Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Secure boot

Also known as: Verified boot, Trusted boot

German: Sicherer Systemstart

In embedded and computer security, secure boot is a mechanism that verifies the digital signature of each piece of boot software, such as bootloader, firmware and operating system, before executing it, starting from a hardware root of trust, so that a device only runs software from an authorized publisher.

  • OT security

In one sentence

Secure boot verifies the signature of each boot stage from a hardware root of trust, so a device only runs software from an authorized publisher.

Example

A PLC with secure boot refuses to start a manipulated firmware image and instead remains in a safe diagnostic state with an error LED.

How it applies

  • Product development: Secure boot builds a chain of trust: immutable boot code verifies the bootloader, which verifies the firmware or operating system. It protects against persistent manipulation of device software. IEC 62443-4-2 includes requirements for verifying software integrity at boot for embedded devices at higher security levels.
  • Operation: Secure boot only protects if it is enabled and keys are managed. On industrial PCs, it is often a BIOS or UEFI setting that must be configured at commissioning.
  • Maintenance: Updates must be signed with keys the device trusts. Replacing a key or revoking a compromised one needs a planned process.
  • Documentation: Manuals should state whether secure boot is supported and enabled by default, how the device behaves when verification fails, and how service staff distinguish a boot failure caused by manipulation from a hardware fault.

Secure boot vs. signed update

A Signed update is checked when it is installed. Secure boot checks the software every time the device starts, so it also detects manipulation after installation.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on embedded security practice and IEC 62443-4-2

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!