Finite State wins industrial IoT award

Finite State has won the 2026 IoThinkTank industrial IoT award for its Product Security OS.

The AI-native platform helps connected-device organisations continuously understand, prioritise and manage firmware and embedded software risk, including the long-lived operational environments that define industrial systems.

Finite State was recognised for a practical, scalable approach to securing the embedded software, connected devices, industrial control systems and operational technology that must run reliably for decades.

As software grows more deeply embedded across manufacturing, energy, logistics and critical infrastructure, visibility into deployed firmware and software components has become essential to keeping operations secure and compliant.

The Product Security OS provides deep visibility into firmware and embedded software through binary analysis, software composition analysis, reachability intelligence, vulnerability prioritisation, compliance workflows and automated security reporting.

Rather than relying on vendor documentation or manually maintained inventories, the platform analyses deployed firmware directly to identify software components, hidden dependencies, vulnerabilities and operational risk. Beyond detection, Finite State connects that analysis to engineering, operations and compliance, keeping what is designed, deployed and operating in the field in alignment.

Finite State’s measurable results include: 90% reduction in vulnerability triage noise through reachability analysis; more than 4.4 million unreachable findings eliminated across analysed firmware environments since 2024; analysis times reduced from over four hours to less than one hour; and 22-times growth in monthly scans since 2024 as organisations adopted continuous monitoring approaches.

“Industrial organisations are increasingly dependent on software running inside connected assets that often remain deployed for decades,” said Jordan Hayes, coordinator of the IoThinkTank Awards (www.iothinktank.com). “Finite State stood out for helping operators understand what is actually running inside those systems, prioritise the risks that matter most and maintain continuous assurance without disrupting operations.”

Product Security OS (finitestate.io/platform) helps industrial organisations continuously monitor software changes, newly disclosed vulnerabilities and operational risk across connected environments. It generates audit-ready outputs, including software bills of materials (SBoMs), vulnerability exploitability exchange (VEX) documents, and compliance reports for ongoing governance and risk management.

AgentOS, the automation engine inside Product Security OS, cuts manual effort by automating vulnerability triage, risk prioritisation and compliance evidence, helping teams make faster decisions without slowing operations.

“Connected devices now run for decades in environments that can’t be taken offline, which turns product security into a continuous engineering discipline rather than a periodic audit,” said Matt Wyckhouse, CEO of Finite State (finitestate.io). “We’re proud to be recognised for helping the teams behind those products keep up, with security they can actually prove.”