Cyber Resilience for IoT: What’s the Right Level of Security for Embedded Devices?

Traditionally, embedded systems have been kept secure by being physically inaccessible to external threats. Consider the difficulty of hacking a CNC machine. Programming the machine required direct interaction with the machine to upload a file from a disk or, if the system is old enough, a paper tape.

To change how the machine operates, a hacker would have to gain access to the factory floor and physically interact with the machine without being noticed by the person managing the machine. In short, the layers of early embedded security depended on physical security measures such as keycard door locks that prevented direct access to equipment.

