Skip to content
AutoST by Zyberum GmbH
Menu
GlossaryOperationsRegulation

VSOC (Vehicle Security Operations Center)

A VSOC monitors a vehicle fleet for cyber attacks and vulnerabilities after start of production. What it does, where UN R155 asks for it and how it links to bench tests.

Updated This page as Markdown

In short

A VSOC (vehicle security operations center) is the team, process and tooling a vehicle manufacturer uses to monitor its fleet in the field for cyber attacks, threats and vulnerabilities, and to respond to them. It collects security events from vehicles and backends, analyses them and triggers incident response and updates. UN R155 requires manufacturers to monitor, detect and respond to attacks on their vehicle types, and ISO/SAE 21434 describes the matching continual cybersecurity activities.

What is a VSOC?

A VSOC is the operational side of vehicle cybersecurity after start of production. Development ends with a released vehicle type, but new vulnerabilities and attack techniques keep appearing for the whole time the vehicles are on the road. The VSOC is where these are watched for and handled.

It typically combines three inputs: security events from the vehicles, for example from an intrusion detection system on the gateway or from ECUs that report failed authentication; logs from the backend, telematics and update servers; and external intelligence such as vulnerability disclosures and researcher reports. Analysts correlate these, decide whether something is an incident and hand it to incident response and product teams.

Where is it defined?

UN R155 does not use the term VSOC, but it requires the manufacturer’s cyber security management system to include processes to monitor for, detect and respond to cyber attacks, cyber threats and vulnerabilities on its vehicle types, and to provide relevant monitoring data. ISO/SAE 21434 clause 8 describes the continual activities behind this: cybersecurity monitoring, event evaluation, vulnerability analysis and vulnerability management. AUTOSAR specifies an Intrusion Detection System Manager that collects security events on the ECU side.

What it means in practice

A VSOC is only as good as the events the vehicles produce. If ECUs do not report failed SecurityAccess attempts, unexpected diagnostic sessions or authentication failures, the VSOC has nothing to see. This links it back to development: the security events an ECU should raise belong in its requirements, and they should be tested like any other function.

The second link is vulnerability handling. When a weakness is found in the field, the VSOC needs to know which vehicle types and software versions are affected, and the product team needs a way to fix it, usually through an over-the-air update.

Common misunderstandings

A VSOC does not replace testing before release; it catches what testing missed and what was not known yet. And monitoring is not only about attacks in progress: tracking new vulnerabilities in components already in the field is a large part of the work.

FAQ

Frequently asked questions

Is a VSOC the same as an IT SOC?

The principle is the same: collect events, detect, respond. The data and the response differ. A VSOC works with in-vehicle intrusion detection events, backend and telematics logs, and its response often ends in a software update for a vehicle type rather than an isolated server.

Does every supplier need a VSOC?

UN R155 puts the monitoring obligation on the vehicle manufacturer. Suppliers contribute: they provide security events from their ECUs, handle vulnerability reports for their components and deliver fixes, as agreed in the cybersecurity interface agreement.

Where do bench test results fit in?

Findings and accepted residual risks from development tell the VSOC what to watch for. A known weakness that was accepted at release is a good candidate for a detection rule in the field.

Sources

Related pages

See it on your ECU

A term that matters for your ECU?

In 15 minutes we tell you how AutoST tests it, what a finding looks like and what it means for your ISO/SAE 21434 evidence.

  • Direct answer from an ECU security engineer
  • Which test covers the term
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk the AutoST team

Pick a time that suits you

Open in a new tab