top of page

Automotive Innovation Requires Cybersecurity by Design

  • CCi Communications
  • Sep 5, 2025
  • 6 min read

Updated: 3 days ago


Vehicles are becoming more connected, intelligent and dependent on software.

Functions that were once controlled primarily by mechanical components are increasingly managed through software, sensors, cloud platforms and electronic control systems. Vehicles can receive remote updates, communicate with external infrastructure and personalize features using driver data.

These capabilities can improve safety, efficiency and the customer experience. They also create more digital connections that automotive organizations must secure.

Cybersecurity can no longer be treated as a separate technical issue. It must be considered throughout the vehicle lifecycle, from design and manufacturing to ownership, service and collision repair.


Software is redefining the vehicle

Software-defined vehicles use centralized digital systems to manage a growing share of vehicle functions.

Instead of relying on isolated components with fixed capabilities, these vehicles can integrate information from multiple systems and receive improvements through software updates.

Software may influence:

  • Driver-assistance features

  • Infotainment

  • Navigation

  • Battery management

  • Vehicle performance

  • Energy efficiency

  • Predictive maintenance

  • Personalization

  • Connectivity

  • Safety monitoring

This creates opportunities for manufacturers to improve vehicles after they have been sold. It also allows different functions to share information and respond more intelligently.

However, greater integration means that a weakness in one system can potentially affect other connected systems. Security must therefore be considered across the complete architecture rather than applied to individual components in isolation.


Every connection expands the potential risk

Connected vehicles communicate with many external systems.

These may include:

  • Manufacturer cloud platforms

  • Mobile applications

  • Charging infrastructure

  • Dealership systems

  • Insurance networks

  • Diagnostic tools

  • Repair platforms

  • Fleet management services

  • Road infrastructure

  • Third-party technology providers

Each connection can create value, but it can also become a possible point of exposure.

A cyber risk does not need to begin inside the vehicle. It may enter through a web portal, mobile application, supplier system, software integration or connected service.

The automotive industry must understand how information and system access move through this broader ecosystem.


Over-the-air updates require strong protection

Over-the-air updates allow manufacturers to improve vehicle software remotely. They may add features, correct performance issues or address security vulnerabilities without requiring a dealership visit.

This capability can make software maintenance faster and more efficient.

It also creates a critical security responsibility. The vehicle must be able to confirm that an update is legitimate, authorized and unchanged before installation.

A secure update process may require:

  • Strong encryption

  • Digital signatures

  • Authentication

  • Integrity verification

  • Controlled access

  • Secure rollback procedures

  • Continuous monitoring

  • Detailed update records

If authenticity checks are weak or encryption is bypassed, a useful connection can become a pathway for malicious software or unauthorized changes.


Artificial intelligence creates opportunity and risk

Artificial intelligence is becoming increasingly important across the automotive industry.

AI can support:

  • Advanced driver-assistance systems

  • Predictive maintenance

  • Automated quality inspection

  • Driver monitoring

  • Natural language interfaces

  • Autonomous functions

  • Manufacturing optimization

  • Vehicle diagnostics

  • Customer personalization

  • Cybersecurity monitoring

Machine learning can analyze large amounts of information and recognize patterns that would be difficult for human teams to identify manually.

For example, predictive maintenance systems can detect early signs of a developing issue. Security platforms can monitor network activity and identify unusual behaviour. Digital twins can help manufacturers test systems and production processes virtually.

However, AI systems introduce their own risks. Models may be influenced by manipulated information, unauthorized instructions or compromised software. They may also produce unreliable results when the data they receive is incomplete or inaccurate.

AI requires strong governance, ongoing testing and clear human oversight.


Security must exist at every layer

The RSM article emphasizes the importance of building security and privacy into every level of automotive technology.

These levels can include:

  • The data layer

  • The vehicle system layer

  • The connection layer

  • The authentication layer

  • The application layer

  • The cloud layer

  • The supplier layer

  • The user access layer

Protecting one layer is not enough.

A secure vehicle can still be affected by a vulnerable cloud account. A protected application can still be exposed through a weak supplier integration. Strong encryption can still be undermined by stolen credentials.

Automotive organizations need defence in depth, which means using multiple safeguards so that the failure of one control does not expose the entire system.


