MAN: Efficient threat analysis for control units
Project duration: 7 months
The requirement: MAN lives safety
With the digitalization of its vehicles, MAN Truck & Bus is facing the challenge that trucks are becoming an increasingly attractive target for virtual attacks. This is why security plays an essential role in the development of MAN's new CM4 connectivity control unit.
Using risk analyses based on the 4×6 methodology, our MaibornWolff experts supported the MAN development teams in protecting the communication channels and digital functions of the control unit - appropriately and in a targeted manner.
The secret to success: close collaboration with the development teams
Working as closely as possible with the development teams. This is our basic philosophy when identifying and assessing threats. No one has a better idea of how the target system could be attacked than its "creator". This allows us to quickly identify relevant threats and immediately develop tangible security measures together with the development team.
Procedure: comprehensive threat and risk analyses
In over 20 threat analysis workshops with various application and system development teams, more than 500 potential risks for the control unit were evaluated - and effective security measures were developed at the same time. The development teams were able to start implementing these measures immediately. At the same time, our technical experts brought the results into line with MAN's overall vehicle risk analysis procedure and ISO21434.
This took a lot of pressure off the teams due to compliance-related documentation requirements and achieved a high degree of parallelization.
Methods: analyze threats quickly and easily
With MaibornWolff's 4×6 methodology and the use of ThreatSea, threat and risk analyses can be carried out efficiently and easily accessible. The methodology provides users with sufficient know-how without having to be security experts themselves. As a result, the developers' knowledge of the system's internals can be utilized efficiently. The technology-independence of the methodology makes it possible to use it both for the control unit itself and beyond (e.g. for the communication channels towards the backend). This enables an end-to-end view of the overall risks.
The feedback from the development teams from the threat analysis workshops and the findings of the project flow directly back into the development of ThreatSea.
With MaibornWolff's threat analysis, we quickly came to tangible results in order to establish the right level of security for the CM4. With the following end-to-end analysis of the 'Secure Diagnostics and Flashing' use case using the 4×6 methodology, we will build on the knowledge gained and gradually bring even more security to our vehicles and their ecosystem.
Our references & projects
A reference is worth more than 1,000 words. Fortunately, we have dozens of them. Click through a selection of our most exciting projects and see for yourself!
-
To the BMW referenceVirtualization of software testing for control units in the AWS cloudAutomotiveCloudTo the BMW referencesince June 2023
To the BMW referenceEfficient software development
To the BMW referencein AWS cloud
-
To the STARTRAIFF referenceSTARTRAIFF: Business Intelligence for the sales forceInsuranceData & AITo the STARTRAIFF referencefor more business intelligence
To the STARTRAIFF referenceand analyzes customer data
To the STARTRAIFF reference60 minutes per customer visit
-
To the MAN referenceMAN - ATLAS L4. Control Center for the autonomous truckAutomotiveTo the MAN referencefor driverless trucks
To the MAN referenceof the vehicle data
To the MAN referenceon autonomous driving
-
To the NOW referenceNOW: National Organization for Change in Mobility: development of a data warehouse systemEnergyAutomotiveTo the NOW reference5 months
To the NOW referenceSecure data integration
To the NOW referenceData and software engineers
-
To the NETZSCH referenceNETZSCH: Development of an IoT platformIoTCloudManufacturingTo the NETZSCH referencesince August 2024
To the NETZSCH referencefor three business divisions
To the NETZSCH referencein a cloud infrastructure
-
To the OroraTech referenceOroraTech - Security & Compliance SupportIT ConsultingCybersecurityTo the OroraTech referenceFebruary 2025 to May 2025
To the OroraTech reference4x6, ThreatSea, workshops, interviews, questionnaires
To the OroraTech referenceSecurity Architects and IT Consultants
-
To the TKE referenceTK Elevator: Health Check Connectivity for the IoT gateway of elevatorsIoTCloudEmbedded Systems & Robotics (SMD)To the TKE referenceconnects elevator with IoT platform
To the TKE referenceand 22 interviews & workshops
To the TKE referenceof the connectivity of the gateways
-
To inCTRL referenceinCTRL Solutions: Modernization of the IoT platform for water treatment plantsIoTCloudData & AITo inCTRL referenceof the IoT platform
