Finite State: Rethinking connected device security for modern requirements

An Intellyx Brief from Black Hat 2026

Finite StateAs a fan of physical supply chains, device-level security isn’t something I get to cover as much as I would like; things never seem to change as quickly as they do for the rest of the software and infrastructure space. But the worm is turning now, with new US executive orders impacting FDA medical device security, and now the EU Cyber Resilience Act setting product security requirements way higher.

Finite State offers an agentic product security OS that automates security architecture discovery, testing, audits, reporting, and response remediation, as well as managed product security services, especially suited to connected device manufacturers in regulated industries that need to institute compliance programs.

Note that we’re not just talking about edge IT devices such as routers and transmitters here, or personal devices such as smartphones. There are consumer-grade and government-issue IoT and OT devices, everything from baby monitors, to medical devices, to connected cameras and smart cars that can contain hidden backdoors and accept unwanted network traffic.

Most organizations that produce devices have a very limited embedded security talent bench, or sometimes none at all, and because device endpoints are distributed, it can be hard to design and update systems. Finite state starts by scanning at the firmware layer, and expanding from there to look at all potential component and network interactions the device may be exposed to. Agentic automation and expert guidance helps these customers safely accelerate delivery and updates to meet ever-expanding safety requirements and regulations.

Hot take from the show: “There’s an arms race, because AI is getting really good at finding vulnerabilities, so we want AI to enable development teams to find them before attackers do. If you were just building web apps, you could cycle pretty fast, at DevOps speed, finding, fixing, and deploying patches,” says Matt Wyckhouse, CEO of FiniteState. “But if there’s a vulnerability on an iPhone for instance, Apple has to go find it, fix it, and test it in a lab to make sure the change doesn’t have unintended side effects such as draining more power or exposing a camera feed, and then it’s slow to ship updates out to everybody. Hardware is hard, right?” 

Copyright ©2026 Intellyx B.V. Intellyx is the change agent analyst firm focused on customer-driven, technology-empowered enterprise transformation. Our thought leadership distills insights across the rapidly evolving enterprise IT landscape, and our advisory helps you and your customers see through the hype and get beyond the fear of technology disruption to take action and realize value through change. At the time of writing, Finite State is not an Intellyx customer. No AI was used to write this article. To be considered for a Brain Candy article or have us visit you at an event, email us at pr@intellyx.com.

SHARE THIS:

Principal Analyst & CMO, Intellyx. Twitter: @bluefug