🎉 GITPROTECT REVEALS: Key DevOps Threats in 2026: Autonomous AI risks, secret leaks, breaches, outages, and more

Download report

The real cost of threats in the automotive industry

Daria Kulikova
8 min read
SHARE

With 19.5% of respondents facing a crisis within 2 hours of downtime, secure pipelines are vital. See how industry leaders leverage immutable DevOps backups.

Wireframe illustration of a car with highlighted connected components
As ransomware and supply chain risks threaten Just-In-Time manufacturing, automotive leaders must adopt immutable DevOps recovery frameworks to prevent costly downtime and ensure compliance.

The automotive industry has emerged as one of the most targeted sectors, according to GitProtect Lab’s 2026 DevOps Threats Unwrapped report. In this research article, we’ll examine the most critical risks facing automotive organizations and outline the essential steps they must take to protect sensitive data and ensure operational stability.

RESPONDENT PROFILE

To gather these insights, we surveyed automotive experts across diverse operational backgrounds. Of those surveyed, the largest group - 29% - were automotive software, DevOps, or technology providers. They were joined by representatives from engineering, testing, and design consultancies - 27.5%, mobility, fleet, and logistics operators - 21%, Tier-1 and Tier-2 suppliers - 14%, and Original Equipment Manufacturers - 8.5%

The extended supply chain as an unprotected entry point

In an ecosystem where modern vehicles are essentially “computers on wheels” and smart factories are hyper-connected, an organization’s security posture is only as strong as its weakest supplier. Attackers rarely waste time trying to breach a heavily fortified OEM directly. Instead, they target Tier-1, Tier-2, or even Tier-3 software, component, and engineering vendors.

When it comes to validating the cybersecurity posture of Tier-1 and Tier-2 suppliers, roughly 2 out of every 5 respondents stated that they perform active, collaborative penetration testing on their joint software or hardware components. However:

  • only 14.5% mandate independent third-party audits (such as TISAX, CSMS, ISO/SAE 21434, or ISO 26262 certification) for all critical vendors.
  • 9.5% admitted they lack a formal or standardized process for validating supplier security altogether.

This challenge becomes even more acute when collaborating with external engineering design or crash-testing partners, where organizations must ensure shared validation records remain secure. In our research, nearly 2 out of every 3 respondents mandate strict controls either requiring partners to hold recognized industry certifications like TISAX or ISO 27001 or forcing all shared data to reside exclusively on internal, audited collaboration platforms, or both options at the same time.

However, significant governance gaps persist; nearly 1 out of 4 automotive leaders rely entirely on trust in their partners’ internal security frameworks, while 9% lack any standardized validation process, leaving data sharing to be handled on an ad-hoc, case-by-case basis by individual teams.

KEY TAKEAWAY

1 in 10 automotive leaders operate on pure blind faith, lacking any standardized process to validate third-party risk.

The real-world use cases of supply chain fallout

Recent real-world events demonstrate why supplier security must be taken seriously. In April 2026, Japanese automaker Nissan confirmed a cybersecurity incident involving a third-party vendor. Threat actors from the Everest group claimed to have infiltrated a file transfer system used by a vendor supporting North American Nissan and Infiniti dealerships, exfiltrating 910 GB of data, including customer and dealership information, according to The Record.

While a Nissan spokesperson noted that they ‘found no indication that Nissan systems were compromised or that any Nissan customer information was accessed or put at risk,’ the incident highlights the ongoing operational and reputational risks associated with extended supply chains.

A month earlier, before the Nissan cybersecurity incidents, in March 2026, Mazda Motor Corporation disclosed a security breach involving an internal warehouse management system for Thailand-sourced parts. As Bleeping Computer stated, the incident exposed 692 records containing professional contact details and IDs for employees and business partners, though no customer data was compromised. While Mazda confirmed no misuse has been detected, it urged affected individuals to stay alert for potential phishing scams.

BEST PRACTICE

To prevent costly vendor-driven breaches, automotive companies must treat third-party security with the same rigorous governance and real-time monitoring as their internal systems.

