Charles Marrow

Head of Center of Excellence - Embedded Device Security
@
IriusRisk

Professional Expertise & Experience

Charles Marrow is a cybersecurity professional and academic with global experience in the software and industrial automation industries. His deep expertise is focused on the complex security challenges of embedded, medical, and industrial IoT (IIoT) devices, a domain where security failures can have critical, real-world consequences.

During his tenure at IriusRisk, his work was centered on:

  • Operational Technology (OT) Security: Providing expert guidance on securing complex systems like Industrial Control Systems (ICS), the energy sector, and oil and gas infrastructure.
  • Embedded Device Security: He specialized in translating the unique security requirements of embedded devices into the threat modeling process.
  • Regulatory Compliance: He focused on the practical application of standards like IEC/ANSI 62443 to ensure critical systems achieve and maintain compliance.

Key Contributions and Achievements

Charles’s contributions have been foundational to IriusRisk’s authority in the OT security domain:

  • Framework Creation: He is the creator of the specialized EMB3D™ Threat Modeling Framework, a structured approach designed specifically to identify, evaluate, and mitigate vulnerabilities in embedded devices.
  • Industry Standards Leadership: He was instrumental in IriusRisk becoming a Technical Member of the ISA Security Compliance Institute (ISCI), actively contributing to the ISASecure Cybersecurity Conformance Scheme.
  • Published Works: He authored extensive technical content detailing the application of the IEC/ANSI 62443 standard to various components, including Medical Devices, OT Communications Protocols, and Hardware Security Requirements.
  • Academic Credentials: He holds an MSc in Cyber Security and continues to support research and teach Cyber Security subjects at Anglia Ruskin University, reinforcing his academic authority.

Blogs by

Charles Marrow

Threat Modeling
Risk Management
Operational technology
Elevating Embedded Device Security: The EMB3D™ Threat Modeling Framework
November 26, 2024
Compliance & Regulation
Threat Modeling
Threat modeling for IoT Devices and Gateways
September 3, 2024
Standards, Compliance and Regulations
Risk Management
Operational technology
IEC/ANSI 62443 Example 5 - Embedded Device Requirements
July 14, 2023
Standards, Compliance and Regulations
Threat Modeling
Operational technology
IEC 62443 Example 6 - Hardware Security Requirements
April 19, 2023
Software security
Threat Modeling
Embedded device security - A security feature gap analysis applying a threat modeling methodology. A guide for users of embedded devices.
November 3, 2022
News
IriusRisk becomes a Technical Member of ISA Security Compliance Institute (ISCI)
May 27, 2022
Standards, Compliance and Regulations
Threat Modeling
IEC/ANSI 62443 Example 4 - OT Communications Protocols
May 5, 2022
Standards, Compliance and Regulations
Software security
IEC/ANSI 62443 Example 3 Medical devices OT IoT Cloud Infrastructure
January 28, 2022
Standards, Compliance and Regulations
IEC/ANSI 62443 Example 2 - Motors Shaft and Panels
December 2, 2021
News
IEC/ANSI 62443 Example 1 - SL-A to SL-T Basic Component
November 19, 2021
Risk Management
Software security
Threat modeling the edge: Building security into industrial control systems
November 8, 2021