
Photo by Mark Blinch/Reuters
Remote Updates Are Becoming a New Risk Factor
OTA allows manufacturers to remotely install software updates, fix identified vulnerabilities, and add new features without requiring a visit to a service center. Tesla was one of the first to adopt this technology on a large scale, introducing wireless updates for the Model S in 2012. Today, most of the world’s leading automakers use OTA solutions.
Siraj Ahmed Sheikh, a professor of systems security at Swansea University, noted in a comment to CNBC that wireless updates allow for faster resolution of software bugs and reduce the costs of service campaigns and vehicle recalls.
At the same time, according to a number of experts, the widespread adoption of OTA updates creates additional risks of unauthorized access to vehicles’ electronic systems. Gabriel Lim, a senior analyst at the S. Rajaratnam School of International Studies (RSIS) in Singapore, believes that the issue goes beyond the scope of personal data protection and may have implications for national security. According to him, if such systems were compromised, it would theoretically be possible to interfere with the operation of vehicles, which is why authorities in the United Kingdom, Denmark, and Norway are paying close attention to this issue.
In May, the American Enterprise Institute (AEI) also called on U.S. authorities to strengthen cybersecurity in the automotive sector. In a published report, experts recommended considering additional security checks, restrictions on the use of certain foreign hardware and software components in vehicles, and stricter requirements for disclosing information about data collection.
Tests and inspections have drawn the attention of regulators
Tests conducted by the Norwegian public transportation operator Ruter gave the discussion additional momentum. The company reported that one of the electric buses being tested was found to be vulnerable to remote access to its battery management system via a mobile network. According to the company’s assessment, this could theoretically allow a manufacturer to remotely restrict the vehicle’s operation. Following the publication of the results, the UK Department for Transport stated that it is working with the National Cyber Security Center to examine the potential risks of such technologies.
Experts emphasize that the problem is not limited to specific manufacturers or countries. OTA technologies are being actively implemented not only in passenger cars but also in buses, rail and maritime transport, unmanned aerial vehicles, industrial equipment, and robotics. In their view, the further digitization of transportation must be accompanied by uniform requirements for cybersecurity, transparency in data processing, and remote control procedures.























