Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

I am The Cavalry issue open letter to automotive industry on car security

by The Gurus
August 11, 2014
in Editor's News
Share on FacebookShare on Twitter

Information security lobbying group and research collective “I am the Cavalry” has issued an open letter to the automotive industry informing them of software failings in cars.
 
The open letter calls for better car safety and for collaboration with the automotive industry specifically on  five key capabilities that create a baseline for safety relating to the computer systems in cars: Safety by Design and development of automotive computer systems with security in mind; Third-Party Collaboration to publish a clear vulnerability disclosure response policy that works with security researchers; Evidence Capture that may assist with an investigation should one be necessary; Security Updates to provide a mechanism for consumers to receive updates to computer systems quickly and easily as issues are found and fixed; and Segmentation and Isolation to ensure that issues in non-critical systems do not impact the performance of critical systems.
 
Tony Sager, chief technologist for The Council on cyber security, said: “I think the proposed framework clearly states important principles and intent in a plain, sensible and workable way. It puts information sharing between vendors and researchers into a constructive framework and establishes a shared goal of continuous safety improvement.”
 
The letter asks CEOs of automotives companies to “unite with us in a joint commitment to safety between the automotive and cyber security industries”. Following the addition of basic automotive safety features, it says that “modern vehicles are computers on wheels and are increasingly connected and controlled by software and embedded devices” and that new “technology introduces new classes of accidents and adversaries that must be anticipated and addressed proactively”.
 
“The once distinct worlds of automobiles and cyber security have collided,” the letter said. “In kind, now is the time for the automotive industry and the security community to connect and collaborate toward our common goals.
 
“We urge the automotive industry to adopt, develop, enhance, and attest to these capabilities. Just as they consider other safety features, concerned consumers will be better enabled to make purchasing decisions based on your attestations against these five areas. We will help you navigate this road to build greater protections for your customers and set a new standard for safety.”
 
Joshua Corman, co-founder of I Am The Cavalry, told IT Security Guru that it wanted to work with “the big goliaths of the industry” having already begun one of four projects in medical device security.
 
He said: “Our goal is to educate the public and policy makers. It is not in our interest to find one bug in infrastructure, and we don’t want to hack products, we want to get out of the echo chamber and speak to think tanks on securing Internet of Things which are different from enterprise environments.
 
“We want to make room for innovation. This is the foundation of critical capability and becomes market signalling. We will ask if they have a published version of their software development lifecycle and take care of safety and logic. We know they miss things so do they have a coordinated disclosure policy? Also because failure is inevitable, do you have evidence capture and a foundational necessity like black boxes in planes? As Heartbleed showed, can you show updat
es, as you will not wait for five years to close gaps?”

ShareTweet
Previous Post

Def Con – Your smartphone could be your privacy downfall

Next Post

Def Con – EFF and McAfee warn on smartphone spies

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol