Skip to content
LIVE
The Executives BriefThe Executives BriefBeta

Over-the-air autos expand attack surface, analysts warn

As cars get more software updates over the network, cybersecurity risk grows, forcing boards to treat OTA as critical infrastructure.

ByLama Al-RashidTechnology Correspondent, The Executives Brief
·3 min read
Over-the-air autos expand attack surface, analysts warn
Executive summary

Analysts say the automotive industry is increasingly using over-the-air technology, making vehicles more susceptible to cyberattacks. For decision-makers, that shift raises governance and risk-management stakes because updates and connectivity become part of the security perimeter.

Cars used to behave like appliances. Now they behave like computers on wheels, and analysts are concerned that the same over-the-air technology that improves convenience also expands the opportunity for cyberattacks.

The core issue is straightforward, and it is already showing up in how people think about auto cybersecurity. As the automotive industry increases its use of over-the-air (OTA) capabilities, analysts say it becomes more susceptible to cyberattacks. OTA is not just a feature that delivers smoother user experiences. It also creates an always-on digital channel into the vehicle, which changes the shape of risk.

To understand why analysts are focused on OTA, you have to zoom out to how the modern car is built. Today, the vehicle is typically a collection of software systems that can be updated after sale. That makes it possible to patch bugs, add features, and fix issues without sending every car back to a shop. That is the upside. The less comfortable reality is that if the update mechanism is compromised, attackers can attempt to interfere with or manipulate what gets installed, when it gets installed, and what code runs inside the car.

This is where governance and board-level attention come in. OTA shifts cybersecurity from something that mostly happens during initial development to something that continues throughout the life of the vehicle. That means the risk does not end at the factory line. It follows the product into the field, where software is updated over networks and the system landscape can vary by region, connectivity conditions, and customer usage patterns. For executives, that creates a moving target: security has to stay current as the software changes.

There is also a market reality behind the analysts' warning. The automotive industry has strong incentives to ship cars that can evolve after purchase. OTA reduces friction for both automakers and customers, and it can be a major lever for delivering improvements faster than traditional recall processes. But incentive and infrastructure rarely sit in separate boxes. When a company leans into OTA, it has to treat the operational systems that deliver updates as part of its core safety and reliability responsibilities.

Regulatory and compliance framing matters here too, even if this particular CNBC piece is focused on analysts rather than a specific rule. Across industries, regulators tend to care about two things: whether you prevent harm and whether you can respond when something goes wrong. OTA changes both. You need preventive controls that reduce the chance of unauthorized access to update paths, and you need response capabilities that can limit damage if an update system is attacked. In practice, that often pushes organizations to strengthen monitoring, incident response planning, and auditability for software delivery pipelines.

Second-order implications follow quickly once OTA is treated like a security perimeter. Boards may have to ask harder questions about vendor and supply-chain exposure, because OTA systems are frequently connected to backend infrastructure, cloud services, and third-party components. They may also need to revisit how they evaluate risk across the whole lifecycle, not just at product launch. In many companies, cybersecurity accountability can become fragmented across product teams, platform teams, and IT operations. OTA compresses those boundaries, and that can create failure points if responsibilities are not clearly owned.

For peers in similar roles, the stakes are not abstract. If analysts are right that increasing OTA use makes autos more susceptible to cyberattacks, then companies that move faster on OTA adoption need to match that speed with security maturity. Otherwise, the same mechanism that delivers updates can also become the easiest path for an attacker to try to reach into cars after they are already in customers' driveways. The strategic takeaway is that OTA is no longer just a software roadmap item. It is an enterprise risk issue that boards and senior leaders should treat with the same seriousness as any other high-impact system that can affect safety, reliability, and customer trust.

Executive ActionsLocked

This story's Key Insights and Take-aways are locked.

Create a free account to unlock Executive Actions for one credit.

Register to Unlock

Always free for Executives Club members. Join the Club

More in Technology