Skip to main content

Corporate training

Enterprise Automotive Cybersecurity Capability Development

Regulation moved cybersecurity from a specialism to an organisational requirement. We build measurable capability across engineering teams — assessed against a framework, evidenced against ISO/SAE 21434, UNECE R155/R156 and AIS, and delivered by practitioners who do this work for a living.

Who we work with

Built for the Organisations That Carry the Obligation

Every audience below faces a different version of the same problem. The programme changes; the standard of evidence does not.

  • Vehicle Manufacturers (OEM)

    Whole-vehicle accountability: type approval, a defensible CSMS and supplier assurance across hundreds of ECUs you did not build.

    Typical challenges

    • Evidencing a CSMS that survives type-approval assessment
    • Holding suppliers to cybersecurity interface agreements
    • Cybersecurity capability spread thin across platform teams

    How we address it

    • CSMS readiness programme with audit-ready artefacts
    • TARA capability embedded in platform engineering
    • Capability assessment across the whole engineering organisation
  • Tier-1 Suppliers

    Delivering to multiple OEMs, each with its own cybersecurity interface agreement, evidence expectations and audit cadence.

    Typical challenges

    • Conflicting cybersecurity requirements from different customers
    • Proving secure development practice in customer audits
    • Embedded teams shipping without secure-boot or key-management depth

    How we address it

    • Secure development programme on production-representative hardware
    • Shared evidence model that satisfies multiple OEM interfaces
    • Engineering upskilling mapped to Capability Framework levels
  • Semiconductor Companies

    Silicon security features are only as good as the integration guidance around them — your customers need to use HSMs and secure boot correctly.

    Typical challenges

    • Customers misusing on-chip security features
    • Explaining hardware security capability in ISO 21434 terms
    • Field application engineers outpaced by regulatory questions

    How we address it

    • Crypto and HSM integration curriculum for customer-facing teams
    • Reference security architecture training
    • Customised academy for field application engineers
  • Software Organisations

    Automotive software vendors and platform teams whose code now sits inside a regulated safety-critical product.

    Typical challenges

    • Applying general secure coding practice to automotive constraints
    • Meeting OEM cybersecurity requirements without automotive background
    • Security validation that fits an existing CI pipeline

    How we address it

    • Secure development programme framed for software engineers
    • Fuzz testing and validation integrated into CI
    • Architecture review capability for platform teams
  • Engineering Service Providers

    Consultancies and service providers whose credibility depends on fielding engineers who can hold their own in a client review.

    Typical challenges

    • Bench capability that must be provable to clients
    • Rapid onboarding onto unfamiliar client architectures
    • Differentiating on cybersecurity depth, not headcount

    How we address it

    • Certification pathway that clients recognise
    • Capability assessment to evidence bench strength
    • Customised academy aligned to your client portfolio

Capability framework

A Maturity Model Your Leadership Can Actually Report On

Six levels, from awareness to enterprise leadership. Teams are assessed against them, programmes are sequenced against them, and progress is reported against them — so “we invested in training” becomes a measurable statement.

  1. Level 1
    Awareness

    Cybersecurity Awareness

    Introduce automotive attack surfaces, the regulatory landscape and security-by-design principles to engineers joining a cybersecurity programme.

    Show level detail

    What this level covers

    • Threat landscape overview
    • Connected vehicle architecture basics
    • Introduction to ISO 21434 and UNECE regulations
    Programs
    Automotive Cybersecurity Foundations
    Certification
    Foundation
  2. Level 2
    Compliance

    Compliance Practitioner

    Implement and audit compliance frameworks across the automotive product lifecycle, from CSMS establishment through type-approval evidence.

    Show level detail

    What this level covers

    • ISO 21434 lifecycle requirements
    • CSMS establishment and audit
    • UNECE R155/R156 type approval
    • AIS 189, 190 and 230 requirements
    Programs
    ISO 21434 and CSMS SpecialistTARA Specialist
    Certification
    Practitioner
    Labs
    AutoSec TARA Lab
  3. Level 3
    Secure Developer

    Secure Developer

    Develop production-grade secure automotive software and embedded systems, with a verifiable chain of trust from boot to communication.

