Back to Cybersecurity Under Pressure. Real Attacks, Real Lessons

Podcast Episode

Supported Hardware, Vulnerable Software: The Hidden Lifecycle Risk in Industrial Firewalls

About this episode

An industrial firewall can remain fully supported as hardware while carrying software risk inherited from another supplier. In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine the vulnerabilities affecting Fortinet software hosted within Siemens RUGGEDCOM industrial hardware — and the broader assurance problem exposed by that combination. The Technical Breakdown moves beyond the vulnerability list to examine the asset itself. An industrial security appliance is not governed by a single lifecycle. The hardware platform has one. The hosted security software has another. Its dependencies may follow additional timelines, support models and remediation processes. That means a supported product can still contain a vulnerable component. The challenge for asset owners is not simply identifying the affected version and installing an update. They must first understand what software is actually running inside the appliance, which supplier controls each layer and whether the supported remediation path can be implemented safely in the operational environment. The Operational Decisions explore where a technically straightforward update collides with industrial reality: restricted maintenance windows, production availability, legacy dependencies, vendor coordination and the need to validate the combined system after a change. In The Pressure Test, you are the operational security lead responsible for a critical, high-value manufacturing ICS environment. A security appliance intended to protect the plant is itself exposed. You must decide whether to update, isolate or continue operating while evidence, time and operational flexibility remain limited. The key lesson is that operational resilience requires visibility into the nested software inside industrial hardware. Product names and hardware support dates are not enough. Organisations need lifecycle intelligence across every software layer capable of changing the risk of the deployed asset. Because an industrial firewall is only as supportable as the software stack operating inside it. Thanks for listening to Cybersecurity Under Pressure. Follow the show for more real attacks, technical breakdowns and practical lessons for cybersecurity leaders. Explore all episodes and resources:https://cybersecurityunderpressure.com/episodes