To inCTRL referencego hand in hand
To inCTRL referencethanks to CI/CD pipelines
-
To the TÜV Nord referenceTÜV NORD: IT system for damage assessmentsCloudDigital Design & UX DesignWebTo the TÜV Nord referencein productive operation
To the TÜV Nord referencetime savings for garages
and the virtual infrastructureTo the TÜV Nord reference -
To the Mixed Reality referenceUniversity Medicine Frankfurt - Mixed reality for the training of doctorsVR/ARTo the Mixed Reality referencefor 4 years
To the Mixed Reality referenceTechnology-supported medical training
To the Mixed Reality referenceInteractive training environment
-
To the Health.exe referenceHealth.exe: AI-supported platform creates training plans for patientsCloudData & AITo the Health.exe reference5 months
To the Health.exe referenceServices for orthopaedics
To the Health.exe referencein practice systems
-
See robotics referenceResearch: AI-supported robotics for employees with physical limitationsData & AIDigital Design & UX DesignEmbedded Systems & Robotics (SMD)See robotics referenceresearch project, funded by the Bavarian Ministry of Economic Affairs
See robotics referencemore individuality thanks to AI
See robotics referencehelps to be able to react quickly during operation
-
See MAN referenceMAN: Efficient threat analysis for control unitsCybersecurityIT ConsultingAutomotiveSee MAN reference7 months
See MAN referenceThreat analyses
See MAN referencePotential risks evaluated
-
See Siemens referenceSiemens: AI demand prediction platform for industrial production planningData & AICloudWebSee Siemens referencesince February 2022
See Siemens referencein a few weeks
See Siemens referencefor 100 different products
-
See TÜV NORD referenceTÜV NORD GPT: Development of AI assistanceData & AICloudSee TÜV NORD referencesince September 2023
See TÜV NORD referenceGPT applications in the first month
See TÜV NORD referencein the European Microsoft Azure Cloud
-
See Schöck Bauteile referenceSchöck components: Improvement of the requirements processDigital Design & UX DesignIT ModernizationIT ConsultingSee Schöck Bauteile referencesince 2022
See Schöck Bauteile reference2-3 Digital Designer:inside
Scalix replaces old softwareSee Schöck Bauteile reference -
See VW referenceVW: Digitization of key production figures with the iProcess appApps (Web, Mobile, AR/VR)CloudDigital Design & UX DesignSee VW referencesince January 2021
See VW reference5 to 10 persons
See VW referencethanks to Digital Design
-
See digikoo referencedigikoo GmbH: Apple Vision Pro for city plannersVR/ARApps (Web, Mobile, AR/VR)Data & AISee digikoo reference4 months
Display building data dynamicallySee digikoo referenceImmersive visualizationSee digikoo reference -
See Miele referenceMiele domestic appliances are networked worldwideCloudEmbedded Systems & Robotics (SMD)IoTSee Miele referencesince 2016
See Miele referencehigh availability and scalability
See Miele referencewith container-based architecture
-
See BMW Group referenceBMW Group: Replacement of a production-critical legacy systemCloudIndustry 4.0IT ModernizationSee BMW Group referenceMid-2018 to the beginning of 2024
See BMW Group reference25 employees
See BMW Group referencereplaced after 20 years
-
See BMW referenceMixed reality: driving a real car in a virtual worldVR/ARDigital Design & UX DesignAutomotiveSee BMW referenceFrom the vision to the prototype
See BMW referencein real time
See BMW referenceUnreal development, XR technology, game design, smart devices, 3D content
-
See KUKA referenceKUKA: Web interface for a new Human Machine InterfaceIT ConsultingCloudWebSee KUKA referenceReplacing the current control software
See KUKA referenceFast and intuitive development
See KUKA referenceProject work
-
See STIHL referenceSTIHL: Control iMOW robotic mower via appCloudApps (Web, Mobile, AR/VR)IoTSee STIHL referencesince August 2020
See STIHL referenceControl via app
See STIHL referencewith the customer
-
See ifm services referenceifm services: Remote maintenance of systems and machinesIndustry 4.0CloudData & AISee ifm services referencesince March 2023
See ifm services referenceintegrated in platform
See ifm services reference5 Developers
-
See DER Touristik referenceDER Touristik Online: Development and migration of a multi-client capable travel booking platformCloudQuality EngineeringWebMulti-client travel portalSee DER Touristik referenceEnd-2-End test automationSee DER Touristik referenceMigration to AWS cloudSee DER Touristik reference -
See MAN referenceMAN: Secure Software Development Life CycleCybersecurityAutomotiveSee MAN reference22 months
successfully integratedSee MAN referenceSee MAN referenceSecurity Champions, DevSecOps, OWASP SAMM
-
See Bayernwerk referenceBayernwerk: Knowledge management via teamsData & AIApps (Web, Mobile, AR/VR)EnergySee Bayernwerk reference6 months
