Security Expertise Videos

Product Security On Demand

Experience the future of product security through our immersive video content. From Al-powered analysis to real-world case studies, discover how industry leaders protect their digital assets.

All Categories

Newest

113 results

• AI in Cybersecurity(18 Videos)

\ \ 2:54\ \ How AI and Supply Chain Risk Are Shaping IoT Security\ \ Generative AI is changing the threat landscape with faster malware development, deepfakes, and highly convincing phishing. Combined with stricter supp...](/content/resources/videos/how-ai-supply-chain-risk-shape-iot-security/index.html)

\ \ Featured\ \ 4:03\ \ AI and the Future of SBOMs\ \ Discover how AI is reshaping SBOMs and software security, driving smarter triage, deeper reachability analysis, and helping navigate rising regulatory...\ \ ai\ \ artificial intelligence\ \ +4](/content/resources/videos/ai-and-the-future-of-sboms/index.html)

\ \ Featured\ \ 3:36\ \ AI Autonomy vs Oversight\ \ Discover how AI agents are reshaping human roles—and why it’s time to rethink your place as the orchestrator of intelligent systems.\ \ ai\ \ artificial intelligence\ \ +2](/content/resources/videos/ai-autonomy-vs-oversight/index.html)

\ \ 6:54\ \ AI Hallucinations Explained\ \ Learn strategies to make your LLM outputs as reliable as your human experts.\ \ ai\ \ artificial intelligence\ \ +2](/content/resources/videos/ai-hallucinations-explained/index.html)

\ \ 5:03\ \ AI: The Secret Weapon for Product Security Compliance at Finite State\ \ Discover how Finite State uses AI to tackle the toughest part of compliance, so security teams can stay focused on protecting products and meeting glo...](/content/resources/videos/ai-the-secret-weapon-for-product-security-compliance-at-finite-state/index.html)

\ \ 4:23\ \ AI's Context Challenge\ \ Discover why AI can’t “one-shot” your entire codebase and how better prompts, tools, and human guidance unlock its real power in finding security flaw...\ \ ai\ \ artificial intelligence\ \ +2](/content/resources/videos/ais-context-challenge/index.html)

\ \ 6:23\ \ AI's Role in Navigating Global Product Security Regulations\ \ Discover how AI is becoming essential for managing exploding regulatory demands in product security, helping teams bridge the gap between scarce human...\ \ ai\ \ artificial intelligence\ \ +3](/content/resources/videos/ais-role-in-navigating-global-product-security-regulations/index.html)

\ \ 4:15\ \ Balancing Security and AI\ \ Explore how organizations can safely adopt AI for product security—even in critical infrastructure—by balancing cloud trust, data governance, and emer...\ \ ai\ \ artificial intelligence\ \ +3](/content/resources/videos/balancing-security-and-ai/index.html)

\ \ 4:18\ \ Beyond the Scan: How AI Adds Real Value in Product Security Workflows\ \ Explore why simply dropping binaries into AI won’t find all your vulnerabilities, and how Finite State uses AI to tackle the massive work that happens...\ \ ai\ \ artificial intelligence\ \ +3](/content/resources/videos/beyond-the-scan-how-ai-adds-real-value-in-product-security-workflows/index.html)

\ \ 4:24\ \ How AI Is Slashing the Workload in Software Supply Chain Security\ \ Learn how LLMs are revolutionizing vulnerability triage and remediation guidance, cutting manual effort by 90% and allowing security teams to focus on...\ \ ai\ \ artificial intelligence\ \ +4](/content/resources/videos/how-ai-is-slashing-the-workload-in-software-supply-chain-security/index.html)

\ \ 2:10\ \ How AI Transforms Vulnerability and Exploit Detection\ \ See how generative AI replaces manual threat intel review, turning mountains of human-written reports into actionable signatures for faster, smarter v...\ \ ai\ \ artificial intelligence\ \ +4](/content/resources/videos/how-ai-transforms-vulnerability-and-exploit-detection/index.html)

\ \ 2:28\ \ How Finite State Is Supercharging Security with AI\ \ See how Finite State harnesses AI to cut vulnerability triage workloads by up to 90% and automate tedious compliance documentation—freeing security te...\ \ ai\ \ artificial intelligence\ \ +3](/content/resources/videos/how-finite-state-is-supercharging-security-with-ai/index.html)

