# VSOC (Vehicle Security Operations Center)

> A VSOC (vehicle security operations center) is the team, process and tooling a vehicle manufacturer uses to monitor its fleet in the field for cyber attacks, threats and vulnerabilities, and to respond to them. It collects security events from vehicles and backends, analyses them and triggers incident response and updates. UN R155 requires manufacturers to monitor, detect and respond to attacks on their vehicle types, and ISO/SAE 21434 describes the matching continual cybersecurity activities.

A VSOC monitors a vehicle fleet for cyber attacks and vulnerabilities after start of production. What it does, where UN R155 asks for it and how it links to bench tests.

Source: https://auto-st.com/glossary/vsoc · Updated: 2026-10-07

## What is a VSOC?

A VSOC is the operational side of vehicle cybersecurity after start of production. Development ends with a released vehicle type, but new vulnerabilities and attack techniques keep appearing for the whole time the vehicles are on the road. The VSOC is where these are watched for and handled.

It typically combines three inputs: security events from the vehicles, for example from an intrusion detection system on the gateway or from ECUs that report failed authentication; logs from the backend, telematics and update servers; and external intelligence such as vulnerability disclosures and researcher reports. Analysts correlate these, decide whether something is an incident and hand it to incident response and product teams.

## Where is it defined?

UN R155 does not use the term VSOC, but it requires the manufacturer's cyber security management system to include processes to monitor for, detect and respond to cyber attacks, cyber threats and vulnerabilities on its vehicle types, and to provide relevant monitoring data. ISO/SAE 21434 clause 8 describes the continual activities behind this: cybersecurity monitoring, event evaluation, vulnerability analysis and vulnerability management. AUTOSAR specifies an Intrusion Detection System Manager that collects security events on the ECU side.

## What it means in practice

A VSOC is only as good as the events the vehicles produce. If ECUs do not report failed SecurityAccess attempts, unexpected diagnostic sessions or authentication failures, the VSOC has nothing to see. This links it back to development: the security events an ECU should raise belong in its requirements, and they should be tested like any other function.

The second link is vulnerability handling. When a weakness is found in the field, the VSOC needs to know which vehicle types and software versions are affected, and the product team needs a way to fix it, usually through an over-the-air update.

## Common misunderstandings

A VSOC does not replace testing before release; it catches what testing missed and what was not known yet. And monitoring is not only about attacks in progress: tracking new vulnerabilities in components already in the field is a large part of the work.

## FAQ

**Is a VSOC the same as an IT SOC?**

The principle is the same: collect events, detect, respond. The data and the response differ. A VSOC works with in-vehicle intrusion detection events, backend and telematics logs, and its response often ends in a software update for a vehicle type rather than an isolated server.

**Does every supplier need a VSOC?**

UN R155 puts the monitoring obligation on the vehicle manufacturer. Suppliers contribute: they provide security events from their ECUs, handle vulnerability reports for their components and deliver fixes, as agreed in the cybersecurity interface agreement.

**Where do bench test results fit in?**

Findings and accepted residual risks from development tell the VSOC what to watch for. A known weakness that was accepted at release is a good candidate for a detection rule in the field.

## Sources

- [UN Regulation No. 155, Cyber security and cyber security management system](https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security)
- [ISO/SAE 21434:2021 Road vehicles, Cybersecurity engineering, clause 8 Continual cybersecurity activities](https://www.iso.org/standard/70918.html)
- [AUTOSAR standards (including the Intrusion Detection System Manager)](https://www.autosar.org/standards)

## Related

- [UN R155 (UN Regulation No. 155, Cyber Security)](https://auto-st.com/glossary/un-r155)
- [CSMS (Cybersecurity Management System)](https://auto-st.com/glossary/csms)
- [OTA Update (Over-the-Air Software Update)](https://auto-st.com/glossary/ota-update)
- [ISO/SAE 21434](https://auto-st.com/glossary/iso-sae-21434)
- [Evidence for your 21434 work, on tap.](https://auto-st.com/iso-21434-testing)
- [AutoST for OEM Security Teams: Supplier ECUs, Gateways and Vehicle Networks](https://auto-st.com/for/oem-security-teams)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/glossary/vsoc
