Automotive Innovation Requires Cybersecurity by Design
- CCi Communications
- Sep 5, 2025
- 6 min read
Updated: 3 days ago

Vehicles are becoming more connected, intelligent and dependent on software.
Functions that were once controlled primarily by mechanical components are increasingly managed through software, sensors, cloud platforms and electronic control systems. Vehicles can receive remote updates, communicate with external infrastructure and personalize features using driver data.
These capabilities can improve safety, efficiency and the customer experience. They also create more digital connections that automotive organizations must secure.
Cybersecurity can no longer be treated as a separate technical issue. It must be considered throughout the vehicle lifecycle, from design and manufacturing to ownership, service and collision repair.
Software is redefining the vehicle
Software-defined vehicles use centralized digital systems to manage a growing share of vehicle functions.
Instead of relying on isolated components with fixed capabilities, these vehicles can integrate information from multiple systems and receive improvements through software updates.
Software may influence:
Driver-assistance features
Infotainment
Navigation
Battery management
Vehicle performance
Energy efficiency
Predictive maintenance
Personalization
Connectivity
Safety monitoring
This creates opportunities for manufacturers to improve vehicles after they have been sold. It also allows different functions to share information and respond more intelligently.
However, greater integration means that a weakness in one system can potentially affect other connected systems. Security must therefore be considered across the complete architecture rather than applied to individual components in isolation.
Every connection expands the potential risk
Connected vehicles communicate with many external systems.
These may include:
Manufacturer cloud platforms
Mobile applications
Charging infrastructure
Dealership systems
Insurance networks
Diagnostic tools
Repair platforms
Fleet management services
Road infrastructure
Third-party technology providers
Each connection can create value, but it can also become a possible point of exposure.
A cyber risk does not need to begin inside the vehicle. It may enter through a web portal, mobile application, supplier system, software integration or connected service.
The automotive industry must understand how information and system access move through this broader ecosystem.
Over-the-air updates require strong protection
Over-the-air updates allow manufacturers to improve vehicle software remotely. They may add features, correct performance issues or address security vulnerabilities without requiring a dealership visit.
This capability can make software maintenance faster and more efficient.
It also creates a critical security responsibility. The vehicle must be able to confirm that an update is legitimate, authorized and unchanged before installation.
A secure update process may require:
Strong encryption
Digital signatures
Authentication
Integrity verification
Controlled access
Secure rollback procedures
Continuous monitoring
Detailed update records
If authenticity checks are weak or encryption is bypassed, a useful connection can become a pathway for malicious software or unauthorized changes.
Artificial intelligence creates opportunity and risk
Artificial intelligence is becoming increasingly important across the automotive industry.
AI can support:
Advanced driver-assistance systems
Predictive maintenance
Automated quality inspection
Driver monitoring
Natural language interfaces
Autonomous functions
Manufacturing optimization
Vehicle diagnostics
Customer personalization
Cybersecurity monitoring
Machine learning can analyze large amounts of information and recognize patterns that would be difficult for human teams to identify manually.
For example, predictive maintenance systems can detect early signs of a developing issue. Security platforms can monitor network activity and identify unusual behaviour. Digital twins can help manufacturers test systems and production processes virtually.
However, AI systems introduce their own risks. Models may be influenced by manipulated information, unauthorized instructions or compromised software. They may also produce unreliable results when the data they receive is incomplete or inaccurate.
AI requires strong governance, ongoing testing and clear human oversight.
Security must exist at every layer
The RSM article emphasizes the importance of building security and privacy into every level of automotive technology.
These levels can include:
The data layer
The vehicle system layer
The connection layer
The authentication layer
The application layer
The cloud layer
The supplier layer
The user access layer
Protecting one layer is not enough.
A secure vehicle can still be affected by a vulnerable cloud account. A protected application can still be exposed through a weak supplier integration. Strong encryption can still be undermined by stolen credentials.
Automotive organizations need defence in depth, which means using multiple safeguards so that the failure of one control does not expose the entire system.
Zero trust offers a useful model
Traditional security models often assume that activity inside an approved network can be trusted.
