Automotive News - September 23, 2019 - Best Practices Supplement - A24
24 | SEPTEMBER 23, 2019
Z I M B R I C K I N C . , M I LWA U K E E A N D M A D I S O N , W I S .
DATA SECURITY FIRST
Email testing, firewalls
and more fight threats
Published in Automotive News April 1, 2019
M
Hannah Lutz
hlutz@crain.com
uch of dealership group Zimbrick
Inc.'s effective cybersecurity strategy comes down to vetting vendors.
"We are not necessarily the vendors' best friend in this world. We make sure
that they can meet our security requirements
or have some compensating controls in place
before we'll sign up with that service," said
Tom Zimbrick, CEO of Zimbrick Inc., a
15-store dealership group in Madison, Wis.,
and Milwaukee. "That
helps us confidently grow
the business because ... we
know the data is secure."
Zimbrick's stringent vendor standards are part of its
broader effort to stay ahead
of data security threats.
The strategy includes installing sophisticated fireZimbrick: Data
"a sacred trust" walls, sending regular
phishing email tests and
limiting network access.
"We implement security not just to protect
customer data; it's also to keep our systems running," said Ryan Horstmann, the group's information technology director. "It's the easiest way
for us to keep our uptime as high as possible."
Some of Zimbrick's toughest battles are with
providers of dealership management systems
that don't meet security requirements, said
Horstmann.
"It is a never-ending battle with all vendors.
The DMS providers are really important to our
business, so in my world, they get the most attention."
Usually, Zimbrick and its vendors come to
an agreement that solves the concern, but the
dealership group has to be persistent, Horstmann said.
In at least one case, a vendor rolled out a security standard developed for Zimbrick to all of its
dealership clients using the Internet-facing
product in question. Zimbrick declined to identify the company.
"We firmly believe that this is our data. We hold
customer data in a sacred trust. We are very uncompromising in that way," Tom Zimbrick said.
Zimbrick, which sold 9,336 new vehicles and
Employees can report a phishing email. If they fall for it, they are routed to a cybersecurity video.
Zimbrick Inc. in Wisconsin strives to
stay ahead of data security threats by
implementing stringent vendor
standards, installing sophisticated
firewalls, sending regular phishing email
tests and limiting network access.
7,855 used retail vehicles last year, has a
three-person IT team, led by Horstmann, that
oversees cybersecurity and other IT tasks. The
dealership group also works with an outside
firm that handles simpler IT issues. Horstmann
was a software developer for a payroll and timekeeping company for 10 years before joining
Zimbrick in 2007. Much of his responsibility in
his previous role centered on protecting data.
Phishing test
Once a month, Zimbrick sends its employees a
phishing email. The subject line may say something like "Donald Trump has a heart attack" or
"One of your employees was behaving badly."
If employees click on the email link, open the
attachment or enter their username and password when prompted, they will automatically
be routed to a video on cybersecurity training.
"If there is going to be a breach or a break-in,
it is most likely going to happen accidentally
through an employee [when] a customer or
an outside person sends a request [and] the
employee forwards it, answers it, opens the
message," said Tom Zimbrick. Phishing is the
primary source of attack, he said.
The phishing tool, a Cofense product called
PhishMe, creates awareness, added Horstmann.
The videos are short and to the point, he said.
PhishMe costs about $8 per user per year,
but "The real question is, how much does it
cost if you don't have it?" said Tom Zimbrick.
In February, about half of employees reported the email as phishing, while 35 percent deleted or ignored it, thus passing the test. About
15 percent clicked the link in the email.
Fear of the unknown
Zimbrick built its systems with security in
mind from the start and has a reliable backup
system, said Horstmann. Since 2015, the group
has run a firewall with 24/7 monitoring to
block threats. Zimbrick's firewall is more cutting-edge than others, Horstmann said, because it identifies not only verified attacks but
what could turn into one.
Zimbrick also has separate networks for
customers and employees and requires twostep authentication for employees entering
the network remotely.
The company has leadership meetings every month with general managers and other
high-level staff. At those meetings, Horstmann "has a seat at the table," Tom Zimbrick
said. "So we're all up to speed."
There was no single event that prompted Zimbrick's commitment to cybersecurity. The group
was motivated by a fear of the unknown.
"Whether it's our business or someone
else's business, we know the attacks are increasing. We know they're getting more sophisticated," Tom Zimbrick said. "We're just
trying to get ahead of them." a
Automotive News - September 23, 2019 - Best Practices Supplement
Table of Contents for the Digital Edition of Automotive News - September 23, 2019 - Best Practices Supplement
Automotive News - September 23, 2019 - Best Practices Supplement - Intro
Automotive News - September 23, 2019 - Best Practices Supplement - A1
Automotive News - September 23, 2019 - Best Practices Supplement - A2
Automotive News - September 23, 2019 - Best Practices Supplement - A3
Automotive News - September 23, 2019 - Best Practices Supplement - A4
Automotive News - September 23, 2019 - Best Practices Supplement - A5
Automotive News - September 23, 2019 - Best Practices Supplement - A6
Automotive News - September 23, 2019 - Best Practices Supplement - A7
Automotive News - September 23, 2019 - Best Practices Supplement - A8
Automotive News - September 23, 2019 - Best Practices Supplement - A9
Automotive News - September 23, 2019 - Best Practices Supplement - A10
Automotive News - September 23, 2019 - Best Practices Supplement - A11
Automotive News - September 23, 2019 - Best Practices Supplement - A12
Automotive News - September 23, 2019 - Best Practices Supplement - A13
Automotive News - September 23, 2019 - Best Practices Supplement - A14
Automotive News - September 23, 2019 - Best Practices Supplement - A15
Automotive News - September 23, 2019 - Best Practices Supplement - A16
Automotive News - September 23, 2019 - Best Practices Supplement - A17
Automotive News - September 23, 2019 - Best Practices Supplement - A18
Automotive News - September 23, 2019 - Best Practices Supplement - A19
Automotive News - September 23, 2019 - Best Practices Supplement - A20
Automotive News - September 23, 2019 - Best Practices Supplement - A21
Automotive News - September 23, 2019 - Best Practices Supplement - A22
Automotive News - September 23, 2019 - Best Practices Supplement - A23
Automotive News - September 23, 2019 - Best Practices Supplement - A24
Automotive News - September 23, 2019 - Best Practices Supplement - A25
Automotive News - September 23, 2019 - Best Practices Supplement - A26
Automotive News - September 23, 2019 - Best Practices Supplement - A27
Automotive News - September 23, 2019 - Best Practices Supplement - A28
Automotive News - September 23, 2019 - Best Practices Supplement - A29
Automotive News - September 23, 2019 - Best Practices Supplement - A30
Automotive News - September 23, 2019 - Best Practices Supplement - A31
Automotive News - September 23, 2019 - Best Practices Supplement - A32
Automotive News - September 23, 2019 - Best Practices Supplement - A33
Automotive News - September 23, 2019 - Best Practices Supplement - A34
Automotive News - September 23, 2019 - Best Practices Supplement - A35
Automotive News - September 23, 2019 - Best Practices Supplement - A36
Automotive News - September 23, 2019 - Best Practices Supplement - A37
Automotive News - September 23, 2019 - Best Practices Supplement - A38
Automotive News - September 23, 2019 - Best Practices Supplement - A39
Automotive News - September 23, 2019 - Best Practices Supplement - A40
Automotive News - September 23, 2019 - Best Practices Supplement - A41
Automotive News - September 23, 2019 - Best Practices Supplement - A42
Automotive News - September 23, 2019 - Best Practices Supplement - A43
Automotive News - September 23, 2019 - Best Practices Supplement - A44
Automotive News - September 23, 2019 - Best Practices Supplement - A45
Automotive News - September 23, 2019 - Best Practices Supplement - A46
