Here is a DIY approach to threat assessment:
Car Hacker's Handbook
And here's what the manufacturers are doing:
Firewalls can't protect today's connected cars | Computerworld
There's your problem. This diagram from the above link disagrees with the above video, which at 5:00 shows a similar block diagram that inserts a CAN Gateway before the OBDII port.