Securing Industrial Software in Design & Operation

How RunSafe Supports IEC 62443-4 for Energy System Manufacturers

Energy infrastructure operates as an essential service where uptime, safety, and reliability are non-negotiable. Industrial systems run continuously for years, often with limited ability to patch or update software. At the same time, cyber threats are evolving, and create exposure to  vulnerabilities that impact operations. To maintain uninterrupted operation of the infrastructure, these systems must remain secure and safe while in-service and throughout their lifecycle.

Advanced Cybersecurity Protection for the Energy Sector’s Critical Infrastructure

IEC 62443-4: What Manufacturers Must Demonstrate 

Manufacturers supplying industrial control systems to energy infrastructure must align with IEC 62443-4 to ensure products are designed with security as a foundation — not an afterthought. Manufacturers must demonstrate end-to-end security maturity across four core areas:

  • Secure Software Design — Define how software is built and proactively designed against threats
  • Embedded Security — Ensure products include the required security protections for operation
  • Visibility & Risk Awareness — Understand software composition and where vulnerabilities exist

Lifecycle Vulnerability Management — Remediate and respond to vulnerabilities throughout the lifecycle

“From our perspective, adding RunSafe means we have more opportunity to shrink the attack surface and reduce overall risks for our customers since security is now already built into our product.”

Senior Director, Business and Product Development

How RunSafe Supports IEC Standards

RunSafe strengthens how manufacturers meet IEC 62443 Series 4 by improving software resilience, visibility, and vulnerability management—without disrupting system operation or requiring code changes.

Secure Software Design

Security designed into software architecture to reduce real-world exploit paths

  • Identifies memory corruption vulnerabilities and exploitability using Risk Reduction Analysis, showing potential threats and attack feasibility
  • Verifies software composition with build-time SBOMs to ensure no known vulnerable components are included
  • Enables risk-informed design decisions based on actual exploitability, not just vulnerability presence

Lifecycle Vulnerability Management

Continuous risk reduction while patches are developed and deployed

  • Monitors for new vulnerabilities and compares SBOM differences between builds to track changes
  • Analyzes exposure to CVEs and potential zero-days to determine which vulnerabilities are exploitable
  • Makes vulnerabilities non-exploitable at runtime, allowing systems to remain secure while patches are developed
  • Supports lifecycle updates and triage through integrations with tools like GitHub, GitLab, and Bitbucket

Embedded Security

Built-in runtime protections that defend software during operation

  • Makes vulnerabilities non-exploitable by randomizing memory layouts and relocating functions at runtime
  • Protects runtime software from memory-based attacks, even if vulnerabilities exist

Visibility & Risk Awareness

Clear understanding of software composition and vulnerability exposure

  • Provides automated build-time SBOM generation with full visibility into components and dependencies
  • Identifies where vulnerable components exist across applications and systems
  • Uses Risk Reduction Analysis to assess exposure to CVEs and zero-days, prioritizing patching based on exploitability

A Stroger Cybersecurity Position

RunSafe provides technical evidence and reporting that supports these elements.

Component Supported by RunSafe
Secure Development Lifecycle Governance **
Threat Modeling and Secure Design
Software Component Visibility and Vulnerability Assessment
VComponent Security Capabilities
Vulnerability Response and Patch Management

** Subject to RunSafe customers’ practice 

Why RunSafe?

Industrial systems can’t always be patched on demand — yet vulnerabilities exist. RunSafe helps manufacturers by making vulnerabilities non-exploitable at runtime and providing build-time SBOMs for full software visibility, strengthening in-service resilience and aligning with IEC 62443-4 across the full product lifecycle.

Latest Resources

Closing the IT/OT Gap: An OT Security Expert’s Field View

Closing the IT/OT Gap: An OT Security Expert’s Field View

Key takeaways Attackers can halt industrial production without ever reaching the plant floor, because the systems that run manufacturing often sit on the corporate IT network. Many OT environments have no firewall between IT and OT, or one left misconfigured, and most...

read more