Keeping Industrial Vehicles Secure in a Digital Landscape
CrossControl and other suppliers must continuously process, assess and identify platform vulnerabilities to prioritize and implement updates that protect systems from cyberattacks and data breaches.
Security researchers have demonstrated that the control systems in vehicles and machines are open to attack.
In 2010, researchers from the University of Washington and the University of California, San Diego demonstrated that by gaining physical access to a vehicle, they could manipulate critical systems like brakes and engines. Just a few years later, security researchers Charlie Miller and Chris Valasek remotely compromised a vehicle over the internet, controlling steering, braking and acceleration, leading to a 1.4 million vehicle recall.
In 2024, researchers at Colorado State University successfully demonstrated a wireless drive-by hack by exploiting vulnerabilities in common electronic logging devices (ELDs). In their proof-of-concept test, they achieved remote control over a truck by reflashing the ELD with malicious firmware, which allowed them to slow down a moving truck and show a design for a truck-to-truck worm virus that could theoretically spread through a fleet.
The rapid advancement of AI has enabled a new paradigm where AI systems themselves discover and weaponize vulnerabilities. In 2025-2026, security researchers demonstrated the use of generative AI frameworks and autonomous AI agents to proactively uncover and exploit zero-day vulnerabilities in connected vehicle architectures, including ECU firmware, CAN bus protocols and telematics systems used in industrial trucks and fleets.
In response to this progression in vulnerabilities, a safe and secure machine is becoming a requirement rather than a differentiating feature or value proposition.
Vulnerability management
New legislation over the past few years has drastically changed the landscape for the industry, with cybersecurity being one of the driving factors. In Europe, the legislation includes the new EU Machinery Regulation, Cyber Resilience Act (CRA) and the Radio Equipment Directive. In the United States, regulations and guidelines include the Internet of Things Cybersecurity Improvement Act and CISA Secure by Design. The majority of on- and off-highway vehicles have some level of electronic control system and need to rely on the integrity of that system for operation.
As with the introduction of the General Data Protection Regulation (GDPR) a few years ago, it will be some time before the exact interpretation of the rules will be understood. For example, on March 3, 2026, the EU published draft guidance to support the application of the CRA, open for comments until April 13, 2026. As this is an important step forward, it is also important to be clear and transparent about the current situation. At this stage, no company can reasonably claim that it – or its products – is compliant with the CRA standards. But as with GDPR, no company wants to be the first to face a $100 million fine or a 6-month prison sentence – both punishments handed out under GDPR within the first year of implementation.
Manufacturers must implement a secure-by-design approach from inception, through production and for the entire expected lifespan of the machine. Products must meet cybersecurity standards to be placed on the market. Manufacturers must have systems in place for vulnerability management, including reporting bugs and providing security patches. As part of this process, a software bill of materials (SBOM) is required as part of the documentation for a product.
Machine builders, system integrators and suppliers need to show they are addressing security risks in the machine system. This introduces the need for a new approach to electronic hardware, onboard computing and software platforms.
Enacting “secure by design”
CrossControl, a Swedish manufacturer of onboard computers for industrial vehicles, believes that the secure-by-design approach begins at the concept level, identifying the use cases and an appropriate risk assessment of the eventual device or machine. TARA (threat analysis and risk assessment) evaluates the risk for the specific vehicle use case and complements the requirements for that implementation with recommendations suited to that machine. This risk-based approach identifies the relevant security threats to the machine through threat analysis and modelling and then allows system designers to implement needed countermeasures.
Threat analysis and truly understanding the system/product and how it will be used (or misused) both now and in the distant future is essential to creating a secure solution. But as machines often operate in similar spaces and are at risk from the same factors, they can take advantage of a common base from which to build, reducing the need for costly customized solutions for every component.
At the electronic hardware level with Hardware Security Modules (HSM) built into the System on Chip, crucial security features such as secure boot can be enabled. This feature ensures system integrity for the entire software stack, prevents the loading of untrusted software during the computer’s startup process (by verifying the digital signatures of the operating system’s bootloader) and acts as a secure access point for applications and operations.
