Embedded Devices and Compliance Pressure: How Teams Are Reducing Risk in Long-Life Connected Devices

Join us Wednesday, September 9, at 10:00 AM ET for a cross-industry discussion on managing cybersecurity risk and compliance across connected products designed to remain in the field for years or even decades.

Leaders from RunSafe Security, Lynx, Rockwell Automation, and Zimmer Biomet will compare how industrial and medical device teams are approaching software visibility, vulnerability management, and risk mitigation—particularly when immediate patching is not practical.

September 9, 2026 | 10:00 AM ET | Online

lynx-visual-engineering-code-section-right-v1--1920x1080

Managing Cybersecurity Across the Device Lifecycle

Long-life connected devices create a difficult security challenge. Software components and vulnerabilities continue to evolve long after a product enters the field, while safety requirements, certification constraints, operational availability, and hardware limitations can make traditional patching difficult.

At the same time, requirements such as the EU Cyber Resilience Act, FDA cybersecurity guidance, and IEC 62443 are raising expectations for how manufacturers identify affected products, evaluate vulnerabilities, document risk, and respond throughout the product lifecycle.

This panel brings together perspectives from medical technology, industrial automation, embedded software, and product security to explore how organizations are addressing those pressures in practice—and what different industries can learn from one another.

What You’ll Learn

  • Moving beyond the SBOM to determine whether products are actually affected by a vulnerability
  • Improving open-source software visibility and vulnerability triage across long product lifecycles
  • Balancing cybersecurity requirements with safety certification and operational availability
  • Reducing risk when a device cannot be patched immediately
  • Applying lessons from medical device postmarket cybersecurity to industrial and embedded systems
  • Preparing practical processes for evolving cybersecurity and vulnerability-reporting requirements

From Compliance Requirements to Practical Risk Reduction

Knowing that a vulnerability exists is only the beginning. Product teams still need to understand which devices contain the affected software, whether the vulnerability is exploitable in their specific environment, and what action is appropriate when an immediate update is not possible.

Hear how organizations across regulated and long-life product environments are connecting software visibility, vulnerability analysis, engineering decisions, and compliance into a more practical approach to product security.

Join the Discussion

Whether you work in product security, embedded engineering, software or firmware development, compliance, or technical leadership, this session will offer practical perspectives for managing cyber risk across products that must remain secure and operational for the long term.

Join Lynx, RunSafe Security, Rockwell Automation, and Zimmer Biomet on September 9.

Meet the Speakers

Shane Fry headshot

Shane Fry

CTO, RunSafe Security

Maciej Halasz headshot

Maciej Halasz

Director, EMEA Open Source Solutions, Lynx

John Howie headshot

John Howie

Chief Information Security Officer, Zimmer Biomet

Joel Max headshot

Joel Max

Senior Manager, Product Security Incident Response Team, Rockwell Automation

Meet the Speakers

Shane Fry headshot

Shane Fry

CTO, RunSafe Security

Maciej Halasz headshot

Maciej Halasz

Director, EMEA Open Source Solutions, Lynx

John Howie headshot

John Howie

Chief Information Security Officer, Zimmer Biomet

Joel Max headshot

Joel Max

Senior Manager, Product Security Incident Response Team, Rockwell Automation

Continue the Conversation

Live panel

A critical CVE lands tonight. Can your team make the call by tomorrow?

Start with the full discussion of the product, engineering, safety, quality, regulatory, and lifecycle decisions that follow a serious vulnerability finding.
Evidence

We can find the component, but not the affected product.

An SBOM may tell you a component is present. It does not automatically answer how it was configured, whether relevant functionality is enabled, which released variants are in scope, or what evidence supports a decision.
Patch gap

The patch exists, but we cannot safely ship it.

An upstream fix may still require a backport, hardware validation, regression testing, safety analysis, certification work, and an update window you do not control.
Lifecycle

The product will outlive its software platform.

Long-life devices depend on the ability to understand, rebuild, change, test, and support software years after the product ships.

Ready to turn compliance pressure into practical risk reduction?

Join the panel to hear how product teams are making defensible security decisions when long-life devices cannot be patched immediately.