IoT / OT

Secure boot, firmware updates, device certificates, VPN, and very long device lifetimes.

Key dependency classes
  • ·Secure elements
  • ·MCUs
  • ·Firmware
  • ·OEM signing PKI
  • ·Gateways
Current policy / industry signalA2

Australia's roadmap explicitly prioritises difficult-to-update systems, and ENISA notes that restricted-access systems make cryptographic replacement especially hard.

Why this cannot be a switch flip

Field device

Secure boot verification

  1. MCU ROM verification algorithm
  2. Secure element capability
  3. Firmware image format
  4. OEM signing PKI
  5. Physical access for replacement
FinanceTelecomCloudAutomotiveHealthcareDefense