Why Elektrobit chose AUTOCRYPT: the rise of development-stage security in the SDV era
2026-08-10 / 09월호 지면기사
/ 한상민 기자_han@autoelectronics.co.kr
INTERVIEW
Deoksoo Kim
Co-CEO of AUTOCRYPT
Automotive cybersecurity is not a single technology. Some companies excel at operations—detecting and responding to vulnerabilities in vehicles already on the road—while others excel at verifying finished products, and still others hold a competitive edge in development, building security in from the design stage. Meeting AUTOCRYPT Co-CEO Deoksoo Kim for roughly 80 minutes—covering everything from changes since the company's IPO to its global partnership with Elektrobit—one point stood out above all: as the shift to Software-Defined Vehicles (SDV) gathers pace, what the industry needs most right now is development-stage security rather than operational security after vehicles are launched, and AUTOCRYPT has spent years building its competitive edge in exactly that area. That is also why Elektrobit reached out, and why the partnership was designed from the start as a global strategy rather than one confined to Korea.
By Sang Min Han@autoelectronics.co.kr
한글로보기
Security Has Different Layers and Stages
You went public in 2025 under the Technology Exemption Listing program. What has changed in how the company operates since the listing, and what would you highlight as your key business achievements?
Deoksoo The automotive industry is a very conservative sector. When a company decides whether to put a given technology into a vehicle, it isn't just about the technology itself — a lot of weight goes into whether the supplier is sustainable, and whether it's a company you can trust and grow with over the long term. We got this question constantly when working with overseas companies. Most of the automotive industry is hardware-centric, so revenue and headcount above a certain scale tend to be treated as baseline criteria, and a software company like ours can look like an outlier against that yardstick. We concluded that going public was necessary to secure greater trust and credibility when working with companies abroad.
Another factor is that the automotive cybersecurity market itself is only now starting to take shape as a regulated industry. Safety regulation built up over 25 to 30 years and has become common sense, but the same hasn't been true on the software side. Serious discussion of making cybersecurity mandatory for intelligent vehicles really got going around 2020, and it's only recently been written into actual laws and regulations. Europe has enforced related regulations since July 2024, and Korea is only now beginning to respond in earnest.
It's hard to say the way we run the company has changed dramatically since going public, but we now carry a responsibility to keep disclosing information and explaining our results. Investor expectations have shifted too. We're a company listed under the Technology Exemption Listing program, but there's now far greater demand — not just for our technology, but for whether the company can generate profit on its own and how quickly it can turn a profit.
Right now, our security solutions are running in more than 8 million mass-produced vehicles on the road. That's our biggest business achievement. We began putting our technology into actual vehicles in mass production from late 2022 through 2023, and our solutions are now in vehicles sold globally — including in China — as well as vehicles on the road here in Korea. Developing a technology and actually applying it to mass-produced vehicles are completely different problems, and we believe having already gained that experience is our biggest competitive advantage.
The term 'automotive cybersecurity' gets used as a catch-all, but I've heard that within it, different companies are actually good at different things. How does it break down?
Deoksoo Automotive cybersecurity can be split into four broad stages. First, developing securely. Second, verifying that it was developed properly. Third, continuously monitoring vehicles after they've been sold. Fourth, resolving issues that are discovered during operation. A complete automotive cybersecurity system needs all four stages in place. And right now, the players in this market each have their strengths at different points across these four stages.
In the past, Continental had Argus Cyber Security, and organizations like PlaxidityX — the rebranded successor to Argus — handled automotive cybersecurity. Argus's strength was in the post-production operational security phase: finding vulnerabilities in vehicles already on the road and monitoring them. But right now, the automotive industry isn't in an operations phase — it's in the phase of building new EV and SDV platforms. The build phase needs its own dedicated solutions. Consulting and development-stage solutions are what's needed first.
We have a real strength in exactly this development and verification. This was also the part that came under the closest scrutiny during our IPO process. We were assessed objectively against competitors on how efficiently we could implement the solution with limited computing resources, how fast it ran, and how well it held the same level of security while drawing minimal power. A car isn't a system like a data center, built to maximize performance by pouring in unlimited power. It has to run on a single charge, and a single charge contains roughly the amount of energy an average household consumes in a week. Layer security on top of that and use computing resources excessively, and you actually start getting in the way of driving. So from the development stage onward, how efficiently a solution is optimized for the hardware, and how little power it draws, become the key competitive edge. This isn't something you can bolt on after the fact — it has to be designed in from the very start.
