Organizing an event like Secure Our Streets, which showcases the latest advances in cybersecurity, is truly a collective effort.
Organizing an event like Secure Our Streets, which highlights the forefront of cybersecurity in the evolving mobility landscape, is truly a team effort.
As a not-for-profit, ASRG relies on the dedication of our volunteers—professionals across cybersecurity, marketing, and business development, many balancing demanding roles in leading companies worldwide. Despite their busy schedules, they’ve devoted countless hours to making this event a reality, united by a shared commitment to advancing security in our increasingly connected mobility ecosystem.
We extend our deepest gratitude to each of them. Without their dedication, SOS 2025 would not have been possible.
We look forward to welcoming you again next year!
Secure Our Streets 2025
This presentation explores the evolution of product cybersecurity requirements in the automotive industry, highlighting the influence of emerging regulations such as UN ECE R.155 and standards like ISO/SAE 21434 on the cybersecurity landscape.
It also addresses the complexities and challenges arising from contractual obligations across the automotive value chain and offers practical recommendations for reducing this complexity through better alignment between regulatory, technical, and commercial requirements.
Dr. Mathias Dehm is the Chief Product Security & Privacy Officer at AUMOVIO, one of the leading Tier-1 suppliers in the automotive industry. With over 14 years of experience in cybersecurity and privacy, he has held various leadership roles and built a strong track record across multiple sectors, including logistics, telecommunications, medical technology, defense, automotive, and startups.
Dr. Dehm holds a Ph.D. from Munster Technological University in Cork, Ireland, and brings a multidisciplinary perspective to product security, combining deep technical expertise with strategic business insight.
Asymmetric cryptography is now in widespread use, but algorithms that are secure today will be broken by the quantum computers of tomorrow. Most of todays and upcoming automotive security measures (e. g. ECU integrity protection, secure onboard communication, V2X, access control etc.) rely on classical cryptography that will be vulnerable. Although a breakthrough in quantum computing might be years away, companies need to prepare for the smooth transition to quantum-secure systems. Finding suitable post-quantum algorithms and migrating to quantum-secure systems can pose many challenges. This presentation aims to facilitate the understanding of challenges in the migration to post-quantum cryptography and describe viable solutions based on existing research. First, post-quantum algorithms and their impact on functions and protocols are analyzed under consideration of ongoing standardization processes and migration research projects. After that, the considerable differences between algorithms based on practical examples and benchmarks on common automotive hardware targets, e.g., Aurix TC375, are described. In the practical examples we focus on the lattice-based algorithms Falcon and Dilithium and briefly point out differences from other mathematical primitives. Furthermore, practical solutions for migration of Public Key Infrastructures (PKIs) are illustrated and respective advantages and disadvantages are discussed. The various categories of crypto agility are presented to highlight the wide scope of methods in this field. At the end, a general strategy for migration is proposed that considers the general uncertainty about the quantum threat by planning ahead and increases the trust in novel post-quantum algorithms by the implementation of suitable solutions.
Dennis Naujoks is a cybersecurity consultant specializing in automotive security at ETAS. He holds a Bachelor’s and Master’s degree in IT-Security from Ruhr-University Bochum, where he developed a strong foundation in applied cryptography and embedded systems. During his Master’s thesis at TÜV IT, Dennis focused on post-quantum cryptography and side-channel analysis—key areas in securing next-generation embedded platforms. Since 2022, he has worked at the intersection of automotive systems and cybersecurity, helping clients navigate complex security challenges in connected and software-defined vehicles.
The rapid integration of connected technologies in modern vehicles has introduced significant cybersecurity challenges, particularly in securing critical systems against advanced threats such as IP spoofing and rule manipulation. This study investigates the application of CHERI (Capability Hardware Enhanced RISC Instructions) to enhance the security of Intrusion Detection Systems (IDSs) in automotive networks. By leveraging CHERI’s fine-grained memory protection and capability-based access control, the IDS ensures the robust protection of rule configurations against unauthorised access and manipulation. Experimental results demonstrate a 100% detection rate for spoofed IP packets and unauthorised rule modification attempts. The CHERI-enabled IDS framework achieves latency well within the acceptable limits defined by automotive standards for real-time applications, ensuring it remains suitable for safety-critical operations. The implementation on the ARM Morello board highlights CHERI’s practical applicability and low-latency performance in real-world automotive scenarios. This research underscores the potential of hardware-enforced memory safety in mitigating complex cyber threats and provides a scalable solution for securing increasingly connected and autonomous vehicles. Future work will focus on optimising CHERI for resource-constrained environments and expanding its applications to broader automotive security use cases.
Saket Mohan is the Founder and CEO of Secure Elements, a recognized leader in automotive cybersecurity. With over 15 years of experience in automotive telematics, connected cars, and cybersecurity, Saket has been instrumental in enhancing the cyber resilience of complex automotive systems. He has contributed to high-profile cybersecurity projects at leading organizations such as Jaguar Land Rover, ClearMotion, EDAG Engineering, and the Transport Research Laboratory. His passion for automotive cybersecurity led to the founding of Secure Elements, where he now leads a skilled team in developing innovative embedded cybersecurity software solutions that ensure the safety and security of software defined vehicles (SDV’s)
Sampath Kalutharage is currently a Cybersecurity and AI Lead Engineer at Secure Elements. He is also a post-doctoral researcher at Lancaster University, specializing in embedded cybersecurity. With expertise in machine learning and Generative AI, Sampath has a solid foundation in the research and development of IoT cyber-critical systems. His career began as a Network Operations Centre Engineer, followed by various roles across network and cybersecurity sectors, including Zonal Technical Manager at NMI Infra and a significant tenure at Airtel. His passion for advancing cybersecurity knowledge led him to transition into academia. Sampath actively contributes to the cybersecurity community, regularly presenting at prestigious events and playing a crucial role in shaping the future of cybersecurity in automotive and critical systems.
