Skip to content
Automotive Cybersecurity Forecasts Are All Over the Map. Ransomware and Recalls Explain Why

Automotive Cybersecurity Forecasts Are All Over the Map. Ransomware and Recalls Explain Why

Theautowire September 15, 2026

Transparency Market Research is out with a fresh round of press releases automotive cybersecurity . The headline number: a global market worth $3.8 billion in 2024, growing 11.9 percent a year to $14.2 billion by 2035, according to TMR’s report page . Software-defined vehicles and rising cyberattacks get the credit.

The trend behind it is real. Cars now run on millions of lines of code, take software updates over cellular connections, and talk to cloud servers that were never designed with a tow truck in mind. But the tidy dollar figure deserves the same skepticism you’d give a used-car ad that says “runs great.”

The Forecast Doesn’t Add Up Cleanly

Start with basic arithmetic. Grow $3.8 billion at 11.9 percent a year for the 11 years from 2024 to 2035, and you land around $13.1 billion, not $14.2 billion. To reach $14.2 billion with 10 years of 11.9 percent growth starting in 2025, the market would need to be worth $4.6 billion in 2025. That’s a jump of roughly 21 percent in a single year before the advertised growth rate even starts.

That $4.6 billion figure should sound familiar. In 2024, TMR was telling a very different story. A July 2025 release from the firm valued the market at $4.6 billion in 2023 and projected $25.5 billion by 2034, growing 17.2 percent a year. Between reports, the same firm cut its starting point by nearly a fifth and its long-range forecast almost in half.

Other research houses can’t agree on the present, let alone the future. Global Market Insights puts 2025 at $3.87 billion, reaching $10.42 billion by 2034. The Insight Partners says 2025 was $7.23 billion, heading to $25.74 billion by 2034. Market Research Future pegs 2025 at $6.38 billion and projects $32.27 billion by 2035.

Tesla’s Cybercab Didn’t Ask Permission to Ditch the Steering Wheel. Now the Feds Want a Word.

Toyota’s Paint-Warranty Program Got Robbed From the Inside. The Dealer Still Had to Pay Toyota Back $2.1 Million.

So the estimates for last year alone differ by nearly two to one, and the 2035 projections span more than $18 billion. The honest summary: automotive cybersecurity spending is growing fast, and nobody agrees on how big it is. The reason is that the category is fuzzy. It can include an intrusion-detection module in a gateway ECU, a cloud monitoring contract, a crypto chip in a telematics unit, or a consultant’s compliance audit. Change the definition and the market changes size.

What’s Actually Driving the Spending: Regulation

Forget “rising cyberattacks” as the main force. The money follows regulators. The UNECE says its Regulation No. 155 on cybersecurity management and No. 156 on software updates entered into force in January 2021. In the EU, R155 became mandatory for new vehicle types in July 2022 and for all newly produced vehicles in July 2024.

That second deadline is where enthusiasts felt it. R155 isn’t a part you bolt on. It requires automakers to prove they manage cyber risk across a vehicle’s development and lifespan, including their suppliers. Platforms engineered before the rule existed often couldn’t be certified without a redesign. Porsche’s own reports blamed lower 718 Boxster and Cayman deliveries in the first half of 2025 on limited availability caused by EU cybersecurity regulations, and said production of the current 718 would end in the fourth quarter of 2025.

The company’s full-year 2025 numbers showed total deliveries of 279,449. Porsche attributed its declines in Germany and the rest of Europe partly to supply gaps for the gas-powered 718 and Macan caused by those rules. Outside the EU, the story was different. In its first-quarter report , Porsche noted it kept selling the combustion Macan alongside the electric one in most countries outside the EU.

That’s the clearest proof yet that cybersecurity rules shape which cars you can buy, not just what’s in the spec sheet. A mid-engine flat-six sports car was retired in its biggest market partly because of an electrical architecture developed a decade earlier.

The U.S. has taken a much softer approach. NHTSA’s 2022 cybersecurity best practices describe themselves as “non-binding and voluntary guidance” for manufacturers. The binding U.S. rules come from a different angle. The Commerce Department’s connected-vehicle rule bars vehicle connectivity hardware from companies linked to China or Russia starting with the 2030 model year. Restrictions on the related software begin earlier, with model year 2027 . That’s supply-chain security, not a certification regime like Europe’s. It still means rewriting a lot of code and replacing a lot of modems.