See Bayernwerk referenceIdentify implicit knowledge
See Bayernwerk referencea user-centered, intuitive and clear UX/UI design
-
See Es geht LOS referenceEs geht LOS: Development of a cloud-based application for citizen participationCloudApps (Web, Mobile, AR/VR)Digital Design & UX DesignSee Es geht LOS referencethrough random selection
See Es geht LOS referencefor citizens' councils via app
See Es geht LOS referencefrom concept to prototype with AWS Amplify
-
See referencePlanning systems: Optimizing the capacity utilization of pressing plantsCloudIT ModernizationIndustry 4.0See referenceCustomer support
Cloud-ready platformSee referenceSite-specific cost planningSee reference -
See referenceGlobal workforce planning systemCloudDigital Design & UX DesignIT ModernizationSee referenceup to 8 employees
See referencedevelopment approach
See referenceallows easy roll-out of new versions
-
See DER Touristik referenceDER Touristik: Become a digital travel companion in 7 monthsApps (Web, Mobile, AR/VR)CloudDigital Design & UX DesignSee DER Touristik referenceFrom Kickoff to Go Live
See DER Touristik referenceDigital travel companion
See DER Touristik referenceUncomplicated integration of additional brands, languages and countries
-
See KUKA referenceKUKA: UI/UX design for an app for load data analysis for industrial robotsDigital Design & UX DesignCloudIT ConsultingSee KUKA referenceProduct Experience Design
See KUKA referenceEasier interaction between users and the system
Optimized load data analysis, fewer support requests, higher satisfactionSee KUKA reference -
See DEKRA referenceDEKRA: Modern enterprise architecture thanks to co-creationIT ConsultingSee DEKRA referenceBuilding an EA community
See DEKRA referenceEnterprise Architecture
See DEKRA referenceat eye level
-
See BMW Group referenceBMW Group: Remote software upgrade for vehiclesCloudEmbedded Systems & Robotics (SMD)IoTSee BMW Group reference5 years
See BMW Group referencereceive new features thanks to "over-the-air" upgrade
See BMW Group referenceAlways up-to-date thanks to remote software upgrade
-
See digikoo referencedigikoo: A data platform for the Azure CloudCloudData & AIEnergySee digikoo reference5 months
See digikoo referencePlan digitally and implement efficiently
See digikoo referenceMicrosoft Azure Cloud
-
See Creditreform referenceCreditreform: Secure proof of identity on the webCybersecurityCloudDigital Design & UX DesignSee Creditreform reference5 years
See Creditreform referencebased on several PoCs
See Creditreform referenceallows tamper-proof storage of identities and company information
-
See SMA referenceSMA: Development of a Web UI for ennexOS platformCloudDigital Design & UX DesignEnergySee SMA referencesince 2016
See SMA referenceModules and components in ennexOS platform
See SMA referenceFuse tests
-
See Weidmüller referenceWeidmüller: Progression of the Industrial Service PlatformCloudDigital Design & UX DesignEmbedded Systems & Robotics (SMD)See Weidmüller referenceup to the MVP
See Weidmüller referenceof professional, technical and organizational factors
See Weidmüller referencefor end-to-end solutions
-
See BMW Group referenceBMW Group: Virtual reality brings vehicle design to lifeQuality EngineeringVR/ARAutomotiveSee BMW Group reference3.2 years
See BMW Group referenceLocation-independent and virtual
See BMW Group referenceScalable and expandable thanks to the cloud
-
To the FinOps referenceTravel information systems: 25 percent savings in cloud costs and stable operation thanks to FinOpsCloudTo the FinOps referencereduced by 25%
To the FinOps referenceof the availability zones in the development environment
To the FinOps referenceof the development environment
-
To the FinOps referenceSupply chain management: Reducing cloud operating costs by 50 percent with FinOpsCloudIT ConsultingIT ModernizationTo the FinOps referenceof the cloud operating costs
To the FinOps referenceto the new release
To the FinOps referenceand control
Why MaibornWolff?
As one of the most innovative IT service providers with a great passion for AI, we focus entirely on the project business and individual software development - without our own products. To stay at the forefront, we continuously invest in our team of digital technology engineers and develop digital solutions that are well thought-out, efficient and reduced to the essentials.
Our principle: simplicity instead of complexity. We only develop what is really needed - tailor-made, useful and reliable. Our results speak for themselves. With over 800 large-scale systems and more than 10,000 person-years of experience in high-end software engineering, we are one of the few who can reliably implement even the largest and most complex IT landscapes. Thanks to close partnerships with leading hyperscalers, our customers operate their solutions in today's most modern and powerful environments.
Less technology. Better Business.