The 75 Billion Device Problem
Connected devices outnumber humans nearly 10 to 1. By 2025, 75 billion connected devices will be online against a world population of 8 billion. A new vulnerability surfaces every 30 minutes. That exposure is not theoretical: 91% of organizations suffered a software supply chain attack in the past year. The attack surface scales with adoption, and adoption has not slowed.
SBOM as the Missing Inventory
Third-party components are the blind spot. Organizations build on open-source libraries, embedded systems, and custom firmware without a complete list of what they contain. Each component is a potential entry point for exploited vulnerabilities or injected malicious code. By 2026, 60% of organizations will be required to provide SBOMs. Without one, there is no clear picture of what is running, let alone whether it is secure.
Three Regulations That Carry Real Penalties
The EU Cyber Resilience Act applies to anyone selling into the European market. Non-compliance means fines of 2.5% of global annual revenue or 16 million USD, whichever is higher. Executive Order 14028 covers US federal contractors, with loss of government contracts as the penalty. The FDA’s 524b guidance covers medical devices: one manufacturer shipped a device with a malfunctioning medication-dispensing button, triggered a recall, and lost US market access for a year.
Common Requirements Across All Regulations
No single global standard exists yet, but the same four requirements appear in almost every framework. Secure-by-design development, meaning security built in during design, not patched in after. An SBOM listing every component, the recipe for what the software contains. Continuous monitoring for new vulnerabilities, which appear on average every 30 minutes. A patching and disclosure process with timelines. NIST, ISO, and IEC frameworks give organizations a practical foundation for meeting these overlapping demands.
What to Do Now
Align with existing frameworks first: NIST, ISO, IEC. Invest in SBOM generation and vulnerability management tooling. Join working groups like CISA’s SBOM community or sector-specific ISACs to track what’s coming. Finite State’s platform embeds binary analysis and SCA into CI/CD pipelines, providing continuous monitoring and auto-remediation from development through deployment. The goal: a single view of every component across the product lifecycle, so nothing ships unexamined and nothing drifts unmonitored after release.
Notable Quotes
discovered on average every 30 minutes Andrea Zadro · ▶ Watch (3:04)
transparency it’s essentially a a recipe Andrea Zadro · ▶ Watch (8:00)
Flying Blind Andrea Zadro · ▶ Watch (4:28)
Key Takeaways
- 75 billion connected devices by 2025 creates an attack surface growing faster than existing defenses.
- Three major regulations now carry financial penalties for missing SBOM and continuous monitoring requirements.
- SBOM adoption, continuous monitoring, and a patch disclosure process form the shared baseline across every framework.