The Hack That Set the Template

Every automotive security presentation eventually brings up the 2015 Jeep Cherokee. The government records are more instructive than the legend. According to NHTSA’s recall query , FCA recalled 1.4 million 2013 to 2015 vehicles with Uconnect 8.4-inch radios. Software vulnerabilities could allow unauthorized access to networked vehicle control systems. The affected models ranged from Ram pickups to the Dodge Viper.

Look at how the fix worked. The cellular carrier closed the exposed port on the radio network on July 22, 2015. FCA then mailed owners USB drives containing a software update. A security patch for more than a million vehicles went out by postal mail and depended on owners plugging a thumb drive into the dash.

That’s the problem R156 exists to address. A regulated software update management system is the difference between a fix that reaches every car overnight and one that depends on how many owners open their mail. It also explains where much of the cybersecurity budget goes: into the plumbing that makes secure over-the-air updates possible, not into flashy anti-hacking gadgets.

The Attack That Actually Hit Car Buyers

The most disruptive automotive cyber incident of recent years didn’t involve a single car. It hit the software dealers use to sell them. In a Form 8-K filed with the SEC, Lithia Motors said CDK Global notified it on June 19, 2024 that CDK had suspended systems in response to a cybersecurity incident. Lithia cut its connections to CDK as a precaution and reported disruptions to its CDK-hosted dealer management system. That platform supports sales, customer relationship management, inventory, and accounting.

For a buyer, the dealer management system is where the deal happens: the paperwork, the financing, the title work, the service records. When it goes down, you’re signing on paper and waiting on everything else. Market research forecasts tend to focus on the vehicle, but that dealer back office is just as exposed.

What It Means for Owners and Buyers

Install the updates. OTA updates are what make modern cars cheaper to fix than the Uconnect-era cars. When your car asks to update overnight, let it. For older models without OTA capability, check your VIN on NHTSA’s recall lookup regularly, because software recalls still exist and some still require a dealer visit.

Expect tighter control over tuning and independent repair. The same architecture that keeps attackers out of your brake controller also keeps unauthorized code out of your engine computer. Signed firmware and authenticated diagnostic access are standard security practice, and they make ECU flashing and some independent repairs more complicated. That’s a trade-off enthusiasts will keep arguing for the decade.

Jaguar Land Rover Is Cutting 4,000 Jobs, and Somehow Not One Is on the Assembly Line

Flock’s Camera Installer Called Police on a Reporter. Your Car Can’t Object.

Wipe your data before you sell. Connected cars store phone contacts, location history, garage codes, and app pairings. Do a factory reset and remove the car from the manufacturer’s app before handing over the keys, and ask the dealer to confirm your account was removed if you trade in.

Pay attention to platform age. Europe showed that aging electrical architectures can be regulated out of the market. As U.S. supply-chain rules take effect for software in model year 2027 and hardware in model year 2030, automakers will retire or redesign components on some older platforms. If you’re shopping for a car near the end of its life cycle, that’s worth factoring into long-term parts and support expectations.

The cybersecurity market will grow. The market research firms just can’t agree on how much. The best evidence isn’t a projection on a sales page. It’s a Porsche that can’t be registered in Germany and a recall notice explaining why a truck needed a USB stick.

How long should an automaker have to keep patching the software in a car you already paid for — five years, fifteen, or for as long as it’s on the road? And would you pay more up front to guarantee it?

Eve Nowell is a writer at The Auto Wire, where she covers industry news, new vehicle launches, and the bigger shifts changing how we get around. Her thing is taking the complicated stuff—manufacturer strategy, new regulations, the latest tech—and making it actually make sense. She's especially curious how innovation, what buyers want, and changing policy all collide to shape what automakers put on the road . She reports with an eye for detail and a knack for writing coverage that works whether you're a hardcore enthusiast or just someone trying to figure out their car. You'll find her writing industry news, new vehicle announcements, market trends and manufacturer strategy, EV tech, and the policy and regulation side of the business.

Extracted Entities