AccuSights
PartnersBlogAbout
Book my 30-minute demo

Auto Repair & Skilled Trades · Cybersecurity, compliance and GRC, in plain English

Your invoices, your customers, your bank account. Yours.

A shop or a trades company runs on a mailbox, an invoicing app and a customer list with nine thousand addresses on it. That is exactly what an attacker wants: sit in the inbox for eleven days, then send your invoices with their bank details. We put MFA on the mailbox, watch for the login from the wrong country, lock down the customer list and keep the shop software running.

Built for 5 to 200 employeesInvoice-fraud controls firstSee your score immediately

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The Monday a plumbing company’s invoices went out with someone else’s bank details

the owner of a 22-truck plumbing and HVAC company

Ray started with one van in Berwyn. Twenty-two trucks later, the office runs on a field-service app, a bookkeeper named Teresa and a customer list of 9,000 homes with every water heater and furnace they have ever installed.

Monday at 7:30, a customer calls to say the invoice she got Friday night had new ‘updated payment instructions’ and she paid it. Teresa did not send that invoice. Someone has been inside the office mailbox for eleven days, reading, waiting, and then sending 140 invoices with a different account number from the real address.

In the version that goes badly, customers pay for a week before anyone notices, the money is unrecoverable, Ray refunds the ones who paid twice to keep his reputation, and the customer list, with addresses and equipment details, is sold to a burglary crew.

In Ray’s version, the login from another country tripped the watch on day one. The engineer cut the session, reset the mailbox and found the forwarding rule the attacker had planted. The 140 invoices never went out. Teresa spends Monday sending the real ones.

Someone has been inside the office mailbox for eleven days, reading, waiting, and then sending 140 invoices with a different account number from the real address.

What changes the ending

  1. MFA on the office mailbox and the invoicing app, with forwarding rules watched (CIS Controls 5 and 9)
  2. Login monitoring that flags a session from a country your business has never been in (CIS Control 13, Network Monitoring and Defense)
  3. A rule, taught to customers, that payment details never change by email (CIS Control 14, Security Awareness and Skills Training)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

What if my service manager walks out with the entire customer list and our pricing?

The field-service app exports 9,000 customers in one click unless exports are restricted and logged. We scope access by role, turn off accounts the hour someone gives notice and keep the audit trail that makes your non-solicitation clause enforceable.

Can money be stolen through the card readers on my trucks?

The readers themselves are usually fine; the risk is the account behind them, the tablet that runs the app and the office PC where the deposits reconcile. MFA on the processor login, updated tablets and a watch on payout changes close that door.

We are a repair shop, not a bank. Does anyone really target us?

In the latest DBIR, 96% of ransomware victims where size was known were small and mid-size businesses, and the FBI counted $3.05 billion in email-payment fraud in 2025. Shops are targeted because the invoice-and-pay cycle is fast and the defenses are usually a shared password.

What you hold, and why someone wants it

Your data protection needs, by the data.

Customer records with addresses and equipment history

Nine thousand homes, when they are empty, and what is installed there. Access limits, export controls and encryption protect them.

Invoices, estimates and payment links

The channel a fraudster hijacks to get paid instead of you. Mailbox MFA and invoice-change monitoring protect it.

Payment processor and bank accounts

Payouts can be redirected with one password. MFA and payout-change alerts protect them.

Diagnostic tools, key programmers and shop-management systems

Modern diagnostic and key-programming tools are networked computers on the shop floor. Segmentation and patching protect them.

Employee records and payroll

Direct-deposit details for a crew that changes with the season. Two-person approval on any change protects them.

