If your dealership group arranges or extends credit, the FTC treats you as a financial institution under the GLBA Safeguards Rule. That means you are expected to have a “reasonable information security program.”
For a CEO, CFO, or GM, the frustrating part is that “reasonable” is not a score you can hit and be done with. The FTC never hands you a number, a certificate, or a pass/fail checklist. Reasonable is a standard, and standards get interpreted. The real question is not “did we buy the nine things,” it is “would a regulator, an insurer, or a plaintiff’s attorney look at how we actually operate and call it reasonable?”
This page is about that judgment: what “reasonable” means as a standard, how the FTC decides whether you meet it, and where dealers most often fall short. For a plain-English walkthrough of the nine specific building blocks the Rule requires, start with our companion guide, the 9 FTC Safeguards Rule requirements explained in plain English. This piece sits one level up from that list.
Note: This is general education, not legal advice. Work with your counsel to interpret how the Rule applies to your stores, state laws, and OEM/lender requirements.
Reasonable is scaled to your dealership, not a fixed bar
The most important thing to understand is that the Rule does not expect a 3-store group to run the same program as a national chain. The Safeguards Rule ties “reasonable” directly to your circumstances. Your program has to be appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of the customer information you handle.
Read that again, because it cuts both ways:
- A larger, more complex group with more rooftops, more integrations, and more people touching data is held to a higher operational bar. “We are a small store” stops being a defense as you grow.
- A smaller group is not off the hook. You still collect driver’s licenses, credit apps, income proofs, and payoff information, which is exactly the sensitive data the Rule cares most about. The concepts apply to everyone; only the scale of the implementation changes.
So “reasonable” is not one bar. It is your bar, set by how big you are, how you operate, and how sensitive your data is. A program that was reasonable for a single point three years ago is often no longer reasonable for the eight-rooftop group that same dealer runs today.
Owning a tool is not the same as being reasonable
Here is the gap the FTC and insurers see most often. A dealer buys MFA, buys an EDR agent, buys a training platform, and assumes the box is checked. But the standard is not “do you own the control.” It is “is the control implemented, overseen, and working across your stores.”
Reasonableness lives in the operating detail:
- MFA that is licensed but not enforced on the accounts that actually reach customer data is not reasonable.
- A written incident response plan that no one has read, assigned, or rehearsed is not reasonable.
- A risk assessment that was done once at go-live and never revisited as you added rooftops and vendors is not reasonable.
- Vendor security language buried in a contract that no one monitors against is not reasonable.
The FTC’s own framing is that safeguards must be designed and implemented to control the risks you identified, and that you must regularly test or monitor their effectiveness. Ownership is the easy part. Reasonable is the part where someone is accountable for making the control real and proving it still works.
Reasonableness is judged with hindsight, so document it forward
Nobody grades your program on a calm Tuesday. It gets judged after something goes wrong: a breach, a stolen deal jacket, a wire-fraud loss, a customer complaint, a cyber-insurance claim. At that moment, the question flips from “are you compliant” to “were your decisions reasonable given what you knew at the time.”
That is why documentation is not paperwork for its own sake. It is the evidence that your choices were reasonable:
- A written risk assessment with criteria shows you actually evaluated risk instead of guessing.
- Testing and monitoring records (vulnerability scans, penetration tests, remediation follow-up) show the safeguards were checked, not assumed.
- Where you could not encrypt customer data or apply standard multi-factor authentication, a compensating control reviewed and approved in writing by your Qualified Individual shows you made a deliberate, informed decision rather than an oversight.
- The annual written report to your Board or a senior officer shows leadership was steering the program, not unaware of it.
A dealer who can show a documented, updated, tested program has a strong reasonableness story even if an incident still happens. A dealer with the same tools but no records is left arguing “trust us,” which is exactly the argument that fails after a breach.
Where dealers most often fall short of “reasonable”
Across dealership programs, the same handful of gaps turn an otherwise decent setup into one that would struggle to be called reasonable:
- Shared logins in sales, F&I, and service. When five people use one DMS account, you cannot control or prove who accessed what, which undercuts access control and your logs at the same time.
- Safeguards that are never tested. Tools are installed, but no one runs the scans, tracks findings, and closes the loop. Untested is functionally unverified.
- Vendors treated as “set and forget.” The Rule expects you to monitor service providers over time, not just sign them once. Your F&I platforms, digital retailing tools, and DMS integrations are part of your security perimeter.
- A stale program. Documentation still describes how you operated before the last two rooftops, the new digital-retailing stack, or the current threat landscape.
- No named owner with real authority. A Qualified Individual on paper who cannot actually change budget, policy, or vendor decisions is not oversight, it is a title.
None of these are exotic. They are the everyday operational drift that separates “we bought security” from “we run a reasonable program.”
What “reasonable” looks like at your size
To make the standard concrete, picture the same program at two scales:
A 3-store group might meet the standard with a designated internal QI supported by a trusted service provider, an annual risk assessment refreshed whenever a major system or rooftop changes, enforced MFA on customer-data systems, scheduled vulnerability scans with a yearly penetration test, ongoing staff training, monitored vendor contracts, and a short written report to the Dealer Principal each year. Right-sized, documented, and tested.
A 20-plus-store group usually has to do more in practice. The Rule lets any dealer choose continuous monitoring or a program of annual penetration testing plus vulnerability assessments, but at scale many groups lean toward continuous monitoring rather than periodic scans, a more formal QI function with dedicated support, tighter access provisioning and de-provisioning as staff move between rooftops, and board-level reporting with real risk trends. Same concepts, heavier operational lift, because the size, complexity, and data volume raise the bar.
The FTC is not looking for the biggest stack. It is looking for a program that fits how your stores actually run and can prove it.
The bottom line
A “reasonable information security program” is not a product you buy or a box you check. It is a standard that scales to your dealership, lives in whether your controls are actually implemented and tested, and gets judged in hindsight against what you documented. Get the standard right and the nine specific requirements become the natural way to satisfy it rather than a list to survive.
When you are ready to see how your stores measure against that standard in practice, a gap assessment maps where you are reasonable today and where you are exposed, and the nine-requirement guide walks each building block in dealership terms.