Responsibility Moves to Suppliers
At this point in the shift to SDVs, why has the 'development stage' specifically become the deciding factor? How are the roles of OEMs and parts suppliers changing?
Deoksoo From an OEM's perspective, the biggest headache is the development stage. That's because while an OEM can take direct responsibility for a vehicle's operation after it's sold, development is mostly done together with parts suppliers. German OEMs have long required suppliers to “develop it with security built in and bring it to us.” That raises the burden on suppliers, but it lets the OEM speed up development overall. Volkswagen tried to do it all in-house through CARIAD, but that proved difficult in practice. Chinese EV makers, by contrast, started out with an SDV architecture from day one, so OEM-led development came naturally to them.
In Korea too, the past two to three years have been a period when OEMs directly supported much of this work. But going forward, suppliers will need to develop cybersecurity capabilities themselves and deliver them as part of their products. That's the only way to make responsibility clear, and to make everyone's role clear in recalls or quality issues. We expect this shift to speed up starting this year and next. Large suppliers like LG Electronics, Hyundai Mobis, and HL Mando are already well along in preparing, but even they can't handle every part of automotive cybersecurity on their own, so ongoing collaboration with specialized companies is still essential.
The rollout of Euro 7 is accelerating this trend too. It brings anti-tampering requirements for control units tied to environmental regulation — things like emissions and tire particulate — requiring proof that the software hasn't been altered. Security used to focus mainly on critical control units like infotainment and telematics; now the requirement is spreading to cover far more components. For suppliers, it's a shift from an era where it was enough to build a good control function, to one where they also have to prove that “this software hasn't been tampered with.”
Organizations are adjusting to this shift too. Safety teams have existed for a long time, but cybersecurity is a fairly new function. At OEMs, the work is already split across separate groups — one that designs security during development, a quality team that verifies the results, an operations team that monitors after sale, and a regulatory-certification team. Many suppliers, by contrast, still don't have a dedicated team — it's often one person inside quality handling it. The supply chain has also become the hardest part since UN R155 took effect. OEMs have no choice but to require suppliers to “develop it with security already built in and bring it to us,” and in a lot of cases the OEM even sets the security test items and evaluation criteria itself.
I've also heard that the shift to zonal E/E architecture is making development-stage security even more important. What are you actually seeing in penetration testing?
Deoksoo Zonal architecture is designed around 'Freedom from Interference' — blocking interference between zones. From what we've seen in actual red-team work, moving to a zonal architecture hasn't increased or decreased the number of threats — it's just changed their shape. Where we put our priority is the outermost point on the attack path: external-facing boundaries directly connected to outside networks. We apply security strictly there, but the reality is that the zones further inside are handled comparatively loosely. Partly that's because regulators would drive costs up too far if they demanded the same level of certification for every zone. Some later-entry competitors are still at the stage where they can pass certification just by covering the outer boundary, but expanding that to the inner zones is a task they'll still have to tackle when they develop their next-generation models.
Once, an executive at a global OEM said something that stuck with me. I asked whether it was fine to load cybersecurity heavily into expensive cars while going cheap on safety in inexpensive ones, and he said no. His point was that security inevitably raises the cost of every vehicle across the board.
AI is adding a new variable here. We've taken part in the DEF CON Car Hacking Village every August for five years running. In 2025 there was a hacking challenge with a car sponsored by Rivian, and the same venue also hosted the finals of DARPA's AI Cyber Challenge (AIxCC). The winning team represented the U.S., but was composed largely of Korean members, in a contest built entirely around hacking with AI and defending with AI. Our own red team has reached the point where we can't produce results without AI either. Testing a vehicle usually means rewiring and physically taking it apart, so it takes far longer than IT testing — extracting firmware from a component and having a person analyze it can be slow work, but running it through AI can produce results in as little as 15 minutes. On the flip side, attackers are automating vulnerability hunting and attack attempts with agents the same way, so security that used to be considered safe now has to be considerably stronger just to hold up. All of this points back to the same conclusion: it's not about relying on post-production patches or updates, but how tightly it's designed from the very start of development.
So, Elektrobit
So is that why you partnered with Elektrobit? What exactly was the background behind this partnership, and why do you see it as a 'global' strategy?
