• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Cross-Divisional Cybersecurity Risk Management in Automotive: Requirements and Current Practices
 
  • Details
  • Full
Options
October 21, 2025
Conference Paper
Title

Cross-Divisional Cybersecurity Risk Management in Automotive: Requirements and Current Practices

Abstract
Collaboration across multiple divisions in the automotive industry, including vehicle engineering, production, and backend services, complicates cybersecurity risk management. While standards such as ISO/SAE 21434, the ISO/IEC 27000 family, and the IEC 62443 series each offer domain-specific guidance, a focused review shows they do not offer a fully integrated, cross-divisional framework. Rather, they present scattered guidance on topics like communication channels, external dependencies, and aligned risk criteria, leaving it to organizations to unify these elements.
To explore how this gap manifests in practice, semi-structured interviews were conducted with six automotive manufacturers, capturing real-world challenges and strategies for cross-divisional cybersecurity risk management. The findings reveal disparate risk assessment methods, inconsistent terminology, and fragmented communication channels among these divisions, which hinder a holistic security posture. Conversely, the results highlight the benefits of coordinated strategies, such as enhanced risk transparency, more efficient resource allocation, and stronger regulatory compliance.
Based on both the standards analysis and interview outcomes, this paper advocates a cohesive framework that harmonizes processes, tools, and language across automotive divisions, ultimately guiding manufacturers toward an overarching, more robust cybersecurity posture.
Author(s)
Wagner, Patrick  orcid-logo
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Mainwork
IEEE 30th International Conference on Emerging Technologies and Factory Automation, ETFA 2025. Proceedings  
Project(s)
Automatisierter Transport zwischen Logistikzentren auf Schnellstraßen im Level 4  
Funder
Bundesministerium für Wirtschaft und Klimaschutz -BMWK-
Conference
International Conference on Emerging Technologies and Factory Automation 2025  
DOI
10.1109/ETFA65518.2025.11205792
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Keyword(s)
  • Cybersecurity

  • Risk Management

  • Standards

  • Expert Interviews

  • Cross-Divisional

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024