Assessment of Cyber Security Attacks in the Automotive Industry and Development of Strategies in a Fuzzy Environment
Abstract
The rapid digitalization of the automotive industry, accelerated by the integration of Industry 4.0 technologies and connected vehicle systems, has significantly expanded the sector's attack surface. This transformation has rendered the automotive ecosystem increasingly vulnerable to complex and multidimensional cyber threats, including ransomware attacks, data breaches, production disruptions, and supply chain infiltrations. This study aims to systematically assess these threats and to prioritize the most effective cybersecurity strategies under conditions of uncertainty. Given the lack of quantitative prioritization models in the existing literature, a comprehensive Multi-Criteria Decision-Making (MCDM) framework integrating Pythagorean Fuzzy Analytic Hierarchy Process (AHP) and Pythagorean Fuzzy Technique for Order of Preference by Similarity to Ideal Solution (TOPSIS) methods was employed. This fuzzy-based approach was adopted to minimize the subjectivity and ambiguity inherent in expert judgments and to yield more realistic outcomes. Within the scope of the study, six major cyber attack types prevalent in the sector were examined, and nine distinct defense strategies were evaluated against eight critical criteria. The Pythagorean Fuzzy AHP results revealed that "Supply Chain and Third-Party Risk Mitigation" and "Coverage Scope" constitute the most decisive factors in strategy selection. The subsequent Pythagorean Fuzzy TOPSIS ranking demonstrated that "Advanced Endpoint and Network Security" is the closest alternative to the positive ideal solution and thus the most effective strategy. Furthermore, "Real-Time Monitoring and Anomaly Detection Systems" emerged as a high-priority approach. The findings underscore the necessity of adopting proactive and holistic security architectures in the automotive sector, rather than relying on reactive measures. In conclusion, this research provides industry stakeholders with a quantitative and systematic decision support framework for optimizing cybersecurity investments and ensuring operational continuity. The findings obtained provide decision-makers with a quantitative and systematic decision support infrastructure for the prioritization of cybersecurity investments, both within the context of the Turkish automotive sector and at the global scale.