Israel Issues Guidelines to Protect Vehicles from Cyberattacks
Israel's Ministry of Transport has released its first comprehensive set of recommendations for the public on how to defend against cyberattacks targeting vehicles, alongside guidelines for garages and service networks on protecting themselves from offensive cyber incidents. The ministry highlighted that both car manufacturers and consumers are vulnerable to malicious actors who could disrupt vehicle functions for purposes ranging from terror attacks to ransomware demands. Potential entry points for these attacks include over-the-air (OTA) updates, electric vehicle charging stations, the multimedia system, the physical OBD diagnostic port, smart keys, and wireless connections like Wi-Fi and Bluetooth.
The public guidelines aim to foster safe habits to minimize cyber risks. The ministry warned that attacks could lead to vehicle location tracking, eavesdropping within the car, and personal data leakage. Specific recommendations include avoiding the installation of unapproved external accessories, limiting the connection of devices like USB drives, ensuring multimedia system connections are authenticated, and being cautious with insurance monitoring systems. Drivers are advised to regularly check for unfamiliar Bluetooth devices and disable car hotspots when not in use. They should also be vigilant for unusual vehicle behavior, such as systems activating on their own or unexpected messages. For vehicles requiring a persistent connection to the multimedia system, setting a strong, unique password is recommended. Before selling a vehicle, users should delete saved navigation destinations, contacts, call logs, and Bluetooth pairings.
For OTA updates, the ministry urges users to perform them promptly from trusted sources, exclusively through official manufacturer applications. Regarding smart keys, it's advised to store remote controls away from the entrance door or use signal-blocking pouches. The ministry also issued recommendations for vehicle importers and garages, building on initial guidelines from the previous year. Importers are required to establish an annual cyber defense policy, appoint a dedicated cyber protection officer, and form a steering committee for cyber defense that meets semi-annually. This committee will map organizational assets and conduct technological risk assessments every 18 months, reporting findings to the Ministry of Transport's cyber unit. Importers must also manage their supply chain, assessing and ranking suppliers based on risk, and incorporating cyber defense requirements into supplier contracts. Garages and importers must adhere to specific procedures for connecting to customer vehicles, whether physically or through applications, under the guidance of their appointed cyber officials.
The ministry stressed the critical importance of vehicle cybersecurity, noting that major manufacturers invest heavily in defenses to prevent attacks that could cost them hundreds of millions of dollars. In Israel, a large-scale cyberattack disabling numerous vehicles on major roadways could also inflict significant economic damage.