Ministry of Land, Infrastructure and Transport, Korean National Police Agency and Hyundai Motor test response chain from incident report to resolution
Imagine a nightmare scenario: your steering wheel suddenly moves on its own while you are driving.
As cybersecurity threats targeting vehicles rise sharply, the government and automakers are joining forces to drill for exactly that kind of attack. The Ministry of Land, Infrastructure and Transport said Tuesday it held a joint public-private automotive cybersecurity incident-response drill at Hyundai Motor's Pangyo AVP headquarters, together with the Korea Transportation Safety Authority's Automotive Safety Research Institute, the Korea Internet & Security Agency, the Korean National Police Agency and Hyundai Motor.
The exercise was designed to verify that incident-response procedures and inter-agency coordination work smoothly in real-world conditions, following the government's introduction of a Cybersecurity Management System for vehicles in response to the rapid growth of connected cars and a surge in automotive cybersecurity incidents. The number of such incidents grew at an average annual rate of about 68.8 percent over the six years through 2025.
The CSMS is a regime for systematically managing cyber threats across a vehicle's entire life cycle, from development through disposal. South Korea began applying it to new vehicle models in August 2025, and certification will expand to all vehicle models from August next year.
The drill was conducted as a tabletop exercise: rather than hacking actual vehicles or systems, organizers presented simulated incident scenarios in stages, and each agency carried out reporting, escalation and response procedures exactly as it would in a real emergency.
The exercise traced the full coordination chain — starting with Hyundai Motor detecting an anomalous signal and filing an incident report, followed by the Automotive Safety Research Institute's technical review and a report to the Ministry of Land, Infrastructure and Transport, the Korea Internet & Security Agency's analysis of the breach, and the Korean National Police Agency's tracking and investigation of the suspected attacker.
Participants then worked through the subsequent phases in accordance with actual procedures: halting software distribution, deploying a patched update to restore affected vehicles, tracking vehicles that had not yet received the fix, and reinforcing vehicle defense layers and supplier security — covering the full arc from containing the spread of an incident to preventing recurrence and formally closing the case.
Park Jun-hyung, director general for mobility and automobiles at the Ministry of Land, Infrastructure and Transport, said automotive cybersecurity incidents differ from ordinary cybersecurity breaches because they directly affect people's lives and safety. "With cyberattacks growing more sophisticated and frequent — including AI-assisted infiltration of automakers' supply chains — we will use this joint drill as an opportunity to continuously strengthen the roles and coordination mechanisms among relevant agencies, and build an automotive cybersecurity environment that puts national security and public safety first," Park said.
smh@heraldcorp.com
