
Chinese electric buses not found to be less cybersecure – Danish investigation completed
A comprehensive investigation commissioned by Movia, the public transport authority for the Copenhagen region, has brought a turn in the cybersecurity debate that emerged around Chinese electric buses last autumn. According to a 38-page risk analysis completed in September by the international consultancy Ernst & Young (EY), risks arising from remote access, software updates and external back-end systems do indeed exist in the case of modern, connected electric buses, but the investigation found no basis for generally associating these risks with Chinese-built vehicles. On the contrary: in a comparison of the documented cybersecurity preparedness of the types operating on Movia’s network, Yutong, BYD and Golden Dragon ranked among the manufacturers with the best results in several areas.
The immediate background to the study was the investigation by Oslo’s Ruter last year, which attracted considerable international attention. The Norwegian transport authority examined a Yutong and an older VDL electric bus, and found that the Chinese vehicle was capable of receiving remote software updates via its built-in data connection, while the VDL tested did not have OTA functionality. In the wake of the case, the issue of the digital vulnerability of electric vehicles used in public transport also came onto the agenda in Denmark.
As early as 2025, Movia turned to the Danish Agency for Societal Security, Styrelsen for Samfundssikkerhed (SAMSIK), primarily because of questions raised in connection with the data handling of Chinese bus manufacturers. At the time, the authority said it was not aware of any specific threat linked to Chinese electric buses, but it also drew attention to several generally known cybersecurity risks and recommended that Movia prepare a comprehensive risk assessment on the use of electric buses. Following this, the transport authority commissioned EY to carry out the investigation that has now been completed.
The current work, however, went significantly beyond examining whether a manufacturer is able to communicate with its vehicles remotely. EY set out to determine whether the current regulatory framework is adequate, how far the compliance of individual manufacturers can be verified, what actual threat remote access or even the remote shutdown of a vehicle could pose, how this may change with the emergence of increasingly advanced driver assistance and automated functions, and what requirements Movia should consider incorporating into its future transport contracts.
Eight bus manufacturers were included in the investigation
The analysis focused on vehicles actually in service with Movia’s operators. The fleet examined included 299 Yutong E9, E12, U12 and E15 buses, 259 BYD K9UD, B12E03, B13E01 and B19 vehicles, 67 MAN Lion’s City 12 E buses, 49 Ebusco 2.2 vehicles, 29 Volvo 7900 Electric buses, 27 Golden Dragon E12 and E13 vehicles, 26 Mercedes-Benz eCitaro buses, and 23 previous-generation VDL Citea SLF 120 E and SLFA 180 E vehicles. In other words, the analysis covered a total of 779 electric buses used in daily operation. Because of Flextrafik, passenger cars were also included: alongside the Tesla Model 3 and Model Y, the BYD Seal U served as the Chinese reference platform.
It is important, however, that EY did not carry out penetration testing similar to Ruter’s investigation, i.e. practical security tests aimed at uncovering system vulnerabilities, nor did it perform physical vehicle inspections. It assessed structured questionnaires completed by the manufacturers, documentation provided, type-approval material and publicly available information. Six areas were examined: cybersecurity governance, risk analysis, system architecture, software update management, validation and incident management. The responses were not separately verified by penetration testing or on-site audits, so the results primarily show the extent to which each manufacturer was able to substantiate its cybersecurity processes with documentation. A high score therefore does not mean that the vehicle in question is unhackable, just as a lower result does not prove that the type concerned is dangerous.
Chinese manufacturers performed particularly strongly
One of the most interesting results of the investigation is precisely that it did not confirm the assumption on which much of last year’s debate was based. According to EY, Yutong, BYD, Golden Dragon and MAN showed a high level of documented cybersecurity maturity in most of the areas examined. Ebusco’s results were rated as medium, while Daimler Buses/Mercedes-Benz was assessed as fundamentally well prepared, with some documentation gaps.
