Automotive Security Research Group
ASRG is a non-profit operating the world's largest automotive cybersecurity community, with 20,000+ members across 50+ global chapters. It delivers threat intelligence, vulnerability disclosure, and research collaboration to OEMs, suppliers, and researchers, funded through tiered corporate sponsorships.
- Company typePrivate
- Founded2011
- HeadquartersStuttgart, Germany
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Automotive Security Research Group does
Automotive Security Research Group (ASRG) is a non-profit organization founded in 2011 (per company history; firmographics record conflicts with 2017) and headquartered in Charlotte, North Carolina, with operational roots in Stuttgart, Germany. ASRG operates the world's largest automotive cybersecurity community, with 20,000+ members across 50+ global chapters, and serves original equipment manufacturers (OEMs), Tier 1 and Tier 2 suppliers, independent security researchers, students/academia, policymakers, and corporate sponsors. Its core technical assets include the Intelligence Platform (a real-time threat intelligence product processing 1,200+ indicators monthly, aggregating OEM reports, CVE databases, researcher submissions, and dark-web monitoring), the AutoVulnDB automated vulnerability database, the Automotive Threat Catalog mapped to vehicle subsystems, the CSMS Tool Evaluation Framework anchored in ISO/SAE 21434, and a Member Portal with REST API access. ASRG is also an authorized CVE Numbering Authority (CNA) for automotive vulnerabilities since 2018 and operates a Responsible Disclosure Program with a 90-day coordinated disclosure timeline.
ASRG is governed as a non-profit, with revenue derived primarily from tiered corporate sponsorships — Platinum at $50,000/year, Gold at $25,000/year, and Silver at $10,000/year — supplemented by event sponsorships and co-branded publications. Individual membership is free. The organization distributes through its website (asrg.io), authenticated member portal (portal.asrg.io), six working groups (V2X Security, Supply Chain, Threat Modeling, Regulatory Compliance, AI & Autonomy, EV Infrastructure), the ASRG Academia program linking 17 universities, a global chapter network, and industry conferences/webinars. Named paid sponsors include Alpitronic (Platinum), C2A Security, Filigran, and itemis (Gold), with SystemWeaver at Silver and 11 supporting organizations including Google, Microsoft, and Trend Micro. Leadership consists of CEO/Founder John Heldreth and Business Manager Rina Espiritu, with board advisors Jennifer Tisdale and Dr. Allan Friedman. The organization has no parent company, no equity funding history, and operates as a neutral industry body rather than a venture-backed entity.
Automotive Security Research Group firmographics
Firmographics- Name
- Automotive Security Research Group
- Legal name
- Automotive Security Research Group
- Website
- https://asrg.io
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- ASRG is a non-profit operating the world's largest automotive cybersecurity community, with 20,000+ members across 50+ global chapters. It delivers threat intelligence, vulnerability disclosure, and research collaboration to OEMs, suppliers, and researchers, funded through tiered corporate sponsorships.
- Ownership category
- akta.pro rank
Automotive Security Research Group industry classification
Industry- Product category
- Automotive Cybersecurity Research
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Attack Surface Management (EASM/CAASM) (HDADAHAC)
- akta.pro secondary industries
- Security Awareness, Training & Compliance Attestation (HDADAIAJ), Audit Management (HDADAIAF), SOAR & Security Automation (HDADAGAB)
Keywords
Where Automotive Security Research Group is headquartered
LocationHeadquarters
- HQ city
- Stuttgart
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Automotive Security Research Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Sponsorship Programs: ASRG generates revenue through tiered corporate sponsorship programs. Platinum sponsors pay $50,000/year, Gold sponsors $25,000/year, and Silver sponsors $10,000/year. Sponsorship provides brand visibility, research access, networking opportunities, and talent recruitment access. The organization also offers event sponsorships and co-branded publication opportunities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Individual Membership |
| Subscription | Annual | Silver Sponsorship - $10,000/year |
| Subscription | Annual | Gold Sponsorship - $25,000/year |
| Subscription | Annual | Platinum Sponsorship - $50,000/year |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels8 records
Automotive Security Research Group product offering
Product offeringCore offering
ASRG is a non-profit global hub for automotive cybersecurity, operating a threat intelligence platform, an automated automotive vulnerability database (AutoVulnDB), and a coordinated vulnerability disclosure program. It serves 20,000+ members across 50+ global chapters with research collaboration, CSMS tool evaluation, CVE assignment as an authorized CNA, and community-driven working groups spanning V2X Security, Supply Chain, Threat Modeling, Regulatory Compliance, AI & Autonomy, and EV Infrastructure.