\ \ 3:47\ \ How to Get Meaningful Risk Scores from AI\ \ Find out why AI risk assessments are only as good as the context you provide and how giving LLMs deeper product and threat insights drives smarter, sa...\ \ ai\ \ artificial intelligence\ \ +2](/content/resources/videos/how-to-get-meaningful-risk-scores-from-ai/index.html)

\ \ 4:42\ \ How Tool-Enabled AI Is Transforming Cybersecurity\ \ See how giving AI tools supercharges its capabilities and why this evolution is poised to revolutionize cybersecurity and software supply chain securi...\ \ ai\ \ artificial intelligence\ \ +3](/content/resources/videos/how-tool-enabled-ai-is-transforming-cybersecurity/index.html)

\ \ 6:38\ \ SBOMs, AI, and the Real Work\ \ Learn why SBOMs are far more complex than a nutrition label and how Finite State is using AI to transform SBOM analysis, triage, and remediation into ...\ \ ai\ \ artificial intelligence\ \ +4](/content/resources/videos/sboms-ai-and-the-real-work/index.html)

\ \ 4:47\ \ Smarter Ways to Prioritize Vulnerabilities\ \ Learn how combining graph analysis with AI can pinpoint which vulnerabilities are truly exploitable so you can focus remediation efforts where they ma...\ \ ai\ \ artificial intelligence\ \ +4](/content/resources/videos/smarter-ways-to-prioritize-vulnerabilities/index.html)

\ \ 5:35\ \ Why Finding Software Vulnerabilities Still Needs More Than AI Alone\ \ Discover why LLMs can’t simply “read binaries” to find vulnerabilities and how combining them with specialized tools unlocks real value in software se...\ \ ai\ \ artificial intelligence\ \ +4](/content/resources/videos/why-finding-software-vulnerabilities-still-needs-more-than-ai-alone/index.html)

\ \ 6:17\ \ Why Security Still Needs Tools, Context, and Smart Integration\ \ Unpack the real strengths—and limits—of LLMs in security, and learn how combining them with purpose-built tools unlocks powerful insights for finding ...\ \ ai\ \ artificial intelligence\ \ +3](/content/resources/videos/why-security-still-needs-tools-context-and-smart-integration/index.html)

• Compliance & Regulations(38 Videos)

\ \ Why Bottom-Up Vulnerability Management Breaks at Scale\ \ Bottom-up vulnerability tracking works for small teams—but breaks at scale. Learn how fragmentation impacts prioritization, compliance, and security r...\ \ eu cra](/content/resources/videos/bottom-up-vulnerability-management-at-scale/index.html)

\ \ Breaking Down Silos in Product Security and Compliance\ \ Siloed teams and one-off tools create outdated compliance. Learn why connected device security needs a continuous, cross-functional workflow.\ \ eu cra](/content/resources/videos/breaking-down-product-security-silos/index.html)

\ \ Why Controls-Only Compliance Fails Connected Device Security\ \ Controls assessments and gap analyses aren’t enough. Learn why compliance must connect security controls to real firmware, releases, and shipped softw...\ \ eu cra](/content/resources/videos/controls-only-compliance-connected-devices/index.html)

\ \ 1:28\ \ Compliance Is an Artificial Adversary—Unless You Tie It to What You Ship\ \ Regulations like the EU CRA demand proof—but real risk lives in releases, firmware, and code. Learn how to connect vulnerabilities to continuous compl...\ \ eu cra](/content/resources/videos/artificial-adversary-compliance-connected-devices/index.html)

\ \ 46:57\ \ Precision Over Panic: How to Focus on Real Risk for CRA Compliance\ \ Dario Lobozzo from Finite State presents a comprehensive approach to CRA (Cyber Resilience Act) compliance, addressing the challenges organizations fa...\ \ eu cra](/content/resources/videos/precision-over-panic-how-to-focus-on-real-risk-for-cra-compliance/index.html)

\ \ 0:58\ \ Why Regulated Industries Choose Finite State\ \ Automotive, medical device, and telecom manufacturers face strict regulatory demands—and high stakes. In this video, Mike Hatherall, Lead Solutions Ar...](/content/resources/videos/finite-state-benefits-for-regulated-industries/index.html)

\ \ 3:21\ \ Why CRA Compliance Is So Challenging for Manufacturers\ \ The EU CRA introduces sweeping new responsibilities for connected product manufacturers—but most aren’t ready. In this clip, Dario Lobozzo, GM of EMEA...](/content/resources/videos/why-cra-compliance-is-so-hard-for-manufacturers/index.html)

