Skip to main content

Knowledge Center

Automotive Cybersecurity Knowledge Center

Analysis written by the engineers who run type-approval assessments and vehicle penetration tests. Regulation explained without the marketing gloss, and method described precisely enough to apply.

The library

Search the Knowledge Center

Filter by format or topic. Everything here is written for practitioners — no gated summaries of the standard text.

Showing 10 resources

  • Blog
    9 min read

    ISO/SAE 21434 Explained: What It Actually Requires of Engineering

    The standard is often summarised as “do a TARA”. It is considerably more than that — a lifecycle obligation that reaches from concept through decommissioning, and touches every supplier interface along the way.

    • ISO 21434
    • CSMS
    • TARA
    Practitioner Editorial Team
  • Regulation Update
    7 min read

    UNECE R155 and R156: Two Regulations, Two Management Systems

    R155 governs cybersecurity, R156 governs software updates. They are routinely conflated, and the conflation produces management systems that satisfy neither.

    • UNECE R155
    • UNECE R156
    • CSMS
    Compliance Practice
  • Whitepaper
    18 min read

    A Defensible TARA: Method, Evidence and Common Failure Modes

    A practitioner whitepaper on running Threat Analysis and Risk Assessment so the result survives independent review — including the four failure modes we see most often.

    • TARA
    • ISO 21434
    • Risk Assessment
    Practitioner Editorial Team
  • Blog
    11 min read

    Building a Chain of Trust on an Automotive ECU

    Secure boot, HSM-backed key hierarchies and SecOC are individually well documented. Getting them to work together, inside an automotive timing budget, is where teams struggle.

    • Secure ECU Development
    • Secure Boot
    • HSM
    Lab Engineering Team
  • Regulation Update
    6 min read

    AIS 189: Cybersecurity Requirements for the Indian Market

    India’s automotive cybersecurity standard follows the structure established by UNECE R155. Global platform teams should understand where it aligns and where local process obligations differ.

    • AIS 189
    • India
    • CSMS
    Compliance Practice
  • Regulation Update
    6 min read

    AIS 190 and Software Update Management in India

    The Indian counterpart to UNECE R156. If your update process cannot say what software is on a given vehicle, this is the requirement that will expose it.

    • AIS 190
    • India
    • Software Updates
    Compliance Practice
  • Regulation Update
    7 min read

    AIS 230 and the Security of EV Charging Interfaces

    Electrification extends the vehicle attack surface past the vehicle. Charging communication is a genuine trust boundary, and it is now inside regulatory scope.

    • AIS 230
    • EV Charging
    • India
    Practitioner Editorial Team
  • Webinar
    52 min watch

    Webinar: Building an Automotive Security Validation Programme

    A recorded practitioner session on turning ad-hoc security testing into a repeatable validation programme with evidence a type-approval assessor will accept.

    • Security Validation
    • Fuzz Testing
    • ISO 21434
    Lab Engineering Team
  • Blog
    10 min read

    Field Notes: What Actually Breaks in Automotive Penetration Tests

    Patterns from offensive engagements against vehicle systems. The findings are rarely exotic — they are the same handful of implementation gaps, repeated across programmes.

    • Automotive Penetration Testing
    • Red Team
    • CAN
    Offensive Security Practice
  • Case Study
    8 min read

    Engagement Pattern: Taking a Supplier from Ad-Hoc to CSMS-Ready

    A representative account of how a CSMS readiness engagement runs — the sequence, the artefacts produced and where the effort actually concentrates.

    • CSMS
    • ISO 21434
    • UNECE R155
    Compliance Practice

Stay current

Regulation Moves. So Should Your Reading.

New analysis, regulatory updates and lab research, sent when there is something worth saying.

Threat intelligence, straight to your inbox

Regulatory updates, lab research and new program announcements. No noise.

What should we send you?

Learn From the Practitioners Who Write This

Everything in the Knowledge Center comes out of the same work that shapes our programs — type-approval assessments, secure development and offensive testing on real vehicles.