Research
Assessed on Faith
What the technology vendors serving automotive retail publish about their own security — measured only from what any dealer’s procurement team could look up unaided.
Findings publish after every assessed brand has received its scorecard
The study
101 brands, 87 independent companies
In August 2026 we assessed 101 vendor brands, operated by 87 independent companies serving automotive retail, against two layers of entirely public signal: email authentication published in DNS, and security documentation published on the web. Every automated positive was verified by hand before it was counted.
- Population
- 101 vendor brands, 87 independent companies, across DMS, inventory and data, F&I and titling, fixed operations, marketing and web, and lending
- Collection window
- August 2026; the exact window is recorded in the report
- Layer one
- SPF, DKIM and DMARC records, queried in public DNS
- Layer two
- Security and trust documentation published on the vendor’s own website, including whether a route exists for reporting a vulnerability
- Verification
- Every automated positive reviewed by hand; an adversarial review of the first dataset produced a corrected release
- Author
- Andrew Tubbs, CISSP, CISM, C|CISO — formerly Director, Information Security at Cox Automotive
Method
What the study does not do
The constraint is the point. A study that tested vendor systems would be a different document with a different set of legal problems, and it would not answer the question a dealer actually faces.
- Nothing was scanned, tested or probed. DNS records were queried and public web pages were read. Every signal in the dataset is one a customer could look up for themselves.
- It measures assessability, not security. A vendor that publishes nothing may run an excellent program. The study measures whether a customer can tell — and a customer who cannot tell has to take it on faith.
- It is not a compliance finding about anyone. The finding is that vendors publish nothing a dealer could use to complete the assessment the Rule requires of the dealer. That is a statement about published evidence, not about any company’s compliance.
- Only vendors that publish are named. In the public release, a company appears by name only where it published something. The aggregate names no one else.
Why it matters
Eighteen elements, and the one that points outward
The FTC Safeguards Rule sets out eighteen discrete requirements for the information security program of every dealership that finances or leases vehicles. Almost all of them look inward, at the dealer’s own program. FTC Safeguards § 314.4(f) looks outward: select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider.
That last obligation is what generates the questionnaire traffic in this market. It is also, if a vendor publishes nothing, an obligation the dealer has no public means of discharging. This study is a measurement of that gap.
Sequence
Vendors first, publication second
No company learns about its own result from a press release.
-
1
Each brand receives its own scorecard
Its result, the evidence behind it, and what would change it — sent privately, with no commercial ask attached.
-
2
Roughly two weeks pass
Time to correct a finding, or to fix the underlying gap before anything is published. Several already have.
-
3
The aggregate publishes
Figures at the level of the market and of each category. Companies that publish security documentation are named and credited. No one else is named.
If you operate a brand serving automotive retail and want to know whether you are in the sample, write and ask. We will send your scorecard.
Request your scorecardDisclosure
The author was Director, Information Security at Cox Automotive, which operates brands appearing in the sample; some of the controls assessed at those brands were built during his tenure. Cox Automotive brands are treated in the study exactly as every other brand is, and the relationship is disclosed wherever they appear.
The study is self-funded. The author’s consultancy has commercial relationships with companies in this market, which may include companies in the sample. No vendor paid for, commissioned, reviewed or influenced this study, and the dataset was collected before any such engagement was discussed.