\ \ 2:19\ \ Solving the CRA Puzzle: A Layered Approach to Compliance\ \ CRA compliance isn’t one-size-fits-all—especially for manufacturers of software-defined products. In this clip, Dario Lobozzo, GM of EMEA at Finite St...](/content/resources/videos/layered-approach-cra-compliance-analysis-methods/index.html)

\ \ 1:46\ \ Automating CRA Vulnerability Reporting for Real Business Impact\ \ Dario Lobozzo, GM of EMEA at Finite State, describes the “holy grail” of CRA compliance: automated, scalable vulnerability reporting. In this clip, he...](/content/resources/videos/cra-vulnerability-reporting-automation/index.html)

\ \ 2:37\ \ CRA Flips the Script on Vulnerability Management\ \ Vulnerability disclosure is nothing new—but CRA introduces a new twist: retroactive reporting. In this clip, Dario Lobozzo, GM of EMEA at Finite State...](/content/resources/videos/cra-retroactive-vulnerability-management/index.html)

\ \ 3:49\ \ The Beauty of the SBOM: Why It’s Essential for CRA Compliance\ \ In this clip, Dario Lobozzo, GM of EMEA at Finite State, lays out the true value of SBOMs in modern product security—enabling visibility, context, and...](/content/resources/videos/why-sboms-matter-for-cra/index.html)

\ \ 3:28\ \ From 26,000 Vulnerabilities to 300: CRA Certification for Legacy Products\ \ What happens when you have a legacy product—already in the field, five years on the market—and now you have to certify it for CRA? Learn how layering ...](/content/resources/videos/cra-certification-legacy-product-prioritization/index.html)

\ \ 1:58\ \ Go Beyond CRA: Why Forward-Thinking OEMs Aim Higher\ \ CRA is the baseline—but many forward-looking manufacturers aren’t stopping there. In this clip, Dario Lobozzo, GM of EMEA at Finite State, explains wh...](/content/resources/videos/cra-compliance-vs-industry-standards/index.html)

\ \ 1:50\ \ Accelerating CRA Readiness: Start Small, Move Fast\ \ General Manager of EMEA Dario Lobozzo outlines a low-effort, high-impact strategy for getting started with CRA compliance. From rapid product risk ide...](/content/resources/videos/accelerating-cra-readiness-finite-state/index.html)

\ \ 3:18\ \ Building a Scalable CRA Vulnerability Disclosure Program\ \ Dario Lobozzo, GM of EMEA at Finite State, shares what it really takes to run a successful CRA vulnerability disclosure program: communication across ...](/content/resources/videos/building-a-scalable-cra-vulnerability-disclosure-program/index.html)

\ \ 3:17\ \ Why CRA’s Coordinated Vulnerability Disclosure Requirement Matters\ \ Unpack the complexity of meeting CRA’s Coordinated Vulnerability Disclosure (CVD) requirements, including why CVD success requires deep visibility int...](/content/resources/videos/cra-coordinated-vulnerability-disclosure/index.html)

\ \ 1:33\ \ Avoiding CRA Pitfalls: Don’t Wait to Fix What’s Broken\ \ Dario Lobozzo, GM of EMEA at Finite State, calls out a common but costly mistake in CRA compliance planning: treating assessments and remediation as s...](/content/resources/videos/cra-assessments-shadow-product-security/index.html)

\ \ 1:15\ \ CRA Readiness Isn’t a Checkbox—It’s a Long-Term Strategy\ \ Treating CRA compliance as a one-time, checkbox exercise is a recipe for failure. While you may get through your first audit with spreadsheets and man...](/content/resources/videos/cra-checkbox-compliance-vs-sustainable-security/index.html)

\ \ 2:39\ \ Why Pen Testing Is Functionally Required for Cybersecurity Compliance\ \ Pen testing may not be named in every regulation, but it’s essential to prove your security controls work.](/content/resources/videos/why-pen-testing-is-required-for-cybersecurity-compliance/index.html)

\ \ 1:43\ \ Are You Impacted by the Connected Vehicle Rule?\ \ Many OEMs, suppliers, and aftermarket companies may be affected by the CVR - here’s what you need to do now.](/content/resources/videos/are-you-impacted-by-the-connected-vehicle-rule/index.html)

\ \ 3:00\ \ What It Takes to Secure a Specific Authorization Under the CVR\ \ Understand how to secure a specific authorization under the CVR—and what cybersecurity evidence you’ll need—to increase your chances of acceptance.](/content/resources/videos/cvr-specific-authorization/index.html)

