How Bentley Motors achieved UNECE Cybersecurity & Software compliance with MHP Consulting

Posted on 2 Oct 2025 by Joe Bush
Company: Bentley

Bentley Motors and MHP Consulting UK have collaborated to establish robust Cybersecurity and Software Update Management Systems (CSMS & SUMS) for the Bentley landscape, achieving compliance with the UNECE (United Nations Economic Commission for Europe) World Forum for Harmonization of Vehicle Regulations (WP.29). We caught up with both parties to find out more.

In the age of connected vehicles and increasing cyber threat, it is vital for OEMs to demonstrate they have robust processes and systems in place to protect vehicles and individuals interacting with them. The UNECE regulations strive to thoroughly address this issue.

Key takeaways

  • The automotive sector is becoming more dependent on data, internet access and connected services
  • Bentley achieved UNECE requirements with zero nonconformities
  • There were two phases of Bentley’s transformative project: Phase 1: Cybersecurity & Software Update Management Systems (CSMS & SUMS); and Phase 2: Operationalisation and execution of Phase 1
  • Via its partnership with MHP, Bentley has entrenched cyber security as a cultural imperative into the brand
  • UNECE compliance is crucial for an OEM’s market access, and can mean a bottom-line impact of millions, even billions, depending on the brand

FAQs

  • What are the UNECE WP.29 regulations, and why are they important for automakers?
  • How did Bentley Motors achieve compliance with UNECE regulations?
  • What impact does cyber security compliance have on Bentley’s operations?
  • Why is cyber security considered a continuous journey for Bentley?
  • What advice do Bentley and MHP offer to other OEMs regarding cyber security compliance?

As of July 2024, OEMs must adhere to these regulations in order to sell any vehicle and product within its 56 member states. In addition to achieving compliance, OEMs are required to introduce the necessary related supporting management systems across their organisations to maintain that level of conformity.

For Bentley Motors, product cyber security is something that has become exceptionally important to the business, and to this end, Product Line Director, Chris Cole, took responsibility for developing the company’s capabilities around this issue back in 2021.

“As our cars have progressively become more connected to the global network, we recognised very early on – ahead of any legislative requirements – the importance of making sure connection to the wider world was exceptionally safe for our customers and for us as a business,” he said.

The UNECE regulation is the first formal requirement for automotive OEMs to demonstrate capabilities for what’s referred to as cyber security management and software update management systems.

Chris Cole, Product Line Director, Bentley Motors“The evolving landscape, in terms of the threats, capabilities and the legislative environment, just means that this is a continuous journey for us.”

Chris Cole, Product Line Director, Bentley Motors

This brings a completely new dimension to the way that Bentley develop new cars and manage them through their lifecycle, and because the company want to be leading the way in this area, the relationship with MHP was established.

Chris continued: “We recognised the need to get some help inside Bentley and bring the very latest knowledge and understanding around product specific cyber security to the table. We went through a significant programme over a two and a half year period, with MHP leading the way for us to grow those capabilities.

“It affected every aspect of operations, from concept and product design, vehicle manufacturer, all the way through to service and after sales support.”

As a result of the collaboration, Bentley were the first OEM to achieve certification for the new regulations for both cyber security and software updates, and also the first to achieve that with no non-conformities.

“We have been continually developing that capability in order for us to really set ourselves as the safest cars against our competitors in the luxury segment,” added Chris. “That’s the overarching objective. Since we achieved the first accreditation, I’m pleased to say that it’s becoming just a normal part of the way that Bentley operates.

“However, it is an exceptionally demanding capability to stay on top of as the threat to vehicles through cyber attack morphs and changes over time, and we’ve got to be very agile in our response to those.”

The evolution of the cyber security landscape

Since first connecting its cars to the internet in 2018, Bentley has progressively grown its capabilities to the point where every Bentley manufactured today has connectivity built in. However, that increase in both functionality and the number of cars connected, has brought with it the added requirement for Bentley to ensure that connection to the car is entirely safe.

There have been numerous examples of the devastating impact that cyber attacks can have on business systems (take the recent M&S breach as an example). Chris continued: “Imagine that every car is like an iPad on wheels. That means any level of threat can be connected through to the remote device (the vehicle). As such, we’ve got to protect that just as much as we protect our core company systems.

“We have to provide exactly that same level of encryption, protection and proof that we can mitigate an attack. This becomes increasingly important as we provide more connected services into the vehicle.”

Chris explained that one of the benefits that Bentley has been able to take advantage of since becoming part of VW in 1998, is access to the very latest thinking, benchmarks and best practice from across the group. “Within these new, cutting-edge, emerging parts of the automotive world, MHP (which works across all VW brands) bring not only their external expertise, but also the knowledge from the rest of the company – it’s a perfect synergetic relationship.”


