Insights & Resources
Mobility cybersecurity articles
Practical guidance from the Cyber Mobility Shield team on R155/R156, ISO/SAE 21434 work products, supplier assurance, TARA, and vehicle network security — written for OEM and supplier practitioners.

UN R156 and SUMS: Making Software Updates Homologation-Ready
What a Software Update Management System must prove under UNECE UN R156 — update integrity, RXSWIN traceability, delivery controls, and the post-production loops OEMs need before type approval.
Read article
ISO/SAE 21434 Work Products That Survive Audit
Which cybersecurity work products auditors and technical services actually use — from item definition and TARA through cybersecurity goals, requirements, integration testing, and post-development evidence.
Read article
Supplier Cybersecurity Assurance Beyond Questionnaires
How OEM and Tier-1 teams move from supplier self-attestation to technical assurance — risk-tiering, contractual flow-down, evidence requests, and verification for ECUs, stacks, and connected services.
Read article
Understanding UN R155: What Automotive OEMs Need to Know
A practical breakdown of UNECE WP.29 UN R155: what a Cybersecurity Management System must demonstrate for type approval, how it connects to ISO/SAE 21434, and where OEM programs usually fall short.
Read article
TARA in Practice: A Step-by-Step Walkthrough
A practitioner walkthrough of Threat Analysis and Risk Assessment for an automotive ECU — from asset identification and damage scenarios to attack paths, risk rating, and treatment decisions that hold up in review.
Read article
CAN Bus Security: Attack Vectors and Defenses
A technical look at Controller Area Network attack patterns — injection, replay, spoofing, and denial-of-service — plus practical defenses and how findings should feed TARA and verification work.
Read article