Skip to main content

Labs

Automotive Cybersecurity Labs

Theory does not secure a vehicle. Every AutoSec program is anchored in labs built on production-representative ECUs, real buses and the tooling engineers use on the job.

The lab estate

Five Labs, One Continuous Capability Path

Each lab targets a distinct discipline. Together they cover the full lifecycle — from threat analysis through implementation, validation and offensive testing.

  • AutoSec TARA Lab

    Model threats against real vehicle architectures

    Run end-to-end Threat Analysis and Risk Assessment on production-representative E/E architectures. Build item definitions, derive attack paths and defend your risk ratings in review.

    You will practise

    • Define items and assets from a real vehicle architecture
    • Derive attack paths and rate feasibility
    • Produce cybersecurity goals and requirements
    • Defend a TARA in a simulated assessment review
    ISO/SAE 21434
    UNECE R155
    CVSS
    Attack trees
  • AutoSec Secure Development Lab

    Harden ECU software on real hardware

    Implement secure boot, SecOC and hardened diagnostic services on automotive-grade microcontrollers, then prove your controls hold under review and test.

    You will practise

    • Implement secure boot on an automotive microcontroller
    • Integrate an HSM-backed key hierarchy
    AUTOSAR
    HSM
    SecOC
    UDS
  • AutoSec Crypto Lab

    Key management that survives production

    Design and operate automotive key hierarchies — provisioning, rotation, storage and revocation — across the vehicle and the backend that supports it.

    You will practise

    • Design a production key hierarchy
    • Provision keys securely at end of line
    PKI
    AES
    ECC
    HSM
  • AutoSec Red Team Lab

    Attack the vehicle to defend it

    Execute full-scope offensive engagements against real ECUs and vehicle networks — from reconnaissance and bus manipulation to exploitation and reporting.

    You will practise

    • Map the attack surface of a connected vehicle
    • Exploit diagnostic and bus-level weaknesses
    CAN
    Automotive Ethernet
    UDS
    Bluetooth
  • AutoSec Fuzz Testing Lab

    Break protocols before attackers do

    Build and operate fuzzing campaigns against automotive protocol stacks, with instrumentation, triage and defect reporting that fits a validation programme.

    You will practise

    • Design a protocol fuzzing campaign
    • Instrument targets for crash detection
    UDS
    DoIP
    SOME/IP
    CAN

Inside the labs

Objectives, Tooling and Exercises

What you will do in each lab, the tools you will use and the outcomes you should be able to demonstrate afterwards.

AutoSec TARA Lab

Model threats against real vehicle architectures

Lab detail

Run end-to-end Threat Analysis and Risk Assessment on production-representative E/E architectures. Build item definitions, derive attack paths and defend your risk ratings in review.

Objectives

  • Define items and assets from a real vehicle architecture
  • Derive attack paths and rate feasibility
  • Produce cybersecurity goals and requirements
  • Defend a TARA in a simulated assessment review

Exercises

  • Central gateway TARA
    intermediate
    4 hours

    Full assessment of a domain gateway including diagnostic and OTA interfaces.

  • Telematics unit attack paths
    advanced
    3 hours

    Derive and rate attack paths across cellular, Bluetooth and Wi-Fi interfaces.

Tools

  • Threat modelling workbenchanalysis
  • Attack path analyseranalysis
  • Risk rating calculatoranalysis

Technology stack

  • ISO/SAE 21434
  • UNECE R155
  • CVSS
  • Attack trees

Learning outcomes

  • Produce audit-ready TARA documentation
  • Justify risk treatment decisions to assessors

AutoSec Secure Development Lab

Harden ECU software on real hardware

Lab detail

Implement secure boot, SecOC and hardened diagnostic services on automotive-grade microcontrollers, then prove your controls hold under review and test.

Objectives

  • Implement secure boot on an automotive microcontroller
  • Integrate an HSM-backed key hierarchy
  • Apply SecOC to a CAN communication matrix
  • Harden UDS diagnostic access control

Exercises

  • Secure boot chain of trust
    advanced
    5 hours

    Build and verify a signed bootloader with rollback protection.

  • SecOC on a CAN bus
    advanced
    4 hours

    Add authentication and freshness to safety-relevant CAN frames.

Tools

  • Automotive-grade evaluation boardshardware
  • HSM firmware toolchaindevelopment
  • Debugger and trace probehardware

Technology stack

  • AUTOSAR
  • HSM
  • SecOC
  • UDS
  • C

Learning outcomes

  • Ship ECU software with a verifiable chain of trust
  • Integrate cryptographic services without breaking timing budgets

AutoSec Crypto Lab

Key management that survives production

Lab detail

Design and operate automotive key hierarchies — provisioning, rotation, storage and revocation — across the vehicle and the backend that supports it.

Objectives

  • Design a production key hierarchy
  • Provision keys securely at end of line
  • Operate certificate lifecycles for V2X and OTA
  • Analyse cryptographic misuse in real firmware

Exercises

  • End-to-end key hierarchy
    advanced
    4 hours

    Model provisioning, rotation and revocation across supplier and OEM boundaries.

  • Cryptographic misuse hunt
    intermediate
    3 hours

    Identify weak modes, hardcoded keys and entropy failures in ECU firmware.

Tools

  • Key management workbenchcrypto
  • PKI simulation environmentcrypto
  • Firmware crypto analyseranalysis

Technology stack

  • PKI
  • AES
  • ECC
  • HSM
  • TLS

Learning outcomes

  • Specify a key management concept that passes assessment
  • Detect cryptographic weaknesses before they reach production

AutoSec Red Team Lab

Attack the vehicle to defend it

Lab detail

Execute full-scope offensive engagements against real ECUs and vehicle networks — from reconnaissance and bus manipulation to exploitation and reporting.

