Finite State’s cover photo
Finite State

Finite State

Computer and Network Security

Columbus, Ohio 4,932 followers

AI-native product security for connected devices.

About us

Finite State empowers device OEMs to ship securely while enabling engineering teams to move at the speed of AI, immediately transforming product artifacts into audit-ready assurance through a single automated workflow. Leveraging deep binary analysis and AI-native execution, the platform unifies code, compiled components, and firmware in minutes—connecting security design with deployed software. By continuously generating SBOMs, VEX, and signed compliance packages, Finite State enables connected device companies across industries such as medical devices and automotive to meet evolving regulations, including the EU Cyber Resilience Act (CRA), and deliver continuous compliance at speed.

Website
https://www.finitestate.io
Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
Columbus, Ohio
Type
Privately Held
Founded
2017
Specialties
cybersecurity, iot, vulnerability research, risk management, ICS, Supply Chain Security, OT, and product security

Products

Locations

Employees at Finite State

Updates

  • A single hacked robot vacuum turned out to be a key to hundreds of thousands of others. A researcher found that one certificate pulled from a Shark vacuum could reach much of the fleet, exposing live camera feeds, home maps, and Wi-Fi passwords sitting in plaintext, with hundreds of thousands of devices reachable in a single cloud region. 🤖 Finite State's Edwin Shuttleworth reviewed the findings, and the takeaway for manufacturers is clear. The most serious vulnerabilities usually live in how a product's layers interact, so testing firmware, cloud permissions, or credential storage in isolation hides the real severity. No single flaw caused this one. A weakly protected device gave up its credentials, the cloud trusted them without checking what that device should actually be allowed to do, and unsafe command handling did the rest. Minor on their own, chained together they turned one vacuum into remote code execution across the fleet. See Edwin's analysis, via @ The IT Nerd: https://lnkd.in/eFq7_MWN #IoTSecurity #ProductSecurity #ConnectedDevices #Firmware #DeviceSecurity #Cybersecurity

    • No alternative text description for this image
  • View organization page for Finite State

    4,932 followers

    Can you spot the attack before operations are impacted? ⏳ Put your incident response skills to the test at the Factory Floor MVP Incident Response Challenge during DEF CON. 📍 AppSec Village™ 📅 Friday, Aug. 7 | 1:00 to 3:00 PM 📅 Saturday, Aug. 8 | 1:00 to 3:00 PM Investigate realistic attacks across OT, industrial control systems, and connected infrastructure in a hands-on team challenge designed for security practitioners. Afterward, stop by and meet the Finite State team to discuss modern product security and connected device risk. 👉 Learn more, reserve your spot, or schedule time with our team: https://bit.ly/3RAclia #DEFCON #AppSecVillage #ProductSecurity #IncidentResponse

  • View organization page for Finite State

    4,932 followers

    Black Hat USA returns with another week of cutting-edge research, practical insights, and collaboration across the global cybersecurity community. If you're attending, meet with the Finite State team to discuss how connected device manufacturers are strengthening product security while reducing manual effort and improving security outcomes. Let's talk about: 🔹Reachability-driven vulnerability prioritization. 🔹PSIRT workflows and rapid vulnerability response. 🔹SBOM and VEX lifecycle management. 🔹Threat modeling and security requirements traceability. 🔹Compliance automation and audit-ready security evidence. 🔹Release readiness and security gating. 🔹Managing product security across complex device portfolios. Whether you're focused on scaling product security operations or preparing for evolving regulatory requirements, we'd welcome the opportunity to connect. Schedule a meeting with our team: https://bit.ly/4f3T4gU #BlackHat #ProductSecurity #Cybersecurity #ConnectedDevices #SBOM #PSIRT #IoTSecurity #SoftwareSupplyChain #BHUSA

    • No alternative text description for this image
  • Strong product security starts with visibility across every release. One recent G2 reviewer shared: "I find Finite State's flexible scan engine lets us easily perform SAST/SCA/SBOM scans across our products." ✨ The reviewer also highlighted the platform's straightforward setup, responsive customer support, and team that is "always engaged and willing to help." Helping product security teams simplify software analysis while delivering the visibility needed to secure connected products is what we strive for every day. 🤝 Learn how Finite State helps connected device manufacturers strengthen product security: https://bit.ly/4vSaN10 #ProductSecurity #SAST #SCA #SBOM #ConnectedDevices #Cybersecurity #ApplicationSecurity

    • No alternative text description for this image
  • ✨ Employee Spotlight: Lindsay B. Every month we recognize someone who brings our company principles to life. This month, that person is Lindsay Bush from our sales team. Lindsay goes the extra mile not only for our customers, but also in supporting the growth of our team. She has a real impact on the people around her, whether she is supporting a customer or helping the team move something forward. The way she shows up, follows through, and delivers value has built a strong sense of trust across both customers and teammates. Lindsay, thank you for the care and commitment you bring to our customers and teammates. This is Customer First in action. 🙌 #EmployeeSpotlight #CustomerFirstInAction #FiniteState

    • No alternative text description for this image
  • View organization page for Finite State

