Software development testing firm Coverity and embedded and mobile software firm Wind River have integrated Coverity's security development testing platform with Wind River's embedded software system. Software is spreading like the plague. It’s infecting phones, cars, household appliances, medical gear, office equipment and even TVs. And where software spreads — such as to Supervisory Control And Data Acquisition Systems (SCADA) — Internet connectivity is sure to follow.The challenge we’ve seen in recent years — even in highly controlled environments — is that these systems are susceptible to attack just as traditional applications are. This creates risk and opportunity. The risk is that critical systems will be found vulnerable, perhaps a Stuxnet-like attack strikes crucial systems in the U.S. or Europe. And therein resides the opportunity for security and software quality and assurance firms to reach a growing new market.Software development testing firm Coverity and embedded and mobile software firm Wind River have integrated Coverity’s security development testing platform with Wind River’s embedded software system. In addition, Coverity will provide an edition of Coverity Static Analysis, pre-configured for Wind River Workbench, which means it’ll support both Wind River Linux and Wind River’s VxWorks real-time operating system.The idea, explains Zack Samocha, senior director, product management at Coverity, is to provide a way for development teams to bring security into the actual embedded development process and squash security-related bugs as the code is being written. Samocha makes an argument that has been long held among software security and assurance vendors: that catching flaws early in the development process is more cost effective than letting them slip into production. “Development firms are always under pressure to produce, and get their products to market,” says Samocha. “This integration helps them to catch and fix security vulnerabilities quickly and early in the process, without slowing down development,” he says.Embedded developers are going to need all of the help they can get. VDC Research Group recently published a report that shows more than 50 percent of engineers who were surveyed expect the products they’ll be developing in two years will have web components. That’s a jump of 20 percent from current projects underway today. “Anyone who develops embedded systems should take a lesson from what happened with software and operating system vendors in the past decade: they became targets of both bad guys and security researchers who evaluated those systems for flaws,” says Pete Lindstrom, research director at Spire Security. “There’s no reason to believe SCADA and other embedded systems will be any different.”With that in mind, Coverty also recently announced the formation of its Coverity Security Research Laboratory. The Coverity lab will investigate the cause of both existing and new security related defects, Samocha says.George V. Hulme writes about security and technology from his home in Minneapolis. You can also find him tweeting about those topics on Twitter at @georgevhulme. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe