
Norway’s public transport authority Ruter has completed an extensive cybersecurity assessment of two electric buses, concluding that while there is no evidence of surveillance through onboard cameras, remotely connected vehicle systems require stronger safeguards.
The tests were carried out inside a specially shielded mountain facility that blocks all radio communications, allowing security engineers to examine the buses without outside interference.
Ruter compared two buses with different digital architectures: a three-year-old vehicle built by Dutch manufacturer VDL and a new bus from Chinese manufacturer Yutong, now one of Europe’s largest suppliers of electric buses.
The VDL bus does not support over-the-air software updates, requiring all system changes to be made through a physical connection. The Yutong bus, however, is designed to receive remote software updates and diagnostics through a mobile data connection.
According to Ruter’s report, the remote connection theoretically provides a pathway through which the manufacturer could disable or stop the vehicle, as it already has legitimate access to battery and power management systems for maintenance purposes.
The authority stressed that no evidence was found that such access has been misused, and engineers also confirmed that the buses’ onboard cameras are not connected to the internet and cannot be used for remote surveillance.
Ruter said the relatively limited integration between the bus’s critical systems makes it possible to isolate remote connections, inspect software updates before installation and protect the vehicles with local firewalls.
Chief Executive Bernt Reitan Jenssen said the testing had transformed concerns into concrete knowledge that will improve the security of the fleet.
The findings will now be used to introduce stricter cybersecurity requirements in future procurement contracts, while Ruter is also working with Norway’s Ministry of Transport on developing national standards for connected public transport vehicles.

