No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Cybersecurity

New Regulations on Automotive, Medical Device Manufacturers Illustrate Similarities Across Industries

Global rules on device security continue to proliferate

by David Barzilai
July 24, 2023
in Cybersecurity
pacemaker

The U.S., EU and China have issued stringent regulations that require automotive and medical device manufacturers to secure their products against cyber attacks. David Barzilai of Karamba Security explores how seemingly disparate industries overlap when it comes to consumer cybersecurity.

Though it may not seem entirely obvious, a fine line connects the cars we drive and medical devices we use. Both run critical applications and are often connected to the internet. Both are, as a result, exposed to cyber attacks that could compromise consumer safety and privacy. 

These are not theoretical risks: Bluetooth vulnerabilities have exposed millions of vehicle users to cyberattacks; a 19-year-old remotely infiltrated 25 Tesla vehicles in 13 countries, switching their engines on and off; Medtronic insulin pumps were hacked remotely by white-hat researchers; and the FDA recalled 500,000 of Abbot pacemakers due to a security vulnerability that could have been used to drain their batteries.

It’s reasonable to assume that such customer safety and brand risks would drive medical device and automotive manufacturers to proactively harden their products and improve their security posture against cyber risks, but that’s not the case. That’s one reason why regulators around the globe have taken action.

Global standards and regulations

Over the past several years, multiple international bodies have sought to establish standards and regulations regarding cybersecurity of both medical devices and automobiles:

  • United Nations Economic Commission for Europe: UNECE’s regulation (R155), which went into effect in 2022, requires automotive manufacturers to prove to an authorized third-party auditor that their vehicle software has gone through rigorous cybersecurity measures during development and after production.
  • International Organization for Standardization: In 2021, this group, along with SAE International, ratified ISO/SAE 21434, which details the steps and work products original equipment manufacturers (OEMs) and Tier 1 suppliers must take and document in order to confirm to the UN’s R155 regulation.
  • China: Just this year, China passed a requirement that OEMs and suppliers prove the vehicles they want to sell are protected from various types of cyber attacks.
  • U.S.: Later this year, the FDA will begin refusing new medical devices for cybersecurity reasons. Starting Oct. 1, the agency will reject applications that lack evidence of cybersecurity best practices being used in the software development lifecycle and lifelong support policies.
chief data officer
Cybersecurity

CDO Roles Are Becoming More Popular, But They Often Lack Staying Power

by Tomas Kratky
June 28, 2023

Increasingly, companies are hiring chief data officers and chief data analytics officers to oversee their data environment. But while the need for these professionals is catching on, studies show they tend not to stay long.

Read moreDetails

Common threads

Though they target different types of products, these regulations have several features in common:

  • Manufacturers must document and prove their vehicles or medical device cybersecurity posture.
  • A failure to prove such posture (i.e. putting customers at risk) would severely affect manufacturers’ business plans, as they are not allowed to sell their products until they remediate the security gaps.
  • Manufacturers’ responsibility to their customer safety doesn’t stop at product release. They must keep track of new vulnerabilities, as they are reported throughout the use of their products and be responsible to patch their devices in a timely manner against exploiting newly reported critical vulnerabilities.

Industry challenges

The requirement to meet those cybersecurity regulations and standards has created business challenges for automotive and medical device product manufacturers. Without implementing cybersecurity best practices as part of their software-development lifecycles, they can’t sell their products. But implementing those processes and security controls may delay time to market, and/or increase the cost of manufacturing them altogether.

Previous Post

The Congo: Cobalt & Your Supply Chain Risks

Next Post

Globally, Regulators Are Making It Clear: FinServ Firms Must Become Resilient

David Barzilai

David Barzilai

David Barzilai is the co-founder and VP of sales and marketing at Karamba Security, an IoT cybersecurity company. David is a serial entrepreneur who holds a bachelor’s degree in computer science from the Technion - Israel Institute of Technology.

Related Posts

GRC News Roundup Cover

GRC News Roundup: Agiloft, Redgate Software MIND, LinkSquares & More

by Corporate Compliance Insights
July 30, 2026

GRC technology is one of the fastest-growing segments in enterprise software, and compliance professions are rapidly evolving. Here’s the latest...

news roundup_062124

Activist Investors Significantly Increase M&A Sale Pushes

by Staff and Wire Reports
July 30, 2026

Massive data security confidence comes with high data security concerns.

us doj building with flag

Once You’ve Decided to Self-Disclose, Here’s How to Do It Right

by Sean M. Farrell and Thomas F. Rybarczyk
July 29, 2026

Deciding to self-disclose is one thing; doing it well is another, and the difference often shapes whether a company earns...

normandy invasion monument

What a D-Day Weather Forecast Teaches About Decision-Making Under Pressure

by Jim DeLoach
July 28, 2026

Two forecasters, two methods and a go or no-go call with thousands of lives at stake, the D-Day story holds...

Next Post
small plant budding in cracked soil

Globally, Regulators Are Making It Clear: FinServ Firms Must Become Resilient

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights