Every new vehicle rolling off the production line today is a connected computing platform, exchanging data with cloud services, receiving over‑the‑air software updates, integrating real‑time data, and increasingly relying on AI to support driving functions and personalize user experience. As the industry accelerates toward AI‑defined vehicles (AIDVs), the value created is substantial, but so is the expansion of the attack surface. For automakers, cybersecurity has become a mission-critical discipline embedded across the entire vehicle lifecycle.

Cybersecurity in Today's Automotive Landscape

The global automotive cybersecurity market is projected to grow from USD 7.13 billion in 2025 to over USD 17.35 billion by 2034. This reflects the rapid adoption of software‑defined vehicle architectures, electrification, pervasive connectivity, and tighter regulatory mandates worldwide. Yet the industry stands at the crossroads of extraordinary technological innovation and mounting cybersecurity challenges. According to Upstream Security's 2026 Global Automotive Cybersecurity Report, ransomware attacks account for 44% of reported incidents—more than double 2024 levels—while 61% of incidents have the potential to impact thousands to millions of mobility assets, underscoring fleet‑scale and ecosystem-level risk.

Cyberattacks in automotive systems can lead to physical consequences, from vehicle immobilisation to road safety incidents. This risk is amplified by distributed architectures, where vulnerabilities across multiple domains can be exploited to influence vehicle behavior.

  • Connectivity and telematics remain the most consistently targeted domains. Backend servers, APIs, and cloud platforms form the operational backbone of modern vehicles, meaning that a single breach can cascade across entire fleets at once. In addition, weak account security practices, such as predictable or reused passwords, could leave smart cars and critical systems exposed to unauthorized access and takeover.
  • Autonomous driving brings new physical-layer risks, where sensors and cameras can be manipulated to distort environmental inputs, leading to unsafe driving decisions.
  • Shared mobility platforms—including ride‑hailing, car‑sharing, and commercial fleets—centralize identity, location, and payment data across large user bases, making them attractive targets for fraud and data extortion.

The integration of AI-enabled features adds further exposure, with emerging threats such as prompt injection and model manipulation. Automotive cybersecurity must therefore evolve from reactive patching toward real-time, anticipatory defense — detecting, responding, and maintaining safe states even under active attack.

Securing the AI-Defined Vehicle Era

Automotive cybersecurity has evolved into a safety-critical discipline spanning hardware, in-vehicle networks, operating systems, back-end services and organizational processes. It is a continuous lifecycle responsibility that must keep pace with software updates, new services and emerging threats. A core principle underpinning this shift is the "secure-by-design", embedding security into development pipelines so that faster release cycles do not outpace risk management. Regulation and standards reinforce this by requiring structured risk assessment, implementation evidence, and continuous monitoring throughout vehicle development and operation.

When applied with appropriate governance and human oversight, AI plays an important role as a defensive tool. Agentic AI strengthens access control by moving from static authentication to continuous, context-aware, multi-factor decision-making across digital keys, biometric authentication, and voice interfaces. Meanwhile, generative AI reduces false positives, accelerates incident investigation, and autonomously generates test cases and scripts to surface edge-case vulnerabilities. When threats are confirmed, AI-driven mechanisms can alert security teams, selectively disable vehicle functions, or lock the vehicle entirely — containing incidents in real time without waiting for human intervention. This enables security teams to scale protection in line with the growing complexity of AIDV ecosystems.

Understanding the threat landscape is only the first step. Acting on it across multi-domain architectures, global regulatory environments, and evolving vehicle lifecycles will require deep automotive engineering capability paired with genuine security expertise.

FPT’s Strategic Role in Securing Automotive Transformation

AI-powered solutions for SDV were showcased at the Automotive World Tokyo 2026, one of the world’s most prestigious and large-scale automotive technology exhibitions

Embedded Cybersecurity and AI-First Engineering Across the Automotive Lifecycle

FPT approaches automotive cybersecurity as a continuous capability aligned with the vehicle lifecycle, covering consulting, engineering, and operating activities.

