Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT security engineering

Secure firmware update

Also known as: Secure firmware upgrade

German: Sichere Firmwareaktualisierung

In embedded security, a secure firmware update is the process of installing new firmware on a device such that only authentic, unaltered and authorized firmware is accepted, typically by verifying a digital signature, protecting against downgrades to vulnerable versions and preserving a working state if the update fails.

  • Security engineering
  • OT security

In one sentence

A secure firmware update installs only authentic, unaltered, authorized firmware, with signature checks, downgrade protection and failure recovery.

Example

A safety relay module checks the signature of the new firmware, refuses an older version with a known vulnerability and falls back to the previous image when the transfer is interrupted.

How it applies

  • Product development: Typical mechanisms are signed images, verification before activation, anti-rollback counters that block downgrades to vulnerable versions, dual image banks for recovery and authorization checks for who may start the update.
  • Operation: Firmware updates on controllers usually require a stop. Plan them with production, and check whether the update affects certified or validated functions.
  • Safety: For safety-related devices, the manufacturer should state whether an update changes safety functions or their parameters and what verification the user must perform afterward. Changes may need to go through change control and revalidation.
  • Documentation: Update instructions must include prerequisites (versions, tools, backups), the verification of the result, behavior on failure and whether the update can be reversed. Release notes should list security fixes with CVE IDs.

Secure firmware update vs. rollback

Downgrade protection prevents installing an older, vulnerable version. Rollback capability restores the previous version after a failed or faulty update. Designs must allow safe rollback without reopening known vulnerabilities.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on IEC 62443-4-2 and embedded security practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!