ALL INSIGHTS
Thought leadership

Software-Defined Vehicles: The Promise and the Emerging Cyber Threats

AutoMobility Advisors, Chip Goetzinger
June 27, 2023
CybersecuritySoftware-Defined Vehicle

Chip Goetzinger joins Upstream Security's H1'2023 Automotive Cyber Trend Report webinar to unpack how software-defined vehicles expand the automotive attack surface — and what OEMs and suppliers should do about it. ~700 registrations, ~200 live attendees.

Software-Defined Vehicles: The Promise and the Emerging Cyber Threats

Software-defined vehicles moved the value of a car into code — and moved the risk with it. In this Upstream Security webinar built around the H1'2023 Automotive Cyber Trend Report, Shachar Azriel (VP of Data, Upstream Security) and Chip Goetzinger (Solutions Director, AutoMobility Advisors) walked through what the incident data actually shows and what it means for product, engineering, and security teams.

The session aired Tuesday, June 27 at 11am ET / 5pm CET and drew roughly 700 registrations with about 200 live attendees.

Why software-defined vehicles widen the attack surface

Every capability that makes an SDV attractive also creates a new way in. Over-the-air update pipelines reach the whole fleet at once. Cloud APIs sit between the vehicle, the mobile app, and the back office. Telematics units, infotainment stacks, EV charging sessions, and dealer and supplier systems all touch vehicle data or vehicle commands. The perimeter is no longer the vehicle — it is the entire connected ecosystem around it.

The report's core finding is a shift in attacker economics: incidents are increasingly remote and scalable rather than physical and one-off. A single weak API or exposed credential can affect thousands of vehicles, and a growing share of activity targets the back-end services and third-party applications feeding the vehicle rather than the ECU itself. Attackers follow the same logic OEMs do — they go where scale is.

The practical takeaways were consistent: build security into the development lifecycle instead of testing for it at the end; stand up real Vehicle Security Operations Center monitoring so anomalies in fleet data are detected in hours rather than quarters; treat APIs and cloud services as in-scope vehicle assets; and align program plans with UNECE R155/R156 and ISO/SAE 21434 so compliance falls out of the process rather than becoming a separate project.

AMA works with OEMs, suppliers, and technology providers on exactly this seam — connected vehicle architecture, data strategy, and the go-to-market and partner decisions that follow. See our consulting services or get in touch to talk through where your SDV program sits today.

Continue reading

More from the AMA team on the topics in this piece.

All news & insights
Book a call

Talk to us about what you want to accomplish

Schedule 20-minutes with AMA. We will use the time to understand what you are trying to accomplish and how AMA can help.

George Ayres, Denise Barfuss, Chip Goetzinger, and Allen Levenson of AutoMobility Advisors at MOVE America.