$1.02B
in losses to auto dealers from the three-week CDK Global software outage in June 2024, plus about 56,200 lost vehicle sales
Source: Anderson Economic Group, July 2024
44%
of publicly reported automotive and mobility cyber incidents in 2025 were ransomware, more than double 2024
Source: Upstream Security, 2026 Global Automotive and Smart Mobility Cybersecurity Report
$3.05B
lost to business email compromise in 2025; the hijacked invoice and the diverted payroll are the contractor’s version
Source: FBI IC3 2025 Internet Crime Report

No regulator at the door, still rules that apply

What you are still on the hook for, in one page.

FTC Safeguards Rule, for dealers only
Federal Trade Commission
Auto dealers that arrange financing are financial institutions under the rule; independent repair shops and trades contractors are not.
PCI DSS v4.0.1
PCI Security Standards Council
Applies to the card readers on the trucks, the shop terminal and the online payment link.
State breach notification laws
State attorneys general
Customer and employee data stolen in an attack triggers notification in all 50 states.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • An attacker inside the office mailbox for days, then sending your invoices with their bank details.
  • The field-service or shop-management vendor going down and taking scheduling, invoicing and history with it.
  • A departing manager exporting the customer list and pricing to a competitor across town.

It happened to businesses like yours

A June 2024 ransomware attack on CDK Global, the dealer-management software used by about 15,000 auto dealerships, took sales and service systems down for roughly three weeks; Anderson Economic Group estimated dealer losses at $1.02 billion.

June 2024 · Anderson Economic Group

Advance Auto Parts disclosed in July 2024 that attackers reached its data stored with a cloud vendor and exposed records on 2.3 million people, mostly job applicants and current and former employees.

May to July 2024 · Cybersecurity Dive

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a auto & trades business

We protect your people, every device, the servers and the website. Day and night.

  • We protect your office and dispatch inboxes, where the fake invoice and the payroll-change request arrive.
  • Every office PC, shop computer and the tablets your techs carry into customers’ homes.
  • The server and the file share, or the cloud drive, holding customer records and job files.
  • The website and the online booking and payment pages.
  • The cloud apps: field-service software, invoicing, payroll, email and the parts portals.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Auto Repair and Trades

Built on the CIS Controls v8.1 IG1 and scoped from what a shop or a contractor stands to lose: the money in the invoice cycle, the customer list and the software that runs the day. Plain-English findings for an owner who has trucks to dispatch.

  • Inventory of every office PC, shop computer, tech tablet and cloud app, including diagnostic tools on the network (CIS Controls 1 and 2)
  • Mailbox and invoicing security review: MFA, forwarding rules, payment-link and payout-change monitoring (CIS Controls 5, 6 and 9)
  • Customer-list protection: who can export, who did, and how access ends the day someone leaves (CIS Controls 3 and 6)
  • Backup and restore test for the field-service, accounting and job-file data (CIS Control 11)
  • Shop network segmentation for diagnostic tools, key programmers and guest Wi-Fi (CIS Control 12)
  • A one-page response plan for the Monday the invoices go wrong, and a ranked remediation plan
Start with the 3-minute test

Packages

Built for auto & trades businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

Do small auto repair shops and contractors really get hacked?
Yes, and the dealer-software outage of June 2024 showed what a single vendor failure does to 15,000 businesses at once. Independent shops are hit through the office mailbox and the invoicing app, which is where the 3-minute test starts.
How do I stop fake invoices being sent from my email?
Turn on MFA for every mailbox, alert on new forwarding rules, watch for logins from places your business does not operate, and tell customers in writing that payment details never change by email. We set all four up and watch them.
Is my shop management or field-service software secure?
The major platforms are well built, but they cannot protect a shared password, an ex-employee’s open account or an unpatched office PC. The assessment checks the accounts, the exports and the devices around the software, and reviews the vendor’s recovery commitments.

People also search: cybersecurity for auto repair shops near me · IT security for HVAC companies in Chicago · for a 22-truck plumbing company · for a three-bay independent auto shop · cybersecurity for electrical contractors in the suburbs · invoice fraud protection for contractors · for a collision repair shop with two locations · cybersecurity for a landscaping company

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test