The differences are clearly visible in the individual sub-areas. In cybersecurity governance, BYD, Yutong and MAN all achieved 100% documented compliance, while Golden Dragon scored 86%, Ebusco 90% and Daimler Buses 86%. In risk analysis, BYD and Golden Dragon scored 100%, Yutong 95%, Ebusco 95%, Daimler 90% and MAN 85%. In the assessment of system architecture, Ebusco, BYD, Golden Dragon, Yutong and MAN all achieved a 100% result.
Software update management is particularly interesting in light of the Norwegian investigation. In this area, Yutong showed full, 100% documented compliance, while BYD, Golden Dragon and MAN achieved 90%, Daimler Buses 70% and Ebusco 60%. According to EY, based on the requirements examined, Yutong was able to demonstrate the processes needed to ensure the authenticity, integrity, compatibility, traceability and secure execution of updates.
In validation, BYD, Ebusco, Yutong and MAN all received a 100% score, while Golden Dragon and Daimler Buses scored 92%. In incident management, Yutong achieved a particularly strong result among the bus manufacturers examined, with 93%; MAN and Golden Dragon scored 86%, BYD 79%, Daimler Buses 64% and Ebusco 43%.
EY’s summary is therefore clear: among the buses examined, Yutong, BYD, Golden Dragon and MAN have the strongest documented cybersecurity maturity. This is, of course, not a general ranking of every type from the individual brands, but applies solely to the specific vehicles examined on Movia’s network and to the documentation available.
An important technical difference lies behind VDL’s weak result
The weakest documented results were shown by the VDL Citeas examined: governance 10%, risk analysis 0%, architecture 56%, software updates 40%, validation 8% and incident management 14%. It would be misleading, however, to conclude from this that VDL’s current electric buses are weak from a cybersecurity perspective.
The Citea SLF 120 E and SLFA 180 E units examined were delivered in 2019, before the UNECE R155 and R156 requirements became mandatory. Moreover, these are not OTA-capable vehicles: software access essentially takes place in a workshop environment. On the one hand, this means weaker documented lifecycle management and auditability; on the other, the very absence of an internet-based OTA connection reduces the practical likelihood that a remote attack could affect the entire fleet at once. EY therefore explicitly warns that the result relates to the old Citea generation and should not be regarded as an assessment of VDL’s current cybersecurity capabilities.
In the case of the Volvo 7900 Electric, no similar assessment was prepared at all: Volvo did not provide a completed questionnaire or equivalent evidence. EY treats this as a lack of information and specifically emphasises that no negative conclusion can be drawn from it regarding the cybersecurity of Volvo’s vehicles.
Remote connectivity is not the problem in itself
One of the study’s most important professional findings is that the risk should not be reduced simply to whether a manufacturer can communicate with the bus remotely. Modern electric buses are increasingly software-based vehicles: they use remote diagnostics, manufacturer back-end systems, cloud services, OTA updates, digital workshop tools and various driver assistance functions. As a result, the potential attack surface no longer ends with the bus itself, but extends to the operator’s IT system, the manufacturer’s servers, the charging infrastructure and maintenance interfaces as well.
EY identified six key risk areas. It considers remote access, OTA updates and dependence on back-end systems to be the most important, followed by the risk of deficiencies in software updates and incident management. Separate categories include the issue of older vehicles not covered by R155/R156, non-factory onboard systems and the protection of the personal data they handle, charging infrastructure, and increasingly advanced ADAS and automated driving functions.
In the case of a compromised or faulty software update, for example, the biggest problem is not necessarily a single vehicle, but the fact that the same update can extend to an entire fleet within a short time. Similarly, the compromise of an external back-end system or privileged supplier access could affect many vehicles at once. EY therefore recommends the use of gradual rollouts, rollback capability, detailed logging and predefined incident management processes.
Operators must even be prepared to cut a bus’s data connection
One of the most specific recommendations is that, in future, Movia must know exactly what remote functions a bus has, who can access them, what data the vehicle transmits, and how these connections can be restricted or terminated if necessary.
