PwC's Global Automotive Cyber Security Management System (CSMS) Survey 2022
The ecosystem of connected vehicles is growing – and with it the attack surface for cyber threats.
The automotive industry is in a state of upheaval: both the boom in alternative drive options and the increased connectivity of vehicles are opening up new business models for manufacturing companies and suppliers. Enabled by numerous new digital features and services from manufacturers and third-party providers, the car is evolving from a pure means of transport into a space for living and working.
This transformation has a strong impact on the ecosystem in which vehicles operate. Ensuring and actively managing the security and functionality of this ecosystem safeguards the well being of all users and also enhance the financial performance of automotive companies. For example, a lane-keeping assistant blocked by a denial-of-service attack endangers not only the occupants but also non-digital vehicles, pedestrians or other road users.
Accordingly, expectations are high around the automotive industry’s response to minimising such risks via the use of resilient cyber security management systems (CSMS). PwC's Global Automotive CSMS Survey 2022 looks at how far OEMs and suppliers have come in implementing these systems and what more needs to be done.
Key findings include: In terms of maturity, there is still considerable variance between different CSMS projects. With a view to the average CSMS implementation period of 30 months, the pressure to act is also increasing – companies are not advanced enough in their implementation journey and must act with urgency to address their contractual and legal obligations. Because CSMS will protect the entire value chain of digital ecosystems in the future, significantly influencing operating costs and ensuring compliance, it is fast becoming a business-critical issue for the automotive industry.
However, it is also clear that the CSMS is just one important milestone on the road to successful digital transformation. Companies in the automotive industry need to network their cyber initiatives much more, embedding cyber security at the core of the company’s operations and integrating cyber risk management into the company's risk management. The digital transformation strategy must also lead the way for purely regulatory-driven projects.
To read more click here.
Eventi in evidenza
AdottaMI 2026
Il rapporto con gli animali da compagnia sta assumendo una dimensione sempre più rilevante nella vita delle persone e, allo stesso tempo, apre nuove riflessioni sul tema dell’adozione responsabile. Dalla scelta di accogliere un animale alla gestione del percorso successivo all’adozione, entrano in gioco bisogni, aspettative e responsabilità che coinvolgono cittadini, rifugi, istituzioni e, sempre più, anche le aziende.AdottaMI 2026, in programma il 3 e 4 ottobre presso Parco Sempione a Milano, nasce come occasione di incontro e confronto sul mondo delle adozioni e sul rapporto tra persone, animali e città, con uno sguardo anche al contributo che imprese e Pubbliche Amministrazioni possono offrire alla costruzione di un ecosistema più consapevole e pet-friendly.PwC Italia sarà presente domenica 4 ottobre, con un intervento di Roberta Anelli, Senior Manager Digital Innovation PwC Italia, dedicato a esplorare il fenomeno attraverso dati, analisi e sentiment online, mettendo a confronto ciò che emerge dalle conversazioni digitali con la percezione del pubblico presente.L’intervento, dal titolo “Pet-friendly? Una green flag che diventa responsabilità condivisa”, partirà dalla dimensione del fenomeno e dalle principali esigenze che accompagnano il percorso di adozione, per approfondire insieme a Empethy come strumenti digitali e nuovi modelli di collaborazione possano supportare adottanti, rifugi e istituzioni. Per maggiori informazioni clicca qui.
L'Architettura della Resilienza. Governance e Prodotto: interdipendenze tra NIS2 e CRA
Il 28 ottobre 2026, presso l’Auditorium Giorgio Squinzi di Assolombarda a Milano, si terrà “L’Architettura della Resilienza. Governance e Prodotto: interdipendenze tra NIS2 e CRA”, l'appuntamento annuale dedicato ai temi della cybersecurity e della resilienza digitale. Giunto alla sua dodicesima edizione, l’evento rappresenta un’importante occasione di confronto per imprese, istituzioni ed esperti del settore sui principali sviluppi normativi, tecnologici e organizzativi che stanno trasformando il panorama della sicurezza informatica.In questa edizione verrà approfondito il rapporto tra il Cyber Resilience Act (CRA) e la Direttiva NIS2, mettendo in luce l'intrinseca indipendenza tra i due ambiti normativi e il loro impatto sulle strategie aziendali. Attraverso il confronto con esperti e casi reali, l’evento aiuta le imprese a orientare con maggiore consapevolezza investimenti, governance e supply chain, ma soprattutto la sicurezza.PwC Italia parteciperà all’evento.Giuseppe D’Agostino, Partner PwC Italia, Cybersecurity & Privacy Leader, interverrà alle ore 11.30 durante il Cyber Talk | Round 2: “NIS2: il cantiere è (ancora) aperto” .