CRITICAL INFRASTRUCTURE NEEDS

Operational Software Assurance

Security cannot stop when software ships. Operational Software Assurance keeps deployed software secure, protected, and compliant throughout its operational life.

Lifecycle Protection
LaPorte Report
Independent Research

The LaPorte Report: The Call for a Digital Golden Dome

Published by Lionfish Tech Advisors

Lionfish Tech Advisors defines the emerging Operational Software Assurance category and explains why protecting deployed software has become a critical cybersecurity priority.

Introducing Operational Software Assurance

Operational Software Assurance (OSA) is the practice of keeping deployed software secure, protected, and compliant across its operational life. 

It spans the full lifecycle from source to runtime, and it is delivered through three pillars: Identify, Protect, and Comply.

OSA Report Landing
Why Now

AI Has Changed the Economics of Software Security

AI is accelerating vulnerability discovery and exploit development. But patching, testing, and certification cannot keep pace. Embedded Runtime Security closes the gap.

44%

of AI-generated code fails security testing, a rate essentially unchanged in four years.

Veracode, 2026

10x

more security findings came out of AI-assisted development by mid-2025, including a 322% rise in privilege-escalation paths.

Apiiro

~70%

of serious security vulnerabilities trace back to a memory-safety defect.

Microsoft and Google analyses

The Evolution of Software Security

OSA Report

Security has moved from the network, to the endpoint, to the software supply chain.

Operational Software Assurance takes the next step: protecting deployed software itself.

“Software security has moved from the network, to the endpoint, to the supply chain. The next step is protecting the software itself after it is deployed.”

Brad LaPorte, Lionfish Tech Advisors

Resources

Explore Operational Software Assurance

In the News

RunSafe Moves to Lead Operational Software Assurance as U.S. Elevates Cybersecurity Across National Security

Independent research and White House strategy spotlight the need to protect fielded software across defense and critical infrastructure from the supply chain to runtime.

FAQs

  • image/svg+xmlimage/svg+xml
    What is Operational Software Assurance?

    Operational Software Assurance, or OSA, is the practice of keeping deployed software secure, protected, and compliant throughout its operational life.

    Traditional Software Assurance focuses primarily on how software is built and acquired. OSA extends assurance into operations, addressing binaries, firmware, and fielded systems that may remain in use for years or decades and cannot always be easily rewritten or patched.

  • image/svg+xmlimage/svg+xml
    Why is Operational Software Assurance needed now?

    The amount of deployed software is growing at the same time AI is making vulnerabilities easier to discover and exploits faster to develop.

    Many embedded, certified, air-gapped, and mission-critical systems cannot patch at the same speed. Operational Software Assurance addresses the resulting gap by focusing on whether software remains secure and resilient after it has been deployed.

  • image/svg+xmlimage/svg+xml
    How is Operational Software Assurance different from traditional Software Assurance?

    Traditional Software Assurance asks: Did we build and acquire the software securely?

    Operational Software Assurance adds another question: Is that software staying secure, protected, and compliant while it is running in the field?

    The two approaches are complementary. Software Assurance builds confidence before deployment; Operational Software Assurance sustains that confidence afterward.

  • image/svg+xmlimage/svg+xml
    Why isn't vulnerability management alone enough?

    Finding vulnerabilities is important, but identifying a flaw does not make the software unexploitable.

    As vulnerability discovery accelerates, organizations increasingly need to determine whether a vulnerability is actually present, reachable, and exploitable in the software they deployed and protect the system when remediation cannot happen immediately.

    Operational Software Assurance shifts the focus from simply counting vulnerabilities to managing their real operational risk.

  • image/svg+xmlimage/svg+xml
    What is Embedded Runtime Security?

    Embedded Runtime Security, or ERS, is the discipline within the Protect pillar of Operational Software Assurance.

    It refers to active, in-place protections that make exploitation of deployed binaries and firmware more difficult or cause an exploit attempt to fail at runtime. These protections are designed for environments where changing source code, deploying traditional endpoint agents, or waiting for a patch may not be practical.

    Software memory protection is a central capability within ERS.

  • image/svg+xmlimage/svg+xml
    What is the Digital Golden Dome?

    The Digital Golden Dome is the policy metaphor Lionfish Tech Advisors uses for the runtime protection component of Operational Software Assurance.

    Just as a physical defense system is designed to intercept a threat before it reaches its target, the Digital Golden Dome describes protections designed to prevent an exploit from successfully taking control of deployed software when an attack occurs.

  • image/svg+xmlimage/svg+xml
    How does RunSafe Security support Operational Software Assurance?

    RunSafe’s work aligns most closely with the Protect pillar of Operational Software Assurance and the discipline of Embedded Runtime Security.

    RunSafe focuses on reducing exploitability in deployed binaries and firmware, particularly in environments where software is difficult to patch, rewrite, or replace. Operational Software Assurance is the broader market category that spans Identify, Protect, and Comply.

Explore Operational Software Assurance

Learn why software security is expanding beyond how software is built to how it remains protected after deployment.