US Department of Transportation and 18 automakers say they'll share cybersecurity data and best practices, work with security researchers who expose flaws
Andy Greenberg / Wired :
Context & Ripple Effects
This pledge lands six months after a Senate bill sought standards for cars' hacker defenses, giving automakers a legislative alternative to head off: rather than wait for mandated security rules, 18 manufacturers plus the Department of Transportation commit to a voluntary framework of shared threat data and researcher engagement.
It also follows Andy Greenberg's reporting beat on connected-car risk at Wired, where the question had been whether automakers would keep treating independent security researchers who expose flaws as adversaries. The agreement formally flips that posture.
First-order effects
- Eighteen automakers now have an obligation to pool cybersecurity incident data and best practices through the DOT, replacing siloed internal handling with an industry-wide channel.
- Security researchers who expose vehicle flaws gain a recognized path to disclosure instead of the legal friction that previously greeted them.
Second-order effects
- Two months later, the FBI, DOT, and NHTSA still issued a public warning to drivers about internet attacks on cars — regulators hedging that the voluntary pact alone doesn't neutralize the threat, keeping pressure on for the binding standards the Senate bill envisioned.
- Non-signatory automakers face reputational pressure to join or explain their absence, since the shared-data framework becomes the visible benchmark for connected-car security.
Third-order effects
- If the voluntary model holds, it becomes the template for governing emerging vehicle tech: NHTSA's later push to ease rules for fully driverless cars while urging companies to share more data repeats the same trade — regulatory flexibility in exchange for transparency commitments.
- Auto cybersecurity governance consolidates around regulator-brokered information sharing rather than statute, leaving enforcement dependent on participation rather than penalty.
The trend: Connected-car security is being governed through voluntary regulator-brokered data-sharing pacts that substitute for legislated standards, a playbook now extending from cybersecurity to autonomous-vehicle oversight.