CC Blog Editor's Letter Insights

Embedded Security Matters

Written by Curtis Franklin

When I started paying attention to the embedded systems world there were many factors that developers had to consider—physical form factor, I/O, how to shoehorn code into very limited on-board storage, and the like. Security was not, overall, something that made the list. Embedded systems were typically isolated and economically obscure, so they weren’t really worth the trouble to attack. Then came the Internet.

Over time, criminals, state actors, and mischief makers discovered embedded systems, most of which were just casually hanging out with their soft electronic underbellies exposed. The result was a growing swell of incidents ranging from state-sponsored destruction (Stuxnet, anyone?) to extortion (hello, Colonial Pipeline) to the sort of electronic vandalism that raises IT experts’ blood pressure but rarely makes the news.

For embedded control developers, it is well past time to put security on an equal footing with the other factors considered when building a system.

Meet the CIA Triad: The people who work in enterprise IT have a decades-long head start on securing the systems they design. There are several principles and factors considered in their work, but there’s a simple way to start thinking about security. Your systems need to be built around the CIA Triad.

The CIA Triad is quite simple. It says there are three things that must be protected in data and the system in which it lives: Confidentiality, Integrity, and Access.

When you break them down to their simplest statements these mean that only those who are supposed to have access to the system do; only those who are supposed to change the system can; and everyone who is supposed to have access to the system does. If you have ensured that each of those statements is true for the system you’ve designed and built, then congratulations—you have a secure system. The problem is that a host of devils lie within the details.

In upcoming issues of Circuit Cellar, we are going to provide articles that show how each of the CIA factors can be satisfied while keeping a project robust, cost-effective, and high-performance. We’ll look at the issues from the points of view of software developers, hardware builders, system architects, and others. And starting with this issue we’ll look at hardware that makes building more secure projects easier.

One of the accepted truths of security is that it is easier to build security into the system than to retro-fit security on top of an insecure project. We’ll look at why that is so, especially when it comes to embedded systems, but we’re also going to have projects that can help make older systems—deployed before security was acknowledged as a significant issue—more secure than they were the day they went live.

This Month’s Questions: So, how much do you think about security when you’re designing projects and solutions? Is it part of the foundation set of design parameters, or do you wait until everything is functional and then make it secure?
Oh, and one other thing: Do you listen to podcasts about electronics or subscribe to channels about electronics on YouTube? If you do, which ones? I’d love to know what I’m missing.

email: c.franklin@circuitcellar.com
LinkedIn: https://www.linkedin.com/in/curtisfranklin/
Facebook: https://www.facebook.com/curtis.f.franklin
Instagram: https://www.instagram.com/curt_franklin/
Mastodon: https://mastodon.sdf.org/@Kg4gwa
Bluesky: https://bsky.app/kg4gwa.bsky.social

Issue Table of Contents can be found here,
as articles are made available online they will be linked.

PUBLISHED IN CIRCUIT CELLAR MAGAZINE • September #422 – Get a PDF of the issue

Keep up-to-date with our FREE Weekly Newsletter!

Don't miss out on upcoming issues of Circuit Cellar.


Note: We’ve made the Dec 2022 issue of Circuit Cellar available as a free sample issue. In it, you’ll find a rich variety of the kinds of articles and information that exemplify a typical issue of the current magazine.

Would you like to write for Circuit Cellar? We are always accepting articles/posts from the technical community. Get in touch with us and let's discuss your ideas.

Editor-in-Chief at  |  + posts

Curtis Franklin has been a journalist working in the computer and technology fields for more than forty years. From his early career as a columnist at Computer Shopper and the founder of the BYTE Testing Lab, he has covered computing devices from handheld to supercomputing and applications from trivial to life-altering. In 1988, he was the first editor of an exciting startup publication that was then called Circuit Cellar INK. Since then, he has edited and written for publications including ComputerWorld, NetworkWorld, InfoWorld, InformationWeek, and Dark Reading. Most recently, he was Principal Analyst for Cybersecurity Management at Omdia.

Curtis co-wrote one of the first books on podcasting and has been a host or co-host on more than 500 episodes of various podcasts, including hundreds of episodes of This Week in Enterprise Technology, a production of the TWiT Podcast Network.

When not telling stories of computers and the people who make them, Curtis is an amateur radio operator (KG4GWA), an artist, and a Florida Master Naturalist. He’s also active in the maker community, working on the teams that produce Maker Faire Orlando and Maker Faire Miami.

Supporting Companies

Upcoming Events


Copyright © KCK Media Corp.
All Rights Reserved

Copyright © 2026 KCK Media Corp.

Embedded Security Matters

by Curtis Franklin time to read: 2 min