Automotive and smart mobility cybersecurity
A modern car is online all day. It sends data to the manufacturer, receives software updates over the air and pairs with the driver’s phone. Each of those connections can be attacked, and one flaw can affect every vehicle of that model at once.
Why this is a boardroom issue
For a carmaker or a Tier-1 supplier, a security flaw is a product defect. It can lead to a recall, a delayed type approval or a held export shipment. UNECE Regulation R155 (the UN rule on vehicle cybersecurity) applies in the EU, Japan, South Korea and other markets. Under it, manufacturers must show a working cybersecurity management system before a new vehicle type is approved. Indonesian plants that build for those markets feel the requirement through their export contracts.
Then there is the driver. Connected services store names, home addresses, travel history and payment details. Under Indonesia’s Personal Data Protection Law (UU PDP, Law No. 27 of 2022), a leak of that data must be reported and can bring sanctions.
Where attackers look first
Most practical attacks begin in the cloud services and apps around the car rather than in the car itself.
- The mobile app and backend APIs (the interfaces the app uses to talk to the server). A missing permission check can let one user locate, unlock or start someone else’s car.
- The over-the-air (OTA) update pipeline. Whoever can push or roll back firmware controls the fleet.
- The telematics unit and the in-vehicle network. Once inside, an attacker can forge messages on the CAN bus, the internal network that links the car’s control units.
- EV chargers and their management platform, which usually speak the OCPP protocol. Weak points here allow free charging, payment fraud or chargers switched off remotely.
- Vehicle-to-everything (V2X) messages and keyless entry, where spoofed signals can mislead or open the vehicle.
What Snipeyes does
We run a penetration test (an authorized, controlled attack that finds weaknesses before criminals do) on the parts of your product that carry the most risk. That covers hardware on a test bench, the cloud backend, the APIs and the mobile apps. Before testing, we prepare a threat analysis and risk assessment (TARA) in the form ISO/SAE 21434 asks for. ISO/SAE 21434 is the engineering standard for vehicle cybersecurity, so the results slot straight into your type-approval file.
Bench and vehicle work takes place in environments you agree to. OTA and backend testing runs in staging, and production fleets are left alone.
Suppliers and mobility software companies often need help with daily practice as well. We review code, add security checks to the development pipeline and prepare the ISO/IEC 27001 or SOC 2 evidence that customers and investors ask for.
Notes for the engineering team
Snipeyes is CREST-accredited and ISO/IEC 27001:2022 certified. Web and API testing follows OWASP ASVS, and mobile apps are tested against OWASP MASVS. Findings are mapped to ISO/SAE 21434 work products and the threat categories listed in UNECE R155. A retest after you fix the issues is part of the engagement, and all work is covered by an NDA.
We work with carmakers, Tier-1 suppliers, EV charging networks, fleet software providers and ride-hailing platforms.