Zero trust offers a useful model

Traditional security models often assume that activity inside an approved network can be trusted.

That assumption becomes difficult to maintain in an automotive ecosystem with connected vehicles, cloud services, suppliers, repairers and mobile users.

A zero trust approach assumes that no person, device or connection should receive automatic trust.

Every request should be verified based on factors such as:

  • Identity

  • Device condition

  • Access permissions

  • Location

  • Data sensitivity

  • Requested action

  • Previous behaviour

  • Current risk signals

Access should also be limited to what is required for a specific task.

A parts supplier may need vehicle and component information. A calibration provider may need sensor and repair data. Neither necessarily needs the customer’s complete claim file.

Restricting access helps reduce unnecessary exposure.


Supply chain transparency is essential

Modern vehicles depend on extensive networks of technology and manufacturing partners.

A manufacturer may work with suppliers that provide sensors, software, electronic components, cloud services, diagnostic tools and communication platforms. Those suppliers may also rely on their own subcontractors.

This creates multiple layers of responsibility.

Organizations need to know:

  • Which companies contribute to a system

  • What information each partner can access

  • How software components are maintained

  • Who is responsible for identifying vulnerabilities

  • How incidents will be reported

  • How updates will be distributed

  • What happens when a vendor relationship ends

Cybersecurity standards must apply throughout the supply chain. One vulnerable partner can introduce risk into an otherwise carefully protected system.

Clear contracts, shared standards and ongoing assessments can help reduce these gaps.


Personalization depends on customer trust

Connected vehicles can use data to create more personalized experiences.

A vehicle may adjust settings, suggest routes, optimize energy use or integrate navigation, communication and entertainment preferences.

These features can make driving more convenient. They also raise important questions:

  • What information is collected?

  • Why is it needed?

  • Where is it stored?

  • How long is it retained?

  • Which organizations can access it?

  • Can the customer control or delete it?

  • Is the information used for purposes beyond the original service?

Customers are more likely to accept personalization when they understand how their information is used and feel confident that it is protected.

Privacy should be designed into the experience rather than presented as a long policy after the technology has already been developed.


Charging infrastructure creates another connected ecosystem

Electric vehicle charging adds new relationships among vehicles, charging providers, payment systems, mobile applications, energy networks and location services.

A charging session may involve account information, payment details, vehicle identifiers and usage data.

Each participant must protect both the connection and the information moving through it.

As charging infrastructure grows, organizations will need consistent security standards, reliable identity management and clear responsibility for responding to incidents.

The security of the vehicle cannot be separated from the security of the infrastructure it uses.


What this means for collision repair

Software-defined vehicles change what it means to complete a proper repair.

A collision may affect cameras, sensors, wiring, electronic control units and communication systems. Repairers may need to access OEM procedures, diagnostic platforms, calibration services and connected estimating tools.

Cybersecurity considerations may include:

  • Protecting customer and claim information

  • Securing diagnostic devices

  • Controlling access to repair platforms

  • Verifying software and firmware updates

  • Using approved calibration systems

  • Documenting changes to electronic components

  • Managing third-party integrations

  • Removing unnecessary customer data from local devices

  • Confirming that repaired systems operate as intended

A vehicle may appear physically restored while still having unresolved software, calibration or security concerns.

Repairers need reliable information and secure connections to understand the complete condition of the vehicle.


Collaboration will determine the industry’s resilience

Automotive cybersecurity cannot be managed by manufacturers alone.

Responsibility is shared across:

  • Automakers

  • Software developers

  • Suppliers

  • Insurers

  • Repair facilities

  • Charging providers

  • Technology partners

  • Regulators

  • Vehicle owners

These groups need common standards, clear responsibilities and secure methods for exchanging information.

Collaboration does not mean providing every participant with unrestricted data. It means ensuring that the correct information reaches authorized people and systems at the appropriate time.


Innovation and security must advance together

Connected vehicles, artificial intelligence and software-defined systems can create meaningful improvements in safety, performance and convenience.

Those benefits will depend on the strength of the systems supporting them.

Cybersecurity should not be added after a vehicle, platform or integration has already been developed. It should guide architecture, data collection, access controls, supplier relationships and user experience from the beginning.

The future of automotive technology will be shaped not only by what vehicles can do, but by how safely and responsibly those capabilities are delivered.

bottom of page