Talk to us: +49 30 86329721

Insights · 2026-09-19

Functional Safety and Cybersecurity in Connected Systems: Dependencies, Conflicts and Standards

Safety and Security Follow Different Risk Logics Functional safety and cybersecurity are based on partly different perspectives. Functional safety focuses in particular on malfunctions and their potential effects on people, property or the environment. Causes may include random hardware failures, systematic development faults or software errors. Cybersecurity, by contrast, considers threats, vulnerabilities and potential attack paths. It introduces an additional dimension: an attacker may intentionally manipulate a system and adapt their actions to existing protective mechanisms. These different perspectives are also reflected in sector-specific standards and frameworks. In the automotive sector, for example, ISO 26262 addresses the functional safety of electrical and electronic systems, while ISO/SAE 21434:2021 defines requirements for cybersecurity engineering in road vehicles. ISO/SAE 21434 covers cybersecurity activities throughout the lifecycle of electrical and electronic vehicle systems. In industrial applications, IEC 61508 provides a fundamental framework for functional safety, while the IEC 62443 series addresses cybersecurity for industrial automation and control systems. IEC 62443-4-1, for example, defines requirements for a secure product development lifecycle, while IEC 62443-3-3 specifies system security requirements and security levels for industrial control systems. When Cybersecurity Becomes a Safety Issue The connection between the two disciplines becomes particularly evident when a compromised digital function can have physical consequences. A typical example is a safety-related control unit with a communication interface. From a functional safety perspective, the primary question is whether the control unit reliably performs its intended safety function. A cybersecurity perspective additionally considers whether data, control commands or software could be intentionally manipulated. A security event may therefore trigger a chain of events that ultimately results in a safety-relevant system state. This interaction is not limited to individual components. Modern systems often consist of embedded software, networks, backend systems, cloud components, diagnostic interfaces, mobile applications and components supplied by different organizations. Consequently, the relevant system boundary may extend far beyond an individual product. Especially in connected systems, interfaces and dependencies between components therefore become increasingly important. Typical Conflicts Between Safety and Security Safety and Security generally share the objective of limiting undesirable system states and their consequences. Nevertheless, individual technical requirements may compete with one another. One example is availability. A safety-related function may require a high level of availability. From a security perspective, however, situations may arise in which a connection must be interrupted, access blocked or part of a system isolated. Another possible conflict concerns software updates. Security vulnerabilities may require modifications to software. In safety-critical functions, however, an update may alter a previously assessed or validated system state. Access rights may also create differing requirements. Cybersecurity often requires strong authentication and restrictive authorization concepts. In emergency or maintenance situations, however, rapid access to specific safety-related functions may also be required. Further interfaces arise, for example, in relation to: - diagnostic and maintenance access, - remote access, - software and firmware updates, - communication interfaces, - logging and monitoring, - network segmentation, - cloud connections and backend systems, - supplier components and software libraries. An assessment based exclusively on either a Safety or a Security perspective may therefore only partially capture these interactions. Automotive: ISO 26262 Meets ISO/SAE 21434 The connection between functional safety and cybersecurity is particularly visible in the automotive sector. Braking, steering, powertrain and advanced driver assistance functions today rely on connected electronic control units and increasingly complex software. At the same time, vehicles communicate through numerous external interfaces with other systems. ISO 26262 addresses the functional safety of safety-related electrical and electronic vehicle systems. ISO/SAE 21434:2021 addresses cybersecurity engineering throughout the vehicle lifecycle. The two perspectives are distinct, but in a specific system they may relate to the same components and functions. The normative environment is also continuing to evolve. In 2026, the next generation of several parts of the ISO 26262 series is already under revision, with multiple parts progressing through the draft stage for a third edition. The interaction between Safety and Security therefore remains a dynamic technical and normative field. Industry: When OT Security Affects Physical Processes In industrial environments, the dependency between Safety and Security can be particularly direct. Industrial control systems monitor or control machinery, production lines and technical processes. At the same time, many of these systems are now connected to corporate networks, remote maintenance systems or cloud services. A security event may therefore affect not only data or the availability of an IT system, but potentially also a physical process. IEC 61508 provides a fundamental normative framework for electrical, electronic and programmable