At the consulting stage, FPT helps clients establish cybersecurity foundations, ensuring compliance readiness for the automotive development lifecycle. This covers homologation and type approval readiness, cybersecurity governance, initial Threat Analysis and Risk Assessment (TARA) to identify threat exposure early, and pre-audit support.

As development progresses, FPT implements cybersecurity engineering services, including conducting both deep-dive TARA at the electronic control unit and vehicle function level, and cybersecurity controls across hardware, communication layers, and partner integrations. Following implementation, security is formally validated through specification-based testing, fuzz testing, and penetration testing to prove the system holds under real attack conditions.

Once vehicles are deployed, operating services provide continuous runtime protection through vulnerability management, software components tracking for known vulnerabilities, and a live security operations capability maintenance that can detect and respond to incidents across the connected fleet.

The company also applies an AI-first engineering approach through FleziPT, a platform designed to bring AI from experimentation into production with enterprise-grade deployment. These disciplines include data readiness, model integration, and operational monitoring—supporting consistency and efficiency across engineering and verification workflows as automotive software systems scale in size and complexity.

This approach is reflected in the company’s delivery across ECU-level projects, where cybersecurity controls, secure communication, and system validation are implemented and verified in alignment with development and operation requirements. For a global Tier‑1 automotive supplier developing next‑generation road test software for the European market, FPT carried out continuous real‑world validation, with daily testing spanning approximately 250 kilometers across diverse driving environments. This helped identify critical defects affecting vehicle safety, advanced driver-assistance systems behavior, and charging reliability, while establishing a standardized and scalable testing framework that supports consistent validation and readiness for EU‑market requirements.

In another case, an Asia‑based semiconductor IC design company partnered with FPT to accelerate its software enablement. FPT developed multiple AUTOSAR-compliant MCAL modules within an accelerated delivery window and reduced overall development time by over 30%, enabling the client to advance its automotive chip roadmap ahead of schedule. These projects demonstrate how cybersecurity is integrated into broader engineering efforts, ensuring both functional reliability and system resilience under real-world conditions.

Standards‑driven security and quality assurance

FPT’s engineering delivery is reinforced by adherence to globally recognized automotive security and safety standards. The company holds ISO/SAE 21434 certification for vehicle lifecycle cybersecurity, and TISAX level 3 security label, supporting its role within security‑critical automotive supply chains. Combined with ISO 26262 functional safety standards, A-SIL (A/B/C/D) coverage and Automotive SPICE Level 3, these credentials reflect FPT’s readiness to meet the stringent security requirements of the global automotive market.

Partnership‑led cybersecurity

FPT’s cybersecurity capabilities are strengthened through a partner ecosystem spanning the AIDV security stack. Collaboration with FESCARO enables joint delivery of automotive cybersecurity services, including threat analysis, security testing, and SDV consulting—initially in South Korea and expanding globally. Through collaboration with over 150 leading OEMs, Tier‑1 suppliers, and chipmakers, FPT operates across the full breadth of the automotive value chain.

Future-ready and scalable talent pipeline

FPT’s security experts successfully exploited in-vehicle infotainment vulnerabilities, winning over 13,000 USD at Pwn2Own Automotive - global hacking competition

FPT brings more than two decades of automotive engineering experience to every project, supported by approximately 5,000 dedicated automotive software engineers and over 30,000 AI‑augmented engineers across the enterprise. This capability is reinforced by long‑term investment in talent development through the Automotive Software Engineering Department at FPT University, cultivating a pipeline of engineers trained specifically for software‑defined and AI‑enabled vehicles.

The Road Ahead: Security as Strategy

As vehicles evolve into AIDV platforms, cybersecurity becomes a determinant of scalability, trust, and long‑term competitiveness. Automotive leaders that embed security into system architecture, engineering decisions, and operating models from the outset are best positioned to scale innovation safely. By combining secure‑by‑design thinking, AI‑enabled execution, and disciplined alignment with automotive standards, FPT approaches cybersecurity as a strategic capability that enables AIDV vehicles to move faster, scale safely, and operate with confidence across global markets.