Bentley Bentayga Speed - interior connectivity
The achievement of UNECE compliance means Bentley’s GT range of vehicles meets the highest levels of cyber security and software update management systems

He explained that having that expertise in-house has been so much easier for Bentley (than having to compete for the very latest external consulting information), and that first-hand knowledge was an integral part of the company achieving the formal accreditation for its products’ cyber capabilities.

Bentley knew assistance was needed to achieve compliance with the regulation and were confident that MHP brought not only the technical and process expertise, but the understanding of the legislation and how it could be applied in the best way for Bentley to make it purposeful for its customers.

However, Bentley also didn’t want to become dependent on MHP, so selected a fairly small team – 12 to 15 people at its peak – who buddied with others in Bentley to work on a project management framework for a whole new way of working; how to understand the requirements of the legislation, the subject of cyber security, and how to start implementing that through processes, roles and skills.

“MHP brought to us this very structured method of running the project,” added Chris. “We did this in two phases, the first of which was establishing all the documentation and having the evidence ready. And the second was to actually certify the vehicles. It was during this second phase where we ‘let go’ of MHP and demonstrated we could do this for ourselves. By this time we’d also been through recruitment and established whole new departments to run this capability going forward.”

Within any digital transformation, we often talk about board level buy-in and an interesting angle that Bentley explored was employing MHP to educate the highest levels of the business around product cyber security. A key individual within MHP – one who has even influenced the legislative landscape within Europe and the US – brought to life the potential threat and the hazard that Bentley has to manage.

“This locked in cyber’s importance right from the earliest stage,” Chris added. “The board’s recognition that this was a really high priority helped with the brand and how the customer can now feel totally protected when they own a Bentley.”

UNECE Vehicle Regulation impact

The regulation is essentially split into two parts. One is focused on the cyber security system, the other on the software update management system over the air. Regarding cyber security, companies are required to establish a holistic cyber security management system which will require a complete threat and a risk assessment across the entire ecosystem and value chain.

This will then involve the implementation of preventive, detection and response measures for any potential threats that could take place, which then need to be applied along the entire value chain – not only production. This means that components need to be developed by an OEM’s suppliers using the same measures.

In the software update management system, only authentic role-based individuals can access the closed ecosystem of the car. Any software being put into the vehicle has to be signed off, verified, 100% traceable and developed according to the regulation. All of this, ultimately, needs to be showcased and documented in order to pass the audit.

Chris added: “This is an extensive process. It affects nearly every part of the business, from concepts all the way through to maintaining cars. And while the car is connected, we have an obligation to maintain its cyber protection.

Bodo Philipp is CEO of MHP Consulting UK“It’s important for OEMs not to make themselves dependent on service suppliers – it’s more about getting the OEM to the point where they are capable of dealing with cyber security and taking it forward themselves.”

Bodo Philipp is CEO of MHP Consulting UK

“So to put that into context, over 80% of the cars that Bentley has built over the last century are still in use today, and we’ve had cars connected from about 2018 – we’ve got to be prepared to support cyber protection throughout their entire connected life.

“In addition, in our production facility at Crewe, we’ve had to introduce an entirely new way of authenticating individuals, to give them permission to access ECUs and software on the vehicles. So you can imagine what that means for the thousands of people that are associated with manufacturing a Bentley. Particular roles are now part of a secure process, and that’s not only engineers in product development. It’s equally the people building and commissioning the cars, and maintaining them through their lifecycle.”

Challenges and hurdles to UNECE cybersecurity compliance

A key issue, Chris explained, was that Bentley had to meet the requirements of the new legislation for 2024 model year. Failure to do so would simply mean that the company would have been unable to sell its cars in the UN’s 56 member states. Fortunately, the company started early and thus had a head-start. “It was like an Olympic event,” he commented. “It was fundamental and it also helped with executive sponsorship. We had to make sure that we were going through a process of programme delivery to support these new capabilities.”

There was also significant changes around process, tool sets and people, again an area where MHP had a key role to play. Bentley had to conduct an overall end-to-end assessment of all processes to establish which had to be changed and where entirely new processes had to be added. This was in order to effectively manage proactive threat detection and end-to-end software configuration and control through the life of the car.

“That identified hundreds of processes that either had to be adapted or created from scratch. We went through a really heavy, controlled method of measuring the maturity of those processes as we built them,” Chris continued.

“With that, the people impacts were significant. Entirely new roles were created. Every single employee at Bentley went through a basic awareness of what product cyber security meant. All the individual roles were then categorised, and we had to conduct training programmes for each one. Nearly every department that managed parts of product development, purchasing or manufacturing had to respond to these process changes and new IT tool sets.”

OEM top tips

Chris continued: “We are in a great position to understand all the different brands within the group and MHP has also provided a tremendous amount of best practice. You cannot underestimate the level of importance of this topic and how it will continuously evolve and iterate as the threat changes over time.”

