For a long time, the automotive industry has remained on the sidelines in cybersecurity discussions, with industry professionals and policymakers often focusing on sectors traditionally more threatened. However, while these industries have built solid defense systems, the automotive industry still lacks protection, leaving manufacturers and their customers exposed to increasingly fierce cyberattacks.

Today, vehicles are more connected than ever, and the number of exploitable features for hackers continues to grow. We have already seen hackers achieve remote access by interfering with remote key fobs or manipulating vehicle functions such as steering and acceleration. More concerning, malicious actors can manipulate driver-assistance features like proximity sensors, directly endangering driver safety.

In 2025, manufacturers may find themselves at the center of the next wave of large-scale cyberattacks—unless they double down on investing in cybersecurity talent. Manufacturers must strive to recruit and retain cybersecurity professionals, build robust internal cybersecurity strategies, and implement aftermarket features for threat monitoring and response.

Talent is the core of every company, so the first line of defense for vehicle manufacturers must be their employees. This means recruiting and retaining professionals with proven experience capable of managing cybersecurity threats.

Industries such as healthcare, government, and finance—those most frequently targeted by cyberattacks—are a treasure trove of cybersecurity talent. They have hired top industry experts to build cybersecurity strategies. It would be a misstep for manufacturers not to recruit directly from these industries.

Cyberattacks in healthcare and finance primarily target consumers, and so does the automotive industry. Cybersecurity professionals from these industries will have experience dealing with the cyber threat landscape and will be adept at handling any attacks targeting customers' own vehicles.

Recruiting top cybersecurity talent is a prerequisite for a successful cybersecurity strategy. Manufacturers must adopt competitive hiring practices—this means doubling down on recruitment and talent retention. To attract top talent away from existing employers, manufacturers must be prepared to offer competitive salaries and industry-best benefits.

However, recruitment is only part of the challenge; manufacturers must demonstrate that they value employees' career development to retain them. Providing ongoing training and upskilling, as well as clear career progression paths, is essential for retaining top talent.

In addition to bringing in new talent, manufacturers must ensure that all employees receive cybersecurity training. They must be trained to identify cybersecurity risks during the design and engineering phases, mitigating threats before vehicles enter the production line.

Having a top-tier internal cybersecurity team is key to achieving cross-departmental upskilling; they are crucial for ensuring that training aligns with company requirements.

Then, after establishing an internal cybersecurity team, manufacturers must develop a robust and well-informed cybersecurity strategy, including measures to identify, manage, and respond to threats. Given the potential scale, scope, and complexity of cyberattacks targeting user-operated vehicles, partnering with cybersecurity agencies is the way to ensure timely and effective incident response.

Public-private partnerships are common in cybersecurity and are a path the automotive industry must take. Various regions have different public agencies, such as the Automotive Information Sharing and Analysis Center in the United States and the European Union Agency for Cybersecurity. Manufacturers can localize their cybersecurity response by ensuring that each subsidiary manufacturing plant partners with local agencies.

This is a reliable way for manufacturers to strengthen their cybersecurity approach, and it allows for intelligence sharing, joint incident response, and more efficient, timely threat detection—all of which are crucial in the rapidly evolving field of cybersecurity.

Cybersecurity vulnerabilities in the automotive industry do not disappear once vehicles hit the market.

Manufacturers must implement robust procedures for continuous, proactive threat detection—ensuring driver safety once vehicles are on the road. As hackers increasingly attempt to exploit connected vehicle features, this is an area manufacturers need to watch closely.

With the relevant cybersecurity talent, manufacturers can develop and implement effective threat responses. Whether it is the ability to roll back software or develop consumer-facing applications to directly communicate threats with vehicle owners, manufacturers must ensure they can act swiftly to minimize the risk of harm.

Combining the work of internal cybersecurity teams with partnerships with cybersecurity agencies, vehicle manufacturers can design and implement customer-facing software that enables real-time threat detection, self-reporting, and guidance.

Manufacturers must begin to eliminate weaknesses in their cybersecurity strategies by bringing in new talent, working closely with national cybersecurity organizations, and adopting a proactive, customer-first approach to aftermarket threat detection. The industry's long-term development and customer safety depend on it.

About the Author

Michael Marcotte
Co-founder of the National Cybersecurity Center (NCC) in the United States, and founder, chairman, and CEO of artius.iD.

Michael Marcotte is a co-founder of the National Cybersecurity Center (NCC) in the United States and the founder, chairman, and CEO of artius.iD. He joined the EchoStar family of companies in 2006, serving as Global Chief Information Officer, Global Chief Digital Officer, and President (Hughes Cloud Services). Nasdaq-listed EchoStar is one of the world's largest satellite communications and internet services companies, operating a fleet of geostationary communications satellites.