THREAT BRIEFING · 09.10.2026 DEENFRES

Strategy & Governance

Cybersecurity as a Competitive Advantage in Connected Vehicles

By Tobias Massow · September 29, 2021 · 6 min read

Vehicle connectivity is surging rapidly, driven by the rollout of 5G and other emerging technologies. It’s not just the vehicles themselves that are becoming more connected – drivers and passengers, too, are increasingly integrated into the automotive ecosystem. These innovations elevate the driving experience to a new level – yet they also open another door for cyber threats.

As a result, security is moving firmly into the spotlight for drivers and passengers alike. The swift revolution toward a new era of mobility means cybersecurity will be central to both safety and customer trust. It therefore deserves top priority in any corporate strategy centered on the connected car.

Data Centers on Wheels

The automotive industry is in the midst of a profound transformation. C.A.S.E. – Connected, Autonomous, Shared, and Electrified – is redefining the very concept of the automobile. Cars are evolving into integral parts of our social lives, seamlessly linked to countless services.

Today’s vehicles already pack an astonishing array of technologies. Capabilities continue to expand as demand for connectivity fuels innovation: app-based remote monitoring and control, autonomous driving, advanced driver-assistance systems (ADAS), and in-vehicle entertainment – to name just a few. These new features require massive real-time data transactions. Vehicles are transforming into data centers on wheels – collecting, processing, and exchanging enormous volumes of data with backend systems. This evolution hinges ever more heavily on software and communication protocols, making the entire automotive ecosystem significantly more complex – and thereby offering attackers far more potential entry points. That’s why learning from IT history – and proactively closing these security gaps – is essential.

In the IT world, we’ve learned that the adage “Opportunity makes thieves” holds true here, too – and opportunities abound in connected vehicles. Attackers almost always act out of financial motive. Most often, they target (user) data to extort ransom payments. Connected cars have thus become prime targets for cybercriminals, presenting a wide range of potential attack surfaces:

  1. Classic data theft: Harvesting data collected, generated, or stored by vehicles. Experts predict connected vehicles will soon consume the largest share of 5G network bandwidth – making them the next “data goldmine.”
  2. Vehicle theft via remote deactivation or full takeover of control.
  3. Attacks targeting vehicle network and processor resources – and the vehicle itself.

Growing User Concerns Around Cybersecurity

Hacking attacks on connected vehicles are no longer science fiction – they’re happening now. Real-world incidents already number in the dozens. Hackers exploit numerous attack vectors – not only against the vehicle itself, but also against its supporting networks and backend infrastructure. Here are two documented cases: One hacker stole up to 100 luxury vehicles by compromising a car-sharing app. A second incident involved a major OEM (original equipment manufacturer). A research team successfully hijacked vehicle controls by exploiting a software vulnerability – prompting a recall of millions of vehicles.

Trend Micro demonstrated how ransomware could be delivered directly to a vehicle’s CAN bus via malicious commands. The number of successful attacks rises year after year – making robust cybersecurity non-negotiable.

Wettbewerbsvorteil Cyber Security in vernetzten Autos

A study found that rising demand for safe, efficient, and comfortable driving is the primary driver behind the growing adoption of connected vehicles. Yet the same study reveals a critical shift in consumer priorities: Over 70 percent express concern about vehicle and system security. In short, cybersecurity will soon play a decisive role in brand choice.

Preparing for Change

Threat scenario analysis makes it clear that, from the user’s perspective, cybersecurity is far more than an add-on feature hidden behind flashy innovations like autonomous driving. Instead, it has become a core functionality – one that automakers can leverage to gain a competitive edge. Cybersecurity must therefore move to the center of corporate strategy.

So how can automotive decision-makers implement an effective, efficient cybersecurity strategy? Our analysis shows that the attack chain targeting connected vehicles closely mirrors typical IT cyberattacks. Once attackers breach a system through a vulnerability, they exploit lateral movement across internal networks – just as they do in enterprise IT environments. This is unsurprising: Connected vehicles rely on hardware, software, and communication protocols that closely resemble those used in IT. Given these parallels, we recommend applying proven methods grounded in IT best practices – and informed by forecasts of future threats:

  1. Intelligent threat detection
  2. Multi-layered security
  3. Security spanning the entire ecosystem
  4. Vehicle Security Operations Center (VSOC)

Trend Micro delivers a comprehensive solution built around these principles. Together, we can secure the ever-evolving world of mobility.

Wettbewerbsvorteil Cyber Security in vernetzten Autos

Trend Micro offers a broad portfolio of cybersecurity solutions. (Source: Trend Micro)

Learn more on our website.

We also recommend reading our research paper, “Identifying Key Cybersecurity Focus Areas in Connected Vehicles Based on UN WP.29 Regulation No. 155: Attack Vectors and Related Aspects,” to implement effective measures against the attack vectors outlined in UN R155 – and other identified threats.

 

Key Facts

Dwell time: On average, attackers remain undetected inside corporate networks for 204 days.

SMEs in the crosshairs: 43 percent of all cyberattacks target small and medium-sized enterprises.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What’s the difference between data privacy and data security?

Data privacy governs the lawful handling of personal data – including legal basis, purpose limitation, and data subject rights. Data security encompasses the technical and organizational measures designed to protect all data against loss, tampering, or unauthorized access.

Does every company need a Data Protection Officer (DPO)?

Under German law, appointing a DPO is mandatory if at least 20 people regularly process personal data using automated systems – or if special categories of personal data (e.g., health data) are processed.

What rights do data subjects have under the GDPR?

The right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection. Companies must respond to such requests within one month.

Related Articles

More from the MBF Media Network

Digital ChiefsC-Level Perspectives on IT SecurityMyBusinessFutureBusiness Future: Trends for Decision-Makers

TL;DR

Translated from the German original using artificial intelligence. The German version is authoritative.

Further reading

A magazine by Evernine Media GmbH