Product overview
ASRG is a non-profit organization that operates as the global hub for automotive cybersecurity research, offering a platform-plus-community model. The core Intelligence Platform provides real-time vulnerability feeds, threat reports, and risk dashboards, supported by research projects including AutoVulnDB (automated vulnerability database), the Automotive Threat Catalog (threat/attack vector repository), and the CSMS Tool Evaluation Framework. The Member Portal serves as the single sign-on gateway to advisories, intelligence, chapter activity, and working-group surfaces. Additional offerings include a Responsible Disclosure Program (coordinated vulnerability disclosure with CVE numbering authority), ASRG Academia (research network with 17 universities), and Working Groups across six focus areas. ASRG serves over 20,000 members across 50+ global chapters worldwide.
Differentiator
Problem solved
Functional benefit
Products and services
- Intelligence Platform Real-time automotive cybersecurity intelligence platform that monitors threats, tracks vulnerabilities, and provides risk dashboards. Aggregates data from OEM reports, CVE databases, researchers, and dark-web monitoring.
- AutoVulnDB Automated vulnerability database for automotive cybersecurity that aggregates, categorizes, and tracks security vulnerabilities specific to automotive systems including ECUs, infotainment, and telematics.
- Automotive Threat Catalog Comprehensive catalog of known threats, attack vectors, and vulnerabilities specific to automotive systems, organized by vehicle subsystem (powertrain, chassis, body, ADAS, infotainment, connectivity) and mapped to relevant standards.
- CSMS Tool Evaluation Framework Community-driven evaluation framework for automotive Cybersecurity Management System (CSMS) tools, anchored in ISO/SAE 21434. Provides a structured methodology for comparing and assessing tools used in automotive cybersecurity.
- Member Portal Single sign-on portal providing access to advisories, intelligence feeds, chapter activity, and working-group collaboration surfaces. Includes account management, API token generation, and chapter community features.
- Responsible Disclosure Program Coordinated vulnerability disclosure program (policy v1.1, effective April 5, 2025) that mediates between security researchers and automotive manufacturers. Includes CVE assignment as an authorized CNA, safe-harbor protections, and a 90-day coordinated disclosure timeline.
- ASRG Academia Global research network connecting researchers, students, and companies focused on automotive security. Provides a platform for young researchers to showcase work, with five focus areas: Autonomous Vehicles, OEMs & Supply Chain, Security for Mobility Systems, Intelligent Transportation Systems, and Artificial Intelligence. Currently includes 17 participating universities.
- Events Platform Platform for conferences, webinars, workshops, and meetups bringing together the automotive cybersecurity community. Includes ASRG-hosted and sponsored events.
- Automotive Security Verification Methodology (ASVM) Framework for security verification in automotive systems, providing structured methodology for assessing and verifying automotive security implementations.
Quantifiable outcome
- Community of 20,000+ automotive cybersecurity professionals
- +3 more outcomes
Companies that use Automotive Security Research Group
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles4 records
Automotive Security Research Group technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability1 record
Feature4 records
Automotive Security Research Group partnerships and signals
Strategic signalPartnerships
24 partnerships are on record, tiered supporting partner, platinum sponsor, gold sponsor, silver sponsor, partner and supporter.
- Manifestsupporting partnerASRG announced Manifest as a supporting partner to enhance cybersecurity and transparency in the automotive industry. The partnership aims to develop new services that improve vehicle cybersecurity through shared tools and risk assessment capabilities, building trust among consumers, researchers, and manufacturers.
- Alpitronicplatinum sponsorPlatinum level sponsor of ASRG. Alpitronic is an electric vehicle charging infrastructure company.
- C2A Securitygold sponsorGold level sponsor providing automotive cybersecurity solutions.
- Filigrangold sponsorGold level sponsor. Filigran's OpenCTI platform is used as a source of automotive threat-intelligence shown on the ASRG Intelligence Dashboard.
- itemisgold sponsorGold level sponsor specializing in model-based systems engineering and security.
- SystemWeaversilver sponsorSilver level sponsor providing collaboration and requirements management tools.
- Auto-ISACpartnerPartner organization - Automotive Information Sharing and Analysis Center for cybersecurity information sharing in the automotive industry.
- ClusitpartnerPartner organization - Italian cybersecurity association.
- e-mobil BWpartnerPartner organization - German center for electromobility and mobility concepts.
- MOTUS-EpartnerPartner organization - Italian e-mobility association.
- OpenTAPpartnerPartner organization - Open-source test automation platform for automotive and aerospace testing.
- openXSAMpartnerPartner organization - Open-source eXtensible Automotive Security assurance model.
- SHIELD Automotive Cybersecurity Centre of ExcellencepartnerPartner organization - Center of excellence for automotive cybersecurity.
- CybellumsupporterSupporting organization for ASRG - automotive cybersecurity solutions provider.
- DI.GI. AcademysupporterSupporting organization - Italian digital academy.
- DriveSecsupporterSupporting organization - automotive cybersecurity services.
- ElevenLabssupporterSupporting organization - AI audio and voice synthesis company.
- GooglesupporterSupporting organization - major technology company.
- MicrosoftsupporterSupporting organization - major technology company.
- RangeForcesupporterSupporting organization - cybersecurity training and simulation platform.
- Secure Code WarriorsupporterSupporting organization - developer security training platform.
