Cyber Threat

Cybersecurity risks pose a growing, system-wide threat to the Electric Bus Ecosystem (EBES), with cascading impacts across fleet operations, depots, charging infrastructure, and the operating environment. These risks include malicious cyberattacks, unauthorized access, manipulation of vehicle controls, disruption of charging schedules, compromise of passenger data, and interference with depot and control room systems. Such incidents may arise from ransomware, malware, phishing, denial-of-service (DoS) attacks, or manipulation of operational data, potentially leading to service disruptions and safety risks.

Explore the expendables sections to see detailed preventive, responsive and recovery measures for the Cyber Threat hazard and for each component (Fleet, Depot, Charging Infrastructure & Operating Environment).

E Bus Ecosystem

Risk or Impact of Hazard​

Prevention Measures

Unauthorized remote access

Electronic Control Units (ECUs) are equipped with encrypted communication protocols & authentication mechanisms.

Manipulation of Vehicle Operations

Firewalls and real-time cyber audits

Operational Disruption

Combine real time data from the cyber and physical domains to improve awareness

Response Action during hazard occurrence

Response plan for bus operations during Cyber attack-

  • Incase of ransomware attack on fleet management system
  • Manipulation of BMS data
  • Monitor BMS battery temp – Pre-cool cabins before dispatch

Response plan for handling vehicle Hijack

  • Attempted override of driving systems like braking, acceleration, or GPS spoofing.

Response Protocols for personnel safety and evacuation

Recovery and Restoration post hazard

  • Conduct root cause analysis using ECU logs and CAN traffic data.
  • Apply security patches and firmware updates.
  • Document incidents and notify OEMs, regulators, and cybersecurity agencies.
  • Perform vulnerability scans across the Fleet.
  • Update SOPs based on incident reports

Response Action during hazard occurrence

PT- Planning Team/ IT Team/

Operator / IT

PT- Depot Manager, IT, Operator

State Police Dept

Risk or Impact of Hazard​

Prevention Measures

Data Theft and Data Breech

Restricted Access

Regular software updates

Employee training on cyber security

Manipulation of the operations schedule and of depot management systems

Implement Backup for important depot operations

Strong password and multifactor authentication for important depot access

Response Action during hazard occurrence

SOPs for Depot operations during Cyber Attack

  • Data Breach of Passenger Data / Payment Gateway
  • Insider Threat or Credential Compromise
  • Tampering with Fleet GPS/Telematics

Recovery and Restoration post hazard

  • Restore systems from clean backups.
  • Conduct third-party penetration testing for Security Audit
  • Revise SOPs based on incident learnings.
  • Document losses and initiate cyber insurance processes.

Response Action during hazard occurrence

PT- Procurement Team & IT team

PT- Depot Manager,  & IT Team

State Police Department

Risk or Impact of Hazard​

Prevention Measures

Physical Cyberattacks – Impersonations

Secure Human Machine Interfaces (HMI) such as touchscreens, card readers with multi-factor authentication.

Ransomware attacks, disrupting the charging cycles and causing operational disruption

SQL Injection -Use parametrized queries to distinguish code from data. 

Provide cyber security related testing and assessment while installing EVSEs.

High Voltage load flow malfunction

The IP addresses should be validated & only pre-approved clients should be allowed to access the system

Response Action during hazard occurrence

Response plan for charging infrastructure operations incase of Breach of Charging Infrastructure (Smart Chargers or EMS)

Recovery and Restoration post hazard

  • Analyze EVCS server logs for intrusion patterns
  • Reset passwords and access tokens
  • Inspect physical and digital components for compromise
  • Inform users of potential data breaches and mitigation steps

Response Action during hazard occurrence

PT- Procurement team, Planning Department

OEMs, Charging Operators, IT Teams, Depot Manager

Risk or Impact of Hazard​

Prevention Measures

Potentially Disrupt Services, poses safety risk

Installation of firewalls, intrusion detection systems, and regular security audits

Compromise Passenger Safety

Aware staff about phishing mails and password security

Response Action during hazard occurrence

Response plan for handling vehicle Hijack

  • Attempted override of driving systems like braking, acceleration, or GPS spoofing.

SOPs for Drivers

  • Incase of Tampering with Fleet GPS/Telematics

Recovery and Restoration post hazard

  • Validate logs and sensor data for tampering to perform Data Integrity Checks
  • Reconfigure affected systems and update firmware for System Recalibration
  • Share incident reports with city authorities and OEMs for Stakeholder Communication

Response Action during hazard occurrence

PT- Planning and Procurement Team

PT- IT Team, Depot Manager and Driver

State Police  Department