\ \ 2:02\ \ Will the DoC Enforce the CVR Strictly from Day One?\ \ Experts weigh in on how enforcement of the CVR might unfold—and why early flexibility could be on the table.](/content/resources/videos/will-the-doc-enforce-the-cvr-strictly-from-day-one/index.html)

\ \ 1:28\ \ Why You Can’t Just “Approve” a Supplier Anymore\ \ The Connected Vehicle Rule demands component-level scrutiny, especially with multi-region suppliers and JV structures.](/content/resources/videos/why-you-cant-just-approve-a-supplier-under-cvr/index.html)

\ \ 2:06\ \ Making the Legacy Software Carve-Out Work\ \ Learn what it takes to remain compliant with the CVR, including codebase transfers and strict developer restrictions.](/content/resources/videos/making-legacy-software-carve-out-work-cvr/index.html)

\ \ 4:55\ \ Firmware Exclusions and the Legacy Carve-Out: What Changed from the Draft Rule?\ \ Learn how the final Connected Vehicle Rule narrows firmware definitions and creates a software carve-out that requires careful planning.](/content/resources/videos/what-changed-from-the-draft-connected-vehicle-rule/index.html)

\ \ 2:42\ \ What’s In Scope (and What’s Not) Under the Connected Vehicle Rule\ \ Understand how to determine what hardware and software falls under VCS and ADS requirements for the Connected Vehicle Rule.](/content/resources/videos/whats-in-scope-under-the-connected-vehicle-rule/index.html)

\ \ 1:58\ \ Jurisdiction, Control, Direction: What Triggers Coverage Under the Connected Vehicle Rule?\ \ Understand the blurry line companies must navigate to assess China or Russia-linked entities.](/content/resources/videos/what-triggers-coverage-under-the-connected-vehicle-rule/index.html)

\ \ 2:47\ \ How Disruptive Is the Connected Vehicle Rule?\ \ Experts explain why this regulation is unlike anything the automotive industry has faced before.](/content/resources/videos/how-disruptive-is-the-connected-vehicle-rule/index.html)

\ \ 4:18\ \ How to Exclude Components Under the CVR & Why It’s So Difficult\ \ Learn what it really takes to identify, document, and verify component origins across your supply chain to comply with the Connected Vehicle Rule.](/content/resources/videos/how-to-exclude-components-under-the-cvr/index.html)

\ \ 3:52\ \ What Is the Connected Vehicle Rule?\ \ A foundational overview of the rule’s scope, prohibitions, enforcement timeline, and supply chain impact.](/content/resources/videos/what-is-the-connected-vehicle-rule/index.html)

\ \ 1:08\ \ Raising the Bar: What Compliance Now Expects From Your Security Program\ \ Today’s regulatory expectations go far beyond shipping secure code. Discover what OEMs and suppliers must do to demonstrate ongoing security maturity.](/content/resources/videos/security-program-compliance-expectations/index.html)

\ \ 1:15\ \ Why the Cost of Compliance Is Far Less Than the Cost of Inaction\ \ Global regulations aren’t just about fines—they impact market access. Learn why compliance is now a business-critical priority for IoT manufacturers.](/content/resources/videos/cost-of-compliance-sdlc/index.html)

\ \ 57:23\ \ Policy to Action: The Connected Vehicle Rule Webinar](/content/resources/videos/policy-to-action-the-connected-vehicle-rule-webinar/index.html)

\ \ 52:48\ \ Securing the Product Lifecycle: Building Global Compliance into IoT Development](/content/resources/videos/securing-the-product-lifecycle-building-global-compliance-into-iot-development/index.html)

\ \ 5:34\ \ Closing Security Gaps for CRA Compliance\ \ See how the CRA pushes manufacturers to unify SBOMs, risk assessments, and vulnerability reporting in this soundbite from our Risk to Resilience webin...\ \ eu cra](/content/resources/videos/closing-security-gaps-for-cra-compliance/index.html)

\ \ Featured\ \ 6:44\ \ Navigating Software Security and Compliance Challenges\ \ Explore how companies meet security regulations through patching, vendor collaboration, or creative compensating controls when direct fixes aren’t fea...](/content/resources/videos/navigating-software-security-and-compliance-challenges/index.html)

