2018年-普华永道全球_Automotive_companies_and_cyber_attacks_PwC_12页_1mb
报告摘要
Cyber Readiness: Are Auto Companies Prepared to Counter the Risk of an Attack?
Core Content
The automotive industry is at a critical inflection point as vehicles become increasingly connected to the internet. This transformation brings significant convenience but also substantial cybersecurity risks. Connected cars are vulnerable to remote attacks that can compromise both privacy and safety, and the threat is expected to grow with the increasing adoption of autonomous vehicles.
Main Cyber Risks
- Remote Attack Vulnerabilities: Connected car components such as telematics units, infotainment systems, and engine control units (ECUs) can be hacked, allowing attackers to control critical functions like steering, braking, and engine operations.
- Consumer Privacy Concerns: In-car networks collect sensitive data including location, speed, and driving behavior. As cars become more connected, the amount of data captured increases, raising privacy risks.
- Enterprise Cyber Risks: Connected vehicles are not only a risk to individual consumers but also to the entire enterprise. Cyber threats can spread across production platforms, internal operations, and supply chains, potentially leading to financial loss, reputational damage, and intellectual property theft.
Key Entry Points for Cyber Threats
- Factory Machines: Often designed for continuous operation, these systems are rarely updated and pose a risk when connected to the internet.
- 3D Printing: Uses digital files that can be stolen, introducing new vulnerabilities in the manufacturing process.
- Auto Finance Arms: Collect large amounts of customer data, making them attractive targets for data theft.
- Supply Chains: Third-party vendors, especially smaller ones, may lack robust security controls, increasing the risk of breaches.
Main Views and Recommendations
1. Proactive Cybersecurity Integration
- Automakers should treat cybersecurity as a business issue, not just a technological one.
- Security must be embedded in the product design from the beginning, as it is not feasible to add security measures after production.
- A holistic, layered approach to security is necessary, combining prevention, detection, and response mechanisms.
2. Quality Management and Testing
- A reactive approach to fixing vulnerabilities is costly and ineffective.
- Early and continuous testing during the product development lifecycle is essential to identify and mitigate risks.
- Retesting after fixes ensures that no new vulnerabilities are introduced.
3. Supply Chain Security
- Collaboration with suppliers is crucial to ensure security across the entire supply chain.
- Contracts should include audit clauses and mandatory testing procedures, especially for smaller vendors.
- Transparency and communication with vendors are necessary to maintain security standards.
4. Information Sharing and Collaboration
- The Auto-ISAC provides best practices and threat intelligence to help the industry prepare for and respond to cyber risks.
- Collaboration with the DHS and other federal agencies can enhance the industry's ability to detect and respond to threats.
- Threat intelligence services can help identify and prioritize emerging threats.
5. Organizational and Cultural Change
- C-level executives and boards must be engaged in cybersecurity initiatives to foster a strong security culture.
- Security awareness training for all employees is essential to prevent incidents like phishing attacks.
- Incident response simulations and structured lessons-learned processes help organizations improve their readiness and response capabilities.
6. Investment in Tools and Technology
- Advanced security tools and cloud-based services are needed to combat evolving threats.
- Customized technology solutions should be deployed to meet specific organizational needs.
- Real-time updates and dynamic threat monitoring are important for maintaining up-to-date defenses.
Conclusion
The automotive industry must adopt a proactive, integrated, and holistic approach to cybersecurity to address the growing risks associated with connected and autonomous vehicles. By embedding security into the design process, enhancing supply chain oversight, promoting information sharing, and investing in advanced tools, automakers can reduce the likelihood of cyber incidents and mitigate their impact. Cybersecurity is not just a technical challenge—it is a strategic imperative that requires leadership, culture, and continuous improvement.
试读结束,高清完整版pdf/doc/ppt,请点下载