Autonomous transport needs a secure technological foundation, not just a low price
Connected and autonomous vehicles are software and data systems, so public procurement should weigh cybersecurity, data governance and supply chains alongside price. Cases from Australia and Norway show what remote access to vehicle systems can mean.

A modern vehicle is no longer just a mechanical product. It is a software and data system fitted with sensors, cameras and communication modules, and it can be updated remotely. In autonomous transport these systems directly affect vehicle control, while the data they collect may include location, audio and video. If a foreign intelligence service gained such access, vehicles used by officials or defence-sector employees could become a national security risk.
Supply chains and the share of Chinese brands
In February the European Commission published an ICT supply chain security toolbox and a separate risk assessment for connected and automated vehicles. It stresses evaluating critical suppliers and reducing dependence on high-risk ones. According to ENISA, almost a fifth of cyberattacks in Europe have targeted operational technology.
Chinese brands made up 14.2% of battery electric cars sold in Western Europe in the first five months of 2026. In Latvia, their share of newly registered electric cars was 40% in the first half of the year. Latvia's Constitution Protection Bureau warns in its 2025 report that using Chinese technology may create vulnerabilities in ICT infrastructure. The author notes the issue is not automatic distrust of every Chinese-made vehicle, but whether a state can assess the dependence a supplier creates.
Examples of remote access
This month a cybersecurity experiment in Australia found that remote access to a BYD Shark 6 was possible. The access point was not password-protected, and a hired hacker could lock doors, switch on wipers and turn off the headlights while the car was moving. Brakes and cameras resisted access. The hacker could also track the car's location in real time and activate the cabin microphone.
In 2025, Norwegian transport operator Ruter compared Chinese Yutong and Dutch VDL electric buses. It found that Yutong has remote access to software updates, diagnostics and the battery management system, which could in theory allow a bus to be stopped. Norway has this year begun discussing extra security requirements for bus procurement.
What the author proposes
In Latvia, it was reported in 2023 that Riga municipal bodies used more than 1,000 surveillance cameras, many made by Hikvision. The author argues that public procurement should set strict requirements on cybersecurity, data governance, component origin, remote access and independent auditing, alongside price. At the same time, European and Latvian capabilities in software, sensors and cybersecurity should be strengthened.

/nginx/o/2022/04/13/14482067t1hbe1b.jpg)
