Your DMS Vendor Has Remote Access to Your Dealership. Does It Have MFA?

Your DMS Vendor Has Remote Access to Your Dealership. Does It Have MFA?

August 14, 2026 · Rodney HolumManaged IT
Share:

Your DMS vendor logs in remotely to fix things. The Safeguards Rule covers that login too, and most dealerships have never asked the vendor to prove it uses MFA.

Your DMS vendor logs in remotely to your dealership every time you call for support. That login reaches your customer data, names, phone numbers, driver's license numbers, financing records. Under the FTC Safeguards Rule, that remote login is not a side issue or a convenience. It is a covered access point, and it carries the same compliance weight as a login by one of your own employees.

Most dealers have never asked their DMS vendor to prove that multi-factor authentication (MFA) is turned on for that remote access. Many assume a large vendor must have it. They do not. And the gap between assumption and reality is exactly where compliance fails.

Your DMS vendor's remote access is covered by the Safeguards Rule

The Safeguards Rule requires MFA for any individual accessing an information system that holds customer information. The rule text is clear: 16 C.F.R. § 314.4(c)(5) requires MFA "for any individual accessing any information system" containing customer data, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.

That rule applies equally to service providers. The FTC's 2025 guidance on the Amended Rule states it plainly: "The Amended Rule requires dealers to '[i]mplement multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.' Again, this requirement applies equally to service providers."

Your DMS vendor is a service provider. When their support staff remote into your network to troubleshoot an issue, they are individuals accessing an information system holding customer information. The rule covers them. If they log in with a password alone, your dealership is out of compliance, even if the vendor is a national company and even if you did not know the rule applied to them.

The same requirement extends to OEM connections (factory telematics systems), CRM platforms, desking tools, financing portals, and any third-party platform that touches customer records. One rule. One standard. Same MFA expectation.

Why the gap is so common

Dealers usually inherit whatever their DMS vendor ships. They do not ask for proof that MFA is on. They assume a large vendor must have it built in. And vendor remote-access tools and service accounts are a known weak spot in cybersecurity, they are designed to be easy to use, not necessarily easy to audit.

The result: a dealer can be years into a DMS contract, call the vendor for support dozens of times, and never once confirm that the person logging in is using a second factor of authentication.

That is not negligence on your part. It is a gap in how the industry has worked. But the Safeguards Rule does not care about industry practice. It cares about whether customer data is protected.

The questions to put in writing this week

Send your DMS vendor a written request for answers to these questions. Put them in writing so you have a record of what you asked and what they said.

  • Is multi-factor authentication (MFA) enforced on every login that touches customer data, including logins by your support staff?
  • Do you support phishing-resistant MFA or passkeys, or do you rely on SMS or app-based codes?
  • Can you share a current SOC 2 Type II report that covers your remote-access controls?
  • How many hours' notice will you give us if you experience a security incident?
  • How is remote access logged, and how often is access reviewed for unauthorized activity?
  • If MFA is not currently enabled, what is the timeline and cost to turn it on?

These questions come directly from CISA's Secure by Demand Guide, which gives small and mid-size businesses a ready-made set of questions to ask software vendors about authentication and security controls.

Do not accept vague answers. "We take security seriously" is not an answer. "MFA is available" is not an answer if it is not turned on by default. You need written confirmation that MFA is enforced on every remote login that touches customer data.

What to do if the vendor can't answer

If your DMS vendor will not share a SOC 2 report, will not confirm that MFA is enforced, or tells you that MFA is not available, document that conversation. That is itself a finding. Your Qualified Individual under the Safeguards Rule has to be able to show due diligence on service providers. A written record of what you asked and what the vendor said is evidence that you took the rule seriously.

If the vendor refuses to enable MFA, you have a business decision to make: accept the compliance risk, or find a vendor that will meet the rule's requirements. That is not a technical decision. It is a business decision, and it belongs with your dealer principal and your Qualified Individual.

CISA's guidance for small and medium businesses recommends confirming that all remote access to your network and privileged or administrative access requires MFA. Your DMS vendor's remote-access tool is exactly what that guidance is talking about.

A local partner can help you pull the settings

If you want to verify the DMS vendor's remote-access settings yourself, you will need someone with access to your network and the technical knowledge to read the logs and audit the service accounts. That is not a phone call. That is an on-site job.

A regional IT partner in your area can sit in the room with you, pull the DMS vendor's remote-access settings from your network, audit the service accounts the vendor uses to log in, and put the vendor questions in writing on your behalf. Coulee Tech works with small and mid-size businesses across western Wisconsin, the Chippewa Valley, and Southwest Florida, including dealerships and auto-services businesses in those regions. A local engineer can do that verification work and help you build a written record of your due diligence.

A national compliance blog cannot. A national MSP cannot show up in your dealership tomorrow morning. A local partner can.

Send the vendor question list to your DMS provider this week and ask for written answers. If you would rather have a local engineer pull the settings and put the questions in writing for you, contact Coulee Tech to set up a short vendor-access review.

dealership DMS securityFTC Safeguards MFA requirementauto dealer vendor access controldealership cybersecurity compliancedealership IT support Wisconsin

Ready to Strengthen Your IT?

Schedule a free discovery call to discuss your technology needs with our team.