\ \ 6:18\ \ Why Security Submissions Are Critical for Connected Medical Devices\ \ Discover why getting security right the first time is essential for medical device approvals and how gaps in your submission can derail time-to-market...](/content/resources/videos/why-security-submissions-are-critical-for-connected-medical-devices/index.html)

• Finite State Feature Focus(14 Videos)

\ \ 1:07\ \ How Finite State Reduces SDLC Complexity and Tool Sprawl\ \ Tool sprawl, manual processes, and disconnected workflows are slowing down security and compliance teams across the software lifecycle. In this video,...](/content/resources/videos/how-finite-state-reduces-sdlc-complexity-and-tool-sprawl/index.html)

\ \ How Finite State Brings Security, Engineering & Compliance Together\ \ Finite State is more than a scanner—it’s a unifying force across engineering, security, and compliance. In this video, Mike Hatherall, Lead Solutions ...](/content/resources/videos/how-finite-state-unifies-security-workflows/index.html)

\ \ 1:52\ \ From Probability to Proof: EPSS + Reachability = Real ROI\ \ Discover how combining EPSS with Finite State’s built-in reachability analysis takes you from “probable” to “provable” with smarter prioritization, fe...](/content/resources/videos/epss-reachability-roi-security-decision-making/index.html)

\ \ 3:23\ \ Why “Secure by Design” Matters and How Finite State Makes It Real\ \ Learn how Finite State’s platform accelerates analysis, powers precise threat modeling, and gives pen testers deep insight in minutes—not days.](/content/resources/videos/why-secure-by-design-matters-and-how-finite-state-makes-it-real/index.html)

\ \ 0:59\ \ Hardcoded Credentials: The Risks Developers Leave Behind\ \ Default passwords and forgotten comments often remain buried in code—posing major risks for connected devices. Learn how Finite State helps uncover th...](/content/resources/videos/hardcoded-credentials-the-risks-developers-leave-behind/index.html)

\ \ 4:13\ \ Finding Clarity and Focus for Complex Embedded System Security\ \ Discover how Finite State reveals what’s truly inside embedded systems and helps you prioritize the few vulnerabilities that matter most, so you can m...\ \ feature focus\ \ product features\ \ +5](/content/resources/videos/finding-clarity-and-focus-for-complex-embedded-system-security/index.html)

\ \ 6:40\ \ Finite State vs Legacy Tooling\ \ Learn why legacy SCA tools focus on licensing while Finite State zeroes in on security, giving you real protection instead of just compliance checkbox...\ \ feature focus\ \ product features\ \ +3](/content/resources/videos/finite-state-vs-legacy-tooling/index.html)

\ \ 3:11\ \ Finite State’s Policy Engine for Tailored Security Decisions\ \ See how Finite State empowers you to customize security policies, automate enforcement, and align vulnerability management with your unique risk toler...\ \ feature focus\ \ product features\ \ +7](/content/resources/videos/finite-states-policy-engine-for-tailored-security-decisions/index.html)

\ \ 5:24\ \ How Finite State Analyzes Every Layer of Your Firmware\ \ Learn how Finite State digs into all code—yours and your suppliers’—using advanced unpacking to deliver deep security insights and accurate SBOMs.\ \ feature focus\ \ product features\ \ +4](/content/resources/videos/how-finite-state-analyzes-every-layer-of-your-firmware/index.html)

\ \ 5:48\ \ How Finite State Reduces False Positives\ \ See how Finite State uses precise binary fingerprints and real-time threat intel to pinpoint real issues and highlight what truly matters.\ \ feature focus\ \ product features\ \ +3](/content/resources/videos/how-finite-state-reduces-false-positives/index.html)

\ \ 5:31\ \ How Finite State Tackles Binary Analysis Challenges\ \ Learn how Finite State blends precise signature matching with probabilistic analysis to identify hidden components in binaries, even when package data...\ \ feature focus\ \ product features\ \ +4](/content/resources/videos/how-finite-state-tackles-binary-analysis-challenges/index.html)

\ \ 2:30\ \ Integrating Finite State into Modern CI/CD Pipelines\ \ Learn how Finite State’s CLI and APIs keep your pipelines fast and secure, so you can automate scans without slowing product delivery.\ \ feature focus\ \ product features\ \ +3](/content/resources/videos/integrating-finite-state-into-modern-cicd-pipelines/index.html)