Another use case? According to Reuters, in 2024, a group of hackers launched a ransomware cyberattack on SaaS provider CDK Global, demanding millions in ransom to restore its software systems. The multi-day outage forced over 15K auto dealerships across North America to revert to manual business continuity processes, severely disrupting sales, financing, and service operations. Some auto reteller groups like Sonic Automotive and Penske Automotive reported hits to their operations. It highlights the vast supply chain risks tied to third-party dealer management platforms.

As these incidents show, relying on third-party tools can lead to severe operational disruptions and data breaches. In our research, we’ve found that while just 26% of respondents have implemented modern Zero Trust Network Access for operational technology, an alarming 37% still rely on high-risk access methods, like granting permanent, unrestricted corporate VPN access, or using generic, shared vendor accounts with minimal logging.

Third-Party Remote Access in Automotive OT

How automotive organizations govern vendor access to critical product data

Pie chart of third-party remote access methods: standard VPNs 22%, Zero Trust Access 26%, physical plant security only 20.5%, disabled by default 16.5%, generic vendor accounts 15%.
  • Standard VPNs with permanent, unrestricted access
  • Specialized OT tools with Zero Trust Access (ZTNA)
  • Physical plant security only; remote access prohibited
  • Disabled by default; manually enabled during maintenance
  • Generic vendor accounts with minimal logging

Although the remaining organizations enforce strict boundaries through manual engineer approvals - 16.5% or air-gapped physical security - 20.5%, the prevalence of unmonitored external access leaves a massive, unprotected attack surface at the very heart of smart manufacturing operations.

Code repository vulnerabilities and SBOM visibility

What happens when a breach hits software repositories or third-party code libraries? When it comes to safeguarding Software-Defined Vehicle code and CI/CD pipelines against source code exfiltration, the automotive industry remains dangerously split between modern zero-trust enforcement and blind reliance on trust:

  • 36% enforce robust defense-in-depth through strict Role-Based Access Control, code signing, and continuous leak-detection scanning.
  • 21.5% isolate code inside locked-down Virtual Desktop Infrastructures (VDIs) that block local code downloads.
  • 23% rely solely on basic password or MFA controls while allowing developers to freely download source code to local machines.
  • 15% rely primarily on non-disclosure agreements and developer goodwill.
  • while 4.5% admit their DevOps pipeline security is entirely unmanaged.

Compounding this issue, immediate visibility into software dependencies is surprisingly rare. Only 31% of respondents can instantly track a compromised component using an automated, centralized Software Bill of Materials. The vast majority - 44.5% - face a 24-to-48-hour delay lost to manual documentation searches, and 12% require a full week of organizational back-and-forth. Worse yet, 1 in 8 leaders admit they have no way to map specific vendor code to vehicle systems, leaving component tracking entirely in the hands of third parties.

Operational resilience and the real cost of ransomware

Ransomware groups have become increasingly aggressive in recent years. Threat actors no longer just encrypt operational data; they leverage double extortion by threatening to leak sensitive corporate records if their demands are ignored. Automakers have become prime targets because their Just-In-Time manufacturing models cannot tolerate operational downtime, where an outage costs millions of dollars per hour.

In our research, we asked automotive professionals how prepared local plant managers are to maintain assembly line operations if their Manufacturing Execution System is frozen by a ransomware attack.

The results expose a concerning gap in operational resilience: 55.5% of respondents admitted they are only moderately prepared or not prepared at all. This reveals that for many organizations, disaster recovery plans exist only on paper, or are completely absent when facing a live ransomware scenario.

Furthermore, 12% of respondents disclosed that their backups remain connected to the primary network or that they lack a centralized backup system for engineering designs and manufacturing configurations altogether, leaving them highly vulnerable to lateral ransomware propagation.

KEY TAKEAWAY

5 in 9 respondents express uncertainty about their ability to fully restore critical operations following an attack.

Real-world incidents underscore the devastating consequences of these security gaps. Thus, in 2024, Hyundai Motor Europe suffered a cyberattack by the Black Basta ransomware gang, which claimed to have exfiltrated 3 TB of corporate data. The disruption was initially described as an IT issue; Bleeping Computer later reported that internal folder structures leaked online revealed that sensitive files across legal, HR, sales, accounting, and IT departments were exposed.

