Cybersecurity is a significant challenge for automotive manufacturers. This is because today’s systems are very complex, with a mix of hardware, software, bus systems and communication protocols. In addition, the industry relies on a fragmented manufacturer and supplier landscape whose cybersecurity requirements were overlooked. Now, with more connected systems and flexible software, cybersecurity is more important than ever.
Cybersecurity is key for applications like Advanced Driver Assistance Systems (ADAS), Firmware Over the Air (FOTA) updates or Vehicle to Vehicle and Infrastructure (V2X) communication. As a result, standards are under development and regulation is already in place for several applications.
We offer a full set of services to help the automotive industry develop cybersecurity capabilities via training, gap analyses, audits and assessments.

Why choose cybersecurity solutions for automotive from SGS?
We help you:
- Ensure the cybersecurity of your automotive hardware, software and business processes
- Confirm that your solutions meet cybersecurity requirements put in place in proprietary and bilateral specifications, standards and regulations
- Develop the required cybersecurity capabilities
Cybersecurity training for automotive
- Introductory cybersecurity training for automotive manufacturers introducing the most relevant standards, regulations, incidents, best practices and certifications
- ISO/SAE 21434 standard, secure development life cycle for automotive
- Secure design and coding principles, security assessment and testing
- Penetration testing for automotive systems
- Common Criteria for automotive applications and available protection profiles (e.g. V2X)


Cybersecurity audits for automotive
Based on ISO/SAE 21434:
- Organizational and product dependent cybersecurity management
- Distributed and continual cybersecurity activities
- Concept, product development and post-development phases
- Threat analysis, risk assessment methods and own application
Cybersecurity assessments for automotive
- Document review based on argumentation, process descriptions or/and work products (security plan and case)
- Cybersecurity threat analysis and risk assessment
- Security related gap analysis and design reviews
- Customized security assessment and penetration test campaigns for automotive components (ECUs, hardware and software)
- Security capability maturity assessments for organizations and business processes against ISO/SAE 21434
- Pre-testing services in the course of certification activities


Cybersecurity certification for automotive
- Audits/assessments and certification against ISO/SAE 21434
- Common Criteria evaluation and certification (German scheme, Dutch scheme, Spanish scheme, Singaporean scheme, Norwegian scheme, Turkish scheme)
- SESIP security evaluation and certification suitable for automotive internet of things (IoT) devices governed by GlobalPlatform