Embedded Devices and Compliance Pressure: How Teams are Reducing Risk in Long-Life Connected Devices

A critical vulnerability has been found in a connected product that has been deployed for more than ten years. The device performs an essential safety or operational function, but a validated patch will not be available for several months.

What should the manufacturer do next?

In this panel discussion, security and engineering leaders from RunSafe Security, Lynx, Rockwell Automation, and Zimmer Biomet compare how medical device and industrial teams manage this challenge.

The speakers examine how organizations determine which products are affected, make defensible risk decisions, select compensating controls, and manage vulnerability reporting across device lifecycles measured in decades.

Watch the webinar to learn:

  • What medical device postmarket reporting can teach industrial manufacturers
  • What evidence teams need beyond an SBOM to make vulnerability decisions
  • How product context changes whether a device is considered affected
  • How organizations respond when a patch cannot be deployed immediately
  • Which mitigations reduce exploitability and which may provide only superficial reassurance
  • What manufacturers should prioritize to improve both compliance readiness and product security

 

Meet the Speakers

Shane Fry

Shane Fry
CTO
RunSafe Security

Maciej Halasz

Maciej Halasz
Director, EMEA Open Source Solutions
Lynx

John Howie

John Howie
Chief Information Security Officer
Zimmer Biomet

Joel Max

Joel Max
Senior Manager, Product Security Incident Response Team
Rockwell Automation

Download our Webinar

What Can RunSafe Security Do For You?

Exclusive Technology

Disrupt Attacker Economics

Remove the structure needed for reliable memory exploitation.

Cyber Bug

Reduce Attack
Surfaces

Neutralize Zero-Days with Moving Target Defense.

Systems Icon

Protect Key
Applications

Proactive Code Level Security to maintain original functionality and mitigate the attack.