Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Embedded Devices and Compliance Pressure: How Teams are Reducing Risk in Long-Life Connected Devices

Solution Category Application Security
Type Webinar
Organization RunSafe Security
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Virtual panel examining cybersecurity risk management for embedded devices with multi-decade operational lifespans
  • Cross-industry perspectives from medical device and industrial automation sectors
  • Regulatory focus on EU Cyber Resilience Act, FDA cybersecurity guidance, and IEC 62443
  • Practical strategies for SBOM management, vulnerability triage, and risk mitigation when patching is not feasible
  • Designed for product security leaders, compliance officers, and engineering executives

Introduction

Connected devices in medical and industrial environments present a distinct cybersecurity challenge: they often remain operational for decades, far outlasting the software support cycles common in consumer technology. This virtual panel discussion, hosted by RunSafe Security, brings together security and engineering leaders from Lynx, Rockwell Automation, and Zimmer Biomet to examine how organisations are navigating the intersection of long device lifespans, evolving regulatory requirements, and persistent vulnerability management pressures.

The timing reflects mounting compliance obligations across both sectors. The EU Cyber Resilience Act introduces vulnerability reporting requirements that will affect manufacturers selling into European markets, while FDA cybersecurity guidance continues to shape expectations for medical device submissions. For industrial automation, IEC 62443 remains the foundational framework for securing operational technology environments. Manufacturers must now demonstrate not only that their devices are secure at launch, but that they can maintain security posture throughout extended operational periods.

About This Event

This webinar-based panel discussion features executive and technical leaders comparing approaches to embedded device security across the medical device and industrial automation industries. The format enables direct comparison of how different sectors interpret similar regulatory pressures and implement risk reduction strategies within their specific operational constraints.

Participants represent organisations with direct responsibility for securing connected products, from industrial control systems to implantable medical devices. The cross-industry structure acknowledges that while regulatory frameworks differ between sectors, the underlying technical challenges of securing long-life embedded systems share considerable overlap.

Regulatory Compliance and Vulnerability Reporting

A central theme of the discussion concerns how manufacturers can demonstrate compliance with multiple overlapping regulatory frameworks. The EU Cyber Resilience Act introduces mandatory vulnerability reporting timelines that require manufacturers to maintain continuous visibility into their software components. This creates operational demands that extend well beyond initial product certification.

For medical device manufacturers, FDA cybersecurity guidance establishes expectations for premarket submissions and postmarket surveillance. The guidance emphasises the importance of software bills of materials as a mechanism for tracking components and responding to newly discovered vulnerabilities. Industrial manufacturers face parallel requirements under IEC 62443, which defines security levels and lifecycle requirements for industrial automation and control systems.

The panel addresses how organisations reconcile these compliance obligations with the practical realities of embedded device development, where safety certifications, hardware constraints, and operational continuity requirements may limit the feasibility of rapid software updates.

Managing Risk When Patching Is Not Feasible

Unlike enterprise IT environments where security patches can typically be deployed within days or weeks, embedded devices in medical and industrial settings often cannot be updated without extensive revalidation. Safety-critical systems may require regulatory reapproval following software changes, while operational technology in continuous manufacturing environments may have limited maintenance windows.

The discussion explores alternative risk mitigation strategies for scenarios where immediate patching is delayed or impossible. This includes vulnerability triage methodologies that prioritise remediation based on exploitability and operational context, compensating controls that reduce exposure without modifying device software, and architectural approaches that limit the impact of compromised components.

Open-source software tracking represents a particular challenge, as embedded devices frequently incorporate numerous open-source components that may receive vulnerability disclosures years after initial integration. Effective SBOM management enables manufacturers to identify affected devices quickly when new vulnerabilities emerge, supporting both compliance reporting and risk-based prioritisation.

Who Should Attend

The session is designed for professionals responsible for product security strategy, regulatory compliance, and engineering leadership within organisations that manufacture or operate connected devices. Relevant roles include chief technology officers, chief information security officers, directors of product security, compliance officers, and engineering managers working in medical device manufacturing, industrial automation, or adjacent sectors.

The content assumes familiarity with embedded systems development and regulatory compliance fundamentals, focusing on strategic and operational considerations rather than introductory concepts.