Cyber risk in automotives
Co-authored by Munich Re
Connected and software-defined vehicles are fundamentally changing the automotive cybersecurity landscape. As vehicles increasingly rely on cloud platforms, software suppliers, over-the-air updates and connected services, cyber risks extend far beyond the vehicle itself. Incidents can now originate anywhere within the digital ecosystem, resulting in vehicle immobilisation, service disruption, data breaches, liability exposure and significant financial losses – even when the vehicle itself has not been directly compromised.
At the same time, evolving regulations such as UN R155/R156, ISO/SAE 21434, the Cyber Resilience Act (CRA) and the revised Product Liability Directive (PLD) are increasing cybersecurity requirements throughout the vehicle lifecycle. However, regulatory compliance alone cannot eliminate cyber risk. Residual risks remain due to software complexity, interconnected ecosystems and continuously evolving cyber threats.
This joint white paper from TÜV SÜD and Munich Re explores how organisations can move beyond a compliance-driven approach towards integrated cyber risk management. It demonstrates how technical cybersecurity assessments, structured risk ratings and financial risk transfer can be combined to improve resilience, support informed business decisions and enable the insurability of connected vehicle cyber risks.
Why download the white paper?
- Learn how connected vehicle ecosystems are transforming cybersecurity into a business-critical risk management challenge.
- Understand the impact of emerging regulations such as UN R155/R156, ISO/SAE 21434, the Cyber Resilience Act (CRA) and the revised Product Liability Directive (PLD).
- Gain insights into the technical, operational, legal and financial consequences of cyber incidents across the connected vehicle ecosystem.
- Discover how residual cyber risks can be assessed, rated and translated into measurable business and insurance risks.
- Explore a practical framework developed by TÜV SÜD and Munich Re that links cybersecurity maturity with financial resilience and risk transfer.
- Find out how OEMs, suppliers and ecosystem partners can strengthen cyber resilience while improving transparency and decision-making.
