IT/OT convergence in automotive manufacturing security

The plant, the backend and the vehicle are one attack surface — securing them as three silos is the gap

17 Jul 20265 min readAutoSifu

Three estates, one attack surface

For most of the history of manufacturing, information technology and operational technology were separate worlds. IT/OT convergence is the collapse of that separation: the enterprise network, the plant floor and — in automotive — the vehicle backend now form one connected system. An attacker who reaches any of the three can often reach the others, and a control that stops at the edge of one estate leaves the seams exposed.

In a vehicle programme the three estates are concrete. The IT estate is the corporate network and the vehicle backend — telematics servers, the update distribution platform, the customer-facing services. The OT estate is the plant: the manufacturing execution system (MES), the PLC and SCADA layer that drives the line, and the flashing and end-of-line stations that write firmware and provision keys into each ECU. The vehicle itself is the third estate, carrying the software and credentials that the first two produced and provisioned.

These are not three problems. They are one problem seen from three positions.

Where the seams are

The risk of convergence lives at the interfaces, not inside any single estate. A few recur across programmes:

  • Software distribution. The firmware that a plant flashing station writes originates from an IT build pipeline and is destined for a vehicle that will later receive over-the-air updates from an IT backend. The image crosses all three estates. If integrity is verified in one and assumed in the next, the assumption is the vulnerability.
  • Key provisioning. Signing keys and per-ECU credentials are generated and stored on IT/security infrastructure, then consumed at OT flashing stations. A key that is well protected in an HSM but exposed on a flat plant network has been undermined at the point of use.
  • Remote access. Line equipment is maintained by vendors who need remote connectivity. That connectivity is an IT-to-OT bridge, and it is a frequent route by which enterprise compromise reaches the plant floor.
  • Data historians and gateways. The systems that lift production data from OT to IT are, by design, dual-homed — and a dual-homed system is a conduit in both directions.
Estate Typical systems Governing framework Primary concern
IT / backend Corporate network, update platform, telematics servers Enterprise + product security, ISO/SAE 21434 Data, service availability, update integrity
OT / plant MES, PLC/SCADA, flashing and end-of-line stations IEC 62443 (zones, conduits, security levels) Process integrity, safety, key handling
Vehicle ECUs, in-vehicle networks, telematics unit UN R155 / ISO/SAE 21434 Firmware and credential integrity in the field

Why a CSMS cannot stop at the vehicle

UN R155 requires an approved cyber security management system that covers the vehicle across development, production and post-production. The word production is doing real work. A CSMS that documents secure design but treats the factory as out of scope has left the widest, least-watched access path — end-of-line diagnostic and programming access — outside its own boundary. We take this further in why the assembly line is in scope for a CSMS.

The convergence lens is what makes the production requirement tractable. You cannot secure the plant as a vehicle problem, because the plant runs on industrial control systems with their own standard — which is why IEC 62443 for the vehicle plant sits alongside R155 rather than inside it. Nor can you secure the vehicle as a plant problem, because a car in the field is monitored by a backend, not by a SCADA operator. The two disciplines meet at the interfaces, and it is the interfaces the assessor should be able to see traced end to end.

The monitoring consequence

Convergence also reshapes detection. An attack that begins as an enterprise phishing email, moves laterally to an OT remote-access jump host, and ends by tampering with what a flashing station writes is invisible to any single team watching a single estate. Post-approval, R155 expects the manufacturer to monitor for and respond to attacks across the fleet and its supporting infrastructure. That monitoring has to span the estates it is meant to protect — which is the argument for a vehicle security operations centre that ingests plant, backend and vehicle telemetry together, covered in building an automotive VSOC.

Getting the architecture right

Convergence is not solved by merging networks; it is solved by making the boundaries between them explicit and defended.

  • Segment deliberately. OT is organised into zones and conduits under IEC 62443. The IT-to-OT boundary is a conduit with a defined security level, not an accident of routing.
  • Verify integrity at every hand-off. The same signed image is checked when it leaves the pipeline, when a flashing station writes it, and when the vehicle boots it. Trust is re-established at each estate, never inherited.
  • Treat remote access as a primary control. Vendor and maintenance access into OT is brokered, logged and monitored, because it is the most common IT-to-OT bridge.
  • Instrument the seams. The interfaces — historians, gateways, distribution platforms — are where detection pays off, because they are where a cross-estate attack must pass.

None of this is exotic. It is the ordinary discipline of drawing trust boundaries and defending them — applied to a system that has quietly become one system while being managed as three.

The AutoSifu view

Most gaps we see are not in any one estate but in the seams between them, where IT security assumes the plant is handled and OT security assumes the vehicle is someone else's file. AutoSifu works one route — compliance, solutioning, and CoC/VTA support — with CIRT in the room, so the CSMS scope is drawn across the plant, the backend and the vehicle from the start, and the interfaces are traced rather than assumed. The approval body seeing that trace early is what keeps the seams from becoming findings.

Questions

What is IT/OT convergence in automotive?
It is the recognition that a manufacturer's information technology (enterprise IT, the vehicle backend) and its operational technology (the plant floor — MES, PLC/SCADA, flashing and end-of-line stations) are no longer isolated networks but a single, connected system. In automotive this extends to the vehicle itself, because the software and keys a vehicle carries are provisioned by plant OT and managed by IT backends. Securing the three as separate silos leaves the seams between them unguarded.
Why does the plant matter for vehicle cybersecurity?
Because the plant is where an ECU is flashed with firmware and provisioned with cryptographic keys before it ever leaves the line. An unsigned image accepted at an end-of-line station, or a signing key exposed on a poorly segmented OT network, is a fleet-wide compromise introduced at manufacture. UN R155 expects the cyber security management system to cover production, not only design.
How are IT and OT secured together?
By treating them as one architecture with defined trust boundaries rather than two disconnected estates. OT is governed under IEC 62443 (zones, conduits and security levels); IT and the vehicle backend under enterprise and product security processes; and the interfaces between them — data historians, remote access, software distribution — are explicitly designed and monitored. A CSMS assessment traces controls across all three.

09 — Start here

Bring us the file you are least sure about.

Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.

Direct

Jaipur · registered office

Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India

Required