The ultimate goal, of course, is to ensure that no car or vehicle is deployed as an attack vector and used as a weapon. As such Chris stressed that it is incumbent on all of industry, not only Bentley and the Volkswagen Group, to share experiences and keep on top of the threat. Cyber security can also be used as a competitive advantage and Bentley is using its UNECE credentials for brand building and making sure its customers feel totally safe.

“The industry has a responsibility to prevent cyber security breaches from occurring, and thankfully, so far, that’s been the case. Moving forward, it is vital that the issue has the same level of priority as a company’s business strategy.

“You then also need to be prepared to continually iterate as both your software complexity growths and the threat level increases. That’s what we do within the VW Group, but we’ll also reach back whenever necessary to MHP for the latest intelligence and best practice, whether it’s from within the group or outside.”

The future for connected vehicles and cyber security

Chris explained that as Bentley continue to grow the capability of the car through its connectivity, it will only increase the necessity to check for threats more broadly. Particularly as autonomous driving functionality evolves and becomes more ubiquitous. “That means we’ll have to build on our threat detection, encryption and all our end-to-end methods of working to protect that,” he said.

He added that the company is starting to see the challenges beginning to be understood by different governments which will also usher in completely new legislative requirements. “We’re now embarking on a whole programme to deal with China’s cyber security measures and we have Japan, South Korea and the US in the pipeline as well.

“Meeting UNECE requirements was just the first step for us. The evolving landscape, in terms of the threats, capabilities and the legislative environment, just means that this is a continuous journey for us.”

Cyber security: a continuous journey, not a destination

Bodo Philipp is CEO of MHP Consulting UK and has 20 years of experience within the automotive world, working directly for different OEMs within the Volkswagen Group, including Porsche, Bugatti and Lamborghini.

How is cyber security evolving for MHP?

BP: We identified that bringing cyber security capability to the automotive space is something very important for us because, from a portfolio perspective, we cover all the aspects that are involved in a cyber security management system. We have these portfolio pieces singularly, and then we have formed a cyber security team within MHP to execute that with the OEMs.

The UNECE regulation is demanding and automotive is a complex ecosystem involving both hardware and software. But with our MHP heritage in the automotive space, we understand what the sector needs in order to comply.

We found the right partner in Bentley who are also demonstrating the same level of willingness to apply cyber security to their products and organisation. As a service supplier, we see OEMs treating the importance of cyber security in different ways. We advise every OEM to take it very seriously. Without the UNECE regulation, you cannot register or sell cars, so it will evidently and immediately impact your business model if you’re not able to comply.

The fact that Bentley passed the audit with no defects, and with flying colours, is evidence of how important it is for us and how seriously we took the execution of the programme.

How did Bentley and MHP work together to achieve UNECE compliance?

Mindset was very important. Just because we are tech people and we all think that cyber security is important, that is still no basis for immediate success. What was also key was the willingness to take that potential threat seriously. That was the starting point which was then followed by putting the right people together to increase the transparency of what we were doing, as the programme touched every aspect of the business.

That transparency helped us in Phase 1 to shape a strategic route going forward, and make sure the audit was passed. If Phase 1 wasn’t so extensive and comprehensively driven by all the stakeholders, then it wouldn’t have been such a success.

We provided the framework, but the operational element to execute was provided by Bentley. We had a back and forth where we would offer guidance and then transport that capability towards Bentley, with the execution then following accordingly.

What was also important was the executive sponsorship. In every business, change needs top level buy-in to be successful. So, it was the board’s responsibility that this was seen as important.

What would be your advice to other automotive OEMs?

It all starts with taking the issue seriously. I’ve been talking to other OEMs outside the VW Group and the understanding around the importance of cyber security doesn’t come by default.

It’s vital within the VW Group however, and we are creating use cases and best practice approaches between the different brands. They learn from each other and it’s amazing to see how the Volkswagen world is dealing with this.

The truth is that other OEMs don’t necessarily take the issue that seriously as it often reverts back to the question of budget. If you talk about return of investment, there is no real business case behind the adoption of cyber security, so there are many OEMs who question why they should invest.

Once it’s been recognised as a serious topic, however, that level of importance needs to be taken into the execution of a cyber security strategy. Bring executive awareness to the topic, get sponsors in place, empower people and bring capability in-house.

We did this at Bentley by showcasing a best practice approach to show how it could be successful. It’s important for OEMs not to make themselves dependent on service suppliers – it’s more about getting the OEM to the point where they are capable of dealing with cyber security and taking it forward themselves.

It’s a continuous journey; systems will become more connected and more complex so it’s important to bring capability to the OEM and empower them to deal with this on their own.

For more articles like this, visit our Digital Transformation channel