Cyber liability insurance for car dealerships
Pays when the Dealer Management System is encrypted and the store stops, F&I credit and Social Security data is stolen, and the FTC Safeguards Rule forces a 30-day notification.

Why Coverwatch
- Markets
- We reach the cyber specialists that underwrite dealerships as Gramm-Leach-Bliley financial institutions and place stores a shared DMS, weak controls, or a prior incident got declined.
- Competition
- 60+ carrier partners compete on the fields that decide a dealer cyber claim: the ransomware and dependent-business-interruption sublimits, the DMS-outage waiting period, and Safeguards Rule regulatory defense, not just premium.
- Endorsements
- We confirm the endorsements a dealer needs are in force: a dependent-business-interruption grant for a DMS vendor outage, a social-engineering limit for the F&I wire, and Safeguards Rule regulatory defense.
For garage & auto
- What it covers
- Restoring an encrypted Dealer Management System, income lost while the store stops, and Safeguards Rule notification and defense after F&I data is exposed.
- What it doesn't
- Physical damage to the servers themselves and a floor-plan lender's own insurance interest in financed inventory.
Trusted by 60+ carrier partners
If our dealership's DMS gets ransomwared, what does cyber cover and what must we report under the FTC Safeguards Rule?
Dealer cyber liability insurance covers the forensics, the restoration of an encrypted Dealer Management System, the income lost while sales and service stop, and a ransom where the law permits. Because a financing dealership is a Gramm-Leach-Bliley financial institution, it also funds the FTC Safeguards Rule notification and defense.
Why dealer cyber must protect DMS and F&I data
A store that arranges financing is a Gramm-Leach-Bliley financial institution, so the FTC Safeguards Rule governs what it reports.
The DMS is a single point of failure
Sales, service, parts, and F&I all run through one Dealer Management System, so encrypting it stops the whole store.
F&I holds the data a thief wants
The finance office concentrates credit applications, Social Security numbers, driver-license copies, and bank-routing data on nearly every buyer.
The Safeguards Rule sets a 30-day clock
A Gramm-Leach-Bliley dealer must run a written information-security program with a designated qualified individual.
How we get you covered
We take cyber liability for garage & auto to 60+ carrier partners, build it to fit your contracts, and keep your certificates compliant.
Read your risk
We map what could actually go wrong in your operation, where a claim would come from, and who would bring it.
Shop 60+ carrier partners
We take your risk to the carriers that know your class and make them compete on price and terms.
Build the endorsements
We add the endorsement wording that decides whether the policy responds to a claim, beyond the base form.
Keep you compliant
We handle the COIs, additional-insured certs, and renewals, so you are never the one chasing paperwork.
What's covered, and what isn't
In the policy
Dealer Management System restoration after ransomware
When the Dealer Management System that runs sales, service, parts, and F&I is encrypted, the policy funds the forensics, the negotiation.
Business interruption while the store cannot transact
A DMS outage stops every department at once, so the store cannot cut deals, run service tickets, or close F&I paperwork and revenue halts across the board.
F&I data breach response and Safeguards Rule notification
When credit applications, Social Security numbers, and bank data in the finance office are exposed, the policy funds the forensics, legal counsel.
Regulatory defense for an FTC Safeguards Rule action
A dealer breach can draw an FTC investigation under the Safeguards Rule, and often a state attorney-general inquiry alongside it.
Funds-transfer fraud in the F&I wire
An attacker impersonating a lender, a floor-plan bank, or a client tricks the F&I office into wiring a payoff or advance to a fraudulent account.
Not in the policy
Fire or physical damage to the DMS servers
If a fire, flood, or power surge destroys the physical servers or on-site hardware, that is damage to your own equipment, not a cyber breach.
Covered by Commercial Property
Employee theft from dealership accounts
An F&I manager or service writer who embezzles, skims cash, or manipulates wholesale purchases is a fidelity loss, not a cyber event.