\ \ 6:24\ \ Speeding Up Remediation\ \ Discover how Finite State accelerates remediation by cutting false positives and helping teams zero in on real, high-priority security issues first.\ \ feature focus\ \ product features\ \ +3](/content/resources/videos/speeding-up-remediation/index.html)

\ \ Featured\ \ 4:04\ \ Unlock Your System's Secrets\ \ See how Finite State helps you know what’s in your system, decide what to fix, and confidently share SBOMs with partners and regulators.\ \ feature focus\ \ product features\ \ +3](/content/resources/videos/unlock-your-systems-secrets/index.html)

Product Security(11 Videos)

\ \ 5:03\ \ Quick-Fire Security Questions with Mike Hatherall\ \ In this rapid-fire Q&A, Mike Hatherall, Lead Solutions Architect at Finite State, tackles some of the most common challenges product security teams fa...\ \ eu cra](/content/resources/videos/quick-fire-product-security-questions-mike-hatherall/index.html)

\ \ 0:35\ \ Advice for Building Scalable Product Security Programs\ \ Mike Hatherall shares advice for security leaders building modern, scalable product security: start with a data model, align terms, and automate visib...](/content/resources/videos/advice-for-building-scalable-product-security-programs/index.html)

\ \ 0:43\ \ How Product Security Workflows Are Evolving Globally\ \ Global regulations—from the EU CRA to the FDA’s cybersecurity mandate—are transforming product security workflows. In this video, Mike Hatherall, Lead...](/content/resources/videos/how-product-security-workflows-are-evolving-globally/index.html)

\ \ 0:53\ \ Why Linking SBOMs, Vulnerabilities & Compliance Data Matters\ \ In this video, Mike Hatherall, Lead Solutions Architect at Finite State, explains the power of unifying these elements in a single platform. When ever...](/content/resources/videos/why-linking-sbom-vulnerabilities-and-compliance-matters/index.html)

\ \ 1:07\ \ How to Align Legal, Security & Engineering on the Same Risk Data\ \ In this video, Mike Hatherall, Lead Solutions Architect at Finite State, explains how a unified platform can deliver shared data in tailored ways—so e...](/content/resources/videos/how-to-align-security-legal-engineering-on-risk-data/index.html)

\ \ 0:50\ \ What a Unified Software Risk Picture Really Looks Like\ \ What would it take to align engineering, security, and legal teams around a single understanding of product risk? In this video, Mike Hatherall, Lead ...](/content/resources/videos/what-a-unified-software-risk-picture-looks-like/index.html)

\ \ 1:14\ \ What Happens When Teams Use Different Tools for SBOMs and Vulnerability Data?\ \ When engineering, security, and compliance teams use different tools—and each relies on their own “source of truth”—vulnerability management falls apa...](/content/resources/videos/when-sbom-and-vulnerability-data-is-fragmented/index.html)

\ \ 0:56\ \ Breaking Silos Between Engineering, Security, and Compliance\ \ Mike Hatherall, Lead Solutions Architect at Finite State, has worked with product security teams across Europe and around the world. In this video, he...](/content/resources/videos/silos-between-engineering-security-compliance/index.html)

\ \ Navigating the Complexity of IoT Device Vulnerability: The Future State of Medical Device Security\ \ Watch this On-Demand Health-ISAC panel discussion to understand how industry leaders are addressing the emerging challenge of protecting IoT devices.](/content/resources/videos/navigating-the-complexity-of-iot-device-vulnerability-video/index.html)

SBOM Management(8 Videos)

\ \ 3:16\ \ What Makes a Quality SBOM? It Depends on Who's Asking.\ \ SBOM quality isn’t a fixed standard—it depends on who's requesting it and how it's being used. In this clip, Dario Lobozzo, GM of EMEA at Finite State...](/content/resources/videos/what-makes-a-quality-sbom/index.html)

\ \ 2:17\ \ Validating Third-Party SBOMs: Trust, Verify, Comply\ \ As CRA and industry standards like UN R155 and ISO/SAE 21434 push supply chain security to the forefront, validating third-party SBOMs is no longer op...](/content/resources/videos/validating-third-party-sboms-oem-supplier-trust/index.html)

\ \ 1:29\ \ Why SBOMs Are the Key to Meeting Compliance Capabilities\ \ Learn how SBOMs enable core compliance capabilities like inventory, risk assessment, and ongoing vulnerability monitoring—without being named explicit...](/content/resources/videos/sboms-key-to-meeting-compliance-capabilities/index.html)