Objectives

  • Map the attack surface of a connected vehicle
  • Exploit diagnostic and bus-level weaknesses
  • Escalate from a wireless entry point to a safety-relevant domain
  • Report findings in a format engineering can act on

Exercises

  • Diagnostic session takeover
    advanced
    4 hours

    Defeat weak seed-key authentication and reach a privileged UDS session.

  • Wireless entry to CAN pivot
    advanced
    5 hours

    Chain a wireless foothold into control of an in-vehicle network segment.

Tools

  • CAN interface and bus toolinghardware
  • Software-defined radiohardware
  • Exploitation frameworktesting

Technology stack

  • CAN
  • Automotive Ethernet
  • UDS
  • Bluetooth
  • SDR

Learning outcomes

  • Run a structured automotive penetration test end to end
  • Translate offensive findings into engineering remediation

AutoSec Fuzz Testing Lab

Break protocols before attackers do

Lab detail

Build and operate fuzzing campaigns against automotive protocol stacks, with instrumentation, triage and defect reporting that fits a validation programme.

Objectives

  • Design a protocol fuzzing campaign
  • Instrument targets for crash detection
  • Triage and de-duplicate findings
  • Integrate fuzzing into a validation pipeline

Exercises

  • UDS service fuzzing
    intermediate
    3 hours

    Fuzz diagnostic services and triage the resulting faults.

  • Automotive Ethernet stack fuzzing
    advanced
    4 hours

    Campaign against SOME/IP and DoIP handling with coverage feedback.

Tools

  • Protocol fuzzing frameworktesting
  • Target instrumentation harnesstesting
  • Crash triage toolinganalysis

Technology stack

  • UDS
  • DoIP
  • SOME/IP
  • CAN
  • Coverage instrumentation

Learning outcomes

  • Operate a repeatable automotive fuzzing programme
  • Produce evidence that satisfies validation requirements

Capability mapping

Which Labs Build Which Capability Level

Lab time is not optional enrichment — it is how each Capability Framework level is evidenced. This shows exactly which labs support which level.

  1. Level 1
    Awareness

    Cybersecurity Awareness

    Introduce automotive attack surfaces, the regulatory landscape and security-by-design principles to engineers joining a cybersecurity programme.

    What this level covers

    • Threat landscape overview
    • Connected vehicle architecture basics
    • Introduction to ISO 21434 and UNECE regulations
    Programs
    Automotive Cybersecurity Foundations
    Certification
    Foundation
  2. Level 2
    Compliance

    Compliance Practitioner

    Implement and audit compliance frameworks across the automotive product lifecycle, from CSMS establishment through type-approval evidence.

    What this level covers

    • ISO 21434 lifecycle requirements
    • CSMS establishment and audit
    • UNECE R155/R156 type approval
    • AIS 189, 190 and 230 requirements
    Programs
    ISO 21434 and CSMS SpecialistTARA Specialist
    Certification
    Practitioner
    Labs
    AutoSec TARA Lab
  3. Level 3
    Secure Developer

    Secure Developer

    Develop production-grade secure automotive software and embedded systems, with a verifiable chain of trust from boot to communication.

    What this level covers

    • Secure ECU development lifecycle
    • Automotive crypto stack
    • Secure Boot, HSM, SecOC and Secure Flash
    • Hardware security features of automotive microcontrollers
    Programs
    Secure ECU DeveloperSecure Automotive Architect
    Certification
    Professional
    Labs
    AutoSec Secure Development LabAutoSec Crypto Lab
  4. Level 4
    Validation

    Security Validation Specialist

    Validate security controls through systematic testing, threat analysis and architecture assessment that stands up to independent review.

    What this level covers

    • Security validation methodologies
    • Automotive TARA execution
    • Architecture security review
    • Fuzz testing fundamentals
    Programs
    TARA SpecialistAutomotive Fuzz Testing ExpertSecure Automotive Architect
    Certification
    ProfessionalExpert
    Labs
    AutoSec TARA LabAutoSec Fuzz Testing Lab
  5. Level 5
    Offensive

    Offensive Security Expert

    Conduct authorised offensive security assessments on automotive systems, from wireless entry points through to hardware-level exploitation.

    What this level covers

    • Automotive penetration testing
    • CAN and Automotive Ethernet attack vectors
    • Red team operations
    • Hardware-based exploitation
    Programs
    Automotive Penetration Testing ExpertAutomotive Fuzz Testing Expert
    Certification
    Expert
    Labs
    AutoSec Red Team LabAutoSec Fuzz Testing Lab
  6. Level 6
    Leader

    Cybersecurity Leader

    Own automotive cybersecurity strategy, governance and organisational capability, with the technical depth to hold engineering to account.

    What this level covers

    • CSMS governance and KPIs
    • Security organisation design
    • Supplier security management
    • Executive reporting and risk acceptance
    Programs
    Certified Automotive Cybersecurity Expert (CACE)ISO 21434 and CSMS Specialist
    Certification
    Master
    Labs
    AutoSec TARA LabAutoSec Secure Development LabAutoSec Crypto LabAutoSec Red Team LabAutoSec Fuzz Testing Lab

Get Your Engineers on Real Hardware

Lab access is included with every program and can be delivered onsite, remotely or as a hybrid corporate academy.