    Show level detail

    What this level covers

    • Secure ECU development lifecycle
    • Automotive crypto stack
    • Secure Boot, HSM, SecOC and Secure Flash
    • Hardware security features of automotive microcontrollers
    Programs
    Secure ECU DeveloperSecure Automotive Architect
    Certification
    Professional
    Labs
    AutoSec Secure Development LabAutoSec Crypto Lab
  4. Level 4
    Validation

    Security Validation Specialist

    Validate security controls through systematic testing, threat analysis and architecture assessment that stands up to independent review.

    Show level detail

    What this level covers

    • Security validation methodologies
    • Automotive TARA execution
    • Architecture security review
    • Fuzz testing fundamentals
    Programs
    TARA SpecialistAutomotive Fuzz Testing ExpertSecure Automotive Architect
    Certification
    ProfessionalExpert
    Labs
    AutoSec TARA LabAutoSec Fuzz Testing Lab
  5. Level 5
    Offensive

    Offensive Security Expert

    Conduct authorised offensive security assessments on automotive systems, from wireless entry points through to hardware-level exploitation.

    Show level detail

    What this level covers

    • Automotive penetration testing
    • CAN and Automotive Ethernet attack vectors
    • Red team operations
    • Hardware-based exploitation
    Programs
    Automotive Penetration Testing ExpertAutomotive Fuzz Testing Expert
    Certification
    Expert
    Labs
    AutoSec Red Team LabAutoSec Fuzz Testing Lab
  6. Level 6
    Leader

    Cybersecurity Leader

    Own automotive cybersecurity strategy, governance and organisational capability, with the technical depth to hold engineering to account.

    Show level detail

    What this level covers

    • CSMS governance and KPIs
    • Security organisation design
    • Supplier security management
    • Executive reporting and risk acceptance
    Programs
    Certified Automotive Cybersecurity Expert (CACE)ISO 21434 and CSMS Specialist
    Certification
    Master
    Labs
    AutoSec TARA LabAutoSec Secure Development LabAutoSec Crypto LabAutoSec Red Team LabAutoSec Fuzz Testing Lab

Enterprise offerings

Seven Ways We Engage

From an organisation-wide awareness programme to a multi-year private academy. Most engagements begin with an assessment and combine two or three of these.

  • Awareness Programs

    Organisation-wide cybersecurity literacy for engineering populations who are not security specialists but whose decisions determine whether a platform is defensible.

    What you get

    • Threat landscape briefing framed around your platform
    • Regulatory obligation overview for non-specialists
    • Security-by-design principles for everyday engineering decisions
    • Baseline awareness assessment across teams
    Typical duration
    1–4 weeks
    Audience
    Whole engineering populations, Project managers, Quality and test teams

    Capability Framework levels

    • Awareness
  • Leadership Workshops

    Half-day and full-day sessions that give engineering and product leaders the vocabulary and judgement to govern cybersecurity rather than delegate it.

    What you get

    • Regulatory obligation briefing for your programmes
    • Governance and KPI model
    • Risk acceptance and escalation framework
    Typical duration
    1–2 days
    Audience
    Engineering leadership, Product owners, Programme managers

    Capability Framework levels

    • Compliance
    • Leader
  • CSMS Readiness

    End-to-end preparation for UNECE R155 type approval and the Indian AIS series — process design, artefact templates and a dry-run assessment.

    What you get

    • CSMS structure mapped to ISO/SAE 21434 clauses
    • Audit-ready evidence pack and templates
    • Supplier cybersecurity interface agreement model
    • Mock assessment with findings report
    Typical duration
    6–12 weeks
    Audience
    Compliance managers, Quality engineering, Programme leadership

    Capability Framework levels

    • Compliance
    • Leader
  • Secure Development Programs

    Implementation-depth training for embedded teams: secure boot, HSM-backed key hierarchies, SecOC and diagnostic hardening on real hardware.

