

Building Secure Embedded Systems: From Threat Modeling to Secure Firmware
Overview
Protecting devices, data, firmware, and communications in a changing threat landscape
Embedded systems are everywhere: in industrial controllers, connected products, medical devices, vehicles, consumer electronics, gateways, sensors, and critical infrastructure. As these devices become more connected, longer-lived, and exposed to remote attackers, security can no longer be treated as a final checklist item before release.
This workshop gives embedded developers and technical teams a practical foundation for building more secure devices. We will start by defining a threat model: what needs protection, who might attack it, what capabilities they may have, and which risks matter most. From there, we will cover the essential pillars of embedded security: securing data at rest, securing data in transfer, designing firmware updates and secure boot flows, and using defensive programming techniques to reduce the attack surface.
The workshop also introduces a forward-looking post-quantum cryptography perspective. Participants will learn why crypto-agility matters, how long-lived embedded products may be affected by future cryptographic transitions, and how to design systems today so that algorithms, keys, certificates, and update mechanisms can be replaced safely when requirements evolve.
By the End You’ll Walk Away With:
A step-by-step threat-modeling method, with a reusable template you can apply to your own products right away.
A practical understanding of how to protect sensitive data stored on devices.
A roadmap for securing communication channels between devices, services, and users.
A high-level architecture for secure boot and authenticated firmware updates.
Defensive programming techniques for reducing common embedded software vulnerabilities.
A practical introduction to crypto-agility and post-quantum migration planning.
A reusable security review checklist and secure design patterns you can take back to your team and apply immediately when designing or reviewing embedded products.
Hands-On Elements:
Guided threat-modeling exercise: participants build a threat model for a realistic connected device, using the template provided.
Live demonstrations of secure boot and signed firmware update flows, showing how image verification and rollback protection work in practice.
Worked examples of defensive programming: dissecting real-world vulnerable code patterns (unsafe parsers, missing bounds checks) and hardening them together.
Interactive milestones and Q&A checkpoints throughout, so participants follow along step-by-step rather than passively watching.
A final checklist walkthrough, applying the security review checklist to an example product.
Who Should Attend:
Embedded software engineers working on connected or security-sensitive products.
Firmware developers who want to understand secure boot, updates, and data protection.
IoT, industrial, automotive, medical, or consumer device engineers.
Engineers building connected IoT products, industrial systems, and edge devices that must remain secure and maintainable in the field.
Technical leads and architects responsible for product security decisions.
Developers who are not security specialists but need to build more secure embedded systems.
What You’ll Learn:
✅ How to define a practical threat model for an embedded product.
✅ How to identify assets, attackers, attack surfaces, and trust boundaries.
✅ How to protect data at rest using encryption, key management, access control, and secure storage concepts.
✅ How to protect data in transfer using authenticated communication, TLS-style concepts, certificates, and protocol design.
✅ How secure boot and signed firmware updates protect device integrity.
✅ How defensive programming reduces memory corruption, input parsing bugs, downgrade attacks, and unsafe failure modes.
✅ Why post-quantum cryptography matters for long-lived embedded devices.
✅ How to design crypto-agile systems where algorithms and keys can be replaced over time.
✅ How to replace legacy cryptographic algorithms without breaking deployed products.
What You’ll Need/Pre-requisites:
A basic understanding of C or embedded software development.
Familiarity with microcontrollers, firmware, or embedded Linux is helpful but not mandatory.
A computer for following examples, notes, and exercises.
Basic familiarity with networking concepts is useful.
No prior cryptography expertise is required.
Why Now?
Embedded products are staying in the field longer, connecting to more services, and handling more sensitive data than ever before. At the same time, attackers increasingly target firmware, update systems, device credentials, weak communication channels, and exposed debug or maintenance paths. Security decisions made early in the design phase can determine whether a device can be maintained safely for years. Regulators are raising the bar as well: the EU Cyber Resilience Act and similar emerging requirements are turning security-by-design, vulnerability handling, and secure update capabilities into legal obligations for connected products, while recent attacks on firmware and software supply chains have made the integrity of build and update pipelines a first-class engineering concern.
The timing is also important because cryptography is entering a transition period. Post-quantum cryptography is moving from research into standardization and adoption, and embedded teams need to start thinking about crypto-agility now. Devices designed today may still be deployed when cryptographic requirements change. This workshop helps teams build products that are secure now and easier to migrate later.
Chris Simmonds will share his learnings through a pre-recorded session video.
🎟️Reserve your seat now - Limited seats. Live support. Real builds.
*By signing up for this event, you agree to receive emails from Packt Publishing.