Another, more recent loud ransomware attack was in 2025; British luxury automaker Jaguar Land Rover suffered two major cyber incidents. First, in March 2025, the attackers from the HELLCAT ransomware group accessed JLR’s Atlassian Jira environment using credentials harvested years earlier via infostealer malware. According to Cyber Security News, those credentials remained valid long after the initial compromise; attackers managed to exfiltrate roughly 350 GB of data, including internal documents, source code, Jira issues, and employee records.

Later the same year, JLR suffered another cyberattack that compromised sensitive payroll, benefits, and personal data belonging to current and former personnel. According to Technadu, the incident forced a factory shutdown lasting over a month, resulting in a financial shortfall exceeding $890 million and causing ripple effects throughout the broader UK automotive supply chain.

The razor-thin survival window

Downtime remains one of the most critical threats facing the automotive industry. Given the sector’s heavy reliance on JIT schedules, 95.5% of organizations cannot survive more than three days of operational downtime before facing severe dealership penalties and unrecoverable financial losses.

KEY TAKEAWAY

19.5% of automotive organizations face an immediate crisis within two hours of downtime.

In fact, nearly 1 in 5 respondents face an immediate crisis within two hours of an outage. Another 39.5% can only survive between 2 and 12 hours before downstream distribution networks break down. Meanwhile, 28% can stretch downtime to 12–24 hours using physical inventory buffers, and 8.5% can tolerate 1 to 3 days of minor delays. Only 4.5% of companies operate business models detached enough from tight schedules to withstand outages beyond three days.

When evaluating operational resilience during business continuity drills, most automotive organizations encounter significant recovery delays:

  • only 23% can fully restore a compromised factory’s golden image templates and configuration data in under 4 hours using automated pipelines.
  • 46.5% require between 4 and 24 hours because their restoration workflows remain heavily manual.
  • 8% admitted they have never conducted a full restoration drill for an entire manufacturing facility’s Operational Technology data - leaving their real-world recovery capabilities completely untested.

KEY TAKEAWAY

Nearly 1 out of every 2 automotive organizations need up to 24 hours to manually restore their critical data.

Key best practices for automotive DevOps backup to build strategic resilience

As automotive organizations scale their Software-Defined Vehicle initiatives, securing the underlying software supply chain requires moving beyond basic code backups. Modern DevOps environments, spanning GitHub, GitLab, Azure DevOps, and the Atlassian stack, demand comprehensive, enterprise-grade protection.

To build a resilient disaster recovery framework capable of withstanding ransomware and third-party disruptions, automotive security and IT leaders should evaluate their backup and recovery systems against four core capabilities:

#1 Complete scope and metadata granularity

Full stack DevOps coverage

To be prepared for any event of failure, automotive organizations should ensure backups capture not just source code, but the full DevOps ecosystem, including pull requests, pipelines, LFS, Jira workflows, and Confluence spaces. This full context is crucial when responding to exposed backend credentials: while 40% of automakers can push emergency over-the-air patches within 24 hours, doing so safely requires complete traceability across Jira vulnerability reports, Software Bill of Materials component maps, and release sign-offs.

Granular backup

Organizations should have the opportunity to have different backup plans depending on data criticality. As some data is more critical and needs more frequent backups, while other data can be backed up once a day, or even once a few days.

KEY TAKEAWAY

Securing automotive software supply chains requires protecting the entire DevOps ecosystem, including source code, Jira workflows, and metadata, with immutable storage to prevent ransomware from propagating across IT/OT networks.

#2 Scalability, performance and rate limiting

API throttling management

Automotive enterprise environments with thousands of repositories generate massive API traffic. Backup solutions must support customizable backup windows to run during off-peak hours, ensuring zero impact on active developer workflows or production pipelines.

RTO and RPO

Organizations operating in the automotive industry should validate realistic Recovery Time Objectives and Recovery Point Objectives in production-like environments. It’s important to look for backup solutions that allow them to prioritize recovery order, restoring critical vehicle software projects first.