Automotive News - September 23, 2019 - Best Practices Supplement - A47
Automotive News - September 23, 2019 - Best Practices Supplement - A48
https://www.nxtbook.com/nxtbooks/crain/an_20241007_supp
https://www.nxtbook.com/nxtbooks/crain/an_20240429_supp
https://www.nxtbook.com/nxtbooks/crain/an3219542277LMDFA_supp
https://www.nxtbook.com/nxtbooks/crain/an3435609782TWTKL_supp
https://www.nxtbook.com/nxtbooks/crain/an2737646517HKDWS_supp
https://www.nxtbook.com/nxtbooks/crain/an2746596872HIAJD_supp
https://www.nxtbook.com/nxtbooks/crain/an4955867723FWRSS_supp
https://www.nxtbook.com/nxtbooks/crain/an1326535475LMTIM_supp
https://www.nxtbook.com/nxtbooks/crain/an3887461294KHGFY_supp
https://www.nxtbook.com/nxtbooks/crain/an3245837562PLINN_supp
https://www.nxtbook.com/nxtbooks/crain/an4756684734HIGTK_supp
https://www.nxtbook.com/nxtbooks/crain/an8475647221RWSTS_supp
https://www.nxtbook.com/nxtbooks/crain/an4475637112TIGSM_supp
https://www.nxtbook.com/nxtbooks/crain/an4472236451GHTLT_supp
https://www.nxtbook.com/nxtbooks/crain/an8875623549CBWAF_supp
https://www.nxtbook.com/nxtbooks/crain/an2713984755IBPIT_supp
https://www.nxtbook.com/nxtbooks/crain/an2365889566CBASA_supp
https://www.nxtbook.com/nxtbooks/crain/an2713985847ISTTW_supp
https://www.nxtbook.com/nxtbooks/crain/an9826351139SHNKT_supp
https://www.nxtbook.com/nxtbooks/crain/an4239576129HTSKA_supp
https://www.nxtbook.com/nxtbooks/crain/an4859867123HPGMF_supp
https://www.nxtbook.com/nxtbooks/crain/an9875632144BLASA_supp
https://www.nxtbook.com/nxtbooks/crain/an5948576134HMTFC_supp
https://www.nxtbook.com/nxtbooks/crain/an4958670126PBWGM_supp
https://www.nxtbook.com/nxtbooks/crain/an9384756453JBFPW_supp
https://www.nxtbook.com/nxtbooks/crain/an8395756432AMIHC_supp
https://www.nxtbook.com/nxtbooks/crain/an9405856762CSFLS_supp
https://www.nxtbook.com/nxtbooks/crain/an3873120954AMTCW_supp
https://www.nxtbook.com/nxtbooks/crain/an8097364512SITPF_supp
https://www.nxtbook.com/nxtbooks/crain/an3478925478LIALS_supp
https://www.nxtbook.com/nxtbooks/crain/an9894756324SSFTL_supp
https://www.nxtbook.com/nxtbooks/crain/an5847323487AICCS_supp
https://www.nxtbook.com/nxtbooks/crain/an3874321237DILDC_supp
https://www.nxtbook.com/nxtbooks/crain/an8784431649FWCWY_supp
https://www.nxtbook.com/nxtbooks/crain/an8392274512LCCSM_supp
https://www.nxtbook.com/nxtbooks/crain/an5623423988AMCTW_supp
https://www.nxtbook.com/nxtbooks/crain/an9384756213BALRS_supp
https://www.nxtbook.com/nxtbooks/crain/an9382218435SPOMB_supp
https://www.nxtbook.com/nxtbooks/crain/ANshowdaily80819
https://www.nxtbook.com/nxtbooks/crain/ANshowdaily80719
https://www.nxtbook.com/nxtbooks/crain/ANshowdaily80619
https://www.nxtbook.com/nxtbooks/crain/an3214543326LCFPC_supp
https://www.nxtbook.com/nxtbooks/crain/an9381127498RISGS_supp
https://www.nxtbook.com/nxtbooks/crain/an8473635224CDSLM_supp
https://www.nxtbook.com/nxtbooks/crain/an8373746387BIMHS_retail
https://www.nxtbook.com/nxtbooks/crain/an7698534210IRHTD_supp
https://www.nxtbook.com/nxtbooks/crain/an8447751218IHAGC_supp
https://www.nxtbook.com/nxtbooks/crain/an8576321197WMPRC_supp
https://www.nxtbook.com/nxtbooks/crain/an6399112438IRHAH_supp
https://www.nxtbook.com/nxtbooks/crain/an8736450912ADGJT_supp
https://www.nxtbook.com/nxtbooks/crain/an8700873122RNARH_supp
https://www.nxtbook.com/nxtbooks/crain/an1093836455HAGTA_supp
https://www.nxtbook.com/nxtbooks/crain/an9808765635GTJTW_supp
https://www.nxtbook.com/nxtbooks/crain/an6525367432FHMLB_supp
https://www.nxtbook.com/nxtbooks/crain/an8597421143MCFPA_supp
https://www.nxtbook.com/nxtbooks/crain/an4298726547VWGGA_supp
https://www.nxtbook.com/nxtbooks/crain/an7799856412ILBOV_supp
