麦肯锡汽车网络安全:应对挑战_36页_2mb
报告摘要
Cybersecurity in Automotive: Summary
Core Content
Cybersecurity is emerging as a critical dimension of quality in the automotive industry, driven by the four ACES disruptions: autonomous driving, connected cars, electric vehicles, and shared mobility. These innovations are fundamentally changing the nature of vehicles, transforming them into data centers and increasing their vulnerability to cyber threats. As a result, cybersecurity is no longer an optional feature but a nonnegotiable requirement for future vehicle type approvals and market access.
Main Trends and Drivers
- Software-driven innovation: Software and E/E components are central to modern vehicle innovation, with the market expected to grow from USD 238 billion in 2020 to USD 469 billion in 2030.
- Increasing code complexity: Modern connected cars have up to 100 million lines of code, with projections reaching 300 million by 2030. This complexity creates more opportunities for cyberattacks.
- Regulatory developments: The UNECE WP.29 regulations on cybersecurity and software updates are set to become a de facto global standard, influencing over 20 million vehicles in the ten largest UNECE member countries.
- Security vulnerabilities: Numerous examples of vulnerabilities in both vehicle systems and their ecosystems have been reported, including access to infotainment systems, CAN buses, and cloud back ends, as well as attacks on charging infrastructure and third-party services.
Key Areas of Cybersecurity Impact
- In-vehicle services: Vulnerabilities in infotainment, telematics, and CAN buses have been demonstrated by researchers.
- OEM back-end services: Security issues in cloud platforms and vehicle data exposure have led to attacks on OEMs and police vehicles.
- Infrastructure and third-party services: Risks include compromised EV chargers, car-sharing apps, and rental car data leaks.
- Enterprise technology: Cloud providers and automotive IT systems have been targets of malware and ransomware attacks.
- Production and maintenance systems: Malware has disrupted production and caused data breaches in manufacturing and supplier networks.
Regulatory Landscape
- UNECE WP.29: This regulation is expected to set a global standard for cybersecurity and software updates, requiring OEMs to demonstrate robust cyber-risk management throughout the vehicle lifecycle.
- ISO/SAE 21434: This standard outlines comprehensive cybersecurity requirements for the entire vehicle lifecycle, from development to after-sales.
- ISO/AWI 24089: A standard for software updates is also under development, expected to include cybersecurity-related content.
Cybersecurity as a New Dimension of Quality
- Security by design: OEMs and suppliers must integrate cybersecurity from the beginning of the development process, ensuring secure hardware and software architectures.
- Continuous monitoring and updates: Security must be maintained throughout the vehicle lifecycle, with the ability to fix issues even years after production.
- Collaboration across the value chain: All players, from OEMs to suppliers and dealerships, need to align on cybersecurity practices and roles to meet regulatory and market demands.
Key Challenges and Opportunities
- New skills and talent: The automotive industry will need to develop new competencies in secure software development, testing, and system integration.
- Risks and costs: Cybersecurity vulnerabilities can lead to significant costs, including dealership visits for software updates and reputational damage.
- Market growth: The cybersecurity market is expected to grow from USD 4.9 billion in 2020 to USD 9.7 billion in 2030, creating new business opportunities for suppliers, IT firms, and start-ups.
- Legal and liability implications: The new standards and regulations will require legal frameworks to address liability in case of cybersecurity-related incidents.
Conclusion
Cybersecurity is becoming a fundamental part of the automotive value chain, influencing everything from development to production and post-sales services. With the introduction of UNECE WP.29 and other standards, the industry is moving towards a more structured and secure approach to vehicle systems. This shift will require new working practices, skills, and collaboration across the entire value chain to ensure that vehicles are secure by design and can be continuously monitored and updated throughout their lifecycle.
试读结束,高清完整版pdf/doc/ppt,请点下载