    4,932 followers

    The future of product security is about to take another step forward. 🗓️ Save the date: August 25 at 2:00 PM ET Join us live for an important product release announcement in cybersecurity compliance. Watch for our LinkedIn Live event link next week! ✨

  • View organization page for Finite State

    4,932 followers

    Embedded and OT devices now stay in service for decades, and their software keeps aging into risk. Finite State CEO Matt Wyckhouse walks through why in eSecurity Planet. He points to three shifts that reshaped the risk around these systems: 🔌 They've become far more connected than they were ever designed to be. 🧩 Their open-source components have accumulated years of known vulnerabilities. 🎯 Attackers now single them out, since embedded systems tend to carry thinner defenses than enterprise IT. AI accelerates all of it, surfacing firmware weaknesses faster than before. But the harder problem is visibility. Most teams can't see the firmware or third-party libraries inside their deployed devices, and vendor SBOMs often miss what got compiled in. The binary itself is the only dependable source of truth, and reading it directly is what keeps long-lived devices manageable. Read the piece, reported by Ken Underhill for eSecurity Planet. https://bit.ly/4pwvcaJ #EmbeddedSecurity #OTSecurity #IoTSecurity #ProductSecurity #SBOM #FirmwareSecurity

    • No alternative text description for this image
  • View organization page for Finite State

    4,932 followers

    Attending DEF CON 2026? We're looking forward to connecting with the security community at @DEFCON DEF CON and contributing to the conversations shaping product security. Meet with the Finite State team to discuss practical strategies for securing connected products, reducing vulnerability noise, and building scalable, audit-ready product security programs. While you're there: 🔸 Hear our experts speak at IoT Village: Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM Speaker: Larry Pesce, VP of Services Date: Friday, August 7 Time: 12:30 PM – 1:15 PM Location: Stage 3, IoT Village AI Safety Theater: What the RAISE Act Regulates, and What It Does Not Speaker: Joshua Marpet, Senior Product Security Consultant Date: Saturday, August 8 Time: 5:00 PM – 5:30 PM Location: Creators Stage 1 🔸Join the Factory Floor MVP Incident Response Challenge at AppSec Village. 🔸Meet with our team to discuss vulnerability prioritization, PSIRT acceleration, SBOM management, and continuous compliance. Schedule a meeting at DEF CON: https://bit.ly/3RAclia #DEFCON #ProductSecurity #Cybersecurity #AppSecVillage #SBOM #IoTSecurity

  • View organization page for Finite State

    4,932 followers

    Russia's FSB has been breaking into U.S. critical infrastructure through poorly secured routers, using default passwords and known, unpatched flaws. 🛰️ NSA, CISA, the FBI, and allied agencies just issued a joint advisory warning that FSB Center 16 is compromising misconfigured routers across energy, healthcare, communications, financial services, government, and the defense industrial base. Their approach is old and low-tech. They scan for exposed devices, then log in with default credentials and exploit vulnerabilities that already have fixes. Finite State's Doc McConnell says it's the same pattern critical infrastructure has faced for over a decade. Nation-state actors keep succeeding through weaknesses the industry already knows how to close, like insecure protocols left running, default passwords, and management access nobody is monitoring. The mitigations are well understood. What most operators still lack is a current picture of which edge devices are exposed, what firmware they run, and which known vulnerabilities sit on them today. Doc's take and the advisory breakdown, reported by Anna Ribeiro for Industrial Cyber. https://bit.ly/4vT4TwL #CriticalInfrastructure #OTSecurity #ProductSecurity #Routers #CISA #Cybersecurity

    • No alternative text description for this image
  • Most product security teams I talk to have one CRA date circled: December 2027. ⭕ The one that should worry them is September 11, 2026. 👈 That's when the reporting obligation kicks in, and it applies to products already on the market. If you're pacing yourself toward full application, you've already missed the first real deadline. That's mistake one. Here are the other four I keep running into: 2. Building the SBOM from the build manifest instead of the binary. Your manifest tells you what you think you included. The binary tells you what actually shipped. Those two disagree more often than anyone wants to admit, especially once a third party has been anywhere near your supply chain. 3. Chasing CVE count like it's a score. "We drove open findings from 3,000 down to 2,000." Down from what, and reachable by whom? Without reachability context, you've spent real engineering hours moving a number that never measured risk in the first place. 4. Assuming compromise happens after you ship. A backdoored component. A poisoned build. A preinstalled bit of unwanted access. A lot of supply chain risk is baked in before the device ever leaves the factory. If your security program starts at deployment, you've skipped the part where the damage usually happens. 5. Writing the vulnerability disclosure policy and never staffing it. The CRA expects a real coordinated disclosure process with a real contact. A mailbox nobody reads is not a process. Tie them together and the theme is obvious. Every one of these mistakes comes from working off what you assume is in the product instead of what's verifiably there. Fix the visibility problem and four of the five solve themselves. Full breakdown in the video below: https://bit.ly/4yO617G #CRA #ProductSecurity #SBOM #SupplyChainSecurity #CyberResilienceAct

    • No alternative text description for this image

Similar pages

Browse jobs