" " indicates required fields
TARA can be performed for a variety of purposes, such as to identify possible vulnerabilities or to assess the likelihood and impact of a cyber-attack. Although TARA is required by the entire supply chain players (OEMs and Tier suppliers alike), for the sake of simplicity, we will use OEMs as the main TARA user.
The primary goal of TARA is to provide insights into the potential risks that an OEM’s system or data may face, and to determine how those risks can be mitigated or managed. Using the TARA process, OEMs are able to identify these potential threats, evaluate their likelihood and potential impact, and determine the risk associated with each threat. This information is then used to develop strategies and plans to manage and mitigate the identified risks. TARA can be used in a variety of contexts, such as cybersecurity, safety, financial risks, and other types of risks that organizations may face.
While many OEMs rely on Microsoft Excel application (app) to automate their TARA process, the limitations of this app become more apparent as the complexity of TARA increases. In this blog post we’ll explore why Excel is not the ideal automation tool for TARA in the automotive industry and offer proper tools and best practices. We’ll also examine crucial aspects such as collaboration, version control, scalability, data visualization and modeling, data integrity, flow and process management, and compatibility with automotive regulations and standards.

Excel files are based on a descriptive approach, which means that the security team creates lists to identify potential risks and vulnerabilities. However, this approach can be limiting when dealing with complex TARA processes. It can also make it difficult to monitor lists and perform analytics on unstructured data, compromising the monitoring capabilities of the TARA process. When dealing with TARA, the cyber security team wants to analyze the data in the most granular way possible, which will allow them to identify and isolate the root causes of the potential threats and address them in the most efficient way manner possible.
Furthermore, the descriptive approach used in Excel doesn’t allow for true risk management beyond the initial TARA conducted during the concept phase. This insufficiency is even more acute when OEMs implement a Cybersecurity Management System (CSMS) to be compliant. This is because the CSMS requires continuous monitoring and risk management, which cannot be achieved with Excel’s limited capabilities.
Excel lacks the features and capabilities needed to efficiently and reliably implement current best practices or reuse existing work from other Excel files.
These limitations can result in errors and inconsistencies, particularly when dealing with complex TARA processes that require precise and accurate data. Reusing data from multiple Excel files or dealing with multiple data sources can be especially challenging, leading to data silos where relevant information is scattered across different files or stored in different locations. This can make it difficult to access and reuse data from previous projects, resulting in time-consuming searches for relevant information and compromising the efficiency and reliability of the TARA process.
Excel files don’t have built-in version control, which makes it difficult to track changes and ensure that everyone is working with the most up-to-date version of the file.
Excel files can become large and unwieldy as the TARA process progresses, making them difficult to manage and maintain, and these limitations become increasingly apparent as the size and complexity of the TARA project increase.
Excel files don’t offer advanced data visualization capabilities, making it difficult to present and communicate TARA results in a clear and meaningful way. This can be particularly challenging when dealing with complex TARA processes that involve models and scenarios.
Excel files are prone to errors and inconsistencies, which can compromise the efficiency and scalability of the TARA process, as well as the accuracy and reliability of the TARA results.
Reasons for these issues include:
Excel files aren’t designed for integration with other systems, making it difficult to import or export data from other sources, such as threat intelligence feeds or asset management systems.
Reasons for these issues include:
Excel files don’t have built-in workflow and process management tools, making it difficult to track the progress of the TARA process and ensure that tasks are being completed in a timely manner.
Reasons for these issues include:
One significant limitation of using Excel for TARA automation is its lack of collaboration and sharing capabilities with different stakeholders. Even with Excel Online, files are simply not designed for real-time collaboration, making it difficult for multiple team members to work on the TARA process simultaneously. This can result in time-consuming and error-prone processes, where team members default need to share files back and forth manually.
Furthermore, Excel files are often saved locally, making it challenging to share files and work on them in real time. This can lead to version control issues, where team members are working on different versions of the same file, resulting in confusion and errors.
This limitation of collaboration and sharing capabilities in Excel can be especially problematic for large teams working on complex TARA projects, where different team members need to contribute their expertise and insights. Using Excel for collaboration can result in delays, miscommunication, and errors that can impact the accuracy and effectiveness of the TARA process, resulting in both revenue risks and high operational costs.
Excel files are plain data sheets and don’t provide relevant guidelines for the regulations and standards that are relevant to the automotive industry. This can result in non-compliance, risking legal liabilities, fines, and penalties, while compromising the reputation and financial stability of the organization.
Excel files are vulnerable to cyber attacks, such as malware infections and ransomware attacks. If an Excel file is compromised, the information it contains (and other privileges) could be exposed to unauthorized parties, which could have serious consequences for the organization. The following are some reasons why security is difficult when using Excel for TARA:
Excel doesn’t allow the kind of direct and intuitive use of the gathered data required for additional automation in the CSMS and in the Cybersecurity DevOps processes. These types of processes include prioritizing security implementation tasks for developer projects, efficiently prioritizing and mitigating vulnerabilities in different software versions, and more.
The following are some reasons why DevSecOps extension is so difficult with Excel:
In summary, the EVSec ANALYSIS module is a comprehensive TARA automation tool that offers advanced automation, collaboration, data analytics, security, integration, workflow and process management, data validation and cleaning, risk management, data visualization and modeling capabilities, as well as compliance tracking and reporting.
In addition, EVSec ANALYSIS also enables OEMs to meet WP.29 regulation easily and ISO/SAE 21434 requirements with scalable TARA for risk management across the entire organization and supply chain, making it a powerful tool for organizations looking to improve their TARA process and ensure the security of their systems.
CRO
C2A Security
VP and GM, Medical Technology
C2A Security
Ken Zalevsky brings over 20 years of medical device cybersecurity experience to his role at C2A Security, where he serves as VP and GM, Medical Technology, following the acquisition of Vigilant Ops in October 2025. A former Bayer executive, Ken founded Vigilant Ops in 2019 after witnessing the consequences of inadequate technical preparation in the healthcare industry. He is an active contributor to CISA’s SBOM working groups and a frequent speaker on software supply chain security. Ken’s mission: transform SBOM from a compliance checkbox into operational intelligence that keeps patients safe while streamlining regulatory processes.