{"id":4840,"date":"2021-12-02T13:10:52","date_gmt":"2021-12-02T10:10:52","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=4840"},"modified":"2022-05-10T15:42:10","modified_gmt":"2022-05-10T12:42:10","slug":"automotive-companies-and-data-security","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/automotive-companies-and-data-security\/","title":{"rendered":"Automotive Companies and Data Security"},"content":{"rendered":"<p>In recent years, connected cars, electric vehicles and automation have been three major driving forces of innovation in the automotive industry. Built on the digitization of in-car systems, these leaps forward by introducing software and connectivity to car IT systems, have opened the door to cyber threats.<\/p>\n<p>The number of annual\u00a0automotive cybersecurity\u00a0incidents have increased by an astounding 605% since 2016, according to Upstream Security\u2019s\u00a0<a href=\"https:\/\/www.prnewswire.com\/il\/news-releases\/upstream-security-releases-2020-automotive-cybersecurity-report-and-announces-first-automotive-threat-intelligence-service-300976874.html\" target=\"_blank\" rel=\"noopener\">2020\u00a0Automotive Cybersecurity\u00a0Report<\/a>. More than half of these\u00a0cyberattacks\u00a0were carried out remotely by\u00a0hackers\u00a0with the aim of disrupting businesses, stealing property, and demanding ransom. Popular attack vectors included keyless entry systems,\u00a0backend\u00a0servers, and mobile\u00a0apps.<\/p>\n<p>Recognizing the need for cybersecurity standards for connected, digitized and\u00a0autonomous vehicles, the World Forum for Harmonization of Vehicle Regulations (WP.29), a working party of the United Nations Economic Commission for Europe (UNECE), issued new regulations to address these growing risks. UN Regulation No. 155 on Cyber Security and Cyber Security\u00a0Management Systems\u00a0is the first international regulation governing\u00a0modern vehicles\u2019 cybersecurity. Under it, among other provisions,\u00a0automakers\u00a0have an obligation to perform\u00a0vehicle\u00a0cybersecurity\u00a0risk\u00a0assessments\u00a0and monitor and report security incidents.<\/p>\n<p>UN Regulation No. 156 on Software Updates and Software Updates Management Systems introduced a series of standards for software updates, including those over-the-air, to mitigate cybersecurity risks. Adopted in June 2020, these two landmark UN vehicle regulations came into force on 22 January 2021 and are applicable in the 54 countries that are parties to the 1958 Agreement.<\/p>\n<h2>Internal Data Security<\/h2>\n<p>However,\u00a0connected vehicles\u00a0are not the only\u00a0vulnerabilities\u00a0the\u00a0auto industry\u00a0faces. They are also big companies with complex IT infrastructures and global\u00a0supply chains. They collect massive amounts of sensitive information from customers, partners and employees and often process payment information on a large scale. Innovation also means the existence of patents and <a href=\"https:\/\/www.endpointprotector.com\/blog\/protecting-intellectual-property-with-data-loss-prevention\/\" target=\"_blank\" rel=\"noopener\">intellectual property<\/a> (IP) whose safeguarding is paramount to an\u00a0automaker\u2019s success.<\/p>\n<p>Personally identifiable information (PII) is protected under data protection laws such as the EU\u2019s\u00a0<a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation<\/a>\u00a0(GDPR) and the\u00a0<a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener\">California Consumer Privacy Act<\/a>\u00a0(CCPA) while the\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/all-you-need-to-know-about-pci-dss-compliance\/\" target=\"_blank\" rel=\"noopener\">Payment Card Industry Data Security Standard<\/a>\u00a0(PCI DSS) enforces the protection of payment systems from breaches, fraud, and theft of cardholder data.<\/p>\n<p>In countries like Germany, carmakers took matters into their own hands: automotive group Verband der Automobilindustrie (VDA) developed an Information Security Assessment (ISA) based mainly on existing international standards ISO\/IEC 27001 and 27002. The VDA then set up the <a href=\"https:\/\/www.endpointprotector.com\/blog\/all-you-need-to-know-about-tisax\/\" target=\"_blank\" rel=\"noopener\">Trusted Information Security Assessment Exchange<\/a>\u00a0(TISAX) to act as an assessment and exchange mechanism through which organizations can submit\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/how-dlp-helps-with-tisax-assessments\" target=\"_blank\" rel=\"noopener\">ISA compliance audits<\/a>.<\/p>\n<p>These laws and standards impose several cybersecurity best practices for vehicle manufacturers and the companies that want to work with them. Noncompliance can mean massive financial penalties when it comes to laws such as GDPR and CCPA, the inability to accept credit or debit card payments in the case of PCI DSS or a loss of business contracts in case of a failure to present a valid TISAX assessment.<\/p>\n<h2>Protecting Sensitive Data<\/h2>\n<p>Automakers can turn to cybersecurity solutions to meet these requirements and protect both personal data and sensitive corporate information. To prevent ransomware and malware attacks, vehicle manufacturers can implement both basic security measures such as the use of firewalls and antimalware solutions, but also more advanced strategies such as the use of\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/tpm-the-new-windows-11-requirement-everybody-is-talking-about\/\" target=\"_blank\" rel=\"noopener\">Trusted Platform\u00a0Module<\/a>\u00a0(TPM) capabilities and the adoption of\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/the-first-steps-towards-zero-trust-security\/\" target=\"_blank\" rel=\"noopener\">Zero Trust<\/a>\u00a0architecture.