Five years ago, we presented “Automotive Penetration Testing with Scapy” at TROOPERS19—a talk that quickly became one of the most-watched sessions on the TROOPERS YouTube channel. In the intervening years, the automotive domain has evolved significantly, particularly in the realm of **Automotive Ethernet** (e.g., 100/1000BASE-T1). Modern vehicles now rely heavily on protocols like **Diagnostics over IP (DoIP)**, **SOME/IP**, and **AUTOSAR PDUs**, combined with sophisticated security approaches and **Over-the-Air (OTA)** update mechanisms. In this fresh deep dive, we revisit the automotive Ethernet security landscape, illustrating how **Scapy** has adapted to accommodate these emerging protocols and testing scenarios. We will demonstrate advanced techniques, including restbus simulations for SOME/IP, emulating malicious OTA update servers, and exploring cutting-edge features in UDS—such as authentication services—all through carefully crafted packet injection and analysis.
Dr. Weiß delved into penetration testing during his Bachelor’s and Master’s, exploring vulnerabilities in embedded systems and entire vehicles. Active in developing open-source penetration test frameworks like Scapy, he co-founded dissecto GmbH in 2022, focusing on simplifying security diagnostics and solutions for embedded systems.
Jonas Horreis is a penetration tester at dissecto with a focus on automotive security. He started by automating ECU security tests for his bachelor’s thesis, expanded into securing EV-charging infrastructure and electric-vehicle architectures during his master’s research, and later investigated advanced fuzzing techniques as a university research assistant. Now he applies this knowledge to secure the ECUs of the future.
This study examines the automation of converting Threat Analysis and Risk Assessment (TARA) data into the openXSAM format within the automotive industry, addressing the growing need for cybersecurity in modern, interconnected vehicles. By leveraging both qualitative and quantitative research methods, the study identifies challenges in data standardization, evaluates current practices, and explores the potential of automation to streamline processes and enhance compliance with ISO/SAE 21434 and UNECE Regulation No. 155. The findings demonstrate that automated data conversion could significantly improve efficiency, data integrity, and interoperability across the automotive supply chain, thereby supporting industry-wide cybersecurity objectives. This research offers valuable insights for automotive engineers, cybersecurity professionals, and policymakers, emphasizing the need for robust tools and collaborative efforts to standardize and automate TARA data processes.
Brazilian professional with over 35 years of experience at ZF Group. Master’s degree in Computer Science with Cybersecurity from Wrexham Glyndwr University (UK), MBA in Strategic Business Management (Brazil), and BS in Mechanical Engineering (Brazil). Responsible for the Cybersecurity Engineering Service at ZF Engineering Solutions in the UK, delivering services for internal and external customer, including fuzz and pen testing.
This presentation explores the complexities and best practices in vulnerability management within the automotive software supply chain, with a focus on the challenges in complex software, including open-source components, third-party libraries, and proprietary software. The most important topics are the SBOM generation process, the difference between source code and binary code analysis, and the difficulties in identifying and mitigating vulnerabilities. In addition, we consider the role of Vulnerability Disclosure Reports (VDRs) and Vulnerability Exploitability Exchange (VEX) in providing a robust foundation for effective vulnerability management.
Irina Kimmel is the Product Manager for Automotive Vulnerability Management at ETAS. In this role, she defines the strategy and develops the content for this service and product area. Irina offers a solution to automate the creation of SBOM (Software Bill of Materials) and identify and manage critical software vulnerabilities and supports customers in achieving conformity to industry security standards like UN R155, CRA and ISO/SAE 21424. In her professional journey, she has a strong background in offensive security and has made significant contributions to the global security and efficiency of enterprise/offboard IT systems through her diverse and extensive experience as a Consulting Lead and Service Architect for the Penetration Testing Service.
APIs are the backbone of today’s connected vehicle ecosystem—powering everything from remote commands, over-the-air updates, to EV charging—but they’re also becoming prime targets for attackers. While cybersecurity teams focus on perimeter defenses and known vulnerabilities, API abuse often flies under the radar, leaving vehicles exposed to threats hiding in plain sight. This session takes a practical look at how automotive APIs are being exploited in the wild and why current security practices aren’t enough. We’ll break down real-world examples, including the VIN Spray technique—where attackers used API manipulation and social engineering to pair unauthorized users with vehicles—and recent research showing how attackers can activate vehicle functions through dealership APIs using nothing more than a license plate. The core challenge? A lack of correlation between API traffic and connected vehicle data like telematics, ADAS events, or sensor anomalies. Without this context, it’s nearly impossible to distinguish normal API usage from malicious intent. We’ll walk through practical strategies and frameworks for bridging this gap, including: Detecting anomalous API behavior with contextual triggers from in-vehicle data Building rules and models that account for cross-layer API abuse Implementing real-time detection pipelines to flag suspicious vehicle-command activity
Elad leads Upstream’s cyber threat intelligence solution, AutoThreat®, the first mobility purpose-built CTI service and platform. AutoThreat® collects, analyzes, and leverages mobility threat intel from multiple public, deep and dark web sources enabling stakeholders to gain domain-specific context of cyber threats impacting their assets and supply chain. Prior to joining Upstream, Elad established and led several CTI teams in the critical infrastructure, IT and corporate due-diligence sectors. Elad served in the Israeli Defense Force’s elite technological unit 8200 and holds an L.L.B in commercial law and is a certified attorney, member of the Israeli bar association. In his spare time he really never misses his weekly basketball training.
