0
Your cart


TOTAL excl.
TOTAL incl.
Pay

Tuesday, October 6, 2026

How do we secure the security solution itself?

AUDIT
How do we secure the security solution itself?

An industrial site is deploying a detection solution to monitor its critical equipment in real time. On paper, this is good news: greater visibility and a faster response in case of an incident. But this solution also adds connected hardware and data streams to the industrial information system. Devices, communication buses, firmware, monitoring interface: each of these elements, if poorly secured, can in turn become an entry point for an attacker.

The question therefore deserves to be asked directly: who secures the security solutions?


An independent audit rather than simple trust


For a supplier, internal testing by the product team remains essential: it ensures that the solution meets its own requirements. However, it is not sufficient to objectively assess its security, as the tool's designer inevitably remains both judge and jury. It is precisely to address this limitation that AIoTrust, a publisher of connected devices dedicated to monitoring critical industrial equipment, called upon ACCEIS to audit its solution before any deployment in a sensitive environment.


An audit that doesn't stop at the software


In IT, cybersecurity auditing is a well-established practice. In OT, it's a different story: the assessment cannot be limited to software, it must also cover hardware, communication buses and embedded firmware, an area that few providers truly master.
In the AIoTrust case, ACCEIS intervened with a decidedly offensive approach, going beyond classic application testing, by positioning itself as the attacker across the entire chain:

• Case analysis: physical study of the hardware to identify access points and protection mechanisms.
• Study of communication buses: searching for vulnerabilities in the exchanges between components.
• Analysis of the embedded firmware: searching for vulnerabilities in the code that controls the device.

The objective: to identify potential weaknesses at each link in the chain: from the hardware, through the AIoTrust box and the supervision, to the industrial information system, and to accompany them with concrete recommendations.


Benefits on both sides


This approach benefits both the manufacturer and the solution provider.

For the manufacturer deploying the solution, the audit provides objective and independent information, a key factor in building trust before any integration into a critical environment. As Yves Duchesne, CEO of ACCEIS, summarizes, the security of a solution is no longer simply asserted, it is demonstrated, and this demonstration requires an external perspective, independent of the tool's designer.

For AIoTrust, the audit goes beyond a reassuring stamp of approval: the identified findings are already informing product development, in a logic of continuous security improvement. The solution is also continuing its path towards CSPN certification.


A requirement that is expected to become widespread


This type of approach is part of a broader regulatory trend. The NIS2 directive now explicitly integrates supply chain security into its cybersecurity risk management requirements. The Cyber Resilience Act goes even further, imposing cybersecurity obligations on connected hardware and software products, from their design to their maintenance. Having your solution assessed by an independent third party is therefore no longer just a best practice: it's a concrete response to requirements that are becoming increasingly formalized, sector by sector, in customer-supplier relationships.

In industry as elsewhere, the first risk would be to believe that a security tool is, by nature, secure.


See you at Lyon Cyber Expo

The ACCEIS and AIoTrust teams will be present on September 16 and 17, 2026 at the Lyon Convention Centre, on the occasion of Lyon Cyber Expo and SIDO, to discuss the cybersecurity challenges of industrial environments and the role of independent assessment in securing OT solutions.

Ce site utilise des cookies pour optimiser le fonctionnement de la plateforme et, mesurer et cibler nos campagnes publicitaires.