    What you get

    • Hands-on lab time on automotive-grade hardware
    • Reference implementations your team keeps
    • Secure coding and review standard for your codebase
    Typical duration
    8 weeks
    Audience
    Embedded engineers, Software architects, Integration teams

    Capability Framework levels

    • Secure Developer
  • Engineering Upskilling

    Broad capability lift across an engineering organisation, sequenced by Capability Framework level so every team moves from a measured baseline.

    What you get

    • Baseline capability assessment per team
    • Level-sequenced curriculum plan
    • Progress reporting against framework levels
    Typical duration
    3–12 months
    Audience
    Whole engineering organisations, Platform teams

    Capability Framework levels

    • Secure Developer
    • Validation
  • Customised Academies

    A private AutoSec academy built around your architecture, toolchain and regulatory exposure, delivered as a standing capability programme.

    What you get

    • Curriculum tailored to your platform and toolchain
    • Dedicated cohorts and delivery calendar
    • Private lab environment
    • Certification pathway for your engineers
    Typical duration
    6–24 months
    Audience
    Large engineering organisations, Multi-site programmes

    Capability Framework levels

    • Validation
    • Offensive
    • Leader
  • Capability Assessments

    An independent, evidence-based read of where your organisation sits on the Capability Framework — and precisely what closes each gap.

    What you get

    • Per-team capability level rating
    • Gap analysis against your regulatory obligations
    • Prioritised development roadmap
    • Re-assessment on completion
    Typical duration
    2–6 weeks
    Audience
    Engineering leadership, HR and L&D, Programme governance

    Capability Framework levels

    • Offensive
    • Leader

Delivery models

Delivered However Your Organisation Actually Works

Distributed teams, confidential platforms and constrained travel budgets are the norm. Every programme can be delivered in the format that fits.

  • Debate-heavy cohorts

    Instructor-led

    Live delivery by a practising automotive security engineer, with discussion grounded in your architecture rather than a generic case study.

  • Confidential platforms

    Onsite

    Delivered at your facility, with lab hardware shipped in. Keeps proprietary architecture discussion inside your perimeter.

  • Distributed teams

    Virtual

    Live remote delivery with individual access to cloud-hosted lab environments and remotely reachable target hardware.

  • Travel-constrained programmes

    Hybrid

    Theory delivered remotely, hands-on blocks run in person. Reduces travel while keeping hardware time uncompromised.

  • Deep capability build

    Lab-based

    Intensive residencies in the AutoSec lab estate — TARA, secure development, crypto, red team and fuzzing on production-representative ECUs.

Outcome measurement

What We Measure, and How

Training is easy to buy and hard to justify. These are the four instruments we use to evidence that capability actually moved — each produces an artefact your leadership can review.

  • Capability Growth

    Movement of individuals and teams up the AutoSec Automotive Cybersecurity Capability Framework™.

    How it is evidenced

    Baseline assessment before the programme, re-assessment on completion, reported as level movement per team.

  • Compliance Readiness

    Ability to evidence ISO/SAE 21434, UNECE R155/R156 and AIS obligations under assessment conditions.

    How it is evidenced

    Artefact completeness review and a mock assessment scored against the same criteria as a type-approval audit.

  • Secure Development Performance

    Whether security controls actually reach production code — secure boot, key handling, SecOC and hardened diagnostics.

    How it is evidenced

    Supervised practical assessment on lab hardware, plus review of controls implemented in your own codebase.

  • Security Validation Capability

    Whether your organisation can independently find its own weaknesses before an external party does.

    How it is evidenced

    Assessed TARA and fuzzing campaign outputs, reviewed by a practitioner panel against defensibility criteria.

Engagement patterns

How These Programmes Run in Practice

Three common shapes an enterprise engagement takes, from first assessment to the capability that remains afterwards.

Representative engagement patterns showing how a programme is structured. They describe our approach, not the results of a specific named customer.

