Cyberattacks are changing faster than ever, and it’s forcing dealerships to rethink how cybersecurity should be approached.

That was one of the recurring themes in the recent episode of Connected, where Greg Uland, vice president of marketing at Reynolds and Reynolds, sat down with Nikhil Kalani, chief information security officer and vice president of information security at Reynolds and Reynolds. They covered everything from AI-powered fraud to identity security, but it all pointed to the same reality: As technology advances, the way dealerships approach cybersecurity must advance with it.

Here were the top five takeaways from the episode: 

1. Cyberattacks are Evolving

When people hear “cyberattack,” they usually picture a system going down or a network being breached in real time.

Some of today’s most successful attacks don’t involve forcing their way into a network at all. Instead, attackers are impersonating trusted vendors, executives, or employees to convince someone to approve a payment, change banking information, or share sensitive data.

That changes what risk looks like, and how dealerships need to respond. When something looks routine on the surface, verification becomes the control that truly matters. 

2. AI Has Changed the Way We Think About Trust

AI is creating new opportunities for attackers to exploit trust and routine business operations.

The obvious phishing emails full of spelling mistakes haven’t disappeared, but they’re no longer the only threat dealerships need to watch for. Using AI, attackers can craft convincingly polished emails, mimic the writing style of trusted co-workers, and even clone voices or manipulate video.

These tactics make it much more difficult to rely on traditional warning signs employees have been trained to recognize. 

3. Verification Should Be Part of the Process

Verification has to be part of everyday work. Whether it’s updating vendor payment information, approving a wire transfer, or responding to an unexpected request from leadership, taking an extra minute to verify the request through another channel can make all the difference.

It can feel like this slows things down. In reality, that extra minute is often what keeps a routine request from becoming a costly mistake. 

4. Identity is the New Perimeter

Cybersecurity has traditionally focused on protecting infrastructure. Today, identities have become one of the most valuable targets for an attacker.

Once someone gets into a legitimate account, they often gain access to everything connected to it. Think email, business applications, shared files, and internal communication. In many cases, they don’t have to “hack” anything. It’s as simple as a login.

That’s why tools like multifactor authentication, password managers, and phishing-resistant authentication have become foundational security controls rather than nice-to-have features. 

5. Attackers Are Moving Faster Than Ever

AI hasn’t just changed how cyberattacks look. It’s changed the speed in which they move. Incidents that once unfolded over days can now happen in hours. Once access is gained, attackers can automate movement through systems and quickly escalate the damage.
 
That puts pressure on organizations to respond just as quickly. Strong processes, good visibility, and the right security tools all play a role, but so does preparation. The faster a dealership can recognize something isn’t right, the better chance it has of limiting the impact. 
Cybersecurity isn’t just about technology anymore. It’s about how people, processes, and tools work together. The good news is that the fundamentals haven’t changed: Strong identity protection, clear verification procedures, and employees who understand what modern threats look like continue to be some of the most effective ways to reduce risk. 

Watch the full episode of Connected with Nikhil Kalani on YouTube to see real-world examples of these threats and what your dealership can do to stay ahead.