FI showroom red and grey logo
MenuMENU
SearchSEARCH

EFG: Digital Retailing, Online F&I Increasing Data Security Risks for Dealers

The F&I product provider issues a call to action to dealers, finance sources and its partners, warning that data security is one of the largest areas of concern in 2018.

by Staff
February 14, 2018
EFG: Digital Retailing, Online F&I Increasing Data Security Risks for Dealers

John Pappanastos, CEO and President of EFG Companies

3 min to read


DALLAS — F&I product provider EFG Companies said this week that data security is one of the largest areas of concern in 2018 for retail automotive dealers, lenders and their partners.

Citing data from the Identity Theft Resource Center and CyberScout, the company noted that 1,579 data breaches occurred in 2017, a 44.7% increase from the year prior. It’s the reason the company invests approximately a quarter of a million dollars on data security enhancements annually, achieved SSAE-16 certification in 2016, and has an ongoing digital security plan that enables it to implement enhanced safeguards ahead of need, officials said.

Ad Loading...

While retail automotive has been regulated under the Safeguards Rule of the 1999 Gramm-Leach Bliley Act, digital data was not considered an important area of focus until recent years. This risk, according to the F&I product provider, is driven in part by the rise of digital technology in the automotive market.

From wirelessly connected cars to digital customer relationship management systems (CMS), data access points have increased exponentially. A recent Frost & Sullivan report indicated that IT spending in the connected automotive market is projected to increase 17.3% from 2015 to 2025, the firm noted. However, the industry is just beginning to address how to protect private consumer information in a digital environment.

In the physical realm, it takes less than one minute and three pieces of information for a motivated thief to execute a security breach at a retail automotive dealership, the firm said. In the digital realm, a computer hacker can gain access to payment processing software in seconds, grabbing data and exiting before the dealership is aware of the breach. According to a 2017 study commissioned by IBM, the average cost of a single stolen data record is $141. The average total cost of a security breach was $3.62 million. The average probability of a company suffering a security breach within the next two years is 27.7%. 

“Machine learning and sophisticated hacking software will make data security an even more important component of the retail automotive sector,” said Maurice Hamilton, vice president of technology at EFG Companies. “For example, we believe any company processing credit cards should complete PCI DSS compliance. Within three years, companies should also implement two-factor authentication. Granted, implementing data security technology is an expense. But, as research has shown, companies cannot afford a breach.”

The company noted in its press release that a study of more than 10,000 consumers by Gemalto revealed that 70% of consumers would stop doing business with a company if it suffered a data breach. Additionally, 69% of consumers believe that companies do not take consumer data security seriously. EFG Companies recommends using the acronym ADRIFT to ask the following questions as the first step in achieving data security:

Ad Loading...

1. Have I conducted a complete security risk assessment, including all access points and partners?

2. Does my written “Information Security Program” document include procedures for each department that handles digital and physical consumer data?

3. Have I reviewed all reasonably foreseeable risks that could result in unauthorized disclosure or compromise of consumer data? Am I protecting customer information from collection to disposal?

4. Have I identified a designated person responsible for customer information security, with authority to implement the program?

5. How do I foresee manageable risks that could result in unauthorized disclosure of private consumer information? For example, am I overseeing partners that might have access to, or take possession of, customer information? Do my agreements with these partners require them to implement appropriate safeguards?

Ad Loading...

6. Does my company have sufficient training, oversight, and procedures for securing private consumer data?

“From vulnerable photocopier hard drives to digital CRMs, we believe digital data security should be a key business objective for every retail automotive dealer, lender and partner,” said John Pappanastos, CEO and president of EFG Companies. “While important, simply locking a file cabinet or putting a screen protector on a monitor is not sufficient. We are calling on all participants in the retail automotive chain to lock down their data.”

More Digital

A customer signs documents on a digital e-contracting tablet using a stylus while a dealership employee points to the screen, alongside the Reynolds and Reynolds and Assurant logos.
Digitalby StaffMarch 6, 2026

Automotive Training Academy by Assurant Grow Offering

A new Atlanta location on Reynolds and Reynolds' docuPAD e-contracting system is designed to broaden access for auto professionals.

Read More →
F&IMarch 4, 2026

Creating Your Own Economy

In this video, Reese Dailey explains how effective follow-up drives better results across the dealership, including increased sales, higher F&I penetration, and stronger customer retention.

Read More →
A dealership customer works with an F&I representative at a desk during the vehicle purchase process.
Digitalby StaffJanuary 30, 2026

Assurant Debuts Virtual Solution for Dealers' Staffing Challenges

Company says on-demand access to F&I specialists is shown to boost dealership efficiency and profitability.

Read More →
Ad Loading...
Chris Walsh, president and acting CEO of Reynolds and Reynolds, standing inside an office building wearing a blue suit.
Digitalby StaffJanuary 12, 2026

Reynolds Highlights Intelligence at Every Touchpoint at NADA

The NADA exhibitor will again bring a full slate of innovations and opportunities to the most anticipated event for auto dealership professionals.

Read More →
DigitalDecember 16, 2025

What to Do When Your Vendor Is Hacked

The quickest way to turn a breach into a crisis is to wing it. Follow this seven-step playbook to ensure you meet your obligations.

Read More →
Digitalby Hannah MitchellDecember 3, 2025

Dealer Credit Service Provider Breached

Hack exposed thousands of dealerships’ customer data

Read More →
Ad Loading...
DigitalNovember 18, 2025

Unearthing the Gold in Your Dealership Data

How to take a smarter path to revenue

Read More →
Digitalby Hannah MitchellOctober 29, 2025

Auto Dealers’ Take on AI

Study finds recognition of its usefulness, but franchisers are treading sometimes confusing waters carefully

Read More →
Digitalby Hannah MitchellSeptember 22, 2025

Synthetic ID Fraud Comes With Clues

TransUnion research reveals telltale signs that the information a customer provides could be faked.

Read More →
Ad Loading...
DigitalSeptember 17, 2025

The Looming Threat of Deepfakes

They represent a new era of auto and financial fraud.

Read More →