Just Auto's interview with Simon Ordish focused on an easily underestimated part of automotive cyber security: the movement of engineering data. CAD assemblies, calibration files, validation results and supplier documents pass between OEMs, Tier suppliers, contractors and specialist partners.
Each handoff changes who can access the information, where copies may remain and how clearly the activity can be traced. Secure storage is only part of the answer. The exchange itself needs control.
The riskiest moment may be the ordinary supplier handoff, not the dramatic breach that follows it.
The central point from the Just Auto discussionA supplier incident can interrupt an entire production network
The automotive sector's dependence on connected suppliers makes cyber resilience an operational concern. In February 2022, Toyota suspended 28 production lines across 14 Japanese plants after a system failure at supplier Kojima Industries. Toyota later confirmed that Kojima had suffered a cyberattack following unauthorised access.
The incident began outside Toyota's factories, yet production still stopped. A weak point in one supplier can affect planning, component flow and manufacturing continuity across the chain.
File exchange creates a similar dependency. A design pack sent to the wrong address, an old calibration retained by a contractor or an unrestricted link forwarded beyond the intended team may not trigger an immediate shutdown. It can still expose intellectual property, introduce version errors or complicate an investigation months later.
The file often leaves one controlled system and enters several less visible workflows
Create
An engineering or programme team prepares the current package.
Release
The files leave the internal PLM, document or engineering environment.
Receive
A supplier downloads, stores and may share the package with its own specialists.
Revise
Comments and replacement files create further copies and another round of access.
General collaboration platforms can support this work securely, often around storage and continued teamwork. A sensitive B2B handoff needs different answers: who is authorised, how long access remains open, whether the package was downloaded and what evidence remains.
Anonymise, Shard and Restore adds an architectural layer
My MX Data, referred to as MX from this point, is a secure B2B file-exchange platform. The Just Auto interview examined its ASR method, which stands for Anonymise, Shard and Restore.
ASR transforms the data, separates it into protected shards and restores it for an authorised recipient. One complete readable file is not retained in a single place through that process. ASR is distinct from encryption and works alongside AES-256, authentication and access controls.
This visual helps explain the distributed model used by ASR.
No single location holds the complete file
Each location contains an incomplete fragment. The full information is restored only through the authorised process.
Keep the claim proportionateASR adds protection by changing how the data is separated and restored. It does not remove every cyber risk, replace secure endpoints or make supplier governance unnecessary.
Security needs to remain practical under programme pressure
Control becomes fragmented
- Links or attachments may reach unintended people.
- Expiry and revocation depend on the tool and sender.
- Comments, approvals and evidence may sit in separate systems.
The handoff stays accountable
- Named recipients replace unrestricted public links.
- Permissions, MFA and expiry define access conditions.
- Uploads, access and downloads remain part of the transaction record.
MX also supports transactions without a fixed platform file-size limit, allowing CAD data, simulation outputs and complete technical packages to move without being split to satisfy the delivery tool.
Five questions for the next supplier release
- Is the recipient named and currently authorised for the programme?
- Does the package contain only the information needed for that task?
- When should access expire, and who can extend it?
- Can the organisation see whether the current version was downloaded?
- Will the exchange history remain available for review or investigation?
What the Just Auto feature gets rightAutomotive data security has to work at the speed of the supply chain. The strongest control is not the one with the most impressive label. It is the one that engineering and supplier teams can use consistently while access, file activity and accountability remain visible.