\ \ 2:05\ \ SBOM Verification: Ensuring Quality & Trust in Final Software Builds\ \ Explore why verifying SBOMs against final software builds is crucial for quality and trust and how emerging standards will strengthen supply chain tra...\ \ sbom\ \ software bill of materials\ \ +3](/content/resources/videos/sbom-verification-ensuring-quality-trust-in-final-software-builds/index.html)

\ \ Featured\ \ 5:20\ \ Spotting SBOM Flaws\ \ Learn how missing dependency details signal an incomplete SBOM and why digging deeper is crucial for true software supply chain security.\ \ sbom\ \ software bill of materials\ \ +3](/content/resources/videos/spotting-sbom-flaws/index.html)

• Software Supply Chain Security(22 Videos)

\ \ 1:49\ \ IoT Security Is Improving—but Risk Is Still Growing\ \ Despite real progress, the rapid growth of devices and threats is outpacing the industry’s ability to secure them. In this clip, Robert Kelley reflect...](/content/resources/videos/iot-security-is-improving-risk-is-still-growing/index.html)

\ \ 1:27\ \ IoT Security Advice: Assume Breach. Plan for What Comes Next.\ \ Stop assuming your device won’t be compromised & start planning for what happens when it is. Learn why defense in depth, credential revocation & real ...](/content/resources/videos/iot-security-advice-assume-breach-plan-for-what-comes-next/index.html)

\ \ 2:06\ \ Build for Failure, Not Perfection\ \ With new mandates like the EU RED and Cyber Resilience Act raising the bar, manufacturers must purpose-build devices with security in mind from day on...](/content/resources/videos/build-for-failure-not-perfection/index.html)

\ \ 0:48\ \ Why Cybersecurity Isn’t One-Size-Fits-All\ \ Security checklists might offer structure but rigid 1-size-fits-all approaches fall short. Cybersecurity must be context-driven not just compliance-dr...](/content/resources/videos/why-cybersecurity-isnt-one-size-fits-all/index.html)

\ \ 2:16\ \ The Hidden Risk in IoT: Insecure Cloud Connections\ \ Securing the device-to-cloud channel is vital to the trust model of connected systems. From rollback attacks and weak TLS to hardcoded tokens and deni...](/content/resources/videos/the-hidden-risk-in-iot-insecure-cloud-connections/index.html)

\ \ 0:28\ \ The Hidden Cost of Being First to Market\ \ In the push to be first, security often gets sidelined—leaving critical vulnerabilities behind.](/content/resources/videos/the-hidden-cost-of-being-first-to-market/index.html)

\ \ 2:18\ \ Top 3 IoT Security Gaps Today\ \ From development to deployment, critical security oversights still plague the IoT ecosystem. Hear why retrofitting security after launch is costly—and...](/content/resources/videos/top-3-iot-security-gaps-today/index.html)

\ \ 1:43\ \ Why Embedded Devices Struggle with Security\ \ Embedded devices operate under intense resource constraints—leaving little room for robust cybersecurity protections. In this clip, Robert Kelley unpa...](/content/resources/videos/why-embedded-devices-struggle-with-security/index.html)

\ \ 1:43\ \ Why So Many IoT Devices Remain Unpatched — Even with Secure OTA Updates\ \ Robert Kelley explains how inconsistent update practices and missing lifecycle guarantees leave IoT devices exposed—even as security matures.](/content/resources/videos/why-so-many-iot-devices-remain-unpatched/index.html)

\ \ 2:13\ \ Building Security Culture: Language, Mission, and Partnership\ \ Driving security across product teams starts with shared language, a customer-centric mission, and a partnership mindset—not policing.](/content/resources/videos/building-security-culture-language-mission-partnership/index.html)

\ \ 0:33\ \ Start Where You Are: The Journey Toward a Secure Product Lifecycle\ \ Perfect isn’t the goal—progress is. Discover why incremental improvements are key to maturing your product security posture and achieving compliance.](/content/resources/videos/secure-product-lifecycle-journey/index.html)

\ \ 0:46\ \ Component Aging: The Hidden Risk You Can Actually Control\ \ Proactively managing aging components can drastically reduce downstream risk and remediation effort. Here’s why it matters—and how to operationalize i...](/content/resources/videos/component-aging-hidden-risk/index.html)

\ \ 3:07\ \ Securing the Release: Pen Testing, Patch Management, and Compliance in Practice\ \ Explore practical best practices for secure releases, artifact distribution, and post-market operations aligned with global IoT security standards.](/content/resources/videos/securing-the-release/index.html)

