Connected fleet vehicles with foreign operating systems: the cyber risk Australian boards are missing
A practical guide to the cyber security and data sovereignty risks of fleet vehicles running Chinese-built connected platforms, and what Australian organisations should do about them.
The fleet vehicle is now an endpoint
A modern fleet vehicle is a rolling data centre. It records precise GPS traces, cabin audio, dash and occupant camera footage, driver behaviour, Bluetooth and phone pairing data, contact lists synced from handsets, and the addresses of every site it visits. It communicates constantly with the manufacturer's cloud over its own cellular connection, and it accepts over-the-air updates that can change how it behaves overnight.
Most organisations assess vehicles on fuel economy, warranty and fleet pricing. Almost none assess them the way they would assess any other networked device that sits inside the business, collects sensitive data and phones home to a third party. That is the gap this article addresses.
Why Chinese-built connected platforms draw particular attention
The concern is not about a single badge on a grille. It is about jurisdiction. Manufacturers headquartered in China operate under national laws, including the National Intelligence Law, that can compel organisations to cooperate with state intelligence work and to keep that cooperation secret. When a vehicle's operating system, telemetry pipeline and cloud backend are controlled from that jurisdiction, the data it collects about your people and sites is potentially reachable under laws your organisation has no say in.
Governments have started to act on this. The United States has moved to restrict Chinese and Russian connected-vehicle hardware and software on national security grounds, and several Australian government bodies have raised similar concerns about Chinese-made electric vehicles used in sensitive contexts. Whether or not Australia follows with formal restrictions, the underlying risk — offshore access to rich, continuous data about your operations — does not depend on legislation to exist.
What these vehicles can actually collect and transmit
The data flows are broader than most fleet managers realise. Location telemetry is continuous, not just when the driver opens a navigation app. Cabin microphones support voice assistants and may stream audio to the manufacturer's cloud for processing. Cameras face inward and outward. Paired phones hand over contacts, call logs and message metadata. Usage profiles build a picture of who drives where, when, and how often — which, for a services business, is effectively a map of your client base and operating rhythm.
Individually, each stream looks benign. Aggregated across a fleet and a region, they describe sensitive patterns: which government sites your staff visit, where executives live, when a depot is empty, and which routes service critical infrastructure. Aggregated data about many organisations is exactly what makes such platforms strategically interesting to a foreign state.
Remote control and over-the-air access: the unassessed supplier path
Connected vehicles ship with remote capabilities as features: remote locking and unlocking, climate preconditioning, location tracking and, increasingly, remote immobilisation for theft recovery or fleet management. Each of these is a command path from the manufacturer's cloud into a vehicle your staff are driving. The same channel that delivers a helpful software update can, in principle, alter braking behaviour, disable a vehicle, or open a microphone — the distinction between capability and intent is governance, not engineering.
This is a supplier access path that bypasses every control you apply to other vendors. Your IT supplier goes through contracts, access reviews and monitoring. Your vehicle manufacturer has a permanent, authenticated, always-on connection into an asset on your balance sheet, and almost no organisation has ever asked to see the terms of that access.
The Australian regulatory lens
The Privacy Act applies to personal information these vehicles collect about identifiable drivers and passengers — and if that data flows offshore, the organisation remains accountable for how the overseas recipient handles it. If a breach of that data is likely to cause serious harm, the Notifiable Data Breaches scheme applies. Directors should note that "we did not know the car collected that" is a governance failure, not a defence.
For organisations in critical infrastructure sectors, the SOCI Act risk management program obligations extend to supply chain and third-party hazards, and a fleet of foreign-controlled connected vehicles operating around critical assets sits squarely in that frame. APRA-regulated entities should read CPS 234 the same way: information assets include data held by third parties, and the vehicle platform is a third party. ASD's supply chain guidance makes the general expectation plain — know who can access your systems and data, and assess what their jurisdiction means for you.
Want this assessed against your environment?
Send us the specifics and a senior advisor will respond within one business day.
This is a supply chain decision, not a vehicle decision
The practical reframe is to stop treating fleet procurement as a facilities decision and start treating it as technology procurement. A connected vehicle platform is a supplier that collects sensitive data, hosts it offshore, holds remote access into your physical operations and can change its software without notice. Run it through the same third-party risk process you would apply to a SaaS platform handling client data.
That means asking, before purchase: where is vehicle data processed and stored; can data flows be disabled or regionalised; what remote capabilities exist and who can invoke them; what happens to the data on resale or lease return; and what contractual audit and breach-notification rights do you have. A supplier unwilling to answer is itself a finding.
Practical controls for organisations that already own these vehicles
Start with an inventory: which vehicles are connected, what features are active, and what accounts and apps are linked. Where the platform allows it, disable or regionalise data sharing, turn off cabin microphones and cameras that are not needed, and avoid pairing work phones that carry contacts or email. Use a dedicated, low-privilege fleet account rather than personal manufacturer accounts.
Where risk warrants it, segment the vehicles physically: rules about which sites they attend, whether they enter sensitive facilities, and what can be discussed inside them. Some Australian government agencies already apply rules of this kind to connected vehicles near secure sites. On lease renewal or replacement, score the data and remote-access posture of candidate platforms alongside cost — the cheapest vehicle can carry the most expensive risk.
A sensible first 30 days
Week one — inventory the fleet: make, model, connected services active, data settings, and who holds the manufacturer accounts. Include leased and salary-packaged vehicles; they still carry your data.
Week two — assess exposure: what sites, clients and conversations do these vehicles see, and where does that data go. Flag vehicles that attend sensitive locations or carry executives.
Week three — apply the fast controls: tighten data-sharing settings, unpair unnecessary devices, centralise account ownership, and write a short vehicle-use policy for sensitive contexts.
Week four — fold it into governance: add connected vehicles to the third-party risk register, set procurement criteria for the next purchase cycle, and give the board a one-page view of the exposure and the plan. The risk is manageable — but only once it is visible.
Sources and further reading
- ACSC Cyber Supply Chain Risk Management guidance
- OAIC guidance on privacy and the Privacy Act
- OAIC Notifiable Data Breaches scheme
- Security of Critical Infrastructure Act risk management program
- APRA Prudential Standard CPS 234 Information Security
This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.
Related reading
A risk-based cybersecurity roadmap for SMEs
Build a sequenced cyber programme around business exposure rather than an unprioritised control list.
Read articleISO 27001 vs Essential Eight for Australian SMEs
How the management-system and technical-control approaches differ, overlap and can work together.
Read articleAI vendor security due diligence
Questions and evidence for assessing AI suppliers across data, models, identity, contracts and exit risk.
Read article