  • Vehicle Manufacturers (OEM)

    OEM approaching type approval

    The situation
    A vehicle manufacturer has a CSMS on paper but no evidence trail, and the first R155 assessment is a platform milestone away.
    Our approach
    Capability assessment across platform teams, then a CSMS Readiness engagement running in parallel with TARA capability build in the engineering organisation.
    What changes
    A CSMS with a complete artefact trail, engineers who can produce and defend a TARA, and a mock assessment completed before the real one.

    Programs involved

    • ISO 21434 and CSMS Specialist
    • TARA Specialist
  • Tier-1 Suppliers

    Tier-1 serving multiple OEMs

    The situation
    A supplier faces divergent cybersecurity interface agreements from three customers, and embedded teams that have never implemented secure boot.
    Our approach
    Secure Development Programs for the embedded organisation, plus a shared evidence model designed to satisfy the strictest of the three interfaces.
    What changes
    One evidence pack that serves every customer audit, and teams shipping a verifiable chain of trust rather than documenting an intention to.

    Programs involved

    • Secure ECU Developer
    • Secure Automotive Architect
  • Semiconductor Companies

    Semiconductor customer enablement

    The situation
    On-chip HSM and secure boot features are being misconfigured by customers, generating support load and undermining the security case.
    Our approach
    A Customised Academy for field application engineers covering crypto integration, key hierarchies and reference security architecture.
    What changes
    Field teams who can lead an integration review, and customer implementations that use silicon security features as designed.

    Programs involved

    • Secure ECU Developer

Common questions

Corporate Training FAQ

The questions procurement and engineering leadership ask before an engagement is scoped.

How does corporate training differ from individual programs?
The curriculum is the same standard, but the engagement is built around your organisation. We start with a capability assessment to establish where each team actually sits on the AutoSec Automotive Cybersecurity Capability Framework™, sequence programs to close the specific gaps that matter for your regulatory exposure, and re-assess on completion so leadership has a defensible before-and-after view. Individual programs are sold by course; corporate engagements are scoped by capability outcome.
Can training be delivered at our facility?
Yes. Onsite delivery brings an instructor and lab hardware to your site, which keeps proprietary architecture discussion inside your perimeter — the usual choice when the training needs to reference your real platform. We also deliver virtually with remotely reachable target hardware, and hybrid, where theory runs remotely and hands-on blocks run in person to reduce travel without compromising hardware time.
How do you measure capability improvement?
Through four instruments: a baseline and post-programme capability assessment reported as level movement per team; an artefact completeness review and mock assessment scored against type-approval criteria; supervised practical assessment on lab hardware plus review of controls in your own codebase; and practitioner-panel review of your TARA and fuzzing outputs against defensibility criteria. Every measure is evidence-based rather than satisfaction-survey based.
Can the curriculum be tailored to our architecture and toolchain?
Yes, and for larger organisations that is the norm. A Customised Academy is built around your E/E architecture, toolchain and regulatory exposure, with dedicated cohorts, a private lab environment and a certification pathway for your engineers. Shorter engagements such as CSMS Readiness or Secure Development Programs are also adapted to your platform, using your own artefacts as working material where confidentiality allows.
Which standards and regulations does the training cover?
ISO/SAE 21434 as the engineering backbone, UNECE R155 and R156 for type approval and software update management, and the Indian AIS 189, 190 and 230 series. Coverage is weighted to the markets you actually ship into, and instructors are practitioners who run type-approval assessments and vehicle penetration tests rather than full-time trainers.

Standards, regulations and delivery model

  • ISO 21434Lifecycle cybersecurity engineering
  • UNECER155 and R156 type approval
  • AISIndian regulatory alignment
  • CSMSManagement system implementation
  • OEM FocusBuilt for vehicle manufacturers
  • Tier-1 FocusSupplier engineering teams
  • Global DeliveryOnsite, remote and hybrid
  • Industry MentorsTaught by practising engineers

Build Capability Your Auditors and Your Engineers Both Respect

Start with a capability assessment. We will tell you where your teams actually sit and what closes the gap — before you commit to a programme.