https://www.nxtbook.com/nxtbooks/crain/an2056982648AHHIA_supp
https://www.nxtbook.com/nxtbooks/crain/an5678154982IEHDT_supp
https://www.nxtbook.com/nxtbooks/crain/an0211270720DPISS_supp
https://www.nxtbook.com/nxtbooks/crain/an2325269754PSINO_supp
https://www.nxtbook.com/nxtbooks/crain/an5627892889EASBC_supp
https://www.nxtbook.com/nxtbooks/crain/an4778021396LTBFA_supp
https://www.nxtbook.com/nxtbooks/crain/an1549365874TIUIG_supp
https://www.nxtbook.com/nxtbooks/crain/an9685896971RTQAT_supp
https://www.nxtbook.com/nxtbooks/crain/an3126539765SSIKM_supp
https://www.nxtbook.com/nxtbooks/crain/an2348716424IHBFN_v2
https://www.nxtbook.com/nxtbooks/crain/an2713112513DPIAA_GEDsupp
https://www.nxtbook.com/nxtbooks/crain/an2713112513DPIAA_GIEsupp
https://www.nxtbook.com/nxtbooks/crain/an5740978765KIYTC_v2
https://www.nxtbook.com/nxtbooks/crain/an8786483429YWIRB_v2
https://www.nxtbook.com/nxtbooks/crain/an1441850607BCEKP_supp
https://www.nxtbook.com/nxtbooks/crain/an2231982341SHRK_supp
https://www.nxtbook.com/nxtbooks/crain/an9824752309LOLIKP_supp
https://www.nxtbook.com/nxtbooks/crain/an8849332574YIKP_supp
https://www.nxtbook.com/nxtbooks/crain/an3756575112SAIKPv2
https://www.nxtbook.com/nxtbooks/crain/an7389812526DOQKPv2
https://www.nxtbook.com/nxtbooks/crain/an7474633298JQMKPv2
https://www.nxtbook.com/nxtbooks/crain/an8763487432NAOKPv2
https://www.nxtbook.com/nxtbooks/crain/an3748383922LRGKPv2
https://www.nxtbook.com/nxtbooks/crain/an8347508927POTKPv2
https://www.nxtbook.com/nxtbooks/crain/an9610620377FSKKP_supp
https://www.nxtbook.com/nxtbooks/crain/an4981263095CBNKP_supp
https://www.nxtbook.com/nxtbooks/crain/an6723445245SDFLF_supp
https://www.nxtbook.com/nxtbooks/crain/an4862340134FSEJC_supp
https://www.nxtbook.com/nxtbooks/crain/an4596813450LQFCN_supp
https://www.nxtbook.com/nxtbooks/crain/an2348692346SDGCN_supp
https://www.nxtbook.com/nxtbooks/crain/an1634224522ASDLC_supp
https://www.nxtbook.com/nxtbooks/crain/an0267104334RTSJC_supp
https://www.nxtbook.com/nxtbooks/crain/an6029878560PGSCN_supp
https://www.nxtbook.com/nxtbooks/crain/an5214469855HGBKP_supp
https://www.nxtbook.com/nxtbooks/crain/an1062061234GSGBL_supp
https://www.nxtbook.com/nxtbooks/crain/an5038325406GSDCN_supp
https://www.nxtbook.com/nxtbooks/crain/an3992752354ASPLF_supp
https://www.nxtbook.com/nxtbooks/crain/an7986445324GHYCN_supp
https://www.nxtbook.com/nxtbooks/crain/an1455687392FTBTE_v2
https://www.nxtbook.com/nxtbooks/crain/an2289678453HBCLF_v2
https://www.nxtbook.com/nxtbooks/crain/an5633892673TBEKP_v2
https://www.nxtbook.com/nxtbooks/crain/an4663981572FBCJC_v2
https://www.nxtbook.com/nxtbooks/crain/ane_7746982457HCTBV_supp
https://www.nxtbook.com/nxtbooks/crain/an8994656823RVGCN_v2
https://www.nxtbook.com/nxtbooks/crain/an4566329884GVTLF_supp
https://www.nxtbook.com/nxtbooks/crain/an7466398157YCPTS_supp
https://www.nxtbook.com/nxtbooks/crain/an5334987156YBHBL_supplement
https://www.nxtbook.com/nxtbooks/crain/an2822679175GTHTS_bestpractices
https://www.nxtbook.com/nxtbooks/crain/an4893356182CJPCN_v2
https://www.nxtbook.com/nxtbooks/crain/an8388619274RBCCN_v2
https://www.nxtbook.com/nxtbooks/crain/an7833092572SPRBW_v2
https://www.nxtbook.com/nxtbooks/crain/an5533789923FTBLF_v2
https://www.nxtbook.com/nxtbooks/crain/an7884599237HYQJC_v2
https://www.nxtbook.com/nxtbooks/crain/an1335576249HBWKP_v2
https://www.nxtbook.com/nxtbooks/crain/an7855749033KPMLF_v2
https://www.nxtbook.com/nxtbooks/crain/an8946778932RBTTS_v2
https://www.nxtbook.com/nxtbooks/crain/an6735519136YBPMG_v2
https://www.nxtbook.com/nxtbooks/crain/an_20130318Top125
https://www.nxtbook.com/nxtbooks/crain/an3766500224HBPJC_v2
https://www.nxtbook.com/nxtbooks/crain/an_080612_supp
https://www.nxtbookmedia.com