Cybellum
Automotive Vulnerability Management Process Survey
Pages
18
Time to read
15 mins
Publication
Language
English
Pages
18
Time to read
15 mins
Publication
Language
English
This technical report presents findings from an industry survey conducted by Cybellum and ASRG, focusing on the vulnerability management processes within the automotive sector in light of new regulations. The survey assesses the current state of vulnerability management among leading Tier-1 suppliers and OEMs, particularly following the approval of UNECE WP.29 R155. The report outlines the challenges faced by manufacturers, highlighting that many still rely on manual processes which are inadequate for the increasing complexity of connected vehicles. It details the necessity for automation in vulnerability management to comply with emerging regulations and to effectively manage the risks associated with automotive cybersecurity. The findings indicate a lack of standardization in approaches to vulnerability management across the industry, with many respondents reporting that they use multiple data sources and varying techniques for vulnerability identification. The report emphasizes the urgency for the automotive industry to adopt automated solutions to mitigate risks and enhance compliance with cybersecurity standards.