A few years ago, the idea that someone could use a mobile application to interfere with a moving vehicle would have sounded like science fiction. In July 2026, India was confronted with a very different reality. The government disclosed that CERT-In had received reports involving certain low-cost electric three-wheelers where publicly available battery-management-system applications could potentially be used to switch off a vehicle while it was moving. The vulnerability was linked to Bluetooth modules that could have default or no credentials, allowing unauthorised access to battery settings.
The incident did not involve an expensive autonomous car or an experimental technology. It involved e-rickshaws – one of the simplest, most affordable and most visible forms of everyday mobility in India.
When software can stop a moving vehicle, cybersecurity is no longer only about protecting data. It is about protecting people.
That is why automotive cybersecurity can no longer be treated as an issue confined to premium connected cars or the IT department of an automobile company. It is increasingly a question of road safety, consumer trust, product liability and industrial competitiveness.
The car is becoming a connected computing platform
The modern automobile is a network of electronic control units, sensors, cameras, telematics systems, infotainment platforms, mobile applications, cloud services and, increasingly, charging interfaces. Connected features, ADAS, telematics and software-enabled functions are steadily moving from premium vehicles into mainstream products.
The benefits are substantial: better safety, predictive maintenance, remote diagnostics, navigation, convenience and continuous product improvement. But every new digital connection can also create another possible entry point for a malicious actor.
A vulnerability may originate in an ECU, the in-vehicle network, a Bluetooth interface, a mobile application, a cloud API or an insecure over-the-air software-update mechanism. In electric vehicles, charging infrastructure and battery-management systems add further digital interfaces. The supply chain adds another layer because a modern vehicle may contain software, semiconductors, sensors and electronic systems sourced from dozens of suppliers.
Cybersecurity, therefore, cannot be bolted onto a vehicle after development. It has to be engineered into the product from the beginning.
From mechanical recalls to digital recalls
Traditionally, a vehicle recall has been associated with a mechanical, electrical or manufacturing defect. Tomorrow, a vulnerability in software could potentially require the equivalent of a digital recall across thousands – or even millions – of connected vehicles.
And unlike a conventional defect, the risk may continue to evolve after the vehicle has left the factory. A newly discovered software weakness, compromised credential or vulnerable third-party component can create exposure years after a vehicle is sold. This changes the industry’s responsibility from securing a product at launch to managing security throughout its lifecycle.
India’s regulatory direction is becoming clear
India is moving towards a regulatory architecture for this transition. AIS-189 addresses Cyber Security Management Systems, while AIS-190 addresses Software Update Management Systems, broadly aligned with the principles of UNECE Regulations 155 and 156. ISO/SAE 21434 provides an engineering framework for managing cybersecurity risk across the vehicle lifecycle.
As India’s type-approval framework evolves, implementation and applicability will need to be read carefully against final government requirements and timelines. But the direction for industry is unmistakable: cybersecurity is becoming part of vehicle engineering, validation, software governance and lifecycle management.
A Cyber Security Management System is not simply a compliance document. It requires an organisation to identify threats, assess risks, assign responsibilities and manage cybersecurity through development, production and post-production. Similarly, a Software Update Management System is not merely an OTA facility; software must be authenticated, traceable, validated and securely deployed.
The next challenge is continuous security
As software-defined vehicles become more common, the traditional model of selling a vehicle whose specification is largely fixed at the factory is changing. Vehicles can increasingly receive new functions, improvements and fixes through software. That creates enormous opportunity, but it also means security responsibility does not end at the factory gate.
India will need stronger vehicle-security operations capabilities that can identify emerging threats, analyse relevant telemetry, coordinate incident response and work with engineering teams on remediation. Responsible vulnerability-disclosure mechanisms also need to mature so that genuine weaknesses can be reported, assessed and fixed quickly.
There are encouraging signs. Collaborations involving automotive testing and research institutions, academia and technology organisations are building domestic capability in automotive cybersecurity, testing and certification. This matters because India cannot aspire to be a global automotive engineering centre while remaining dependent on imported cybersecurity capability.
India needs automotive cybersecurity professionals
This may ultimately be the most important challenge – and opportunity.
India does not merely need more cybersecurity professionals. It needs automotive cybersecurity professionals.
We have built one of the world’s largest software talent pools, but automotive cybersecurity demands an unusual combination of capabilities. An engineer must understand both the vehicle and the threat.
We need embedded-security specialists who understand ECUs, secure boot and vehicle networks; ethical hackers familiar with automotive protocols; software engineers trained in secure coding; vehicle-security analysts; security-operations professionals; and engineers who can connect functional safety with cybersecurity.
This is where skilling institutions have a direct responsibility. At the Automotive Skills Development Council, we see that the future automotive workforce can no longer be divided neatly into mechanical, electrical and IT categories. Those boundaries are disappearing. The technician, engineer and software professional of the next decade will increasingly need interdisciplinary capabilities.
Four priorities for India
• Design security in, not on. Threat analysis, secure architecture, secure software development and vulnerability management must begin at the concept stage rather than becoming a final-stage testing exercise.
• Secure the entire supply chain. An OEM’s cybersecurity is only as strong as the weakest connected component, software dependency or supplier interface. Capability must therefore reach Tier-1 and Tier-2 suppliers, engineering partners and technology vendors.
• Protect the vehicle throughout its life. Manufacturers need mechanisms for vulnerability monitoring, incident response, responsible disclosure, secure updates and controlled remediation long after the vehicle has been sold.
• Treat cybersecurity skills as industrial capability. India needs accessible testing infrastructure, stronger industry-academia collaboration, workforce certification and practical training that teaches people how a cyber vulnerability can become a safety event on an Indian road.
From compliance to global opportunity
The e-rickshaw example should be a wake-up call, not a cause for alarm. It demonstrates that cybersecurity risk can emerge anywhere – including in simple and cost-sensitive mobility products.
India’s strength has always been its ability to engineer for scale and affordability. We now need to add security to that equation.
With our engineering talent, software industry, manufacturing base and enormous vehicle market, India has an opportunity to do more than comply with global automotive cybersecurity expectations. We can build capability in secure automotive software, cybersecurity engineering, testing, certification and skilled human capital – and potentially serve the world from India.
The automobile of the future will be defined as much by its software as by its steel, battery or engine. In the mobility of tomorrow, protecting the code will ultimately mean protecting the person sitting inside the vehicle – and everyone sharing the road with it.

By Vinkesh Gulati, Chairperson Automotive Skills Development Council (ASDC)


















