The software-defined vehicle (SDV) is set to revolutionise the in-vehicle experience however achieving this means managing sensitive information. Functions like navigation, infotainment and autonomous driving, all generate large amounts of customer data including location, driving habits and personal details. This data is vulnerable to cyberattacks, breaches and misuse.
This week Jaguar Land Rover (JLR) confirmed that data was compromised in the recent cyber attack on the company. The large scale attack which occurred on the 31st August severely disrupted the automaker’s vehicle production and retail operations, triggering factory shutdowns both in the UK and overseas. The attack, which is estimated to have cost the Tata-owned manufacturer around £5m (US$6.8m) in lost revenue each day, underscores the escalating cybersecurity risks confronting global manufacturers.
As connected cars grow in popularity, incidents like this don’t just slow production they also give consumers pause. It makes them question the safety of their personal data in the vehicle and could lead to slower adoption of connected car technologies. Our recent Consumer and OEM Research highlighted that 49% of car users — across the U.S., Germany, Japan and the UK — already worry about being hacked. And recent high-profile data breaches of mobile network operators — such as AT&T in the US and Orange Belgium — have not helped.
For automakers it’s a double edged sword: delivery of safe, personalised user experiences rely on in-depth customer data but failing to protect this information means OEMs face significant risks. Balancing innovation with data privacy and security must be a key priority for OEMs right now.
Delievering robust customer data protection
Connectivity underpins the software-defined vehicle, offering many benefits but also expanding potential attack surfaces (e.g., V2X, cellular). At the same time, however, it also provides faster response to vulnerabilities, enabling quicker security resolutions.
For automakers, safeguarding customer data requires a multi-faceted approach. From embedding security practices and compliance with industry standards to implementing data encryption and delivering over-the air (OTA) updates, connectivity is pivotal to it all.
Integrate security into software development
Security practices should be implemented into software development from the start. This includes threat modelling, secure coding standards, automated vulnerability scanning, code reviews and penetration testing. Frameworks like AUTOSAR (Automotive Open System Architecture) also ensure automakers are creating a resilient software that will stand to them in the future.
Connectivity supports the use of cloud-based cybersecurity tools, such as AI-led threat analytics and automated vulnerability scanning, And as the volume and complexity of software-defined vehicle data grows these tools will scale with it.
Ensure compliance with standards and regulations
Compliance with standards like ISO 26262 (functional safety) and regulations like GDPR, CCPA, and emerging personal data protection laws is critical. Strong data handling practices help to minimise risks and promote transparency.
Connectivity enables real-time data management practices, providing customers with access to their information and managing consent. It also supports the use of Standard Contractual Clauses (SCCs) by enabling the secure, efficient and compliant transfer of personal data across borders.
Implement data encryption and access controls
Strong encryption methods like AES help protect data at rest (stored in vehicles or databases) and in transit (being transferred between vehicle systems and cloud servers).
Connectivity enables secure vehicle-to-everything (V2X) communication, allowing sensitive customer data to move safely between vehicles, cloud servers, and OEM system. This reduces the risk of interception by cybercriminals.
In addition, connectivity centralises data management. Information is held in secure cloud environments, allowing OEMs to apply advanced security measures like multifactor authentication (MFA), role-based access controls (RBAC), data encryption and continuous monitoring. This approach offers better protection against data breaches compared to relying only on in-vehicle storage, which is more difficult to secure and update.
Leveraging over-the-air (OTA) updates
Secure OTA updates are crucial for safeguarding data. They allow OEMs to patch software vulnerabilities, fix security flaws and enhance data protection remotely. This reduces the need for physical recalls.
Seamless connectivity is critical to OTA deployment. By delivering rapid, location-independent updates, emerging threats are managed efficiently and vehicle data security is maintained throughout its lifecycle.
Strengthening supply chain security
It’s not enough for automakers to carefully manage their data privacy, their suppliers must do so also.
Connectivity ensures secure communication channels with suppliers, enabling OEMs to share Software Bills of Materials (SBOMs) and conduct real-time security assessments of third-party components. This allows for early identification and mitigation of vulnerabilities in external software, enabling customer data protection.
Minimising data and enhancing transparency
When it comes to gathering and managing of customer data, the rule of thumb is: only collect essential data, anonymise it where possible and provide opt-in/opt-out options to customers.
Connectivity via connected infotainment systems and mobile apps offer real-time access to privacy settings and data usage details. This helps automakers promote transparency and build trust with their customers.
Real-time threat detection, response and recovery
Connectivity enables real-time monitoring of vehicle systems through cloud-based security solutions like intrusion detection systems (IDS) and security information and event management (SIEM) tools.
This allows OEMs to swiftly detect cybersecurity breaches, isolate affected systems and deploy fixes remotely. Thereby, minimising the risk to customer data. In the event of a breach occurring, connectivity also facilitates communication with customers and authorities, ensuring timely notifications and coordinated recovery efforts.
Driving innovation securely
Secure connectivity allows automakers to safely collect and analyse customer and vehicle data. Compliance with data privacy regulations build customer trust while at the same time OEMs gain valuable insights into how their customer behave — information that is crucial for software-defined vehicle innovation.
OEMs secure management of customer data enables them to deliver personalised, real-time experiences, which, in turn, enhances customer satisfaction and operational efficiency.
How Cubic3 Cloud helps
Cubic3 Cloud simplifies every aspect of connectivity management, maximising the potential of the software-defined vehicle while also giving you peace of mind. Our advanced cloud platform has in-built security, helping you reduce data breach risk, meet evolving regulatory requirements and maintain customer trust.
- Zero-trust security architecture: every access request is verified, ensuring strict control over who can access data and when.
- Data encryption: customer data is encrypted at rest and in transit. This prevents unauthorised access.
- Role-based access control (RBAC): granular permissions ensure users and systems only access data necessary for their function.
- Compliance alignment: our platform is built to comply with global data protection regulations (e.g., GDPR, CCPA) so you meet all legal requirements.
- Audit trails and monitoring: comprehensive logging and real-time monitoring enable detection of anomalies and support forensic investigations.
- Isolation of tenant data: multi-tenant environments isolate automakers’ data, preventing cross-contamination between clients.
- Secure APIs: all API communications are secured and authenticated to prevent interception or misuse.
Learn more about Cubic3 cloud.





