How Auto Supplier Harman Learned To Fight Cyber Carjackers

When researchers remotely hacked a Jeep Cherokee in 2015, slowing it to a crawl in the middle of a U.S. highway, the portal the hackers used was an infotainment system made by supplier Harman International. Harman, now part of Samsung Electronics, has since developed its own cyber security product, and bought Israel-based cyber security company TowerSec for $70 million to help it overhaul manufacturing processes and scrutinize third-party supplier software.
The expensive efforts have prevented another public breach and helped it become a key player in automotive cyber security, but they show the strain suppliers and automakers face in dealing with this new dimension of automotive technology.
"At the end of the day, automotive is a very competitive business with small margins. If a competitor wants to eat the cost to win the business, you have to do the same thing," said Geoffrey Wood, Harman's director of cyber security business development, who joined the company in late 2016.The automotive cyber security market has seen exponential growth. While global revenue was at around $16 million in 2017, it is expected to reach $2.3 billion in 2025, according to IHS Markit, driven by Harman, Garrett Motion Inc, German suppliers Continental AG, Robert Bosch and a range of smaller U.S. and Israeli companies.
Securing cars from hackers is a complex task for these companies. Modern vehicles run on 100 million lines of code, are equipped with hundreds of different technologies and can have up to 150 electronic control units using various operating systems.
Unlike consumer electronics, cars can stay in use for decades, long after operating systems and component software cease being supported through updates that patch vulnerabilities - a challenge the industry is still grappling with.
Automotive cyber security requirements now number in the hundreds of pages from just a page five years ago, according to interviews with a dozen automotive cyber security professionals.For its 2024 vehicles under development at BMW AG, for example, suppliers are required to ensure that driving system control units have no direct connection to customers' internet-connected devices, said Michael Gruffke, head of security system functions at BMW, which sources parts from Harman.
Small auto suppliers with thin profit margins are often the weakest link for hacks, said Rotem Bar, a cyber security professional until recently at Israeli company Cy Motive which has partnered with German automaker Volkswagen AG.
But automakers typically still hand off testing and ensuring the security of data systems to their subcontractors, industry experts said.
"It's really shifting the burden onto the suppliers because the automaker is not able to test and verify everything along the supply chain," said Dennis Kengo Oka, senior solutions architect at Synopsys Inc (SNPS.O), who conducts research on automotive cyber security.
At BMW, more than 70 per cent of the components in its vehicles are manufactured by suppliers. "We therefore must expect our partners to take responsibility for implementing cybersecurity in respective deliveries," the automaker said in a statement.General Motors (GM.N) said in a statement that it handles "a significant amount of work" related to security and testing without passing the expense to its supply chain partners.
Ford Motor Co and Fiat Chrysler did not respond to requests for comment. Volkswagen and Daimler AG declined to comment.
BUILDING CYBER SECURITY BUSINESS
Harman saw its Jeep hack experience as a viable business opportunity: the supplier today sells cyber security software that allows automakers to monitor their fleets and provide over-the-air software updates. Analysts at IHS Markit consider Harman one of the top players in that segment, with some 20 automakers using its over-the-air services.
Harman does not break out revenue for that business. But the company does try to recover some costs by charging higher prices for advanced security."We have to educate our sales people in conversations with carmakers' purchasing departments and say 'don't let this go without adding cyber security to your quote'," said Amy Chu, Harman's senior director of automotive product security.
Asaf Atzmon, the Israel-based vice president and general manager for automotive cyber security, said Harman has come a long way since he joined in March 2016 as part of the TowerSec deal.
At the time, Harman employed only some security architects, and the company later changed its organizational structure, appointing or hiring professionals such as Wood and Chu to oversee cyber security efforts, Atzmon said.
The changes helped Harman consider cyber security issues at every stage of the production process, creating a checklist for engineers that includes scanning third-party software for bugs, increasing Harman's own cyber security defences and creating a risk analysis of potential vulnerabilities for every component.
Instead of simply adding comfort features such as Bluetooth, for example, designers now first have to show how they would secure such a connection.A particular challenge is securing vehicles over their entire lifecycle, said Chu. Cybersecurity professionals are used to simply issuing software patches, but automotive engineers caution that only a fraction of vehicles can receive over-the-air updates.
