Cybersecurity: a key issue in the automotive industry
Cyber security is a new challenge for everyone involved in the industry. This sector remains particularly vulnerable, not only because it is part of a chain of multiple players, but also because it generates and exchanges huge amounts of data.
As digitalization increases, so do the threats to all links in the supply chain. Geolocation of vehicles, administrative and regulatory monitoring of drivers, vehicle maintenance and all data exchanged are potential targets for cyber-attacks, hacking and theft. The consequences can be catastrophic for professionals in the industry.
The emergence of networked and autonomous vehicles or intelligent goods exacerbates the threats. Modern transportation is becoming increasingly computerized and is therefore exposed to the risk of cyberattacks. Vehicles are increasingly program-controlled, networked and semi-autonomous.
For this reason, manufacturers and equipment suppliers like ACTIA take system security very seriously. We have developed a holistic approach that integrates cyber security into the life cycle of its products intended for vehicles. In this way, the Group is helping to limit the risks of successful cyber attacks on vehicles.
ACTIA is ideally equipped for norms and standards in the field of cyber security
ACTIA participates in the development of ISO/SAE 21434 standards on cyber security for road vehicles and UNECE WP29 regulations on cyber security and software updates for road vehicles. The group’s experts represent ACTIA in global standardization communities and are involved in the development of standards.
ACTIA is thus prepared to take the latest standardization requirements into account in the design process of its products and to offer its customers products and services that comply with the latest standards.
ACTIA IME is TISAX certified
With TISAX (Trusted Information Security Assessment Exchange), the ENX Association supports the common acceptance of information security assessments in the automotive industry on behalf of the VDA.
The TISAX assessments are carried out by accredited assessment service providers who provide proof of their qualifications at regular intervals. TISAX and TISAX assessment results are not intended for the general public.
ACTIA IME GmbH attaches great importance to the confidentiality, availability and integrity of information . We have taken extensive measures to protect sensitive and confidential information. We therefore follow the information security questionnaire of the German Association of the Automotive Industry (VDA ISA). The audit was carried out by an audit service provider, in this case the TISAX audit service provider DEKRA. The result is only available via the ENX portal:: https://portal.enx.com/en-us/TISAX/tisaxassessmentresults

ACTIA is ISO 27001 and TISAX certified
ACTIA’s branch in France is ISO 27001 and TISAX certified.
Other branches in Spain, Belgium, Tunisia and the USA are ISO 27001-certified or in the process of certification. ISO 27001 certification measures and the introduction of various cyber security standards, in particular ISO/SAE 21434, are carried out jointly by optimizing synergies and exchanging opportunities.
Design, development & production of communication products in the networked environment
The pandemic has accelerated the digital transformation that has been underway for several years. Among the various sectors of the economy, manufacturing with its factory of the future is particularly affected by this transformation. This new vision for the industrial sector opens up opportunities driven by significant technological advancements: more highly automated and connected factories, the proliferation of sensors, robots, and cobots, the cloud, real-time data processing, machine learning, and artificial intelligence. These are the technologies that give shape to the IIoT—the Industrial Internet of Things—and make the factory of the future a reality.
This development necessitates another: With the proliferation of IT systems alongside OT systems (Operational Technology, industrial facilities), industrial systems are increasingly exposed to cyber threats. ACTIA, an industrial company, has mitigated these risks by implementing a comprehensive approach and solutions to secure its entire ecosystem (infrastructure, onboard systems, personnel, third-party providers, etc.).
Beyond the technical security aspects of the ACTIA production environment, addressing these challenges requires a broader view of cybersecurity at the level of business processes, people, supply chains, etc.
The ACTIA Group has committed itself to treating cybersecurity as a prerequisite for the success of its factory of the future and as a guarantee of the reliability of its onboard systems.
ACTIA integrates security into its organization
Dedicated Information Security Management System (ISMS) Team
This multidisciplinary team manages the company’s information, data, and physical security—from procurement to human resources to development, maintenance, and so on. These experts define, implement, review, and improve the information security policy.
Experts in Safe and Secure Products
This team ensures that cyber security is properly considered from the beginning to the end of the design, development and manufacturing cycle of the products offered by the Group. But that’s not all: ACTIA also supports its customers in protecting themselves against cyber security risks, particularly with regard to its telematics products. For example, the TGU-R telematics unit, which is aimed at the truck, bus and specialty vehicle market, comes with a “Cyber Security Manual”. This manual enables customers to develop their applications independently and in accordance with product safety restrictions.
ACTIA relies on a cybersecurity coordinator
For each project, ACTIA appoints a dedicated cyber security project manager who acts as a point of contact for cyber security issues. He/she organizes the joint work on risk assessment and compliance with current requirements. He/she supports in the definition of threats and product security objectives.
ACTIA integrates cybersecurity into every stage of the product and service lifecycle
The ultimate goal is to assess and address cybersecurity risks. ACTIA has implemented a security risk assessment methodology based on ISO SAE 21434, which helps identify and reduce the extent of cybersecurity risks. By applying this methodology throughout the entire lifecycle, ACTIA ensures that risks remain acceptable at all times.
Through continuous collaboration with our customers, we are able to integrate a holistic approach focused on cybersecurity risks into all of our products and services and throughout the entire vehicle lifecycle: from design to end-of-life. ACTIA is able to apply ISO SAE 21434, the new global technical standard for cybersecurity, to automotive projects.
In this way, the Group helps its customers demonstrate that their vehicles comply with UN cybersecurity regulations for road vehicles. ACTIA has experience certifying products according to the Common Criteria for Information Technology Security (ISO 15408) up to EAL4+ level.
Cybersecurity step by step
1. in the tendering phase
ACTIA can support customers in defining their cyber security strategy.
It can provide a secure product architecture and security concept that meets all customer requirements, including those imposed by regulations or standards (e.g. GDPR, UN-ECE regulation, ISO SAE 21434).
2. design & development
ACTIA can strengthen its product development efforts with the activities and documentation provided in ISO SAE 21434.
The group is currently mapping cyber security activities and requirements in the product design and development process. This enables the integration of cyber security into all other disciplines and the establishment of best practices in this area.
3. after development
The security of the production environment is also part of ACTIA’s expertise and the production plant in Colomiers (France) has been ISO 27001 certified since 2018.
Under a contractual framework, ACTIA is able to maintain the cyber security of its products throughout their use by monitoring the state of cyber security, analyzing vulnerabilities and responding to incidents.
Cybersecurity in ACTIA Products: Defense in Depth
As early as the design phase, ACTIA products can be planned to include measures that strengthen the cyber security of the system, including:
- Authentication and integrity check of the software at startup,
- Storage of encryption keys, generation of random numbers,
- Communication encryption,
- Secure software updates,
- Mutual authentication between the product and remote servers.