- START 4.0supporterSupporting organization - Italian Industry 4.0 competence center.
- ThreatQuotientsupporterSupporting organization - threat intelligence platform provider.
- Trend MicrosupporterSupporting organization - cybersecurity software company.
Scale indicators9 records
Recent moves7 records
Expansion highlights5 records
Automotive Security Research Group competitors and assessment
Company assessmentEmerging players
- IOActive: Cybersecurity services firm with a well-known automotive security research practice. IOActive competes in automotive penetration testing and vulnerability research, partially overlapping with ASRG's research and disclosure mission.
Direct peers
- Karamba Security: Automotive embedded cybersecurity vendor providing ECU hardening and intrusion detection. Karamba is a direct peer in automotive-specific security tooling serving Tier-1 suppliers and OEMs.
- Auto-ISAC: The Automotive Information Sharing and Analysis Center is the industry body for automotive cybersecurity information sharing. Auto-ISAC is a direct peer to ASRG as both convene OEMs, suppliers, and researchers around vehicle cybersecurity intelligence, and Auto-ISAC is already listed as an ASRG partner.
- Cybellum: Automotive product security platform for vulnerability management and risk assessment across vehicle components. Cybellum is listed as an ASRG Supporter and competes in component-level vulnerability assessment.
- Upstream Security: Commercial automotive cybersecurity vendor offering a vehicle security operations center (VSOC) platform and threat intelligence. Competes with ASRG in automotive threat intelligence and vulnerability management, particularly for OEM and Tier-1 customers.
- VicOne: Automotive cybersecurity vendor providing vulnerability management, VSOC, and penetration testing services. Directly competes with ASRG's commercial counterparts in delivering threat intelligence and CSMS tooling to OEMs and suppliers.
- C2A Security: Automotive cybersecurity product lifecycle management platform aligned with ISO/SAE 21434. C2A Security is an ASRG Gold sponsor and a direct peer in the CSMS tooling and threat intelligence space.
- Argus Cyber Security: Automotive cybersecurity company (acquired by Continental) providing in-vehicle network protection and VSOC. Argus is a direct peer offering commercial alternatives to community-led threat intelligence.
Broad incumbents
- NCC Group: Global cybersecurity services firm with a dedicated automotive practice covering penetration testing, threat modeling, and ISO/SAE 21434 consulting. A broad incumbent serving overlapping automotive cybersecurity needs via commercial services.
- Harman International (Samsung): Connected car and automotive cybersecurity provider (a Samsung subsidiary) offering layered vehicle security solutions to OEMs. Operates as a broad incumbent with deep OEM relationships, overlapping with ASRG's threat intelligence audience.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Automotive Security Research Group social profiles
Digital presenceAutomotive Security Research Group compliance and trust
Trust signalCompliance1 record
Automotive Security Research Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
Automotive Security Research Group leadership team
Management profileNumber of profiles
Profiles4 records
Automotive Security Research Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Automotive Security Research Group M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Automotive Security Research Group
What does Automotive Security Research Group do?
ASRG is a non-profit global hub for automotive cybersecurity, operating a threat intelligence platform, an automated automotive vulnerability database (AutoVulnDB), and a coordinated vulnerability disclosure program. It serves 20,000+ members across 50+ global chapters with research collaboration, CSMS tool evaluation, CVE assignment as an authorized CNA, and community-driven working groups spanning V2X Security, Supply Chain, Threat Modeling, Regulatory Compliance, AI & Autonomy, and EV Infrastructure.
Is Automotive Security Research Group a public or private company?
Automotive Security Research Group is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Automotive Security Research Group founded?
Automotive Security Research Group was founded in 2011. It employs 51 to 100 people.
Where is Automotive Security Research Group based?
Automotive Security Research Group is headquartered in Stuttgart, Germany, in the Europe region.
How does Automotive Security Research Group make money?
One revenue line is on record: sponsorship Programs.
Who are Automotive Security Research Group's main competitors?
IOActive is listed as an emerging player. Direct peers are Karamba Security, Auto-ISAC, Cybellum, Upstream Security, VicOne, C2A Security and Argus Cyber Security. Broad incumbents are NCC Group and Harman International (Samsung).
Does Automotive Security Research Group have an API?
Yes. ASRG provides a REST API for accessing threat intelligence endpoints (e.g., /api/v1/intelligence/*). Programmatic access requires hashed personal API tokens for authentication. API tokens are one-way SHA-256 hashed and displayed once at creation. The intelligence data accessed via API may not be redistributed, sold, or used for commercial purposes without explicit authorization, governed by supplemental terms in the Terms of Use.
What industry is Automotive Security Research Group in?
Automotive Security Research Group's product category is Automotive Cybersecurity Research. Its primary akta.pro industry code is HDADAHAC, Attack Surface Management (EASM/CAASM), with a secondary code of HDADAIAJ, Security Awareness, Training & Compliance Attestation. Its NAICS code is 54151 and its SIC code is 7373.