Markets Closed
Global Markets
S&P 500 7,457.69 ▼ -1.0% DOW 52,146.42 ▼ -0.8% NASDAQ 25,520.24 ▼ -1.4% RUSSELL 2K 2,962.22 ▼ -0.4% VIX 18.77 ▲ +12.2% GOLD 4,013.7 ▲ +0.0% CRUDE OIL 83.42 ▲ +1.1% EUR/USD 1.14 ▼ -0.1% BTC 64,838 ▲ +0.2% ETH 1,879.59 ▲ +1.1%
Markets

Vehicle software updates draw cyber scrutiny as OTA systems spread

Analysts say wireless vehicle updates can cut service costs but may widen cyber and national security exposure across transport networks.

Sarah Jenkins

By Sarah Jenkins · Chief Macro Economics Correspondent

· 3 min read

Vehicle software updates draw cyber scrutiny as OTA systems spread
Photo: CNBC

Automakers’ growing use of over-the-air software updates is drawing cyber scrutiny from analysts who say the technology can lower maintenance costs while expanding potential attack surfaces in transport systems. The concern centres on vehicles that can receive software, firmware, fixes and data wirelessly, a capability that links operational systems to external communications networks.

Tesla began sending over-the-air updates to Model S vehicles in 2012, a move that helped make the practice more accepted across the sector, according to Jason Van der Schyff, a fellow in cyber, technology and security at the Australian Strategic Policy Institute, who spoke to CNBC.

Siraj Ahmed Shaikh, professor in systems security at Swansea University in the U.K., told CNBC the technology is valued because it lets manufacturers manage vehicle systems faster and at lower cost than traditional approaches, which could involve recalls or scheduled maintenance visits.

The same mechanism creates a security challenge. An OTA system requires a path between a vehicle and the entity sending the update. If that path, the software supply chain or the connected control functions are compromised, analysts say the risk extends beyond data loss to the operation of vehicles and transport infrastructure.

National security concerns

Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC that OTA use in vehicles presents “a unique national security concern.” Lim said that, beyond privacy issues, countries including Norway, Denmark and Britain have expressed worries about the possibility of a foreign actor interfering with the controls of a moving vehicle.

The American Enterprise Institute said in a May report that protecting the automotive sector is important for limiting the espionage capabilities of foreign governments. The institute said the U.S. should consider further security reviews, restrictions on some foreign-made vehicle hardware and software, and stronger requirements for disclosures about data collection.

Those concerns have been sharpened by practical testing in public transport. Late last year, Norwegian bus operator Ruter tested two buses and found potential risks in one of them linked to OTA technology. Ruter said there was access to the control system for the battery and power supply through a mobile network using a Romanian SIM card. “In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer,” the company said.

Ruter’s work prompted further attention in Britain and Denmark. The U.K. Department for Transport said it was looking into the issue and working closely with the National Cyber Security Centre, according to parliamentary evidence cited by CNBC.

The tests involved buses made by Chinese manufacturer Yutong. Shaikh told CNBC the issue should not be viewed as limited to one company or one country, because OTA systems are becoming more common across connected machinery and transport.

Beyond passenger vehicles

Shaikh said other fields adopting OTA technology include maritime and rail transport, aerospace, particularly drones, industrial machinery and robotics. That wider use means the security model for software updates is becoming part of broader infrastructure resilience rather than only a consumer vehicle feature.

Lim said public awareness and accountability are needed as OTA systems run in the background of everyday technologies. For automakers, transport operators and regulators, the question is how to retain the efficiency benefits of remote software management while setting safeguards for systems that can affect physical operations.

This story draws on original reporting from CNBC.

More from Markets

All Markets →