Skip to main content

Eagle

Digital 3D wireframe outline of a software-defined connected car resting on an electronic circuit board, representing automotive cybersecurity and ECU protection.

Modern vehicles are no longer mechanical machines alone. They have become vehicles defined by software with the help of electronic control units (ECUs) and software-defined services. Such features like remote access, navigation, assistance, and over-the-air updates are transforming modern cars into software-defined vehicles and adding smart and connected capabilities to vehicles.

According to Subir Sangal, CEO of Eagle, each new connection provides a new opportunity for hackers to attack the system. They could gain access not only to vehicle data and processes, but also to customer information, fleet management systems, and even compromise safety.

Subir Sangal, CEO of Eagle, emphasizes that securing this modern automotive transition requires a proactive and comprehensive understanding of how software architecture and connectivity reshape traditional vehicular risk profiles.

The Automotive Attack Surface Is Expanding

Within the connected vehicle, there are different systems that work together and interact with other networks as well. There are more possible points to attack within such a system.

Subir Sangal, CEO of Eagle, notes that the first type of attack may include hacking of digital keys and key fobs in order to get access to the car. The second possible way is using vulnerabilities in infotainment or telematics systems for further penetration into the vehicle’s network, such as CAN, which makes communication between different ECUs possible.

The usage of cameras, sensors, and other devices increases the number of vulnerabilities, since those collect and exchange information. Any attack on commercial vehicles or fleets might result in problems with their operation or logistics, meaning the issue is not just about protecting the vehicle but the whole connected vehicle environment as well.

Third-Party Software Can Create Hidden Risks

Nowadays, many manufacturers of cars use tier-1 and tier-2 suppliers and software vendors. As a result, a significant number of different suppliers may participate in the manufacturing process of each single car.

Subir Sangal, CEO of Eagle, explains that such issues as supply chain security appear because the vulnerability of third-party software, media system, or ECU firmware may affect the security of several car models. For this reason, the manufacturer needs to identify all software and components used in his car and conduct proper testing of this product.

This may be done with the help of ISO/SAE 21434 automotive cybersecurity engineering. However, security isn’t only about automakers; suppliers need to present proper security measures as well.

Over The Air (OTA) Updates Are Becoming a Cybersecurity Battlefield

OTA technology makes it possible for auto makers to deliver updates and security fixes remotely via communications technology. It increases the ability to remedy any vulnerabilities after the car is released into the market.

Subir Sangal, CEO of Eagle, points out that this update becomes a security threat in its own right. An attack on the OTA server or interception of the update package through the network can result in the spread of malware in the car’s network.

OTA technology will need stringent security measures in place in order to address such threats. These include code signing, encryption, authentication, and software verification, with frameworks like UN Regulation R156 providing necessary software update management specifications.

Who Protects the Data Generated by Connected Cars?

Connected vehicles generate massive amounts of data which include vehicle locations, driving patterns, vehicle operations, and even data collected via cameras and sensors. Connected data will, of course, increase rapidly and the question that follows this natural progression is, “Who will secure it?”

Subir Sangal, CEO of Eagle, highlights that connected data security is the responsibility of automakers, fleet operators, IT suppliers, insurers, and any other company or entity that handles vehicle data. Compromise in any part of this process could lead to exposure of critical personal and operational information.

The first instance that comes to mind involves telematic data collected by insurance companies to determine drivers’ driving patterns. Such data can easily be breached or tampered with if robust safeguards are absent.

Security Must Follow the Vehicle Throughout Its Life

However, when considering the issue of cybersecurity in relation to automobiles, the matter should not be approached by way of a final test after the manufacture of the car is completed. On the contrary, cybersecurity in relation to the automobile should be considered throughout the whole process of car manufacture and use.

Subir Sangal, CEO of Eagle, concludes that as the trend of software-defined cars continues, there will always be a need for cybersecurity in such an industry. Every part of the manufacturing process will have to observe stringent cybersecurity practices.

Future development of intelligent transportation systems will rely not only on the intelligence that cars of tomorrow will have but also on their safety while operating. The security of software and systems in cars is the security of those who operate them.

Frequently Asked Questions

1. What is a Software-Defined Vehicle (SDV), and why does it need cybersecurity?

A Software-Defined Vehicle (SDV) is a modern car whose features, functions, and operational capabilities are primarily managed, updated, and enhanced through software and electronic control units (ECUs) rather than traditional mechanical systems. Because these vehicles rely heavily on connectivity features like navigation, remote access, and over-the-air (OTA) updates, their digital surface area expands significantly. According to Subir Sangal, CEO of Eagle, each new connection introduces potential vulnerabilities that malicious actors can exploit to access vehicle data, disrupt fleet operations, and compromise physical safety.

2. How do Over-The-Air (OTA) updates impact automotive cybersecurity?

Over-the-air (OTA) update technology allows automakers to remotely deploy software patches, performance upgrades, and security fixes directly to vehicles after they are released to the market. While OTA is essential for lifecycle maintenance, it also introduces a critical cybersecurity vector. Subir Sangal, CEO of Eagle, points out that compromised OTA servers or intercepted update packages can allow malware to infiltrate an entire vehicular network, making strict verification controls like code signing, encryption, and frameworks like UN Regulation R156 mandatory.

3. What is ISO/SAE 21434 in automotive cybersecurity?

ISO/SAE 21434 is the international engineering standard that defines structured frameworks and processes for identifying, assessing, and managing cybersecurity risks throughout a vehicle’s entire lifecycle. The standard covers everything from concept and manufacturing to post-production and decommissioning. As Subir Sangal, CEO of Eagle, highlights, meeting these guidelines helps automotive brands and their multi-tiered supply chains systematically test components, secure ECU firmware, and demonstrate rigorous due diligence.

4. Who is responsible for securing the massive data generated by connected cars?

Securing connected vehicle data is a shared responsibility across the entire automotive ecosystem, including original equipment manufacturers (OEMs), Tier-1 and Tier-2 suppliers, fleet operators, IT vendors, and insurers. Modern connected cars continuously harvest sensitive operational data, including driving patterns, precise geolocations, and telemetry feeds. Subir Sangal, CEO of Eagle, stresses that a security failure at any point in this processing chain can lead to severe breaches of critical personal and operational information.

5. Why must automotive cybersecurity extend beyond the manufacturing stage?

Automotive cybersecurity cannot be treated as a one-time final test completed before a car leaves the factory floor; it must be maintained continuously throughout the vehicle’s operational lifetime. Because software-defined cars remain dynamically connected to external networks long after purchase, risks evolve continuously. Subir Sangal, CEO of Eagle, emphasizes that embedding stringent security practices across every phase of design, production, and active use is vital to safeguarding both intelligent transportation systems and the drivers operating them.