Integration? What's that and what do I do with it? What about my DMS?
- By DEP
Great Post! When vendors tell you that your group is overprotective they might be referring to the fact that you actually take the time to run third party requests for integration through a legal team. All too often I witness dealers and office staff who sign these types of contracts and agreements without even browsing over them. Many times, these contracts include clauses or disclaimers that release the third party vendor from liability for data loss, corruption, or theft caused by the integration hence the responsibility often falls solely on the dealership.
I do work in the industry for a third party company that does invest in secure integration with several DMS partners including the "Big Three" as you refer to them. We view the certification process as an important aspect of our business that allows our clients to do business with us in confidence. Unfortunately, it's not always the easiest or most popular stance to take. If you think about it, many of your customers would probably be happy if you told them them that they can neglect costly procedures in their maintenance guide and still enjoy optimal performance from their new car. Much the same way a vendor might tell you to ignore your data providers cerification policy guidlines for protecting your system and data. The argument to keep using vendors that rely on hostile integration to access data is often based on a broken correlation: Nothing negative has occurred to this point, therefore nothing negative will ever occur. My point is, it’s always easy to "drink the kool aid" and there will always be plenty of companies happy to serve it as long as decision makers are willing to drink.
In today’s market, clients often place focus and expectations on fast and easy. As we've all witnessed in the credit card industry, fast and easy doesn't always mix well with private or sensitive information. In making credit cards faster and easier to use than ever, credit card companies and the vendors that process them have made it easier in many cases, for criminals to commit data theft and fraud. Sometimes it might make sense to be careful what we wish for, at least before we consider unintended consequences. (Ask any individual who has gone through identity theft or a company that’s been through a class action lawsuit for failing to adequately protect sensitive data)
Data security can be like auto insurance. Unfortunately, it's often just not that important until a problem occurs. The saying, "An ounce of prevention is worth a pound of cure" seems relevant when talking about this issue. To anyone faced with decisions involving data security and integration, I recommend examining motivations and agendas of the companies using non-certified integrations to gain access to data just as you scrutinize the companies that implement and maintain the certification programs.
I do work in the industry for a third party company that does invest in secure integration with several DMS partners including the "Big Three" as you refer to them. We view the certification process as an important aspect of our business that allows our clients to do business with us in confidence. Unfortunately, it's not always the easiest or most popular stance to take. If you think about it, many of your customers would probably be happy if you told them them that they can neglect costly procedures in their maintenance guide and still enjoy optimal performance from their new car. Much the same way a vendor might tell you to ignore your data providers cerification policy guidlines for protecting your system and data. The argument to keep using vendors that rely on hostile integration to access data is often based on a broken correlation: Nothing negative has occurred to this point, therefore nothing negative will ever occur. My point is, it’s always easy to "drink the kool aid" and there will always be plenty of companies happy to serve it as long as decision makers are willing to drink.
In today’s market, clients often place focus and expectations on fast and easy. As we've all witnessed in the credit card industry, fast and easy doesn't always mix well with private or sensitive information. In making credit cards faster and easier to use than ever, credit card companies and the vendors that process them have made it easier in many cases, for criminals to commit data theft and fraud. Sometimes it might make sense to be careful what we wish for, at least before we consider unintended consequences. (Ask any individual who has gone through identity theft or a company that’s been through a class action lawsuit for failing to adequately protect sensitive data)
Data security can be like auto insurance. Unfortunately, it's often just not that important until a problem occurs. The saying, "An ounce of prevention is worth a pound of cure" seems relevant when talking about this issue. To anyone faced with decisions involving data security and integration, I recommend examining motivations and agendas of the companies using non-certified integrations to gain access to data just as you scrutinize the companies that implement and maintain the certification programs.