Ruslan is a Senior Cyber Security Solution Engineer at Upstream Security, helping global mobility and connected services providers secure their APIs, telematics, and digital infrastructure. Leveraging expertise in API security, SIEM, and incident response, he works with customers to design proactive detection, threat hunting, and vulnerability discovery strategies tailored to automotive and IoT environments. Prior to his current role, Ruslan was a Senior Cyber Security Analyst at Upstream, developing detection logic and threat models for connected vehicle ecosystems.
As vehicles evolve to be more software-defined, automotive cybersecurity must also adapt to meet the demands of increased system complexity, real-time threat detection, and distributed architecture. Edge AI, the deployment of artificial intelligence directly on a vehicle’s computing systems, offers a promising path forward. It enables low-latency, context-aware cybersecurity capabilities critical for protecting software-defined vehicles (SDVs) and their complex software ecosystems. However, realizing edge AI’s full potential requires overcoming significant technical and operational challenges, while ensuring alignment with growing regulatory demands. This presentation examines key questions surrounding edge AI implementation and integration, including: How can edge AI models be optimized for reliable, low-latency threat detection across resource-constrained automotive embedded systems? What challenges arise in deploying and maintaining AI models at the edge in vehicles? How does edge AI complement cloud-based security operations and support regulatory compliance within a holistic cybersecurity architecture for SDVs?
Gregor Knappik is a Senior Cybersecurity Solutions Architect at VicOne. He has built his expertise in integrating large-scale embedded software projects using state-of-the-art cybersecurity solutions for over 15 years. Recently, he has been helping automotive OEMs to build defense systems for their Zonal Architecture including IVI, T-BOX, Zonal Controllers, Power Domain and ADAS Systems.
Krzysztof is a Senior Cybersecurity Engineer at VicOne with over 6 years of experience in the Automotive industry. He has worked on both the Tier 1 and OEM sides specializing in System and Software development for Cybersecurity applications. At VicOne, he is the technical representative of R&D in Europe, taking responsibility for projects such as IDPS, VMS or VSOC platforms. He is certified with TÜV Nord as an Automotive Cybersecurity Engineer and with VDA/intacs as an ASPICE Assessor.
Due to the recent advances in the development of powerful quantum computers, the issue of cryptographic agility has once again become a focus of cyber security. While increasing the key lengths of existing algorithms has primarily provided the necessary security in recent years, this approach is not an option for the threat presented by quantum computers in asymmetric cryptography. This is due to the fact that the mathematical problems on which asymmetric cryptography is based can be solved much more efficiently with the help of these new types of processors. As a result, the affected algorithms must be completely replaced in order to guarantee the necessary security in the future. This flexible replacement of cryptographic algorithms is known as crypto-agility and is particularly relevant for systems that are to be supplied with software updates over several years. Modern cars based on the SDV principle can be described as one type of such system. The idea is that the functionality of the vehicles is no longer defined by the hardware, but by the implemented software, which can be continuously enhanced during runtime. Resource-limited systems, which are primarily used in real-time applications, pose a particular challenge. This special type of control device relies on microcontrollers, which compensate for their lower performance with hardware accelerators for dedicated functions. As modern cryptographic algorithms have high resource requirements, they are primarily implemented with appropriate hardware support. The advantage of this approach is the high-performance computation, but these hardware accelerators cannot be updated, which is a problem in the context of crypto-agility. For this reason, this presentation proposes a concept that enables the updating of existing ECUs for real-time capable applications based on the AUTOSAR Classic Platform. To prove the correctness of the corresponding approach, all post-quantum algorithms currently standardized by NIST are implemented and evaluated on two different automotive microcontroller generations.
Martin Manthe studied computer science at Stralsund University of Applied Sciences and has been working as a development engineer in the automotive and aerospace sector for many years. His professional career began with driver programming for communication systems in motor vehicles. He is currently working on post-quantum cryptography and secure runtime environments on embedded control units in the automotive environment. He also regularly reports on his field of work at symposia in the embedded domain.
Dr. Claude Pascal Stöber Schmidt studied Mechanical Engineering at the TU Braunschweig, focusing on Vehicle Technology and Internal Combustion Engines. His research career and PhD thesis were based on software development and the simulation of combustion processes for engines. After joining IAV GmbH in 2015, he started as a team lead responsible for software development for aftertreatment and engine functionalities for embedded systems of heavy-duty vehicles. From 2021 onwards, he took over the management of cybersecurity engineering and validation projects. Since 2025, he has been technical sales manager for SDV enabler topics.
Philipp Jungklass studied computer science at Stralsund University of Applied Sciences and has been working as a development engineer in the automotive sector for many years. His professional career began with driver programming for communication systems in motor vehicles. He is currently working on multicore microcontrollers and secure runtime environments on embedded control units in the automotive environment. He is also responsible for educational support and regularly reports on his field of work at symposia in the embedded domain.