electronic systems that perform safety functions. The IEC 62443 series, by contrast, addresses cybersecurity in industrial automation and control systems. The importance of a system-level perspective becomes particularly evident at the interfaces between safety systems, production networks, engineering systems and external communication links. Medical Technology: Cybersecurity Can Affect Patient Safety Safety and Security are also increasingly interconnected in medical technology. Medical devices may today include software, network interfaces, mobile applications, cloud services or external data sources. Cybersecurity events may therefore, under certain circumstances, affect the availability or correct operation of medical systems. ISO 14971:2019 provides the fundamental international framework for risk management of medical devices. For health software, IEC 81001-5-1:2021 specifically addresses cybersecurity activities throughout the product lifecycle. Of particular interest in the context of Safety and Security is that the standard explicitly refers to an appropriate balance between Safety, Effectiveness and Security. The regulatory environment also continues to evolve. In February 2026, the U.S. Food and Drug Administration published updated final guidance on Cybersecurity in Medical Devices, replacing the previous version issued in June 2025. The System-Level Perspective Is Becoming More Important In complex connected systems, looking at individual components alone is often insufficient to identify all relevant dependencies. System risks may develop across several technical and organizational levels. A software component may communicate with a control unit. The control unit may form part of a subsystem. That subsystem may in turn communicate with other systems and potentially with external platforms. Additional dependencies may exist in relation to manufacturers, software suppliers, cloud providers and maintenance processes. As a result, Safety- and Security-related interactions may extend throughout the entire lifecycle of a system – from development and integration to production and operation, as well as updates, maintenance and decommissioning. This development also helps explain why modern standards increasingly address lifecycle aspects, interfaces and supply-chain dependencies. Additional Relevance Through the EU Cyber Resilience Act The regulatory framework for digital products is also continuing to develop. For many products with digital elements, the EU Cyber Resilience Act – Regulation (EU) 2024/2847 – establishes a new European cybersecurity framework. A particularly relevant development is that, since 11 September 2026, certain reporting obligations concerning actively exploited vulnerabilities and severe security incidents already apply. Most of the remaining provisions of the Regulation will apply from 11 December 2027. The specific applicability of the Cyber Resilience Act depends on the individual product and, where relevant, existing sector-specific legislation. Cybersecurity is therefore increasingly becoming not only a technical issue, but also a regulatory product and system topic. Safety and Security: Two Disciplines – One Connected System Functional safety and cybersecurity use different methods, terminology and normative frameworks. In a connected safety-critical system, however, both disciplines affect the same technical system. A Security event may have Safety consequences. Conversely, technical measures introduced to secure a system may influence characteristics that are relevant to its functional safety. Automotive systems, industrial automation and connected medical devices illustrate particularly clearly that modern system risks do not arise exclusively within individual technical disciplines. With increasing connectivity, software dependency and reliance on digital supply chains, the interface between Safety and Security is therefore becoming an important technical and normative field in its own right. intellcert Services intellcert GmbH provides, depending on the respective scope of service, Functional Safety, inspection and training services in the fields of cybersecurity and functional safety. Our certification and inspection activities are based on independent assessment and evaluation and do not include consulting services. Further information about our services and current training dates is available at intellcert.com. Keywords Functional Safety; Cybersecurity; Safety and Security; Functional Safety and Cybersecurity; Safety & Security; System Risks; Connected Systems; Safety-Critical Systems; ISO 26262; ISO/SAE 21434; IEC 61508; IEC 62443; Automotive Cybersecurity; Industrial Cybersecurity; OT Security; Medical Device Cybersecurity; Cybersecurity Engineering; Functional Safety Certification; Inspection; Training Action-Oriented Keywords for Internal Links or Buttons Request Certification; Explore Inspection Services; Discover Training Courses; View Training Dates; Functional Safety Services; Cybersecurity Services Hashtags #FunctionalSafety;#Cybersecurity;#SafetyAndSecurity;#ConnectedSystems;#SystemRisks;#ISO26262;#ISO21434;#IEC61508;#IEC62443;#AutomotiveCybersecurity;#OTSecurity;#IndustrialCybersecurity;#MedicalDeviceCybersecurity;#CybersecurityEngineering;#ConformityAssessment;#intellcertCybersecurityISO 26262Certification

Comments

No comments yet. Be the first to write one.

Write a comment

intellcert reviews your comment before it appears. Your e-mail address is not published.

intellcert is your competent partner for certification, inspection, testing, and training.

We look forward to your request for a free personal meeting.

Call us · +49 30 86329721