PCA Cyber Security vs VicOne
PCA Cyber Security
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Pros
- Elite offensive research talent. Repeat Pwn2Own Automotive contestants in 2024 and 2025
- Proven track record of high-impact disclosed vehicle research (Skoda/VW, Nissan Leaf)
- Deep hands-on embedded and hardware expertise via dedicated lab facilities
- TISAX Assessment Level 3 with protection of prototype parts; speakers at Black Hat, Hexacon, Escar and Hacktivity
- Registered PCI SSC Associate Participating Organization, taking part in PCI SSC Community Meetings
Pricing: Project-based; contact for an engagement.
VicOne
VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.
Pros
- Backed by Trend Micro's 30+ years of cybersecurity experience and global threat intelligence
- Access to the Zero Day Initiative, which also runs Pwn2Own Automotive
- Broad portfolio spanning in-vehicle, VSOC, threat intelligence, and SBOM
- Strong partner ecosystem (NXP, AWS, Arm, Harman) and multiple industry awards
Pricing: Custom (contact sales)