Threat Analysis and Risk Assessment (TARA) is one of the cornerstones for complying with UN-R155 automotive cybersecurity regulation. In fact, the UN-R155 requires OEMs to perform risks assessments and demonstrate the appropriate management of risks throughout vehicle lifecycle. To meet this regulation, automotive stakeholders rely on the ISO/SAE 21434 standard which addresses several cybersecurity aspects including TARA methods. More specifically, the UN-R155 provides a list of threats to be considered in TARAs. These threats are not always relevant when analyzing a given feature as it depends on the attacker’s motivation. If we consider the threat related to physical attacks, a vehicle user would be more interested in tuning his vehicle than triggering safety related feared events; whereas a thief would be interested in inviolability related features, and he has very limited interest in infotainment features. In this talk, based on our experience with the ISO/SAE 21434 standard, we describe how to achieve pragmatic and efficient risks assessments. First, we propose improvements related to attack feasibility rating. Then, relying on TVRA methodology, we show how relevant threat agents’ capabilities and motivation can be considered to focus on relevant attack paths and determine risk values that better reflect the probability of real attacks, thus facilitating risk treatment decisions.
I worked initially on network and telecom for IS/IT and have joined the automotive engineering in 2011 to work on first connected cars. I endorsed very quickly a cyber position in the engineering team and widely contributed to highlight cybersecurity challenges on cars and initiated many cyber related transformations on EE architecture, ECUs requirements, validation… and because I spent some money to let a brand new shiny car be bullied by external auditors – during the first pentests done in the automotive industry – I inherited and kept a label of “the bad crazy guy” for few years … but now, pentests are part of regular cyber activities, so they freed me and I’m even allowed to speak in conferences. 😊
This paper presents PIBuster, a new attack vector against the EV charging infrastructure. The attack targets the Qualcomm HomePlug GreenPHY modems used inside CCS chargers and vehicles, and is enabled by a common misconfiguration in their Parameter Information Block (PIB). The vulnerability allows an attacker to overwrite the PIB of modems, which contains many critical fields. We create a safe laboratory testbed for evaluating PIB security, use it to pinpoint the necessary conditions for the attack, and determine that a single configuration byte is responsible. We collect a large dataset of PIBs from real-world EV chargers, and evaluate them using our test bed, determining that 41 out of 69 charging stations exhibit the vulnerable configuration. Finally, we identify a specific high-impact attack that results in a persistent denial of service, and that can only be resolved by replacing hardware.
Marcell Szakály is a DPhil student in the Systems Security Lab at the University of Oxford. He studies the security of the EV charging infrastructure, and supervises master’s students on related topics. His research has revealed potential security issues in the CCS charging process, and his measurement study showed that many currently deployed chargers use outdated (and less secure) version of the protocol. Marcell began pursuing cybersecurity research after earning a Master of Physics from Oxford. His work still incorporates many physical aspects, with a strong focus on electronics and RF hardware. He is primarily interested in finding and understanding potential attacks, caused in part by physical design flaws.
This session explores how modern vehicle infotainment systems can be exploited to gain deep access to a car’s network. It demonstrates implanting a persistent backdoor, establishing a reverse shell, and leveraging exposed ADB and other services to interact directly with the CAN bus. Attendees will follow the full attack chain, from initial foothold to complete vehicle network access and gain insights into the security implications of connected mobility. The findings highlight critical vulnerabilities that could allow remote manipulation of safety-critical systems and offer practical lessons for improving automotive cybersecurity.
Abhay Vishnoi is a Lead Security Researcher based in India, specializing in automotive cybersecurity. He focuses on penetration testing, RF security, reverse engineering, and securing connected vehicles, helping manufacturers identify and mitigate emerging threats. Abhay has a proven track record of uncovering zero-day vulnerabilities, executing live attack demonstrations, and advising global OEMs to strengthen the security of next-generation mobility solutions. His work bridges research and real-world application, advancing the safety and resilience of connected vehicles worldwide.
This presentation explores the integration of Artificial Intelligence (AI), particularly Large Language Models (LLMs), in safety-critical automotive systems and the emerging cybersecurity risks they introduce. We discuss the current gaps in regulations like UN Regulation No. 155 (UN R155) regarding AI-specific threats such as adversarial attacks and data poisoning. The talk proposes extending existing frameworks to include AI-focused security measures, leveraging industry standards like OWASP Top 10 for LLMs, MITRE ATLAS, and the Automotive Threat Matrix. Finally, it highlights how the Cybersecurity Management System (CSMS) can evolve to ensure secure AI deployment throughout the vehicle lifecycle, aligning automotive cybersecurity with the latest AI-driven challenges.
Natasha Alkhatib is a cybersecurity leader specializing in AI-driven security solutions for the automotive industry. She holds a PhD in AI for Automotive Cybersecurity from the Polytechnic Institute of Paris. Her experience spans leading cybersecurity teams, integrating AI/ML for intrusion and anomaly detection, conducting threat modeling, and aligning with global standards such as ISO/SAE 21434, UNR155, and UNR156. Natasha has worked with major automotive and technology companies including Symbio, and ETAS BOSCH and has authored multiple IEEE publications on AI-based intrusion detection for in-vehicle networks. She is passionate about advancing security-by-design and fostering awareness of AI’s role in protecting next-generation mobility solutions.
Required innovation in the automotive market is driven by inter-connectivity and software, increasing the attack surface. In the case of an actual incident, companies should be prepared to respond appropriately, and to ensure this in the area of business and IT incident response, simulations are an established way to practice this response. In the field of automotive systems, the awareness for the need to respond to incidents exists, but incident response simulation or training for incidents is not common. In this presentation, we identify different requirements towards an appropriate incident response, showcase different techniques that can be employed to perform incident response simulation, and evaluate them in an automotive context. Finally, an example showcasing the benefits and challenges of automotive incident response simulation is presented. From this, we draw the conclusion that it is beneficially and recommended to perform incident response simulation in the scope of IT security.
