Auto-ISAC Cybersecurity Summit Keynote
NHTSA Administrator Jonathan Morrison
AS PREPARED FOR DELIVERY
A NHTSA leader has spoken at every one of these summits, and I’m pleased to keep that streak alive. Thank you all for taking the time out of your very busy schedules to be part of this conference and for your continued commitment to cybersecurity, transparency, and vehicle safety.
NHTSA supported the launch of Auto-ISAC 11 years ago to meet the demands of our rapidly changing world, which requires new ways of thinking, communicating, and collaborating.
While open communication isn’t second nature in competitive industries, discovering cybersecurity vulnerabilities and mitigating risks together makes us all stronger and safer. Auto-ISAC exists to build these connections, and I encourage you to use this conference to foster new partnerships and deepen existing ones.
When someone gets behind the wheel of their car in the morning, they’re not thinking about cybersecurity. That’s because of the dedicated work of professionals like you, who work behind the scenes to make our world a little bit safer for everyone. The public doesn’t think twice about the cybersecurity of their vehicles thanks to your work to protect them.
In an ever more complex, ever more interconnected world, cybersecurity is more important than ever. October is Cybersecurity Awareness Month and an opportunity to recommit and refocus our efforts on constant vigilance.
In fact, this year’s conference theme is the Cost of Vigilance. Building on that, I’d like to pose a question: What is the cost of complacency?
The cost may be financial. Cyberattacks and downed systems can result in tens or hundreds of millions in lost business.
The cost may be reputational. How will the public perceive your brand in the wake of a major attack? Will they still have confidence in your company and the auto industry as a whole?
The cost may be public safety. While we fortunately have not yet experienced a real-world cyberattack with vehicle safety ramifications, thanks to cybersecurity researchers, we are all aware of the imminent risk of one. Constant vigilance is necessary to guard against vulnerabilities in the era of software-defined vehicles and respond quickly when one is identified.
Investing in cybersecurity is good business, good for your reputation, and good for our nation’s security and public safety. Every company has a role to play in the collective security of our nation’s vehicles. Auto-ISAC facilitates this security and information sharing, with its members accounting for the vast majority of light-duty vehicles in North America. I’m pleased that you’ve expanded your membership to heavy trucking OEMs and suppliers, as well as the commercial vehicle sector, including fleets and carriers. And we hope more companies will continue to join, because you are stronger as a united front against domestic and foreign threats.
Because in a global economy, cybersecurity must be an international priority. I applaud Auto-ISAC for establishing a European office, as well as signing a memorandum of understanding with Japan Auto-ISAC. These efforts strengthen global situational awareness and advance cybersecurity resilience.
NHTSA stands with Auto-ISAC and is ready to support you however we can. NHTSA closely monitors and reviews vehicle cybersecurity incidents, including those disclosed by researchers, presented at hacker conferences, reported by consumers, covered by the media, or disclosed by companies. I’ve made a priority, in my time as Administrator, to push for more technical engagement with industry, and security is a critically important area for such engagement. Information sharing is invaluable. Whether you have identified a new vulnerability, uncovered something of concern, or simply want to leverage our technical guidance, our doors are always open to you.
Our mission is to save lives, prevent injuries, and reduce the economic cost of crashes, and advanced technologies are a critical part of our portfolio. It’s also infused throughout every aspect of modern vehicles, with software becoming more complex with every model year. Recalls that required an owner to go to a dealership are increasingly remedied over the air. New technology and enhanced connectivity may improve vehicle safety and satisfy consumers’ demands, but they also may introduce new potential attack vectors. Presenting a coordinated, unified front is vital to ensuring cybersecurity readiness and resilience.
This is perhaps no more important than in the realm of machine learning, which offers both opportunities and challenges for the automotive industry moving forward.
MACHINE LEARNING & BEST PRACTICES
The practice of software development has undergone a foundational shift. With the advent of generative models, from machine-assisted code generation and factoring to automated testing, software is no longer written line-by-line by humans. Contemporary computational tools also have dramatically accelerated the development lifecycle across every tier of the automotive supply chain. Code is now being generated at a volume and velocity that was unimaginable even a few years ago. With this speed and complexity comes both risks and rewards.
On one hand, bad actors can harness these capabilities to discover new vulnerabilities. Today's generative and automated tools drastically reduce the time and cost required for malicious actors to identify and exploit vulnerabilities in vehicle sensors and systems, lowering the barrier to entry for cyberattacks.
On the other hand, you can leverage ML as well to strengthen your cybersecurity by improving your code at scale. By using ML-assisted analysis and automated fuzzing, developers can identify and patch flaws earlier in the lifecycle. ML-augmented development tools can help the industry stay ahead of emerging risks.
These issues are not purely hypothetical. I trust many of you are aware of the documented uses of ML agents being used, mostly by organizations themselves, to identify cybersecurity weaknesses of their own systems. Consider OpenAI’s recent security evaluation of Hugging Face, where an autonomous ML agent escaped its testing sandbox and accessed production infrastructure.
Many of you are actively using Hugging Face to build and share AI ML models for advanced driver assistance systems and automated vehicles. That makes this recent incident highly relevant to where the industry is heading right now. And while this is just an example that made the news, these kinds of uses and outcomes are definitely not limited to this one case. The potential power of generative capabilities is still not fully known, and these kinds of instances demonstrate a glimpse of the risks and the challenges yet to be addressed.
Like you, the federal government is also very interested in and, while optimistic, also cautiously concerned about the power ML, deep learning, and large language models bring to the cybersecurity landscape, with a particular interest in public safety and national security. Investments are being made across the government to develop best-in-class tools to help support the improvement of the critical infrastructure resilience and security. We are coordinating within the U.S. Department of Transportation and across the government to better understand this toolset and their potential uses as well as governance.
I know Faye and Auto-ISAC have also been in contact with colleagues from the White House and the Cybersecurity and Infrastructure Security Agency on ANCHOR-CI, a new framework for public-private collaboration for critical infrastructure sectors and the emerging ML capabilities. As these tools continue to evolve, we will continue to coordinate and communicate with not only government agencies but you, especially in relation to software-defined vehicles and AVs.
Cybersecurity hygiene will always be an element of consideration under our National AV Framework. It is also one of Secretary Duffy’s top priorities, and the Department has committed to ensuring our nation’s transportation critical infrastructure is secure and resilient by design when encountering cybersecurity threats.
We continue to encourage you to develop a robust safety culture that prioritizes cyber vigilance, oversight, and redundancy.
NHTSA’s cybersecurity best practices for modern vehicles provide you a framework to develop your security programs. Our framework emphasizes that safety cannot be an afterthought. It requires a layered, defense-in-depth approach spanning the entire lifecycle of the vehicle, from initial concept and architectural design to incident response and secure over-the-air updates. It also addresses aftermarket device manufacturers, because cybersecurity doesn’t start and end with the OEM. Everyone in the automotive supply chain has a role to play in a strong, unified front against malicious attacks.
Information sharing is one of our strongest defenses, and we encourage everyone in the auto industry to use Auto-ISAC’s communication channels and threat-intelligence networks. Adopting NHTSA’s best practices and using Auto-ISAC’s resources will help you prepare for emerging risks, several of which I’ll touch on briefly.
CONNECTED VEHICLES
One area we’re looking at closely is infotainment systems, which continue to grow in complexity. These systems meet consumers’ demand for convenience features while allowing for over-the-air updates and recall remedies.
However, these systems bridge external communications with internal vehicle control networks, which may significantly expand a vehicle’s attack surface. Their complexity and wide variety of software sources may create additional vulnerabilities.
I’m sure you remember the 2015 incident where two security researchers were able to exploit a specific cellular vulnerability in a Jeep Cherokee’s Internet-connected dashboard. This case continues to illustrate what could happen if a head unit is not properly secured.
By leveraging this exploit, they successfully injected unauthorized commands into the vehicle’s internal network, disrupting critical physical functions such as the brakes, transmission, and steering. This showed that without proper network segmentation and firewalling, a compromised infotainment system can directly threaten the operational integrity of connected vehicles. And while we haven’t seen a real-world incident of this nature, the industry should anticipate such exploits and prepare accordingly.
Cloud infrastructure is yet another area of interest. Backend cloud infrastructure manages remote features like locking and unlocking doors and remote start, convenience features consumers enjoy. It also manages real-time diagnostics and over-the-air updates. Because cloud vulnerabilities could impact an entire fleet, securing backend infrastructure is just as important as securing in-vehicle networks.
A real-world incident involving backend cloud infrastructure happened earlier this year. A Breathalyzer company’s servers fell victim to a cyberattack in March, which left drivers across the United States stranded, unable to start their vehicles.
And researchers have repeatedly gained access to vehicles through cloud infrastructure. In one instance, researchers uncovered exploits that allowed remote vehicle unlocking, horn honking, engine start, and location tracking via tailored API requests using a target’s VIN. We’ve also seen researchers discover vulnerabilities through satellite radio connected vehicle services, which reminds us all of the importance of all suppliers in the chain.
AFTERMARKET PRODUCTS
Cybersecurity is about more than just the vehicle that rolls off your assembly line. Suppliers must have strong cybersecurity practices in place, as should aftermarket device manufacturers. Each component introduced into a vehicle may create new pathways of attack.