At the operating system level, security begins with set up and configuration. CrossControl can provide a security manual for its custom version of the popular operating system, CC Linux. This enables platform adopters to enable and disable security and system settings to create an OS that meets their needs and limits any attack vectors.
As anyone with a smartphone can attest, an operating system is not static once it is purchased – security updates are essential. This is the case not just for protecting messaging or banking apps but also for maintaining secure machines. But industrial vehicles operate in harsh environments with demanding schedules – being offline for a period is not a realistic option. To solve this challenge, OEMs should look for platforms that support silent and robust updates.
Silent updates download, verify and install the new release in the background, allowing the machine to continue normal operation. Robust A/B updates protect against sudden power losses, connectivity interruption or unexpected events, ensuring the machine remains operational and the issue can be solved by the system later. These features help facilitate security updates without inhibiting operation, which are necessary to comply with the incoming regulations.
Updates need to be managed by a secure update manager like RAUC (Robust Auto-Update Controller) for Linux systems. RAUC is a lightweight, open-source framework designed for secure and reliable software updates and uses cryptographic signatures to verify the integrity and authenticity of update bundles, making it suitable for critical systems where robustness and security are paramount.
Secure systems utilize keys to manage access. Public Key Infrastructure plays a significant role in the security of digital products by providing a framework for secure communication and data protection. Public Key Infrastructure ensures the integrity, confidentiality and authenticity of data through asymmetric encryption and digital signatures to manage trust, authenticate identities and secure data transmission, which are essential for maintaining cyber resilience.
CrossControl supports Secure Manufacturing signed operating system and software bundles, including customer signed versions that can be loaded during production with the secure software loading station.
Creating additional value
A secure system design, hardware to enable the features, an operating system configured to minimize risk – the journey leading to vulnerability management is not over. This applies to monitoring, prevention and mitigation. The CRA requires a software bill of materials that declares the inventory of components used to build a software application and is created from the exact load out of the system. SBOM tools are used to scan for Common Vulnerabilities and Exposures (CVE).
CrossControl and other suppliers must continuously process, assess and identify platform vulnerabilities, to prioritize and implement updates that protect systems from cyberattacks and data breaches. In the case of discovering zero-day critical vulnerabilities, CrossControl’s internal testing pipeline allows for a fully tested and signed software fix in a matter of hours.
OEMs and system integrators will navigate this new landscape with different levels of available resources and experience. With open platforms, a larger manufacturer with mature software solutions can start work with just the hardware and the available board support package (BSP), while other operations can take advantage of full chain support with application integration, signing and productization services available.
The onboard computing platform should be designed and built with security in mind, both from the hardware and software selection. OEMs and system integrators need platforms that offer tools and solutions from firewalls to secure updates, including extensive reports such as SBOM and code review protocols needed for audits and certification.
Software that is regularly updated, including security patches as well as meeting other newly introduced requirements, is a must. Moving to this approach with an updated, secure machine also unlocks opportunities to create additional value with machine intelligence, releasing new features and unlocking revenue streams.
Finn McGuirk, communications expert and technical educator, CrossControl , wrote this article for SAE Media Group.
Top Stories
INSIDERUnmanned Systems
Airbus, Boeing Reveal New Autonomous Aircraft Technologies at ILA Berlin 2026
INSIDERWeapons Systems
A Joint Laser Weapon System for Next Generation Drone and Cruise Missile Defense
NewsElectronics & Computers
Mercedes-AMG Unveils Racing-Inspired EV
NewsPower
We Ride Along in Slate's $25,000 Electric Pickup
Q&AManned Systems
Volvo Turns Attention to Vocational Trucks
NewsEnergy
Webcasts
Energy
Hydrogen & Alternative Fuels Summit 2026
Automotive
Engineering Extended-Range Hybrid Systems
AR/AI
Why Your Integration Stack Is Blocking Your AI Roadmap
Transportation
Hybrid-Electric Solutions for Off-Highway Vehicles
Aerospace
Why the Next Medical Breakthrough May Come from Space



