Automotive Cybersecurity: 5 Companies compared
Automotive cybersecurity companies protect connected and software-defined vehicles across their lifecycle. From ECUs, in-vehicle networks, and telematics to cloud backends, fleets, and EV charging. This guide compares the firms that OEMs…
Looking specifically for vehicle pen testing? Read our deep-dive on automotive penetration testing. Scope, standards, Pwn2Own, and the firms doing the research.
Automotive Pen Testing guide →By use case
Our read on which firm suits which job. Editorial, not paid, and separate from the alphabetical listing below.
PCA Cyber Security
An offensive-security specialist for vehicles and embedded products: penetration testing, TARA and managed product SOC monitoring. Repeat Pwn2Own Automotive contestants with publicly disclosed vehicle research.
Upstream Security
Agentless and cloud-native, pairing a V-XDR platform with a managed 24/7 Vehicle SOC and dedicated threat intelligence for connected fleets.
VicOne
A single-vendor portfolio spanning in-vehicle IDPS, a vehicle SOC, threat intelligence and SBOM, backed by parent Trend Micro and the Zero Day Initiative.
Quick comparison
All automotive cybersecurity companies side by side, alphabetical.
| Company | Founded | Engagement | Specialism | Standards / accreditations |
|---|---|---|---|---|
| PCA Cyber Security | 2019 | Project-based engagements | OEMs and suppliers that need elite offensive testing, TARA, and managed monitoring for co… | TISAX Assessment Level 3ISO/SAE 21434UNECE R155 |
| Upstream Security | 2017 | Subscription (custom) | OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle… | ISO/SAE 21434UNECE R155UNECE R156 |
| Vector Informatik | 1988 | Quote-based licensing for embedded software and tools, with separate fees for consulting and training | Automotive OEMs and Tier 1 suppliers needing production-grade ECU security software and I… | ISO/SAE 21434 product certification for MICROSAR HSM firmware (exida, June 2025)Cybersecurity Management System (CSMS) certification |
| VicOne | 2022 | Subscription (custom) | OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an… | ISO/SAE 21434UNECE R155Automotive SPICE (ASPICE) Level 2 |
| VxLabs | 2022 | Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering services | OEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace,… | — |
PCA Cyber Security
Automotive CybersecurityOEMs and suppliers that need elite offensive testing, TARA, and managed monitoring for connected vehicles and embedded products
PCA Cyber Security (formerly PCAutomotive) is a Budapest-based specialist in offensive security and threat intelligence for vehicles and embedded systems. The firm runs dedicated CyberLab and CyberGarage research facilities and has built a strong public reputation through repeated Pwn2Own Automotive participation and disclosed vehicle vulnerability research, including 21 vulnerabilities across Skoda and Volkswagen vehicles and their cloud backend. While rooted in automotive, PCA has expanded into fintech, manufacturing, consumer electronics, and energy. It is a services-led firm focused on penetration testing, TARA, verification and validation, and managed product SOC monitoring rather than off-the-shelf software.
Upstream Security
Automotive CybersecurityOEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets
Upstream Security operates a cloud-native, agentless AI platform purpose-built for connected vehicles and mobility IoT. It ingests telematics, OTA, diagnostic, and dealership data to deliver cybersecurity detection and response (V-XDR), automotive threat intelligence, and data-driven applications. Upstream pairs its platform with a managed 24/7 Vehicle Security Operations Center and monitors tens of millions of vehicles, making it one of the largest-scale players in connected-vehicle security. Because it works server-side without in-vehicle agents, it is typically deployed alongside embedded ECU protection rather than replacing it.
Vector Informatik
Automotive CybersecurityAutomotive OEMs and Tier 1 suppliers needing production-grade ECU security software and ISO 21434 verification tooling inside an existing AUTOSAR toolchain.
Vector Informatik is a Stuttgart-based automotive software and tooling company founded in 1988, whose portfolio includes embedded cybersecurity components for electronic control units. Its MICROSAR HSM firmware provides secure boot, secure key storage and cryptographic services on ECU hardware security modules, and was certified to ISO/SAE 21434 by test house exida in June 2025. The MICROSAR Classic basic software includes a crypto stack with drivers for SHE and HSM trust anchors and the AUTOSAR Key Manager for in-vehicle key and certificate handling. On the verification side, vTESTstudio provides fuzz test design executed in CANoe, and Vector Consulting Services delivers TARA, ISO/SAE 21434 and UNECE R155 work.
VicOne
Automotive CybersecurityOEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent
VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.
VxLabs
Automotive CybersecurityOEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering.
VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.
Related guides
Other categories you might be evaluating alongside automotive cybersecurity.
About this listing
Automotive Cybersecurity companies, listed alphabetically and compared on public information. How we work →