Skip to content
BritonOne Technology
CybersecurityAutomotive

Threat modelling a connected vehicle

Mapped and mitigated attack paths for a UNECE R155-regulated connected vehicle.

R155
STRIDEISO 21434UNECE R155Threat modelling
Threat modelling a connected vehicle
IndustryAutomotive
DisciplineThreat Modelling
CountryGermany
Headline resultR155
The story

Problem, approach, and the outcome

About the client

The client is a German carmaker developing a connected vehicle whose attack surface spans the car, its app, and the cloud. Here, security flaws carry safety risk, and under UNECE R155 demonstrable cybersecurity engineering is a condition of type approval.

They needed to find and address design-level risks before they were welded into production hardware.

The challenge

A connected vehicle exposed a wide attack surface across the car, its companion app, and the cloud backend. The threats spanned three very different domains that had to be reasoned about together.

Here, flaws carried safety risk, not just data risk, and under UNECE R155, demonstrable cybersecurity engineering is a condition of type approval. The consequences reached from data into physical safety and market access.

The manufacturer needed to find and address design-level risks before they were welded into production hardware. Once in hardware, fixes become enormously more expensive.

Our approach

We threat-modelled the vehicle, app, and cloud as one connected system against ISO 21434, rather than assessing each in isolation. Modelling the whole system is what surfaces the cross-domain attack paths.

Attack paths were prioritised by anything that could affect safety, so the most consequential risks led the remediation. Safety-first prioritisation is what a regulated automotive programme demands.

We worked with the engineering teams to turn findings into concrete design changes and mitigations, and structured the evidence to align with UNECE R155, supporting the type-approval case directly. Security work fed straight into approval.

Results
  • Attack paths mapped across vehicle, app, and cloud
  • Safety-critical risks prioritised
  • Findings driven into concrete design changes
  • Evidence aligned to UNECE R155 for type approval
Next step

Get a senior architect on the call, first time, every time.

No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.