Sergej Webber is a seasoned cybersecurity professional with over a decade of experience in the automotive and technology sectors. He currently serves as Lead Consultant and Cybersecurity Instructor at Kugler Maag Cie by UL Solutions, where he supports organizations in implementing cybersecurity practices across the automotive development lifecycle. Sergej is also the Berlin Chapter Lead for the Automotive Security Research Group (ASRG) and has been a dedicated member of the Program Committee for the Secure Our Streets (SOS) Conference since 2022. Sergej’s academic background spans multiple disciplines and countries. He is currently pursuing a Master of Engineering in Cybersecurity at JAMK University of Applied Sciences in Finland. He also holds a Master’s degree in Industrial Economics and Management from Blekinge Tekniska Högskola in Sweden, and a Bachelor’s degree in Applied Media and Communication Studies from Technische Universität Ilmenau in Germany.
Felix Bräunling is a Principal Software Engineer with UL Solutions – Software Intensive System. He previously worked for Schaeffler Technologies in the field of embedded software development for electrical motor applications. His main focus points are designing and implementing secure embedded software systems for the automotive and medical industry. Besides that, he is a trainer for software architectural, functional safety and security topics, a member of the iSAQB and drives the usage of Rust in safety- and security-critical applications.
The Threat Analysis and Risk Assessment (TARA) is a central element of the cybersecurity engineering process in the automotive domain, as mandated by ISO/SAE 21434. It defines the rationale for security controls and documents system-level risks and assumptions, serving as the foundation for regulatory compliance and engineering decisions. A commonly used method for risk quantification within TARAs is the attack potential-based approach, adapted from evaluation schemes like Common Criteria. In theory, it enables a structured assessment of feasibility and attacker effort. In practice, however, its reliability hinges on the evaluator’s understanding of real-world attack scenarios and techniques. Based on observations from multiple development projects across OEM and supplier environments, this paper highlights a critical gap: most TARAs are authored by engineers with limited or no hands-on experience in penetration testing, software exploitation, or hardware attack techniques. As a result, the calculated attack potentials often suffer from false precision, giving a misleading impression of analytical rigor. The consequence is a systemic underestimation or misprioritization of threats. This paper calls for a re-evaluation of current practices, advocating for deeper integration of offensive security expertise into the TARA process to ensure its outputs reflect realistic threat feasibility.
Jannis Kelter is Head of Cybersecurity at Holon, bringing over a decade of experience in product cybersecurity, cloud security, and application security. He is passionate about creating pragmatic security architectures and processes that withstand real-world threats while meeting the highest industry standards. His focus is on advancing cybersecurity practices that enable the secure deployment of autonomous mobility solutions and resilient, high-availability cloud infrastructures
As vehicles become increasingly connected, the cybersecurity landscape is evolving at a rapid pace. This timely discussion brings together leading voices from industry and academia to explore the challenges, innovations, and strategies shaping the future of automotive cybersecurity. Moderated by Faye Francy, Executive Director of Auto-ISAC, the conversation will feature insights from: Dr. Markus Tschersich – Head of Security & Privacy Research and Governance Jörn Eichler – Head of Security Engineering, Volkswagen AG & Head of Secure Systems Engineering Group, Freie Universität Berlin Christoph Krauss – Professor for Network Security, Darmstadt University of Applied Sciences / Head of Automotive Security Research, INCYDE From addressing today’s most pressing risks to building the secure systems of tomorrow, this panel will highlight collaborative approaches, cutting-edge research, and practical solutions driving resilience in the automotive sector.
Joern is responsible for security architectures of vehicle platforms, secure product development processes and methods as well as related standardization activities within the Technical Development of Volkswagen Passenger Cars. His research is focused on development of secure systems and he is giving lectures on Security Engineering at Freie Universität Berlin. Joern has more than 20 years of experience as researcher, developer, architect, and manager in various industry and research organizations, including 15 years in the security domain. Joern holds a PhD in Computer Science from the Technical University of Munich and a MSc in Business Economics from the Freie Universität Berlin.
Dr. Markus Tschersich is heading the Security & Privacy Research and Governance team in the central Product Cybersecurity Office at AUMOVIO. He is involved in regulation and standardization activities in the fields of Cybersecurity and Privacy in the context of Automotive products. In this role he is member of the German delegation of ISO TC22/SC32/WG11 that was in charge to work on the ISO/SAE 21434 Cybersecurity Engineering and ISO PAS 5112. In the regulatory environment, he is CLEPA delegate in the UN IWG on Cybersecurity/OTA issues and he is Co-Chair of the VDA Working Group for Automotive Cybersecurity. He acts as the Liaison Officer between the ISO committee and the UN Task Force. Based on this, he is leading the internal implementation of the Cybersecurity Management System and further Compliance and Conformity topics at Continental.
Auto-ISAC serves as the automotive industry’s hub for cybersecurity collaboration, fostering intelligence sharing and best practices to enhance the resilience of the entire ecosystem. Through its collective efforts, Auto-ISAC helps member organizations stay ahead of emerging threats.
