Previous All Posts Next

Auto Dealerships: The Next Healthcare-Style Target

Posted: June 8, 2017 to Cybersecurity.

Tags: Malware, Data Breach, Cloud Security

When you think about it, hospitals are pretty dangerous places. Everyone one with a serious illness is gathered in one place and are frequently visited by healthy people who go back into the regular world. Even if a healthy person doesn’t have someone to visit at the hospital, they’ll have to go at some point to see a doctor. You can see why it’s so important for hospital staff and visitors to thoroughly wash their hands and be hygienic. But this blog is devoted to computer viruses, not real viruses, so what does hospital hygiene have to do with cybersecurity? Even though hospitals are major targets for cyberattacks, they’re not what we are talking about today. We’re talking about auto dealerships. Auto dealerships are just like hospitals for cars. Anytime a car needs maintenance or has a problem that needs to be fixed, they’re taken to an auto dealership for repair, just like a person with a hospital. Of course, mechanics aren’t washing their hands between every job because cars can’t get viruses like people can. At least they couldn’t in the past. Every day cars with Wi-Fi hotspots, remote parking abilities, and vehicle to vehicle technology are rolling off the line and onto the lot. Cars are more computer than torque today, and that means they are susceptible to viruses. Which turns the average car dealership service department into a hospital. If one car comes in and its malware infected computer is connected to the dealership network not only will their network be infected but every car that’s brought into the dealership and connects to the same network will be sent out carrying the virus. Just like a contagious virus in a hospital. And it’s not going to get any easier for car dealerships either. Driverless cars are on the horizon, which means that car dealerships will need to employ tech professionals if they already haven’t. And that’s only to maintain cars and keep them safe, not to protect the dealership's network from hackers. Dealerships are not only great places to spread viruses, but they handle sensitive information just like any other business. Customer’s names, addresses, phone numbers, and payment information are all given to dealerships by customers under the condition that they will be kept safe. If a dealership fails to do that, the customers will stop coming. Now you might think this is all speculation and what if, but cybersecurity professionals have already proven that it’s possible. In 2015, Craig Smith presented a device called the ODB GW that used vulnerabilities in the devices that mechanics use to update the software in cars. Smith’s device worked by appearing to be the port behind the dashboard that mechanics connect to, but actually connected the mechanics to a PC that uploaded malware. The kick is that the device only cost Smith $20 to build. Fortunately, Smith was presenting the device to warn people, but that doesn’t change the fact that people have created ways to hack car dealerships. Auto dealers can’t just shut down their service departments or their payment centers, so they only have one choice: Get with the times or be left behind. Every business should have an IT professional on speed dial, but with the amount of technology being pumped into cars, auto dealers should seriously reconsider the amount of cybersecurity measures they have in place. That could mean anything from a simple audit to hiring a cybersecurity firm that specializes in auto dealerships, it depends on the size of the dealership and amount of security measures already in place. If auto dealers want to keep the cars they service safe and healthy, there’s no debate that they need to get serious about their cybersecurity.

Protect Your Business Today

Petronella Technology Group has provided cybersecurity, compliance, and managed IT services from Raleigh, NC for over 23 years. Contact us today for a free consultation and technology assessment.

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent more than 30 years working at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential (RP-1372) issued by the Cyber AB, is an NC Licensed Digital Forensics Examiner (License #604180-DFE), and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. Craig also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served 2,500+ clients, maintained a zero-breach record among compliant clients, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next
Free cybersecurity consultation available Schedule Now