That assumption becomes difficult to maintain in an automotive ecosystem with connected vehicles, cloud services, suppliers, repairers and mobile users.
A zero trust approach assumes that no person, device or connection should receive automatic trust.
Every request should be verified based on factors such as:
Identity
Device condition
Access permissions
Location
Data sensitivity
Requested action
Previous behaviour
Current risk signals
Access should also be limited to what is required for a specific task.
A parts supplier may need vehicle and component information. A calibration provider may need sensor and repair data. Neither necessarily needs the customer’s complete claim file.
Restricting access helps reduce unnecessary exposure.
Supply chain transparency is essential
Modern vehicles depend on extensive networks of technology and manufacturing partners.
A manufacturer may work with suppliers that provide sensors, software, electronic components, cloud services, diagnostic tools and communication platforms. Those suppliers may also rely on their own subcontractors.
This creates multiple layers of responsibility.
Organizations need to know:
Which companies contribute to a system
What information each partner can access
How software components are maintained
Who is responsible for identifying vulnerabilities
How incidents will be reported
How updates will be distributed
What happens when a vendor relationship ends
Cybersecurity standards must apply throughout the supply chain. One vulnerable partner can introduce risk into an otherwise carefully protected system.
Clear contracts, shared standards and ongoing assessments can help reduce these gaps.
Personalization depends on customer trust
Connected vehicles can use data to create more personalized experiences.
A vehicle may adjust settings, suggest routes, optimize energy use or integrate navigation, communication and entertainment preferences.
These features can make driving more convenient. They also raise important questions:
What information is collected?
Why is it needed?
Where is it stored?
How long is it retained?
Which organizations can access it?
Can the customer control or delete it?
Is the information used for purposes beyond the original service?
Customers are more likely to accept personalization when they understand how their information is used and feel confident that it is protected.
Privacy should be designed into the experience rather than presented as a long policy after the technology has already been developed.
Charging infrastructure creates another connected ecosystem
Electric vehicle charging adds new relationships among vehicles, charging providers, payment systems, mobile applications, energy networks and location services.
A charging session may involve account information, payment details, vehicle identifiers and usage data.
Each participant must protect both the connection and the information moving through it.
As charging infrastructure grows, organizations will need consistent security standards, reliable identity management and clear responsibility for responding to incidents.
The security of the vehicle cannot be separated from the security of the infrastructure it uses.
What this means for collision repair
Software-defined vehicles change what it means to complete a proper repair.
A collision may affect cameras, sensors, wiring, electronic control units and communication systems. Repairers may need to access OEM procedures, diagnostic platforms, calibration services and connected estimating tools.
Cybersecurity considerations may include:
Protecting customer and claim information
Securing diagnostic devices
Controlling access to repair platforms
Verifying software and firmware updates
Using approved calibration systems
Documenting changes to electronic components
Managing third-party integrations
Removing unnecessary customer data from local devices
Confirming that repaired systems operate as intended
A vehicle may appear physically restored while still having unresolved software, calibration or security concerns.
Repairers need reliable information and secure connections to understand the complete condition of the vehicle.
Collaboration will determine the industry’s resilience
Automotive cybersecurity cannot be managed by manufacturers alone.
Responsibility is shared across:
Automakers
Software developers
Suppliers
Insurers
Repair facilities
Charging providers
Technology partners
Regulators
Vehicle owners
These groups need common standards, clear responsibilities and secure methods for exchanging information.
Collaboration does not mean providing every participant with unrestricted data. It means ensuring that the correct information reaches authorized people and systems at the appropriate time.
Innovation and security must advance together
Connected vehicles, artificial intelligence and software-defined systems can create meaningful improvements in safety, performance and convenience.
Those benefits will depend on the strength of the systems supporting them.
Cybersecurity should not be added after a vehicle, platform or integration has already been developed. It should guide architecture, data collection, access controls, supplier relationships and user experience from the beginning.
The future of automotive technology will be shaped not only by what vehicles can do, but by how safely and responsibly those capabilities are delivered.