Prof. Dr. Christoph Krauß is Professor for Network Security, Spokesperson of the IT Security expert group, and Co-head of the Applied Cyber Security Darmstadt (ACSD) Research Group at Darmstadt University of Applied Sciences (HDA). Furthermore, he is Head of Automotive Security Research at INCYDE GmbH, which he co-founded. He has over 20 years of experience in IT security. His fields of interest and activities are focused on applied cryptography, security protocols, and security engineering within the application domains of automotive, railway, Internet of Things, and intelligent energy networks.
Automotive security has come a long way but where are we really headed? In this session, Bosch Chief Technical Expert Robert Kaster takes us on a journey through the history of automotive security from an engineer’s perspective, highlighting how the field has evolved and where the energy of today’s security community is focused. He will explore the organizational and technological challenges ahead, from embedding a “quality mindset” into security practices to navigating the complexities of Software-Defined Vehicles (SDVs) and long-term maintenance. Finally, Robert will offer insights on how to measure success in vehicle security and, just as importantly, how to make the case for sustained investment to ensure a secure future.
Robert Kaster is Chief Technical Expert at Bosch Americas, where he leads product security efforts across the region and globally for the mobility sector. He also serves on the Board of Directors of the Auto-ISAC, shaping industry-wide collaboration in automotive cybersecurity. Over his career, Bob has designed more than 40 million braking ECUs, earned 18 patents, and was named Innovator of the Year in North America three times. His global experience includes a four-year assignment in Germany and leadership as Safety Electronics Tech Lead and Chair of the Auto-ISAC European Task Force. In 2024, he completed his Ph.D. in Automotive Cybersecurity with research focused on software attestation for autonomous driving safety. Known for blending deep technical expertise with visionary leadership, Bob continues to advance security and safety at scale across the automotive ecosystem.
As agricultural machinery becomes increasingly connected and automated, cybersecurity has emerged as a critical factor for safety, compliance, and operational resilience. This panel discussion at SOS 2025 will explore the potential implications of the UNECE R155 regulation for agricultural-relevant vehicles, examining best practices, challenges, and strategies for implementing robust cybersecurity measures. Industry experts will share insights on regulatory requirements, product security processes, and real-world experiences in protecting agricultural equipment against emerging cyber threats, helping manufacturers, operators, and stakeholders stay ahead in an evolving regulatory landscape.
PANEL MEMBERS:
Bradley Nielsen
Machine Electrical Engineer, CNH
Brad Nielsen is the Vehicle Cybersecurity Architecture Lead at CNH Industrial, bringing more than 36 years of experience in machine electrical engineering and product security. Throughout his career at CNH, Brad has held multiple roles spanning machine product cybersecurity, machine communications standardization, diagnostic tool and protocol development, and machine control systems design.
He currently leads the authoring team for the ISO 24882 Off-Road Cybersecurity Standard and serves as the Security Expert Team Lead for the Agricultural Electronics Foundation (AEF). His expertise is centered on advancing connected vehicle security, ensuring robust protections across agricultural and off-road machinery.
John Potter
Product Cybersecurity Architect, John Deere
John Potter worked at John Deere for nearly 30 years. His last major role there was leading the development of next generation product security for embedded devices. Currently he works for Iowa State University, John Deere and DG Tech – helping development next generation (mostly agricultural) vehicle network architectures and security.
Nicolas Hummel
Digitization Expert, VDMA Agricultural Machinery
Nicolas Hummel is a Digitization Expert at VDMA Agricultural Machinery (since 2023), where he focuses on the development and standardization of interoperability standards, as well as safety and cybersecurity frameworks. He actively contributes to international standardization through ISO/TC 23/SC 19, helping drive the digital transformation of agricultural machinery.
Hans Juergen Nissen
Manager Solution Controls Strategy , John Deere
Hans Juergen Nissen is the Manager Solution Controls Strategy at John Deere’s Global Production Systems Organization, where he drives global strategies advancing solutions from automation to autonomy, with a focus on safety, security, and multi-brand integration. Since joining John Deere in 1997, he has held leadership roles in precision farming, systems engineering, and automation & electrohydraulics, contributing to the development of intelligent machine systems and control solutions worldwide. Beyond his corporate work, Hans-Jürgen has been a leading voice in ISOBUS standardization for over two decades. He chaired the ISO/SC19 Agricultural & Forestry Electronics Committee (2010–2019) and the AEF Automation Team (2008–2019), earning the VDI Max von Eyth Recognition Award (2011) for his contributions to agricultural technology.
Alex Roberts
Director, Product Security, AGCO Corporation
Alex Roberts is the Director of Product Security, bringing over 20 years of experience in engineering and cybersecurity. He holds a degree in Electrical and Computer Engineering from Wichita State University and spent a decade testing hardware and firmware for a major storage manufacturer before transitioning to the agriculture industry. For the past decade, Alex has focused on implementing product security practices in agricultural machinery, most recently leading preparations for the RED and CRA cybersecurity legislation in Europe. His work ensures that connected agricultural systems meet the highest standards of safety, compliance, and resilience.
Leonhard Stutz
Development Engineer, CLAAS
Leonhard Stutz is a Development Engineer at CLAAS, where he supports product development teams with expertise in cybersecurity. With more than 12 years of experience in the agricultural sector and nearly five years at CLAAS, he specializes in securing digital systems within agricultural machinery. He is an active contributor to international standardization and industry collaboration, serving as a member of ISO/TC 23/SC 19/JWG 12 in the development of ISO 24882, and participating in cybersecurity working groups within AEF and CEMA. Leonhard holds an academic background in Bioinformatics, bringing a strong interdisciplinary perspective to his work at the intersection of agriculture, technology, and security.