The study recommends that operators and their manufacturers should be required to document OTA updates, remote access and the automatic transmission of vehicle, operational and location data. Contracts should also specify whether individual functions can be fully or partially disabled, who can do this, how long it would take, and what impact it would have on the vehicle’s safety, type approval, warranty or operational capability.
EY goes even further: it recommends ensuring that vehicles’ data connections can be provided through a European mobile network operator, and that in the event of an elevated threat level, SIM-based communication can be selectively disabled for a single vehicle or even for the entire fleet. The same could apply to OTA updates, remote access and automatic data transmission.
Automation also raises the stakes
According to EY, more advanced ADAS systems and later automated driving functions do not necessarily pose a greater risk because they are easier to hack in themselves, but because the consequences of a software fault, incorrect configuration or compromised remote connection may have an increasingly direct effect on the movement of the vehicle, and, through a central system, potentially on several vehicles at the same time.
Future contracts should therefore require a safe fallback mode, full driver intervention capability, the ability to disable automated functions, gradual software deployment and the option to roll back to a previous version.
It is not only the bus itself that needs protection
The report also devotes a separate chapter to systems that do not originate from the vehicle manufacturer. These may include automatic passenger counting, passenger information, infotainment, camera systems, ticketing systems, the operator’s IT equipment or depot charging systems.
These are typically not capable of directly intervening in propulsion, braking or steering, but in the case of poor network segmentation they can create new entry points for an attack. They also raise serious data protection issues: CCTV footage, raw images from passenger counting systems, ticketing data, GPS information and certain telemetry data may qualify as personal data. EY therefore also recommends separate networks, access logging, clearly defined responsibilities and GDPR-compliant data management for these systems.
The study also treats charging infrastructure as a separate risk area. An attack on a charging system does not necessarily make it possible to control the buses themselves, but it can cripple the operation of an entire depot, thereby indirectly causing significant service disruption. EY therefore recommends applying IEC 62443 or equivalent industrial cybersecurity requirements.
The regulatory basis is adequate, but not sufficient on its own
According to EY’s assessment, UNECE Regulations Nos. 155 and 156, ISO/SAE 21434 and ISO 24089 together provide a fundamentally adequate framework for the cybersecurity of modern connected vehicles. R155 requires the manufacturer to have a Cyber Security Management System and risk analysis covering the entire vehicle lifecycle, while R156 regulates the Software Update Management System for the secure and auditable handling of software updates. ISO/SAE 21434 sets out automotive cybersecurity engineering processes, while ISO 24089 details the technical management of software updates.
Compliance with the rules, however, does not mean absolute security. Some older vehicles were not yet covered by R155 and R156, while type-approval requirements do not fully cover retrofitted onboard systems and, in themselves, do not provide the transport authority with rights of insight, audit or intervention. EY therefore recommends that Movia turn these into specific contractual requirements.
In future tenders, compliance with R155 and R156, as well as ISO/SAE 21434, ISO 24089, ISO/IEC 27001 for operator and back-end systems, and IEC 62443 for charging infrastructure — or equivalent evidence — could thus become a requirement. In addition, rapid incident reporting, audit rights, minimum requirements for older vehicles and the ability to disable remote functions if necessary would also be stipulated.
The final conclusion of the analysis prepared for Movia is therefore far more nuanced than the question with which the debate began last year. A remotely accessible electric bus does indeed carry cybersecurity risks, but remote connectivity is not an anomaly in itself, and based on the available data there is no professional basis for generally regarding Chinese electric buses as less cybersecure than their European competitors. According to EY, the emphasis should therefore not be on the vehicle’s country of origin, but on verifiable cybersecurity processes, transparent remote access, appropriate system architecture, incident management, and the ability of the transport authority and the operator, in a critical situation, to restrict connections and isolate the possible impact to a single vehicle or to as small a part of the fleet as possible.
![Magyarbusz [Info]](/mbi/header-logo.png)











