Cars are more vulnerable to cyber-attacks as they become intelligent and connected. The threats have gone beyond vehicles to mobility applications and EV charging infrastructure. Experts said it is critical to have cybersecurity solutions supporting the entire security lifecycle and establish real-time collaboration among vehicle, IT and enterprise security operation center (SOC) cybersecurity perspectives.
Upstream Security's 2023 Global Automotive Cybersecurity Report shows that remote keyless vehicle theft and break-ins accounted for 18% of total cybersecurity incidents in 2022. About 23% of the attacks resulted in service or business disruption.
Upstream recently shared some key findings of the report with DIGITIMES Asia. The Israel-based company focuses on post-production cyber protection - for vehicles driven on the road. It opened its first US-based vehicle security operation center (VSOC) in Michigan last September.
It stated in the report that a 380% increase in automotive API attacks was found in 2022. Besides, more ransomware attacks targeting the automotive supply chain arose.
China-based EV maker Nio just suffered a data breach in December 2022. The personal information of vehicle owners and Nio employees was put online for sale after the company refused the hacker's demand for US$2.25 million worth of bitcoin.
Upstream said vehicle security teams worldwide are challenged by threats going beyond direct attacks against cars to fleets, mobility applications and services and EV charging infrastructure.
Roy Fridman, CEO of C2A Security, said hackers will target charging stations to access a car driver's bank or insurance information. They might also hack banks or government systems due to the hyperconnectivity of vehicles.
Founded in 2016, Israel-based C2A just announced a partnership with Valeo to enhance the automotive supplier's cybersecurity offerings on its products in development and continuous operations.
Fridman said there were also a few cyber-attacks on robotaxis last year. Vehicles were stopped randomly or called to the same place, creating mayhem on the roads.
The automotive industry will see more complex relationships between vehicles and their outer environments with the growing adoption of vehicle-to-everything. Fridman said the situation will lead to an increase in cybersecurity threats.
He suggested OEMs and parts suppliers automate their cybersecurity management system to tackle the growing issues. The automation will require the adoption of DevSecOps (short for development, security and operations) – integrating security at each phase of the software development cycle.
Fridman said implementing DevSecOps software will create opportunities for developers to focus on new features and innovations while allowing companies to maintain competitiveness.
Upstream said new cyber-attacks may significantly impact a wide range of mobility assets, requiring a fresh outlook on technology and mitigation methods. It added that real-time collaboration among the vehicle, IT and enterprise SOC will be critical to detect and effectively mitigate complex attack vectors seen nowadays.
As more automotive cybersecurity incidents are reported, Upstream said customers and regulators become more aware of the dangers of connectivity. OEMs and smart mobility stakeholders must proactively establish trust for their vehicles and services.