Nicolas Hummel is a Digitization Expert at VDMA Agricultural Machinery (since 2023), where he focuses on the development and standardization of interoperability standards, as well as safety and cybersecurity frameworks. He actively contributes to international standardization through ISO/TC 23/SC 19, helping drive the digital transformation of agricultural machinery.
John Potter worked at John Deere for nearly 30 years. His last major role there was leading the development of next generation product security for embedded devices. Currently he works for Iowa State University, John Deere and DG Tech – helping development next generation (mostly agricultural) vehicle network architectures and security.
Hans Juergen Nissen is the Manager Solution Controls Strategy at John Deere’s Global Production Systems Organization, where he drives global strategies advancing solutions from automation to autonomy, with a focus on safety, security, and multi-brand integration. Since joining John Deere in 1997, he has held leadership roles in precision farming, systems engineering, and automation & electrohydraulics, contributing to the development of intelligent machine systems and control solutions worldwide. Beyond his corporate work, Hans-Jürgen has been a leading voice in ISOBUS standardization for over two decades. He chaired the ISO/SC19 Agricultural & Forestry Electronics Committee (2010–2019) and the AEF Automation Team (2008–2019), earning the VDI Max von Eyth Recognition Award (2011) for his contributions to agricultural technology.
Alex Roberts is the Director of Product Security, bringing over 20 years of experience in engineering and cybersecurity. He holds a degree in Electrical and Computer Engineering from Wichita State University and spent a decade testing hardware and firmware for a major storage manufacturer before transitioning to the agriculture industry. For the past decade, Alex has focused on implementing product security practices in agricultural machinery, most recently leading preparations for the RED and CRA cybersecurity legislation in Europe. His work ensures that connected agricultural systems meet the highest standards of safety, compliance, and resilience.
Leonhard Stutz is a Development Engineer at CLAAS, where he supports product development teams with expertise in cybersecurity. With more than 12 years of experience in the agricultural sector and nearly five years at CLAAS, he specializes in securing digital systems within agricultural machinery. He is an active contributor to international standardization and industry collaboration, serving as a member of ISO/TC 23/SC 19/JWG 12 in the development of ISO 24882, and participating in cybersecurity working groups within AEF and CEMA. Leonhard holds an academic background in Bioinformatics, bringing a strong interdisciplinary perspective to his work at the intersection of agriculture, technology, and security.
The rapidly evolving threat landscape targeting the automotive sector, particularly with the rise of Software-Defined Vehicles (SDVs) and extensive connectivity across vehicle, cloud, and charging ecosystems, necessitates a shift from traditional, static security testing towards dynamic, continuous validation. This presentation details a case study from Rivian, an American electric vehicle manufacturer focused on adventure and sustainability, showcasing our practical implementation and operationalization of a Continuous Threat Exposure Management (CTEM) program built upon a foundation of internally developed cybersecurity infrastructure integrated with powerful open-source solutions.
As Director of Cybersecurity Operations at Rivian, Chris Mandich leads the critical function of protecting the company’s enterprise systems to accelerate its mission to keep the world adventurous forever. He has spearheaded initiatives to reduce risk through strategic cybersecurity planning, decisive incident response, and fostering strong partnerships. Chris leverages his deep expertise in offensive security and resilient architecture design, applying a hands-on leadership style to mature Rivian’s threat detection and response posture. He is committed to building scalable security solutions and cultivating high-performing teams grounded in a culture of continuous learning and cybersecurity excellence. ● Director, Cybersecurity Operations at Rivian, leading security strategy to enable sustainable innovation. ● Broad cybersecurity leadership experience across diverse sectors including Tech (EV), Consulting, Finance, Healthcare, and Energy/Utilities. ● Deep expertise spanning offensive security, incident response, risk management, and resilient security architecture design. ● Proven success in architecting, implementing, and operationalizing advanced security solutions including SIEM, SOAR, Cloud Security, EDR, and ICS/OT security platforms. ● Holds a Master of Science in Information Security Engineering from SANS Technology Institute.
Juso leads the Detection and Response Team at Rivian, where he has spent the last four years building the company’s cybersecurity capabilities from the ground up. He leads the talented teams responsible for detection engineering, incident response, and threat hunting. With over a decade of experience in cybersecurity, Juso is passionate about developing robust defense strategies and leading teams to execute them. His leadership ensures the protection of Rivian’s innovative electric vehicles and connected ecosystem.
As a Senior Staff Cybersecurity Engineer at Rivian, Rob specializes in building advanced, in-house cybersecurity platforms. He architected and developed “TRAILS,” a comprehensive cybersecurity data lake that streamlines data and detection engineering, and “Cyber Streams,” a scalable, containerized log streaming platform for efficient data processing across cloud and on-premises environments. Rob also created the “FIRE” SOAR platform, an event-driven system that automates security operations through real-time alarm handling, automated response playbooks, and a flexible container-based task engine. These platforms form the core of Rivian’s modern, automated cybersecurity infrastructure.
