Product Security
The integrity of product artefacts, release evidence, software provenance and lifecycle decisions.
What changes in product security
Dealer-installed security hardware can cross the vehicle trust boundary without being governed like an OEM security component.
Read →AnalysisWhy Patching Windchill Is Not EnoughA PLM recovery problem becomes a product-assurance problem.
Read →AnalysisAn IDPS Alert Is Not an Incident Response CapabilityDetection matters only when the organisation can translate it into an owned product decision.
Read →AnalysisEuro 7 Turns Emissions Compliance into a Cybersecurity Evidence ChainWhen regulatory evidence depends on sensors, ECUs, onboard monitoring and off-board data, integrity has to survive the complete chain.
Read →AnalysisWhen Legitimate Engineering Workflows Can Carry Malicious Control LogicIndustrial logic can be malicious even when it was compiled and deployed by the organisation’s own trusted engineering process.
Read →AnalysisThe Connected Vehicle Perimeter Includes Dealer APIsThe Kia research showed how a public identifier and an over-privileged dealer workflow could become an internet-to-vehicle control path.
Read →