PUBLISHER: VDC Research Group, Inc. | PRODUCT CODE: 1706272
PUBLISHER: VDC Research Group, Inc. | PRODUCT CODE: 1706272
Software DevSecOps, deployment, observability, and over-the-air (OTA) solutions are evolving to keep pace with the changing methods of building and releasing software for IoT devices and systems. As competition in IoT markets intensifies, developer organizations must accelerate the transition of software from development to deployment, automating as many processes as possible to achieve rapid time-to-market. Rising standards and regulations have shifted the responsibility for device security and health to manufacturers, creating a demand for robust commercial solutions that continuously monitor device fleets and provide ongoing software maintenance and updates.
This report explores and sizes the IoT market for software DevSecOps, deployment, observability, and OTA solutions. It discusses trends, vertical and regional markets, leading vendors, and provides selected insights from VDC Research's survey of embedded device engineers and developers.
|
|
|
As DevSecOps methodologies and continuous integration/continuous delivery (CI/CD) practices mature, developers integrate faster feedback loops into the earlier stages of the software and device development lifecycle, improving time to market, product quality, and software deployment in IoT. This blending of development processes is evident in the commercial market for deployment and maintenance solutions, where platforms now combine software testing with deployment features, offering developers a unified solution for automation across the design, build, test, and deploy phases.
DevSecOps observability enables teams to continuously monitor, measure, and analyze the health, performance, and security of applications and infrastructure throughout the software development lifecycle. It includes a combination of metrics, logs, and traces to provide insights into the system's operational and security aspects, allowing teams to detect issues early and respond quickly. The secure wireless distribution of software updates supports the continuous delivery aspect of the CI/CD pipeline.
OTA updates, initially introduced for mobile phones, expanded into the consumer electronics and automotive sectors. Vendors help fuel the wider adoption of updates by integrating OTA solutions across diverse IoT industries, offering both specialized solutions for specific applications and versatile platforms designed to serve multiple IoT market segments. The combination of regulations mandating the updatability of connected devices and the growing adoption of CI/CD and DevSecOps practices within development organizations is increasing the demand for commercial solutions to replace in-house developed alternatives.
Tied with cost sensitivity, ease of use ranks as the second-most important factor influencing the selection of OTA deployment solutions [See Exhibit 13]. The deployment of OTA update campaigns is oftentimes a very manual task, requiring engineers to weigh multiple factors including rollout timing, device downtime, and potential versioning issues. This is one area where AI-driven OTA campaigns and the pairing of monitoring solutions can introduce increased ease of use to OTA solutions. By intelligently connecting update campaigns to real-time device status and analytics, device manufacturers/fleet managers can minimize the potentially costly consequences of failed update campaigns. Vendor reputation noticeably ranks amongst the lowest purchasing decision factors, suggesting a yet-to-be-determined competitive positioning of embedded OTA solution vendors. This consumer sentiment offers a considerate opportunity for new entrants seeking to deliver OTA capabilities to embedded markets. For those seeking to enter or increase their positioning within this segment of the IoT, focus should be dedicated towards enabling seamless yet confident deployment capabilities, bolstered by real-time capabilities and insights into campaign rollouts.
As with many areas of the IoT, the impact of integrating OTA solutions into toolchains and software stacks remains the topmost priority for development organizations. Failed software deployments can not only cause monetary and opportunity costs in the form of patches and downtime but also increase the attack surface for exploitation. Furthermore, an insecure OTA solution can enable threat actors to deploy malware alongside software packages to devices. Other opportunities for exploitation within the deployment process include hijacking and interrupting updates mid-deployment, leading to corrupted devices and systems. Partnerships with IoT security vendors (e.g., public key infrastructure (PKI) vendors) offer one avenue for OTA solution providers to bolster the security of their solutions (such as those between Excelfore/IIJ Global, Karma Automotive (Airbiquity)/QNX, and Telit Cinterion/Thales).