smartnuts … the world on the cabaret-style dissecting table

AuthorMichael Bunzel

Michael Bunzel (aka maschasan) is a lawyer and engineer currently living in Germany. He has been working in the field of Cybersecurity and related laws and regulations for over 25 years now.Mike took on various roles and functions in the context of Information Security, Cybersecurity, and SCADA/Shopfloor Security at a German car manufacturer in southern Germany for more than fifteen years - currently in the R&D resort, with focus on E/E-systems in the context of automotive cybersecurity and related regulations in different markets (e.g. UN, EU, China, Korea, India, US, and others).Mike has worked with global organizations across dozens of countries, cultures and languages, well-travelled in EMEIA, APAC and the Americas.All articles in this blog do NOT reflect the opinion of his employer, but are all an expression of his personal view of things.

Der überlesene Absatz – ODER: Wann der AI Act das Fahrzeug erreicht

D

… und warum das bestehende Cybersecurity-Management-System die geforderte AI-Security (noch) nicht trägt. Eine Deadline, die in einigen Roadmaps falsch Verortet wurde In zahlreichen Compliance-Roadmaps der Automobilindustrie ist der 2. August 2026 als harte Frist vermerkt: ab diesem Tag, so die verbreitete Lesart, greife der EU AI Act mit vollem Pflichtenkatalog auf Fahrzeuge mit KI...

Das Cybersecurity-Ablaufdatum

D

… oder wie der ZDK aus einem VDA-Positionspapier einen digitalen Aftermarket-Horrorfilm macht. Der Zentralverband Deutsches Kraftfahrzeuggewerbe hat eine Pressemitteilung veröffentlicht, die ungefähr so klingt, als würden deutsche Hersteller planen, nach zehn Jahren kollektiv den Stecker aus Millionen Fahrzeugen zu ziehen, während freie Werkstätten machtlos danebenstehen und der...

The Commission’s Latest Regulatory Land Grab: Why CSA 2 Should Stay Out of Automotive

T

In its regulatory frenzy, the European Commission has once again found itself a new patch of turf to conquer: connected and automated vehicles. Because apparently a sector already covered by type-approval law, dedicated cyber rules, software update rules, data protection law, artificial intelligence law and assorted compliance machinery was still looking a bit too relaxed. So now the idea is to...

TPMS Security – again

T

The IMDEA Networks research group, together with academic and government partners, has published a new paper on a long-standing problem (e.g. 1, 2, 3, and 4) in vehicle security and privacy: TPMS wheel sensors still tend to broadcast tyre telemetry over the air in clear text and include identifiers that remain stable for long periods. The paper’s central claim is not that this is a new weakness...

Global CSMS Certifications — The After-Effects of Korea

G

English version: The after-effects of the CSMS certification required for market access in Korea, based on UN R155, are multifaceted. They do not play out in isolation within individual OEMs; they have also become a topic in the discussions around amending a free trade agreement (FTA) between the European Union and Korea. How are the two connected? From the perspective of the OEMs that, over...

smartnuts … the world on the cabaret-style dissecting table

Get in touch

Tags

Meist gesehene Beiträge