<\/p>\n<p>However, malicious outsiders are not the only concern. The automotive industry must also be mindful of insiders. Especially when it comes to IP and sensitive business information, car companies are vulnerable to insider data theft and corporate espionage. Removable devices, in particular, have long been a problem vehicle makers have <a href=\"https:\/\/www.endpointprotector.com\/resources\/case-studies\/erich-utsch-ag-germany-en\" target=\"_blank\" rel=\"noopener\">struggled to address<\/a>. Through small devices such as USBs, data can easily be exfiltrated even from computers located in secured environments and offline machines.<\/p>\n<p>A simple way to address this issue is to use <a href=\"https:\/\/www.endpointprotector.com\/solutions\/manufacturing\" target=\"_blank\" rel=\"noopener\">Data Loss Prevention<\/a> (DLP) solutions with <a href=\"https:\/\/www.endpointprotector.com\/blog\/6-standout-endpoint-protector-device-control-features\/\" target=\"_blank\" rel=\"noopener\">device control\u00a0<\/a>modules. Through them,\u00a0automakers\u00a0can monitor, control and block the use of peripheral and USB ports and Bluetooth\u00a0connections. By applying user-based authorization of <a href=\"https:\/\/www.endpointprotector.com\/blog\/how-to-control-usbs-and-removable-devices-with-endpoint-protector\/\">removable devices<\/a>, they can identify which employee has used a removable device at what time.<\/p>\n<p>DLP also helps prevent sensitive data from leaving the company network. Through predefined profiles for regulations such as the GDPR or CCPA or standards such as the PCI DSS, but also for different categories of IP such as patents, blueprints or proprietary algorithms, automotive companies can apply policies at the data level, ensuring that files containing sensitive data cannot be transferred and any attempt to move it will be logged and reported. Through both device control and DLP policies for data transfers, companies in the automotive industry can thus identify potential <a href=\"https:\/\/www.endpointprotector.com\/blog\/what-are-insider-threats-and-how-can-you-tackle-them\/\" target=\"_blank\" rel=\"noopener\">malicious insiders<\/a> attempting to steal data and prevent it in real-time.<\/p>\n<h2>Securing all operating systems<\/h2>\n<p>The\u00a0automotive industry\u00a0often runs multi-operating system networks. Linux is the preferred OS for secured environments and while it is true that it is more resistant to external threats than Windows, it is just as vulnerable to insider threats, whether they come in the form of malicious or careless employees. The same is true of macOS that has recently started gaining more traction in the enterprise.<\/p>\n<p>Automotive companies should therefore search for suitable solutions that offer the same data protection features for Linux and macOS as they do for Windows. While rare, cross-platform solutions like <a href=\"https:\/\/www.endpointprotector.com\/\" target=\"_blank\" rel=\"noopener\">Endpoint Protector<\/a>, which can be applied to all three, do exist. Such tools make company-wide implementation easier and allow admins to control data protection policies for all endpoints from a single interface.<\/p>\n<p>Vehicle manufacturers and all the companies that make up their supply chain, process not only personal and financial information but also sensitive data concerning their prototypes, patents and schematics. Losing them can have a severe impact on a company\u2019s competitive advantage which is why businesses must do all in their power to protect them from both insider and outsider threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In recent years, connected cars, electric vehicles and automation have been three major driving forces of innovation in the automotive industry. Built on the digitization of in-car systems, these leaps forward by introducing software and connectivity to car IT systems, have opened the door to cyber threats. The number of annual\u00a0automotive cybersecurity\u00a0incidents have increased by &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/automotive-companies-and-data-security\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Automotive Companies and Data Security&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":4843,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[174,1],"tags":[],"class_list":["post-4840","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-automotive","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=4840"}],"version-history":[{"count":6,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4840\/revisions"}],"predecessor-version":[{"id":5722,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4840\/revisions\/5722"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/4843"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=4840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=4840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=4840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}