Covered by Crime / Fidelity
An F&I disclosure error with no breach
A mistake in the APR disclosure, a mispriced add-on, or a Truth in Lending Act failure with no attacker involved is a professional error, not a cyber claim.
Covered by F&I Errors and Omissions
A floor-plan lender's own separate insurance interest
A cyber policy protects the dealership's data and systems, not a floor-plan lender's coverage of its security interest in financed inventory.
Covered by Dealer Open Lot
A breach the store already knew about
An incident already in progress, or a prior breach known before the policy started, is excluded.
Covered by not insurable once known
Claims cyber liability pays
Dealer cyber produces a narrow set of high-severity claims, most tracing to the Dealer Management System, the F&I data, or a deceived wire. These are the ones dealerships actually file, with the typical cost to respond, defend, and settle each.
Ransomware encrypts the Dealer Management System
Attackers lock the DMS and the store cannot cut deals, run service tickets, or close F&I paperwork.
$150K–$2M+
F&I data breach exposes customer credit files
An intruder copies the credit applications, Social Security numbers, and bank data the finance office holds on nearly every buyer.
$100K–$5M+
Business email compromise diverts an F&I wire
An attacker impersonates a lender or floor-plan bank over email and tricks the F&I office into wiring a payoff to a fraudulent account.
$50K–$1M+
FTC Safeguards Rule investigation after a breach
A regulator opens an inquiry into whether the store ran the written information-security program the Safeguards Rule requires.
$100K–$1M+
Ranges are typical response, defense, and settlement bands for these claim types, not a quote. Actual exposure depends on the volume of credit files you hold, your security controls, your DMS dependency, and your limits.
What garage & auto buyers are required to carry
The limits contracts and statutes set for this line, and what moves your premium and terms.
- Floor-plan lender credit agreement
- $1M–$5M cyber
- OEM / franchise data-security addendum
- Program-specified
- FTC Safeguards Rule (16 CFR 314)
- Written program + 30-day notice
A floor-plan lender increasingly conditions the credit line on the dealer carrying cyber liability, because a DMS ransomware shutdown stops the payoffs the lender depends on. The agreement sets a cyber floor alongside the open-lot loss-payee requirement, and a lapse can let the lender freeze the line.
A manufacturer franchise agreement carries a data-security addendum requiring the store to protect the data flowing between dealer and OEM and to carry cyber coverage as a condition of the brand. It ties to the same Gramm-Leach-Bliley obligations the Safeguards Rule imposes, so the program satisfies both.
This is not a private contract. It is the federal floor a financing dealer must meet: a written information-security program, a designated qualified individual, encryption, multi-factor authentication, and continuous monitoring. Since May 2024 it also requires FTC notice within 30 days once a breach reaches 500 or more consumers. Underwriting checks these controls before binding.
- Security controls the Safeguards Rule requires
- Multi-factor authentication, encryption, continuous monitoring, tested backups.
- The record count in the Dealer Management System
- Cyber rates on how many consumer credit files, Social Security numbers, and bank records the store holds.
- DMS dependency and business-interruption exposure
- How completely the store runs on one Dealer Management System, and how much a day of downtime costs.
- Prior incidents and loss history
- A clean record and a documented incident-response plan set the rate, while a prior breach, a ransomware event.
Endorsements that close the gaps
The base form is the start. These add-ons are where the policy gets built to fit garage & auto.
Dependent business interruption (DMS vendor outage)
Extends lost-income coverage to an outage at a vendor the store depends on, most importantly the Dealer Management System provider.
Ransomware sublimit buy-back
Restores ransomware and extortion coverage toward the full policy limit when the base form caps it at a fraction.
Regulatory defense and Safeguards Rule fines
Confirms coverage for the defense cost and, where insurable by law, the penalties from a regulator's investigation.
Social engineering and funds-transfer fraud
Adds or raises the sublimit for a deceived F&I wire, where staff are tricked into sending a lender payoff, floor-plan advance.
By the numbers
The federal rule numbers, the DMS-outage precedent, and the notification thresholds that surface when a dealership gets underwritten for cyber liability or answers a floor-plan lender's insurance requirement.