Deoksoo Elektrobit has very strong capabilities in the development-platform space, and we have strengths in designing and validating automotive cybersecurity. That's why our capabilities connect so naturally. We're not just working with Elektrobit in the Korean market — we're genuinely moving forward with a solid position on a global scale.
We're rapidly catching up in areas German companies have been developing since the late 2010s, and there are areas that have not been fully addressed by Israeli companies. Going forward, new players will keep emerging out of China and India too, but in the end I think competitiveness will come down to who has accumulated the most mass-production experience and advanced-development experience.
Our partnership with Elektrobit has been built around global collaboration from the very start. Elektrobit is active across many regions, including India and Japan, and we're working together within that global network. In a similar vein, Cybellum, an Israeli company that partners with LG Electronics, is also worth looking at. Cybellum isn't a company that builds security functions itself the way we do — it's more a company that makes lifecycle process software, managing the requirements and processes across each stage of the cybersecurity lifecycle. What all these partnerships point to is the same thing: automotive cybersecurity isn't something one company can do alone. It only comes together when each company's strengths are linked across the lifecycle.
You're expanding your portfolio into digital keys, V2X, and EV charging infrastructure — is that also an extension of the same 'development capability'?
Deoksoo That's right. Our competitors in the market right now are automotive software platform companies like ETAS and Vector. That's because automotive cybersecurity is no longer a standalone function — it's being folded into SDV development platforms. Vector covers software broadly and handles part of cybersecurity as one piece of that, while ETAS runs cybersecurity components directly inside its AUTOSAR business. In Korea there's also a company called Fescaro. What sets us apart from them is that we're not simply a company that provides security solutions. Smartphone-based digital keys are also built on cybersecurity technologies, and V2X, which is moving toward becoming mandatory in India, also depends on having a trustworthy security framework in place.
The same goes for EV charging infrastructure. Going forward, a vehicle won't just charge — it'll become part of an energy storage system (ESS) and exchange power both ways. For that to work, vehicles and chargers need to be able to trust and authenticate each other. There's a national-level project underway in Korea right now to build a mutual-authentication system for charging infrastructure, and we're responsible for the core technology behind it. In the past this was built around Hyundai Motor, but for a range of global manufacturers, including BMW, to take part, you need a national-level trust and authentication framework rather than one tied to a specific OEM. Not many companies handle work at this scope. You can think of this, too, as our capability for designing trust frameworks from the development stage extending beyond cars into the broader connected ecosystem.
What kind of company do you want AUTOCRYPT to be in 10 years?
Deoksoo I want us to be a company where, when people hear “this vehicle has AUTOCRYPT technology in it,” they naturally think of it as a safe vehicle. A lot of people think of cybersecurity as basically defense against hacking, but we see it as part of software safety. If brakes, airbags, and seatbelts are physical safety, cybersecurity is the technology responsible for software safety. We don't want to be a company focused only on cybersecurity; we want to take responsibility for software safety as well.
Lately, what I'm watching most closely is China. The number of EV companies in China once reached around 300 before consolidating to roughly 100, and there's talk it will eventually consolidate into around 15 large players. That's not just a shakeout — it's a strategy to build global competitiveness through mergers. Korea runs a self-certification system; it originally followed the European-style type-approval model, but switched to the U.S. approach after the FTA. That's helped Hyundai get into the U.S. market, but it's also made it relatively easy for Chinese companies to enter the Korean market. So every time I meet with policymakers, I make this point: Korea needs to think about sovereignty in autonomous driving and in cybersecurity too. The U.S. has already declared that vehicles running Chinese software can't be sold there. We probably can't go quite that far, but I do think we need to protect and grow our domestic industry through cybersecurity regulation and technological competitiveness at the very least.
In July, at AID 2026, Elektrobit CCO Arvind Murthy took the stage with AUTOCRYPT Global CTO Eui-suk Kim to discuss the future of the two companies.
In Conclusion
Before wrapping up the interview, I summed up what I'd heard in one sentence and asked him to confirm it. “At the start of the SDV era, security at the development stage has become more important than security during operation, and AUTOCRYPT is pursuing global collaboration with Elektrobit on the strength of its position in that area — is that a fair way to put it?”
Co-CEO Deoksoo Kim answered briefly and clearly.
“Yes, that's right.”
AEM(오토모티브일렉트로닉스매거진)
<저작권자 © AEM. 무단전재 및 재배포 금지>