PCA Cyber Security
Embedded and automotive product security firm combining penetration testing with continuous vehicle and product security operations monitoring.
Visit Website ↗ + Add to CompareOverview
PCA Cyber Security, formerly known as PCAutomotive, provides offensive security testing, vulnerability research and continuous threat-intelligence monitoring for embedded, connected and automotive products. Its automotive and embedded practice covers vehicle and ECU penetration testing, threat analysis and risk assessment, while its proprietary TICAP threat-intelligence platform powers ongoing Product and Vehicle Security Operations Centers (PSOC/VSOC) that give OEMs and suppliers continuous monitoring rather than a one-time audit.
The company has built a public track record of disclosed vulnerability research: in 2025 its team identified the PerfektBlue Bluetooth stack vulnerabilities affecting vehicles from Mercedes-Benz, Volkswagen and Skoda, following earlier disclosures of 21 vulnerabilities across Skoda and Volkswagen vehicles and their cloud backends. The company has also repeatedly participated in Pwn2Own Automotive competitions.
Founded in 2019 in Budapest, Hungary, PCA Cyber Security has expanded from its automotive roots into finance, energy and industrial embedded systems, adding regional offices in Germany and Spain in 2024. It holds TISAX Assessment Level 3 certification, relevant to automotive supply-chain security requirements, though it remains a small specialist firm relative to larger product-security vendors.
Innovation Matrix Assessment
Active, ongoing public vulnerability research output, including the 2025 PerfektBlue disclosures and prior Skoda/Volkswagen findings, indicates a steady research cadence for a modestly sized team.
Combines pentesting services with a proprietary continuous-monitoring platform (TICAP powering PSOC/VSOC), but a team on the order of a few dozen people limits scale versus larger product-security vendors.
Added European offices in Germany and Spain in 2024 and broadened from automotive into finance, energy and industrial embedded systems, but no funding events are publicly disclosed to independently gauge financial momentum.
Applying continuous SOC-style monitoring (VSOC/PSOC) to embedded and connected products, rather than one-off point-in-time assessments, is a meaningful shift from traditional pentesting delivery, though not unique to this vendor.
Backed by independently verifiable, named CVE disclosures (PerfektBlue Bluetooth stack, prior Skoda/Volkswagen vehicle and backend vulnerabilities) and public Pwn2Own Automotive participation, real checkable technical output rather than unverified vendor marketing claims.
Automotive, embedded and IoT product security is an active and growing regulatory and threat concern as connected-vehicle attack surfaces expand under frameworks such as UNECE R155.
Why CISOs Should Care
Relevant to OEMs, Tier 1 suppliers and connected-device manufacturers that need independently demonstrated embedded/IoT and automotive vulnerability research plus ongoing product security monitoring rather than a one-time audit.
What Makes It Different
Backs its threat-intelligence platform with a public track record of disclosed CVEs and Pwn2Own Automotive results, distinguishing it from generic pentesting shops that do not publish verifiable research.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A credible, research-backed embedded and automotive security specialist with genuine disclosed vulnerabilities to its name; small scale and the absence of disclosed funding limit visibility into its longer-term growth trajectory.
Editorial Note: Claims vs. Verified Findings
The PerfektBlue Bluetooth stack vulnerabilities, prior Skoda/Volkswagen disclosures, Pwn2Own Automotive participation and TISAX Level 3 certification are independently reported and verifiable findings. Company-published figures such as '700+ products tested' and '300+ companies certified' are vendor-reported and not independently verified.
Sources
Alternatives to PCA Cyber Security
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…