smartnuts … the world on the cabaret-style dissecting table

AuthorMichael Bunzel

Michael Bunzel (aka maschasan) is a lawyer and engineer currently living in Germany. He has been working in the field of Cybersecurity and related laws and regulations for over 25 years now.Mike took on various roles and functions in the context of Information Security, Cybersecurity, and SCADA/Shopfloor Security at a German car manufacturer in southern Germany for more than fifteen years - currently in the R&D resort, with focus on E/E-systems in the context of automotive cybersecurity and related regulations in different markets (e.g. UN, EU, China, Korea, India, US, and others).Mike has worked with global organizations across dozens of countries, cultures and languages, well-travelled in EMEIA, APAC and the Americas.All articles in this blog do NOT reflect the opinion of his employer, but are all an expression of his personal view of things.

When Lawyers Get Lazy: PwC’s Data Act Hiccup

W

Sometimes satire writes itself. The European Union’s Data Act, a landmark piece of legislation on data access and portability, is Regulation (EU) 2023/2854, which has been adopted on 13 December 2023, published in the Official Journal of the EU on 22 December 2023 and fully applicable since 12 September 2025. That number 2023/2854 matters. It tells compliance officers which obligations to...

Dear Consultants, AI Ate Your Pyramid

D

Dear Management Consultants, We need an intervention. It’s about your future, or what’s left of it after the invoice templates stop printing themselves. You’ve had a lovely run at the top of the corporate terrarium: tailored suits, status lounges, and fees that soar on the thermals of “we have the best people, trust us.” Charming. Unfortunately a new colleague just walked in, knows everything...

Cybersecurity Type Approval in Germany: A Layered Guide (As of 2025)

C

A Preliminary Note … The motivation for this post was follow-up questions prompted by several more technically focused or legally specific articles that asked for a general discussion of the normative foundations of automotive cybersecurity as a type-approval-relevant element. Here it is. Cybersecurity is now a non-negotiable entry ticket for vehicles in the EU, and Germany enforces it with...

EU In-Vehicle-Data-Access vs. Automotive Cybersecurity (ACS)

E

Im November 2023 verabschiedete die EU die Verodnung (EU) 2023/2854 “über harmonisierte Vorschriften für einen fairen Datenzugang und eine faire Datennutzung“ (nachfolgend als “Data Act” bezeichnet). Der Data Act wird zum 12. September 2025 anwendbar und regelt ab diesem Zeitpunkt Nutzer- und Drittzugriffsrechte auf Daten vernetzter Produkte, zugleich aber Sicherheits- und...

Insolvenzvorsorge im Lichte der UN-R155

I

Die UN-R155 hat die Automobilwelt aufgemischt: Sie verpflichtet Hersteller, ein Cybersecurity Management System (CSMS) nachzuweisen, um neue Fahrzeugtypen überhaupt genehmigt zu bekommen. Klingt erstmal nach einem reinen OEM-Thema – doch wer genauer hinsieht, erkennt: Auch Supplier stehen unter Druck. Denn der OEM trägt die volle Verantwortung für die Cybersicherheit der Lieferkette. Wenn ein...

smartnuts … the world on the cabaret-style dissecting table

Get in touch

Tags

Meist gesehene Beiträge