Mobility in cybersecurity: between disruption and vulnerability We live in a world where technology has completely redefinedmobility. Not so long ago, cars were purely mechanical machines.Today, they are rolling, hyper-connected, software-driven datacenters, where every decision - from optimal routing to energyconsumption - is managed in real time through thousands of linesof code.Esta revolución tecnológica ha traído consigo una nuevaparadoja:lo que nos hace más eficientes, también nos haceLa This technological revolution has brought with it a new paradox:whatmakes us more efficient also makes us more vulnerable.The connectivity that makes it possible to optimize routes in realtime, improve logistics or make an autonomous vehicle stop in frontof a pedestrian, is the same that opens the door to cyberattackscapable of disabling entire fleets, collapsing transportationnetworks or compromising the safety of passengers andcitizens. The threats are no longer theoretical.We have seen real attackson navigation systems, disruptions in rail infrastructure andcritical vulnerabilities in connected vehicles.And mobility isjust one more piece on a chessboard where cybersecurity hasbecomea weapon of geopolitics, a matter of sovereignty andan unprecedented regulatory challenge. This report is not just a technical analysis, but an invitation torethink mobility security as a strategic pillar.Europe faces thechallenge of consolidating its technological sovereignty in a worldwhere digitalization is inevitable. It is not enough to adapt to globalregulations, we must define our own and ensure that the securityof our mobility does not depend on third parties. The question is no longer whether mobility is a targetfor cyberattacks. The real question is whether we areprepared to anticipate and respond. José Miguel Rosell TejadaCEO and Founding Partner of S2GRUPO Index 1. Executive summary6 2. Introduction8 2.1 Development of a new methodology2.2 Vehicles used2.3 S2GRUPO’s Mobility Laboratory2.3.1 Equipment and capacities2.3.2 Test scenarios and attack surfaces2.3.3 Principal assets2.3.4 Test scenarios9141617181920 3. Proposed measures24 3.1. Migration to more secure protocols and protocol securitizationCAN3.2. Securing electronic control units (ECUs)3.3. Network segmentation3.4. Implementation of a secure and centralized diagnostic mode3.5. Secure and regular updates3.6. Improving physical security protection3.7. Securing vehicle entry vectors3.8. Monitoring and detection of attacks2628293132343537 4. Conclusions39 4.1. Automobile manufacturers and other players in the CEVecosystem4.2. CEV users4.3. Fleet managers4.4. Insurance companies41424243 5. Risk analysis methodology and its stages45 5.1. Identification of the target system (SUC)5.2. Development of a detailed risk analysis5.2.1. Determination of consequences and impacts5.2.2. Threat identification5.2.3. Identification of existing vulnerabilities andcountermeasures5.2.4. Calculation of the probability of the materialization of thethreats5.2.5. Calculation of the probability of the materialization of therisk scenarios5.2.6. Risk calculation5.2.7. Recommendations474848595254575961 6. Applying the Risk Analysis Methodology to the CEV63 6.1. Identification of the target system6.2. Establishment of security objectives and their criticality6.3. Threat identification and probability calculation6.4. Calculation of the probability of materialization of a risk scenario6.5. Risk calculation6569727682 7. How S2GRUPO can help your organization86 Executivesummary1. The Second Report on Cybersecurity in Connected ElectricVehicles (hereinafter CEV) prepared by S2GRUPOis a brutalreality check for the motor industry. Faced with the traditionalrisks associated with driving or owning a car, the technologicalrevolution, the irruption of artificial intelligence as a transversaltool, digitalization and the unstoppable rise of cybercrimeconverge to create a scenario filled with complexities. Whether electric or not, a vehicle contains a multitude ofcomponents that are susceptible to attack. Brakes can beblocked, sensors altered or proximity radars deactivated. Themaximum speed limit is susceptible to manipulation, as are themost intimate data of the car (where it sleeps every night orwhich highway it crosses in real time). The value of the S2GRUPO report lies not only in theidentification and prioritization of these dangers. It alsosuggests solutions that, if implemented, would enable theindustry to reconcile innovation and (cyber)security. Introduction For years now, S2GRUPO has been working on cybersecuritymonitoring and detection of anomalies in the field of electric andconnected vehicles. This explains its participation in the StrategicProject for Economic Recovery and Transformation (PERTE)related to the electric and connected vehicle, financed withNext Generation funds from the European Union. The initiative isbased onthe development of a new technological solution for