The threat from aftermarket hardware can hide in plain sight. University of California, San Diego researchers highlighted a new vulnerability at DEF CON a few months ago that they discovered almost by accident. While analyzing wireless traffic, researchers kept seeing identical, highly common Bluetooth device names broadcasting from parked vehicles.
The team traced them back to aftermarket anti-theft modules quietly installed by dealerships on an estimated two million cars. When the researchers reverse-engineered the system’s mobile app, they found a catastrophic security failure. Instead of giving each vehicle a unique digital password, the manufacturer used fixed credentials—a single, hardcoded cryptographic key shared across every single device.
Because these modules are wired directly into the dashboard, anyone within Bluetooth range who had that single master key could send commands to remotely unlock the doors, silence the alarm, or disable the ignition.
Similarly, vulnerabilities have been identified in electric vehicle chargers, as EV supply equipment serves as the critical physical and digital bridge between a vehicle’s high-voltage battery management system and the local power infrastructure.
Recent security competitions have repeatedly demonstrated that EV chargers are a highly susceptible attack surface. Researchers have routinely exposed dozens of zero-day vulnerabilities across major commercial Level 2 and Level 3 chargers, proving that the barriers to compromising these devices are alarmingly low.
If a device interfaces with vehicle networks, then new cybersecurity risks are introduced to those vehicles. We expect all aftermarket manufacturers to meet high industry standards and secure their components against potential attacks and weaknesses. We oversaw a recall in 2024 for an aftermarket electronic logging device for a firmware vulnerability, for example.
NHTSA’s cybersecurity guidance specifically addresses aftermarket devices and manufacturers. First, the automotive industry should consider the risks that could be presented by user-owned or aftermarket devices when connected with vehicle systems and provide reasonable protections.
Second, any connection to a third-party device should be authenticated and provided with appropriate limited access.
And third, aftermarket device manufacturers should employ strong cybersecurity protections on their products.
If you haven’t already done so, I encourage you to revisit NHTSA’s best practices to examine how you can improve your cybersecurity and strengthen your vehicles’ resiliency against attacks introduced through aftermarket products and other entry points. We’re in the process of reevaluating these best practices in light of the latest trends, and I welcome your thoughts about any needed updates.
FEDERAL ROLE
In addition to NHTSA, industry, and Auto-ISAC best practices, it’s important for the automotive sector to continue to adhere to the Department of Commerce’s connected vehicle supply chain final rule. NHTSA provided technical assistance to the department as it developed the final rule and stands ready to support other agencies and departments. Further, the Federal Communications Commission added foreign-produced advanced robotic devices and power inverters to the banned list in July, which has some implications for you as well.
Cybersecurity is a priority across the entire U.S. Department of Transportation and the Trump Administration. Recently, USDOT established an internal Cyber Coordination Council to sync transportation vector vulnerabilities with CISA’s resources. The council’s goal is to identify vulnerabilities and mitigations in transportation technologies and facilitate information sharing – like Auto-ISAC does.
I invite you to stay connected with NHTSA, as we have several upcoming events I think you’ll find useful. We’ll be hosting our annual Safety Research Portfolio Public Meeting on December 1 and 2 at USDOT headquarters in Washington, D.C. One of the projects we’ll present is an evaluation of offensive cybersecurity models for the automotive domain. The event is free, and we’ll have recordings available later for those unable to make the trip.
I’d also like to invite you to attend the Cybersecurity Workshop we’re hosting with SAE International in Washington on Jan. 19, which is held in coordination with SAE’s Government/Industry Meeting. We have a jam-packed agenda in the works, including a panel of government leaders, that will be well worth your time.
CLOSING
I would like to leave you with this: We are stronger together. Constant vigilance makes all of us safer. Sharing information and being transparent is the only way you can be prepared for potential attacks – because with the new tools being developed with ML by malicious actors, one day those attacks won’t be theoretical, they’ll be reality. How you communicate, how you plan, how you respond, and how you learn from one another will determine how you meet the challenge in the moment and whether and the extent to which such an attack will be successful.
We need to be proactive in embracing and harnessing the power of ML to improve our defenses and do so before adversaries do the same for malicious reasons. Collectively, we need to identify and address the remaining threats, risks, and vulnerabilities on this path.
Secrecy and complacency don’t breed security. They make you more vulnerable than ever to those who want to exploit your weaknesses.
Auto-ISAC is an invaluable tool in your cybersecurity arsenal. Stay active, engaged, and learn from one another. I encourage you to see each other not as competitors but as allies united against bad actors across the globe.
NHTSA will continue to support Auto-ISAC’s mission of transparency and information sharing, and our door will always be open to you. Please don’t hesitate to reach out, because we want every vehicle on our roads to be as cyber ready as possible. Let us help you achieve that goal.
Thank you again for the opportunity to be here today, and I wish you the best for the rest of your conference.