Conference Description
Key Takeaways
- Annual gathering focused on cybersecurity challenges specific to the automotive industry
- Addresses the tension between regulatory compliance and genuine cyber resilience
- Explores supply chain security, risk management, and operational constraints facing manufacturers and suppliers
- Designed for CISOs, IT/OT leaders, product security managers, compliance officers, and technical practitioners
- Hybrid format combining executive presentations, technical workshops, and networking opportunities
Introduction
The 10th Annual Auto-ISAC Cybersecurity Summit brings together automotive manufacturers, suppliers, policymakers, and security practitioners to address the increasingly complex cybersecurity landscape facing the global automotive sector. Taking place October 6–9, 2026, in Novi, Michigan, the summit arrives at a critical moment as the industry contends with accelerating regulatory requirements, sophisticated threat actors, and the operational realities of securing interconnected vehicle systems and sprawling supply chains.
This year’s theme, “The Cost of Vigilance,” reflects a maturing conversation within the industry. As automotive systems grow more connected and software-defined, the resources required to maintain effective security programmes have expanded significantly. The summit examines whether current approaches—often driven by compliance mandates—translate into meaningful protection against real-world threats.
About the Auto-ISAC Cybersecurity Summit
Auto-ISAC, the Automotive Information Sharing and Analysis Center, serves as the central hub for cybersecurity intelligence sharing across the automotive industry. The organisation’s annual summit has become the sector’s flagship cybersecurity event, providing a forum where competing manufacturers collaborate on shared security challenges. Now in its tenth year, the conference has evolved alongside the industry’s understanding of cyber risk, shifting from foundational awareness toward practical implementation and operational effectiveness.
The 2026 event offers a hybrid format, accommodating both in-person attendance in Michigan and virtual participation. Programming spans executive-level presentations, hands-on technical workshops, and structured networking sessions. Certain sessions remain exclusive to Auto-ISAC members, while others are open to the broader automotive security community.
Compliance Versus Resilience: The Central Tension
A recurring theme throughout the summit concerns the distinction between achieving regulatory compliance and building genuine cyber resilience. Regulations such as UNECE WP.29 and ISO/SAE 21434 have established baseline requirements for automotive cybersecurity management systems, compelling manufacturers to formalise their security practices. However, compliance frameworks necessarily represent minimum standards rather than comprehensive protection.
The summit explores how organisations can move beyond checkbox exercises toward security programmes that deliver measurable risk reduction. This involves aligning security investments with business objectives, quantifying cyber risk in terms executives understand, and building capabilities that adapt to evolving threats rather than static regulatory requirements. For many organisations, the challenge lies in justifying security expenditure when compliance alone satisfies legal obligations.
Supply Chain Security and Supplier Oversight
Modern vehicles incorporate components and software from hundreds of suppliers, creating complex interdependencies that extend cybersecurity risk far beyond the original equipment manufacturer. A vulnerability in a tier-two or tier-three supplier’s software can propagate through the supply chain, ultimately affecting vehicles across multiple brands. The summit dedicates significant attention to supplier oversight mechanisms, contractual security requirements, and practical approaches to validating supplier security claims.
Geopolitical factors add further complexity. Regulatory requirements vary across jurisdictions, and suppliers operating globally must navigate divergent—sometimes conflicting—compliance obligations. The summit examines strategies for managing this fragmentation while maintaining consistent security standards across international operations.
Operational Realities and Resource Constraints
Theoretical security frameworks often collide with operational realities. Many automotive organisations operate with constrained cybersecurity budgets, legacy systems that resist modern security controls, and competing priorities that limit available resources. The summit addresses these practical challenges, sharing approaches that deliver security improvements within realistic operational constraints.
Sessions examine how organisations balance security investments against other business demands, prioritise limited resources against extensive threat landscapes, and build security cultures that extend beyond dedicated security teams.
Who Should Attend
The summit serves professionals across the automotive cybersecurity spectrum. Chief Information Security Officers and IT/OT leaders will find strategic content addressing programme development and executive communication. Product security managers and technical practitioners benefit from implementation-focused workshops and peer discussions. Compliance officers and risk managers gain insight into regulatory developments and assessment methodologies. The event also attracts representatives from government agencies, consultancies, and technology vendors serving the automotive sector.
Industry Participation
The summit draws support from across the automotive and cybersecurity industries. Ford serves as Titanium sponsor, with Booz Allen at the Platinum level. Gold sponsors include Fescaro, Remedio, and Zscaler, while Silver sponsors encompass Utimaco, DQS Global, Pentest Partners, and Upstream Auto. Additional participating organisations include KPMG, Denso, Vultara, RunSafe Security, ReversingLabs, FossID, ENX, Plaxidityx, Varonis, and Flashpoint, representing a cross-section of manufacturers, security vendors, and consultancies engaged in automotive cybersecurity.

