07 Jul The Hidden Risk of Automobile Cyber Exposures
In the past, auto exposures included collisions, theft, and weather damage. Now, there is a new exposure: cyber risk. Vehicles are now connected, software-driven machines, and individuals and businesses face risks that insurance and risk management approaches weren’t designed to handle.
Today’s vehicles are essentially computers on wheels. They are connected to smartphones, cloud platforms, and other vehicles through telematics systems, mobile apps, Bluetooth, and over-the-air (OTA) updates. Although these features improve convenience and safety, they also expand the horizons for cybercriminals.
The most obvious exposure is vehicle theft using technology. Thieves can capture a key fob signal and unlock and start a car without ever touching the key. Other threats include unauthorized access to vehicle apps, which allows cybercriminals to track, unlock, or even disable a vehicle remotely. In addition, cars now store sensitive personal data such as contacts, messages, and navigation history, which creates a privacy risk if systems are compromised or the vehicle is sold without deleting data.
Cybercriminals can also exploit vulnerabilities in vehicle systems to manipulate steering, braking, or acceleration. These events are rare, but the potential severity is significant. If a cyber event leads to an accident, was it driver error, a manufacturer defect, or a failure to keep software up to date?
Personal auto policies generally respond to the outcome of a loss, such as theft or physical damage, but not the cyber cause itself. Personal cyber insurance provides protection against identity theft, data recovery, and cyber extortion, but it typically does not cover system failures.
The cyber exposure for businesses is even more complex. Organizations such as delivery services, contractors, logistics firms, or rideshare operators depend on connected vehicle systems. An attack targeting software could immobilize vehicles, disrupt routes, and halt operations entirely. This is a significant business interruption risk.
The liability exposure is also increased. If a compromised vehicle causes bodily injury or property damage, plaintiffs could argue the business failed to secure its systems. Also, vehicles often collect data on customers, employees, and routes. A breach involving this data could trigger regulatory obligations under laws such as the California Consumer Privacy Act or even the General Data Protection Regulation for companies with international exposures.
Traditional commercial auto and general liability policies were not built with the cyber risk in mind. As a result, businesses must look closely at cyber liability policies to address gaps. However, not all policies contemplate operational technology, making careful policy review essential.
Risk management for cyber exposures requires a proactive approach. Individuals should use strong passwords for vehicle apps, update software regularly, and take steps to prevent keyless entry theft. Businesses should have vehicle cybersecurity protocols, do background checks on technology vendors and networks, and develop incident response plans.
ISO has developed the CA 04 65 01 24 Auto Hacking Expense Coverage Endorsement. There is a Personal Auto 2026 Multistate enhancement for the ISO PAP underway. Some PAP insurers use proprietary forms, and some provide a combination of ISO and proprietary wording. You need to ask your carriers if they will offer the coverage.
Automobile cyber risk is not a future concern — it’s here now. Understanding and addressing these risks will be critical for both personal and commercial insureds.