Guide · 7 min read
Device identity from manufacture to retirement
A practical architecture for provisioning, attestation, signed updates, recovery, and evidence across the life of a connected product.
Read the guideIdentify, update, isolate, and recover the systems you operate.
A device identity is useful when it survives the realities of manufacturing, deployment, maintenance, and incident response. These guides connect provisioning and attestation with the decisions to authorize, update, revoke, and retire a system.
Start with a question
Guide · 7 min read
A practical architecture for provisioning, attestation, signed updates, recovery, and evidence across the life of a connected product.
Read the guideField note · 5 min read
A proposed approval pattern that preserves a binding decision and the full review record for trust lists, signing releases, and other consequential changes.
Read the field noteGuide · 7 min read
Build certificate operations that can handle shorter lifetimes, changing trust policies, and the next algorithm transition.
Read the guidePractical guide · 6 min read
A practical operating model for secure releases, vulnerability response, and EU Cyber Resilience Act readiness.
Read the practical guidePractical guide · 5 min read
Build a decision around operating costs, required capabilities, and testable risk reduction. Make every assumption visible.
Read the practical guideOn Thursday, the FBI gave the water-sector cyberattack story its first national count. Utilities in at least seven states had reported incidents since July 27, and some had…
On December 29, 2025, while Poland endured sub-zero temperatures and snowstorms, attackers systematically compromised approximately 30 wind farms, solar installations, and…
On September 2, 2025, the Aisuru botnet launched a 29.7 terabits-per-second DDoS attack—shattering the previous 22.2 Tbps record set just three weeks earlier…