- CDK Global ransomware attack, dealerships affected
- ~15,000 dealerships
- FTC Safeguards Rule breach-notification trigger
- 500 consumers / 30 days
- GLBA definition of a financial institution
- 15 U.S.C. 6801
- Safeguards Rule information-security program
- 16 CFR 314
- US average cost of a data breach
- $9.36 million
The June 2024 ransomware attack on CDK Global, a leading Dealer Management System provider, disrupted roughly 15,000 dealerships for up to three weeks. It is the case study for why underwriting weighs the DMS as a single point of failure.
Since May 2024 the FTC Safeguards Rule requires a financial institution, including a financing dealership, to notify the FTC within 30 days of discovering a breach involving 500 or more consumers' unencrypted information.
The Gramm-Leach-Bliley Act obligates financial institutions to protect customer nonpublic personal information. Because a dealership that offers or arranges financing meets the Act's definition, it falls under the FTC Safeguards Rule implementing this duty.
The FTC Safeguards Rule is codified at 16 CFR Part 314. It requires a written information-security program, a designated qualified individual, access controls, encryption, multi-factor authentication, continuous monitoring or penetration testing, and an incident-response plan.
IBM's Cost of a Data Breach 2024 report put the average US breach at 9.36 million dollars, the highest of any country. For a dealership the F&I record concentration and notification duty push response cost toward the high end.
Common questions
about cyber liability for garage & auto insurance
Dealer cyber covers both recovery and reporting. First-party, it funds the forensics, negotiation, the ransom where the law permits, restoration of the Dealer Management System, and the income lost while sales and service stop, after a waiting period. Because a financing dealership is a Gramm-Leach-Bliley financial institution, the FTC Safeguards Rule applies: a breach of 500 or more consumers' unencrypted information requires FTC notice within 30 days. Cyber funds that notice, legal counsel, and regulatory defense.
Yes, if the store arranges financing. The Gramm-Leach-Bliley Act classifies a business that offers or arranges consumer financing as a financial institution, so the FTC Safeguards Rule, at 16 CFR 314, governs the store. It requires a written information-security program, a designated qualified individual, encryption, multi-factor authentication, continuous monitoring, penetration testing, and employee training. Since May 2024, a breach of 500 or more consumers triggers a 30-day FTC notice. Underwriting checks these controls before binding.
Yes, through the business-interruption grant. Because sales, service, parts, and F&I all run on one Dealer Management System, an outage stops the whole store, and the policy replaces the income lost. A waiting period must pass first, so a brief outage pays nothing. An outage at the DMS vendor rather than your network falls under dependent business interruption, a separate sublimit. The June 2024 CDK Global outage that stopped roughly 15,000 dealerships is that vendor-side event.
The data it concentrates and the system it runs on. The finance office holds credit applications, Social Security numbers, and bank-routing data on nearly every buyer, the exact records a thief wants. Sales, service, parts, and F&I all run through one Dealer Management System, so ransomware that reaches it stops the entire store. Add Gramm-Leach-Bliley status, the FTC Safeguards Rule, and its 30-day reporting duty, and a dealer carries more regulatory exposure per breach than most businesses its size.
Usually no. F&I errors-and-omissions answers for a professional mistake, such as a Truth in Lending Act disclosure error, where no attacker is involved. Garage liability covers bodily injury and physical property damage, not lost electronic data or a hacked system. Some packaged programs add a small cyber sublimit, often ten or twenty-five thousand dollars, exhausted before the forensics bill is paid and useless for Safeguards Rule notification. A standalone cyber policy is built for breach response, ransomware, and regulatory defense.
Focus on the work.
We'll be your risk team.
Send us your policy and a licensed advisor checks your cyber liability against 60+ carrier partners, flagging gaps and overpricing. If your limits already hold up, we'll tell you.
Your quote
Coverage that pairs with this policy
Most businesses layer a few of these together. Explore the lines that commonly sit alongside it.