\ \ 4:01\ \ Security by Design: Building Compliance Into Every Stage\ \ From planning and vendor assessments to secure builds and SBOM creation, see how to embed compliance into every phase of your product development life...](/content/resources/videos/security-by-design/index.html)

\ \ 2:49\ \ Modern IRT: Seeing the Unseen in Firmware with a Multi-Layered Security Approach\ \ Discover why modern incident response demands end-to-end visibility, scanning code, binaries, and firmware, to secure what’s often hidden in plain sig...\ \ supply chain\ \ software security\ \ +3](/content/resources/videos/modern-irt-seeing-the-unseen-in-firmware-with-a-multi-layered-security-approach/index.html)

\ \ Featured\ \ 2:37\ \ Modernizing Software Supply Chain Security\ \ Hear Roland's practical advice for product security leaders on modernizing supply chain security.\ \ supply chain\ \ software security\ \ +5](/content/resources/videos/modernizing-software-supply-chain-security/index.html)

\ \ 3:12\ \ Shifting Security Left Across Your Organization\ \ Learn how moving security earlier in development, integrating automation, and engaging more teams helps organizations transition from reactive complia...\ \ supply chain\ \ software security\ \ +3](/content/resources/videos/shifting-security-left-across-your-organization/index.html)

\ \ 5:34\ \ The Biggest Misconception in Supply Chain Security\ \ Learn why blaming upstream components isn’t enough and why owning security for all your product’s parts is critical to protect customers and your bran...\ \ supply chain\ \ software security\ \ +5](/content/resources/videos/the-biggest-misconception-in-supply-chain-security/index.html)

\ \ 3:10\ \ The Hidden Risk of Precompiled Binaries\ \ Discover why relying on vendor binaries leaves you blind and how binary analysis reveals what’s really inside to secure your products.\ \ supply chain\ \ software security\ \ +2](/content/resources/videos/the-hidden-risk-of-precompiled-binaries/index.html)

\ \ 3:39\ \ Untangling Supply Chains\ \ Explore how complex layers of open and closed source components create hidden supply chain risks and why visibility into every vendor’s dependencies m...\ \ supply chain\ \ software security\ \ +4](/content/resources/videos/untangling-supply-chains/index.html)

\ \ 2:17\ \ Zero Trust & IoT: Prepare for Breaches & Verify Everything\ \ Learn why breaches are inevitable—and how regular risk assessments and layered defenses are key to building zero trust security for IoT systems.\ \ supply chain\ \ software security\ \ +2](/content/resources/videos/zero-trust-iot-prepare-for-breaches-verify-everything/index.html)

\ \ 33:31\ \ Sans ICS 2022 Jason Ortiz Presentation - Finite State](/content/resources/videos/webinar-sans-ics-2022-product-security-meets-detection-and-response/index.html)

• Vulnerability Management(8 Videos)

\ \ 0:45\ \ How Silos Complicate Vulnerability and Compliance Management\ \ When engineering, security, and compliance teams don’t share a single source of truth, product security suffers. In this video, Mike Hatherall, Lead S...\ \ regulation](/content/resources/videos/how-silos-impact-vulnerability-compliance-management/index.html)

\ \ 2:56\ \ Most IoT Breaches Aren’t Zero-Days—They’re Trust Failures\ \ IoT devices often fail not from rare exploits but from trusting the wrong code, inputs, or components. Learn why securing your own code isn’t enough &...](/content/resources/videos/most-iot-breaches-are-trust-failures/index.html)

\ \ 1:37\ \ IoT Security Isn’t Just About the Device\ \ Real security means understanding the entire ecosystem—firmware, cloud APIs, mobile apps, local interfaces, and everything in between. Learn why you’r...](/content/resources/videos/iot-security-isnt-just-about-the-device/index.html)

\ \ 2:29\ \ When Should You Run a Pen Test? Here’s the Real Answer\ \ With regulations across industries like automotive & medical, regular pen testing, discover why ethical hackers are your best defense against real one...](/content/resources/videos/when-should-you-run-a-pen-test/index.html)

\ \ 4:30\ \ Risk-Based Security: How to Focus on What’s Real, Reachable, and Exploitable\ \ Not all vulnerabilities are created equal. See how KEVs, weaponized exploits, and reachability analysis can help you prioritize real-world risk.](/content/resources/videos/risk-based-security-how-to/index.html)

Privacy choices