#3 Enterprise security and immutable storage

WORM and BYOS support

Organizations can protect their critical data against double-extortion ransomware by enforcing immutable storage - a WORM-compliant one.

This becomes critical given that 78.5% of respondents from automotive organizations operate with flat, dual-homed, or improperly segregated IT/OT networks, where a corporate ransomware attack can laterally propagate to wipe local plant backups.

To mitigate this risk, organizations should follow the 3-2-1 backup rule by maintaining multiple backup copies across diverse storage destinations, combining both on-premises and cloud environments. Furthermore, enterprise backup solutions must support Bring-Your-Own-Storage so organizations with strict security requirements can retain full control over their backup destinations. On the other hand, if using vendor-provided storage, organizations must have the flexibility to select specific storage regions to comply with strict global data residency regulations (e.g., EU, US, AUS).

KEY TAKEAWAY

26% of automotive leaders said that they keep their backups in immutable, write-once-read-many storage completely isolated from the network

Zero-Trust Access and governance

The backup solution should support granular Role-Based Access Control to enforce the principle of least privilege. This ensures team members are restricted to specific, authorized actions, such as viewing backup logs, executing restores, or configuring backup policies, without granting unnecessary administrative rights across the entire environment.

Encryption and compliance

Organizations should choose backup solutions that enforce end-to-end encryption for data both in-flight and at-rest with the top-tier standards such as AES-256-GCM. To maintain complete sovereignty over their data, organizations should also have the option to implement Bring Your Own Key policies.

Furthermore, the backup platform itself should be validated by leading third-party security attestations, including SOC 2 Type II and ISO 27001 certifications.

#4 Operational recovery and cross-platform flexibility

Granular restore

Given the mission-critical nature of automotive data, organizations should choose backup solutions that support granular recovery alongside full-system rollbacks. The ability to selectively restore specific repositories, configurations, or other data allows teams to prioritize core production assets first, drastically slashing RTO. This capability is critical considering nearly 1 in 5 respondents reported a maximum tolerable downtime of less than 2 hours, where tight just-in-time supply chains leave zero margin for operational pauses.

Cross-platform restore

Unplanned outages and cloud disruptions are inevitable. To maintain operational continuity during a critical failure, automotive organizations should be able to restore their data to an alternate platform.

Beyond disaster recovery, with cross-platform restore, organizations can simplify enterprise migrations, allowing teams to seamlessly restore workloads from one environment to another, such as migrating from Bitbucket to GitHub or Azure DevOps to GitLab, without data loss or proprietary vendor lock-in.

KEY TAKEAWAY

To support rapid emergency OTA patching and meet decades-long compliance mandates, automotive organizations must implement continuous disaster recovery testing, granular restore capabilities, and cross-platform flexibility.

Long-term retention

Automotive compliance frameworks, such as CSMS, ISO/SAE 21434, and ISO 26262, demand long-term data retention up to 20+ years across the full vehicle lifecycle. Because native DevOps platforms typically offer limited retention windows, often under 3 years, automotive organizations should deploy dedicated backup solutions that support extended or unlimited retention policies. Moreover, these long-term archives must utilize open, non-proprietary formats to ensure code, configurations, and metadata remain exportable and fully accessible over decades, free from vendor lock-in.

Continuous DR tests

Disaster Recovery testing is critical for automotive organizations to validate that their systems and data can be restored within target recovery timeframes during an incident. This capability is vital given that 24.5% of organizations suffer from severe over-the-air patching friction, taking months due to manual sign-offs - 11%, forcing physical dealership visits - 8%, or lacking a Vulnerability Disclosure Program - 5.5%, altogether.

Regular DR testing ensures recovery pipelines remain agile when emergency patches must be generated. Furthermore, 18% of respondents said that full data restoration required between 2 to 5 days or even longer during business continuity testing. It underscores the urgent need to practice and optimize recovery workflows before a live crisis strikes.

DISCOVERY CALL

Secure your code. Automate compliance. Restore in minutes.

Discover how GitProtect protects your full DevOps stack.