Connected

Connected

Korea-US-Global Briefing

Saturday August 22, 2026

Cadence: Briefing Mon-Fri, Sunday Week in Review, plus special updates most Saturdays.


In this week’s Saturday Update, I’d like to share a partial preview of my work in progress, “Connected.”

Chapter 1 focuses on the connected vehicle architecture. Other chapters, so far, include semiconductors, AI, robotics, shipbuilding, steel, and batteries, all tied to the “Connected” theme.

Again, this is only a partial of my first draft. That said, it does share my thought process.

Enjoy.


CHAPTER 1

Connected Vehicles

A “connected car” is defined as any vehicle with a network connection linking it to external systems: the OEM cloud, mobile apps, other vehicles (V2V), and road infrastructure (V2I).

Architecture Basics

The core components are:

  • Telematics Control Unit (TCU). The vehicle’s cellular modem and gateway to the outside world.
  • In-vehicle network. The Controller Area Network (CAN bus) is a specialized internal communications network. It allows microcontrollers and Electronic Control Units (ECUs) to talk to each other directly, without a central computer, over the Ethernet linking the ECUs for engine, brakes, infotainment, and ADAS.
  • Over-the-air (OTA) update system. Pushes software and firmware to ECUs remotely.
  • Backend cloud platform. OEM servers handling data, diagnostics, and app connectivity.

Software Update Management System (SUMS)

The core requirements are:

  • A certified SUMS process covering the full update lifecycle: development, validation, deployment, and rollback.
  • RXSWIN (RX Software Identification Number), a traceable ID confirming which software version is installed.
  • Safe update delivery. Updates must not compromise safety-critical systems, even if interrupted mid-update.

Cybersecurity Management System (CSMS)

What OEMs must demonstrate:

  • A certified CSMS covering the full vehicle lifecycle: design, production, and post-production in-service monitoring.
  • A risk assessment process for identifying and mitigating cyber threats before type approval.
  • Incident monitoring and response, meaning the ability to detect and react to cyberattacks on vehicles already on the road.
  • Supply chain oversight, verifying that supplier components meet the same cybersecurity bar.

Risk

Every one of the connection points above is also an attack surface. Connected vehicles face threats similar to any networked IT system, but with physical safety consequences.

Key risk categories:

  • Remote exploitation. An attacker gains control via the TCU, infotainment, or app APIs.
  • Supply chain risk. Vulnerable components or software from Tier 1 and Tier 2 suppliers.
  • OTA update hijacking. Malicious or corrupted software pushed to fleet vehicles.
  • Data privacy. Location, driving behavior, and biometric data exposure.

The Global Compliance Landscape: R155 and R156

More connectivity also means more regulatory exposure.

Regulators responded with two linked UN regulations: R155 on how you manage cyber risk, and R156 on how you manage software updates safely. Together they are now a precondition for vehicle type approval in many major markets.

More specifically, R155 requires a certified, organization-wide Cybersecurity Management System covering design, production, and post-production in-service monitoring, plus risk assessment, incident response, and supplier verification.

R156 governs how OTA and wired software updates are planned, deployed, and verified. It is the companion regulation to R155.

OEM Approaches

I am assuming the major vehicle manufacturers may be taking similar approaches, while maintaining their own proprietary oversight.

What is universal is how they look at the shared landscape: the links to external systems noted above, the OEM cloud, mobile apps, other vehicles (V2V), and road infrastructure (V2I), as well as V2G (Vehicle-to-Grid) and V2H (Vehicle-to-Home).

One example is Hyundai and their connected vehicle architecture and compliance.

Hyundai Motor Group is converging its connected vehicle effort on one in-house software brand (Pleos), one consolidated telematics unit (Mobis MTCU), and in-house certification through Hyundai AutoEver.

This vertical integration allows for greater oversight of the supply chain that R155 imposes on OEMs, as well as tighter internal governance.


Question Call Don 310-866-3777

Don Southerton
Founder & CEO, Bridging Culture Worldwide
www.bridgingculture.com

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.