Endpoint Cybersecurity GmbH
- Why SSDLC is helping shipping faster and more secure code
- Security User Stories How-To – for product managers and developers
- ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance
- ISA VDA 6.0.3 (part 4) — Information Security Sheet: IT Security / Cyber Security
- ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management
- ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization
- TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1)
- AI Adoption for companies in the USA
- AI Adoption for companies (based on OECD data)
- SOC 2 Type 2 mapping to Secure SDLC Requirements



The Automotive industry’s inadequate approach towards software (in the cars)
/in EducationalIntroduction The automotive industry has witnessed a paradigm shift with the increasing integration of software in vehicles. Modern cars are no longer just mechanical devices with a motor, wheels and steering; they are now sophisticated machines having dozens of CPUs (called ECU), entire computers, high speed network to connect them (called CAN-bus) and relying on […]
ChatGPT and automotive cybersecurity #2/2: TISAX certification
/in EducationalThis is the 2nd post about Automotive Cybersecurity. Since I am working these days on CSMS (based on ISO ECE 21434 and TISAX), part of my companies consulting offer for automotive I thought maybe I check what ChatGPT things about them. First post was about CSMS and ISO 21434 and this one is about […]
ChatGPT and automotive cybersecurity #1/2: About CSMS from ISO 21434
/in EducationalAs promised, I played more with ChatGPT and this time I started to dig a bit into cybersecurity for automotive. Since I am working these days on CSMS (based on ISO ECE 21434 and TISAX), part of my companies consulting offer for automotive I thought maybe I check what ChatGPT things about them. Unfortunately, nothing […]
A brief history of software vulnerabilities in vehicles (Update 2023)
/in EducationalUpdated in 2023: 2023: Sam Curry: Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More Kia, Honda, Infiniti, Nissan, Acura Fully remote lock, unlock, engine start, engine stop, precision locate, flash headlights, and honk vehicles using only the VIN number Fully remote account takeover and PII disclosure via VIN […]
Risk Assessment of AWS services used in building a resilient Web App on AWS
/in EducationalWe wrote here in the article “Building Resilient Web Applications on AWS: A Comprehensive Approach to Security” how to use certain AWS services to implement a resilient web based application. The services mentioned require also a brief analysis in respect to Security, Confidentiality, Integrity, Availability and Privacy. Contents Toggle CloudTrail Risk Assessment Mitigation Privacy CloudWatch Risk […]