The regulatory landscape for automotive cybersecurity is undergoing significant transformation. On one hand, emerging domain-specific standards such as ISO/SAE PAS 8477 and ISO/SAE TR 8475 are contributing to the harmonization of automotive specific cybersecurity concepts. On the other hand, new horizontal regulations are being introduced that are particularly relevant for automotive-related products and services that fall outside the scope of traditional type approval processes. As automotive companies increasingly offer digital services that extend beyond the vehicle, and as suppliers and also OEMs operate in different roles and across multiple industries (or vehicle categories) a broader understanding of cybersecurity obligations is essential. The presentation will focus on the European Union’s Cyber Resilience Act (CRA), highlighting its implications and the opportunities it presents for the automotive industry. We will explore the conditions under which the CRA becomes applicable and examine its intersection with established standards such as ISO/SAE 21434. By comparing CRA requirements with existing automotive cybersecurity practices, we aim to clarify compliance pathways and identify areas of alignment. Additionally, we will offer a forward-looking perspective on how organizations can leverage the CRA as a catalyst for strengthening their overall product security posture. This includes developing tailored cybersecurity capabilities within a robust framework, which is also applicable for dual- or multi-use items.
Stefan is part of the Deloitte Cyber team, specializing in Secure Product Engineering and regulatory frameworks such as ISO/SAE 21434 and the Cyber Resilience Act. He has supported automotive companies and software subsidiaries in building effective Product Security Offices and Management Systems, and brings extensive experience from projects with OEMs, suppliers, and connected product manufacturers, including certification and type approval processes.
Anne Zachos is a Cybersecurity Research Engineer at the National Motor Freight Traffic Association, Inc. (NMFTA)™. Anne has a strong background in embedded systems engineering and is dedicated to advancing cybersecurity within the trucking industry. Her work is centered on securing connected vehicle technologies, focusing on both the technical challenges of embedded firmware and the broader cybersecurity threats facing commercial transportation. Anne contributes to several American Trucking Association (ATA) TMC task forces as well as technical standards committees under SAE International. At NMFTA, Anne contributes both to research initiatives and educational efforts, helping to strengthen the industry’s overall cybersecurity posture and awareness.
Anne Zachos is a Cybersecurity Research Engineer at the National Motor Freight Traffic Association, Inc. (NMFTA)™. Anne has a strong background in embedded systems engineering and is dedicated to advancing cybersecurity within the trucking industry. Her work is centered on securing connected vehicle technologies, focusing on both the technical challenges of embedded firmware and the broader cybersecurity threats facing commercial transportation. Anne contributes to several American Trucking Association (ATA) TMC task forces as well as technical standards committees under SAE International. At NMFTA, Anne contributes both to research initiatives and educational efforts, helping to strengthen the industry’s overall cybersecurity posture and awareness.
A heightened global focus on software supply chain security — plus a range of emerging industry regulations — have made SBOMs (software bill of materials) an increasingly important initiative for automotive suppliers and manufacturers. Of course, the scope of SBOM programs often varies by an organization’s role in the automotive ecosystem. This presentation (“SBOMs in the Automotive Industry: Real-World Insights and Recommendations”) will focus on three distinct parts of the SBOM lifecycle I’ve observed from my work supporting automotive industry clients. I’ll provide an overview of each part of the lifecycle, plus actionable guidance for improving results. The three scenarios are as followers: 1. SBOM distribution and generation: Based on our experiences, most organizations across the automotive software supply chain — manufacturers along with all tiers of suppliers — are in a position to need at least basic SBOM generation capabilities. 2. SBOM ingestion and aggregation: While Tier 2 suppliers may not be concerned about ingesting and combining SBOMs from external teams, automotive manufacturers (and many Tier 1 suppliers) very much are. 3. SBOMs as a vehicle for continuous monitoring and vulnerability management: Similar to ingestion and aggregation, automotive suppliers without extensive supplier networks of their own may not be focused on using SBOMs to achieve vulnerability management objectives. But manufacturers and more interconnected suppliers often are. Each section of this talk — which is based on extensive firsthand experience directly supporting automotive manufacturers along with Tier 1 and 2 suppliers — will include specific guidance to help attendees understand how SBOM programs within their organizations can more effectively manage these parts of the SBOM lifecycle.
Cortez Frazier Jr. is a Principal Product Manager at FOSSA. He leads development for the company’s SBOM (software bill of materials) and vulnerability management solutions. Before joining FOSSA, Cortez served as product lead for all of Puppet’s SaaS-based products, primarily within the CSPM (Cloud Security Posture Management) domain. Earlier, Cortez worked as a Senior Cybersecurity Architect for GE Power, where he was responsible for around 1,800 developers and 600 applications. In his free time, Cortez participates in local Atlanta AppSec meetups while being an avid gamer and stoicism enthusiast.
This session presents the development and impact of AutoRFKiller, a tool designed to exploit vulnerabilities in cars using learning code RF (radio frequency) technology for remote locking and unlocking. Over more than a year, the discovery and testing process culminated in responsible disclosure, resulting in two CVEs officially published by ASRG in June 2025. Attendees will gain a behind-the-scenes look at RF car hacking, the technical challenges of automating the exploit, and the complex process of coordinating with vendors for responsible disclosure. The talk also includes the public release of AutoRFKiller, offering a unique insight into real-world automotive cybersecurity, exploitation, and vulnerability management.
Danilo Erazo is an independent Security Researcher from Ecuador, with experience in developing electronic devices, pentesting, software development, reverse engineering and hardware hacking. He is currently engaged in research into embedded devices and automotive systems, he is a volunteer in the DEFCON CHV. He is the founder of the Car Hacking Village at Ekoparty, the founder of the security conference PWN OR DIE in Ecuador and the founder of his own company Reverse Everything. He has been a speaker at major international cybersecurity events, including DEFCON33, Recon 2025, Hardwear USA 2025, DEFCON 32, Ekoparty, Bsides and more.