Connected cars: security risks and the driving forces behind a business that already accounts for 40 per cent of a vehicle’s value
Connected cars move and operate in a way that generates a data economy and raises the major issue of cybersecurity: security risks and opportunities for a multi-billion-euro business for consumers and European industry, including Italian and Mediterranean industries
Key points
From purely mechanical objects made up of pistons and a few electronic circuit boards to connected mobility systems based on processors, sensors and cloud-based data exchange – not only for operation but also for production, maintenance and the provision of services: in less than twenty years, cars have become veritable sensors and bidirectional data gateways constantly on the move across the country, which, in turn, map their surroundings using cameras and GPS. As a direct consequence, not only are the business models of those who sell them changing, but also the habits of those who use them – drivers and passengers – and therefore also the cybersecurity and physical security parameters that need to be considered and enforced, with full awareness of what is at stake. It is no coincidence that on 21 August, the manager of Lexus in Australia stated quite openly that the privacy of car data and the way it is processed must be given equal importance to that of physical security. Both the political sphere and the manufacturers’ associations have been taking action for some time, and whilst regulatory responses are being organised, the automotive world has adopted the pace of evolution from the IT sector in the areas of maintenance, fleet management and the sale of services. One example is ‘remote’ vehicle updates (so-called Over-The-Air updates), which, according to industry studies, cost manufacturers a tenth of the price of traditional updates; these are already taking place and are commonplace whilst the car is parked. The same applies to the sale of ‘time-limited’ options: for example, you can purchase matrix LED headlights for a month rather than ‘autonomous driving’ packages. Everything is online and entirely “dematerialised”, from activation to the purchasing process. This extends to innovative forms of customer engagement that blur the lines with advertising or the sale of services: take the case of BMW, which issues press releases not – as one might expect given the brand’s tradition – on driving dynamics or engine specifications, but instead to announce that drivers of the latest models will be able to view a banner for the latest Spider-Man film on the in-car display.
The issue of online safety
A sign of the new era in the automotive industry, but with one common feature that also exposes users to security and privacy risks: at the heart of it all lies the exchange, storage and ‘monetisation’ of data and services that connect customers, car manufacturers, and developers of apps or services accessible via touchscreen or even via one’s own smartphone. Personal devices are increasingly serving as keys for access, control and ignition, enabling remote interaction with the vehicle – for example, to check the battery charge or the interior temperature. These are no longer niche topics or the preserve of tech enthusiasts: already today 9 out of 10 new cars in the US are ‘connected’ from the outset, whilst in Europe, the market for ‘connected’ cars is already worth a total of €26 billion and, according to all automotive analysts’ forecasts, will be a business with double-digit CAGR growth over the coming years: Germany, France and Italia (and the UK too, if we broaden our view to the continent) are the main markets.
Today in Italia (data from the Polimi Connected Vehicle and Mobility Observatory) it is estimated that one in two cars is already connected to the network and over 6 million are fitted with a ‘native SIM’ dedicated to data connectivity, generating a turnover of 3.7 billion. If everything is based on data, and on certain trends such as electrification or regulatory provisions – such as the requirement for new cars to be ‘connected’ – it should also be noted that on-board electronics risk no longer having a single ‘passport’ for production, let alone for control and connectivity.
Cameras, sensors, lidar, GPS modules, and native systems based on Android rather than on ad hoc software may be manufactured in China, Korea rather than the EU, and be fitted to German cars rather than Italian or French ones, depending on the manufacturing plant; and these cars, in turn, will travel without predefined borders, exchanging data with servers and telecoms providers: just think of a latest-generation vehicle that is loaded onto a ship in Genoa and unloaded in Africa, to give just one example.
Traceability of installed hardware and software
The key issue remains cyber security, and there must also be certainty regarding the traceability and production of hardware and lines of computer code, as well as the entire supply chain involved in manufacturing cars, which are increasingly comparable to IT systems. There are critical scenarios that may involve a single incident, but also ‘collective’ scenarios where, via networks and the cloud, many vehicles on the road at the same time could be ‘infected’ in a matter of seconds: the most critical scenarios involve ‘weaponisation’ – that is, cars which, when controlled remotely, can become weapons under the control of malicious actors. It is no coincidence that car manufacturers, IT firms and connectivity providers have been working for some time to manage and minimise these risks, attempting to protect cars in the same way one protects a PC with antivirus software, firewalls and encrypted access systems to data management servers. Data which, for example, manufacturers can use to analyse how a vehicle is used and improve its features. The same applies to insurance companies. There are also potential risks relating to industrial espionage, privacy breaches or security policy violations: this is a hypothetical and rare scenario, but what if the person driving a privately owned or hire car – perhaps in a ‘hostile’ country – were an army officer or government official on holiday with their family, yet were to receive a work-related phone call or email that was relayed via the vehicle’s multimedia systems? Solutions lie in data protection and a regulatory approach; countries are taking a piecemeal approach across various fronts. The geopolitics of the connected car can also impact industrial and financial decisions, as seen in the case of Pirelli’s Cyber Tyre – tyres can be connected and transmit data, particularly premium tyres and those fitted to high-performance cars – and the resulting decision to manufacture in the United States to avoid falling foul of the restrictions of the “Connected Vehicle Rule” which, from model year 2027 onwards (a term used in the automotive world to refer to cars produced from that year onwards), will ban Russian and Chinese software and hardware from being fitted ‘on board’ vehicles. Can we go back to non-connected cars? It’s difficult; drivers – just like users of social media or online services – no longer want to, or are unable to, do without the conveniences and services offered by connectivity. At the same time, cars – much like smartphones – are designed to deliver these services, and manufacturers’ business models have embraced this philosophy, not least from a ‘revenue’ perspective.

