A self-driving car.

Your car is a computer on wheels. Israel is telling drivers how to protect it

The Transportation Ministry's new guidelines outline how attackers could track vehicles, steal personal data or interfere with vehicle functions, while setting new cyber requirements for the automotive industry.

After a long wait, the Ministry of Transportation is publishing, for the first time, recommendations for the public on protecting vehicles against cyber incidents, alongside guidelines for garages and service chains on defending against cyberattacks. As cars become increasingly connected, manufacturers and customers are exposed to attacks that could disrupt vehicle operations as part of a terrorist attack or ransomware campaign. The attack can come from several directions, ranging from an over-the-air (OTA) software update to an electric vehicle's charging station.
The recommendations for the public amount to a basic cyber defense guide for developing habits that can reduce the risk of attacks. According to the document, there are four main entry points for malicious actors: the multimedia system, which can be exposed through the installation of files and applications; the OBD connection, the physical diagnostic port found in modern vehicles that allows a mechanic to connect a laptop; the smart key, which can potentially be copied; and wireless communications such as Wi-Fi and Bluetooth.
1 View gallery
מבחן רכב אורה 5
מבחן רכב אורה 5
A self-driving car.
(Photo: Tal Saar)
Drivers are also advised to check every two weeks whether an unfamiliar Bluetooth device has been added to the list of devices connected to the vehicle, and to disable, where possible, the hotspot functions found in modern cars.
The Ministry of Transportation also urges drivers to pay attention to "unusual behavior" by the vehicle, such as a system turning on by itself or unfamiliar notifications appearing on the display.
In cases where the multimedia system requires a permanent connection, the public is advised to set a fixed password and ensure that it is difficult to guess or crack.
Before selling a vehicle, the ministry recommends deleting saved destinations from the navigation system, as well as contacts and call logs, and unpairing Bluetooth devices.
For OTA updates, software updates used, among other things, to upgrade vehicle systems and software versions, the recommendation is to install them as soon as possible, using only a trusted source and the vehicle manufacturer's official app.
For smart keys, the ministry recommends storing the remote away from the entrance door or keeping it in a signal-blocking pouch.
Recommendations for car importers: monitor suppliers, rank risks
Alongside the recommendations for the public, the ministry is publishing expanded recommendations for importers and garages, building on initial guidelines issued last year.
Under the new guidelines, car importers will be required to prepare a corporate cyber policy document and update it annually. They will also appoint a cyber protection officer who is either a company employee, a member of management or reports directly to a member of management.
Importers will also establish a cyber protection steering committee that will meet twice a year and present work plans in the field. The committee will map the organization's assets, including applications, software, infrastructure, hardware and its up-to-date network architecture.
Every 18 months, the organization will conduct a technological risk assessment and examine potential avenues for cyber intrusion. The procedures and findings will be reported to the cyber unit at the Ministry of Transportation.
The guidelines also place greater emphasis on the automotive supply chain. Importers will be required to address risks associated with parties that have remote access to information systems, technical support providers, suppliers that store or process company information, service providers, equipment suppliers and suppliers with physical access to company facilities.
Suppliers will be ranked according to their level of risk, while contracts with suppliers will now include cyber protection requirements.
Importers and garages will also be required to follow a range of procedures governing connections to customers' vehicles. Connections made at garages, as well as connections made through apps used by importers to schedule garage appointments, will be subject to guidelines set by the importer's cyber protection officer.
The growing importance of vehicle cybersecurity is not limited to the risk facing individual drivers. Major automakers are investing significant resources in protecting vehicles against hacking attempts that could potentially cause hundreds of millions of dollars in losses if large numbers of vehicles were compromised.
In Israel, there is an additional security dimension. A cyberattack that disabled a large number of vehicles on a major traffic artery could cause significant disruption to transportation and the wider economy.
Most vehicle importers in Israel had already begun preparing for the issue last year, when the ministry published its initial recommendations. The latest documents expand those guidelines and, for the first time, provide the public with a dedicated set of recommendations for reducing the cyber risks associated with increasingly connected vehicles.