During the Jeep hack, costly recalls had to be issued for 1.4 million vehicles to fix software flaws at dealerships. Tesla Inc, which offers over-the-air updates as a standard for even safety-critical functions, is so far the exception.
"Things are just not that easy for us in the auto industry," said Chu.
Conscious of the many challenges, the industry over the past years has come together in a rare show of collaboration. Automakers in 2015, soon after the Jeep hack, created a group to share threats and vulnerabilities and companies currently try to define industry-wide cyber security standards that in turn could lower costs to suppliers.
Still, common standards are not expected to be published before next year. And some of the standards might be watered down to protect smaller suppliers and ensure they have the resources to comply, said Victor Murray, a group leader at the Southwest Research Institute, which tests cars and components for cyber security vulnerabilities.
"You want to be careful and not box anybody in because if smaller suppliers get overwhelmed with mandates they're out of business," Murray said.
Latest News
Jaiveer Mehra | Jan 13, 2026Tata Punch Facelift Launched At Rs 5.59 Lakh; Gets Turbo-Petrol Engine OptionUpdated micro SUV gets revised styling, new features and a new turbo-petrol powertrain option.1 min read
car&bike Team | Jan 12, 2026Updated Royal Enfield Goan Classic 350 Launched: Gets Slip And Assist ClutchThe updated Goan Classic also gets a faster Type-C charging port.1 min read
Jaiveer Mehra | Jan 12, 2026Tata Punch Facelift Launch Tomorrow: What To ExpectUpdated internal combustion Punch gets a design in line with its larger siblings as well as a new engine option.3 mins read
Jafar Rizvi | Jan 9, 2026KTM RC 160 vs Yamaha R15: Specifications, Features, Prices ComparedKTM’s new RC 160 goes head-to-head with the Yamaha R15 in the entry-level sportbike category. Here is how the two fare on paper.1 min read
Amaan Ahmed | Jan 9, 2026Suzuki E-Access Launched At Rs 1.88 Lakh; LFP Battery Promises 95 KM RangeOriginally confirmed for a June 2025 launch, Suzuki's first electric two-wheeler for India has finally arrived almost a year after making its global debut at Auto Expo 2025.3 mins read
car&bike Team | Jan 9, 2026Kawasaki Ninja, Versys Models Offered With Discounts Of Up To Rs 2.50 LakhThe Ninja ZX-10R is offered with maximum benefits, followed by the Ninja 1100SX and Versys 1100.1 min read
Bilal Firfiray | Jan 9, 2026Toyota Urban Cruiser Hyryder: 10,000 km Long-Term ReviewAfter spending over three months and 10,000 km with the Toyota Urban Cruiser Hyryder Hybrid, we were impressed by its real-world mileage, seamless hybrid, practical comfort, and Toyota reliability. Is it the best C-SUV then?5 mins read
Seshan Vijayraghvan | Jan 8, 20262026 Mahindra XUV 7XO Review: Big On Tech, Bigger On ComfortThe new Mahindra XUV 7XO is flashier, feature packed, and comes with more advanced tech. But are the changes just incremental or actually substantial?1 min read
Preetam Bora | Jan 10, 2026Simple One Gen 2 First Ride Review: 265 km Claimed Range!The Gen 2 model of Simple Energy’s first electric scooter gets a fair few updates, including new features, tech, more range and lighter weight. We spent a couple of hours with the Simple One Gen 2 to find out if it manages to impress.6 mins read
Amaan Ahmed | Jan 3, 2026VLF Mobster 135 300 KM Review: Fun But FlawedA 125 cc scooter with Italian design and Chinese genes is a rare combination, and while some may be tempted to dismiss it because of its origins, the VLF Mobster shows 125s can also be exciting – but not without compromises.11 mins read
Preetam Bora | Dec 30, 2025TVS Orbiter Review: Real-World Performance and Range TestedThe TVS Orbiter is a promising electric scooter promising decent range, practicality and pricing. But is there any reason to avoid it? We spent a few days getting to know it better.9 mins read



















































































































