevention (DLP)  detect and manage employee data-sharing practices. 
                • Device-level encryption for Windows and macOS
                • Public & unencrypted wifi blocking
                • Next-gen antivirus
                • Automated password policy and session locking enforcement