Exein's Photon Brings Runtime Security to AI-Native IoT Devices
Rome-based Exein launched Photon, a runtime security product that monitors firmware execution on embedded and AI-native IoT systems. The timing aligns with a 124% surge in IoT malware attacks and tightening EU device security mandates.
Exein targets embedded AI systems with Photon runtime security
Exein, a Rome-based IoT cybersecurity vendor, released Photon, a runtime security product designed to detect and block attacks during code execution on embedded and AI-native IoT devices. The product monitors firmware and operating system execution flows on constrained hardware, stopping anomalous behavior before it becomes an exploit.
The launch matters because most enterprise IoT security operates at the network layer—monitoring traffic, correlating device behavior, enforcing access policies—but remains blind to what happens inside the firmware itself. Photon shifts the interception point to the runtime environment, targeting devices running on-device machine learning inference where traditional network tools cannot see model tampering or malicious code injection.
Exein claims millions of devices already run its earlier security stack, primarily in automotive and industrial IoT. Photon extends that footprint to AI workloads, addressing a class of threats that emerged as manufacturers embedded inference engines into cameras, sensors, and controllers without hardening the execution path.
How runtime security changes the device security model
Photon competes with network-centric tools from Armis, Forescout, and SecuriThings, which provide visibility and policy enforcement but inspect devices externally. Silicon vendors like Qualcomm and Silicon Labs offer secure boot and trusted execution environments at the chip level, but these protect integrity at power-on, not during active operation.
Photon occupies the middle ground: runtime inspection on constrained devices, specifically tuned to detect threats against AI models or inference engines. If an attacker modifies a model or injects code during execution, Photon is designed to block it before the device processes malicious instructions.
The mechanism shifts budget allocation. Traditional IoT security spending concentrates on detection and response—network monitoring tools, SOC labor, incident response. Photon makes the case for prevention built into the device bill of materials, trading higher device CAPEX for lower OPEX from fewer incidents. For operators deploying tens of thousands of smart sensors or robotic controllers, this changes the cost structure.
Pricing is not yet public. Exein sells Photon through direct enterprise engagements and OEM agreements, which is standard for embedded security but limits price transparency during procurement.
Device Authority raises $7M for IoT identity management
Device Authority, an IoT-focused identity and access management vendor, closed a $7 million Series A funding round to expand its platform for device identity, certificate management, and automated policy enforcement. The product handles provisioning and lifecycle management of credentials and certificates for large fleets of industrial, medical, and smart city devices.
The funding is modest compared to general-purpose PKI vendors like Keyfactor or Venafi, but notable within the niche of IoT-only IAM. It indicates continued investor belief that generic X.509 certificate management and cloud IAM are insufficient for IoT deployments at scale.
The competitive context matters. Cloud providers offer device identity through AWS IoT Core and Azure IoT Hub, but require custom integration for complex PKI policies. Kigen recently highlighted GSMA eSA-certified eSIMs with security patching for IoT devices, raising the baseline expectation that device identity should root in hardware, not software certificates alone. Device Authority must show integration with secure elements, eSIMs, and hardware-rooted keys to compete.
For enterprise buyers, the funding signals improved scalability and integration support, making dedicated IoT IAM a realistic alternative to bolting IoT onto existing IT IAM tools. IoT malware attacks increased 124% globally in recent data, with many tied to weak or absent device authentication. Strong device identity enforcement reduces botnet recruitment risk and limits lateral movement from IoT to IT networks.
Regulatory timelines tighten budget and risk planning
The EU Cyber Resilience Act is shifting from policy to implementation. The regulation mandates secure-by-design and secure-by-default requirements for connected devices sold in the EU, with compliance timelines approaching. Buyers should ask device vendors whether they offer embedded runtime security, how runtime telemetry integrates with existing SIEM and SOAR tools, and what their roadmap is for meeting regulatory expectations.
The BadBox botnet, which compromised over 10 million devices by pre-infecting firmware at the supply chain level, demonstrates the risk Photon targets. Devices passed functional QA but shipped with exploitable runtimes. Runtime security addresses this by inspecting execution behavior after deployment, not just at power-on.
What changes in procurement
Enterprise buyers evaluating IoT deployments should now include three questions in RFPs:
1. Does the device vendor offer embedded runtime security, either Exein Photon or an equivalent product? 2. How does device identity and certificate lifecycle management integrate with existing PKI and IAM infrastructure? 3. What is the vendor's roadmap for compliance with EU and future U.S. device security regulations?
The shift is from treating IoT security as a network monitoring problem to treating it as a device integrity and identity problem. Budget planning should reflect higher per-device costs in exchange for lower incident response labor and reduced exposure to supply chain compromise. The absence of public pricing for both Photon and Device Authority's platform remains a friction point in procurement, requiring direct negotiation to model total cost of ownership.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
