Uploaded August 2026 | Updated September 2026, 2 hours ago
OROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find Vulnerabilities at Earlier Phases of Product Lifecycle
Yuki Osawa (Panasonic Holdings Corporation, JP), Chih-Hsiang Chang (Panasonic Cyber Security Lab, TW)
The concept of Shift Left for security testing at earlier phases of development, by enabling vulnerability assessments to be conducted by development teams, is one of the keys for product security management. We have developed a basic tool set for vulnerability assessments against an IoT device, designed for product development teams in Panasonic group. It aims for a ""pre-test, or a simple security assessment, at earlier phases of development"" to supplement the comprehensive assessments by the Product Security Center, the security team that conducts vulnerability assessments before product shipment groupwide. We designed the tool with the goal of enabling uniform testing quality no matter who uses it, so that development, test and quality assurance teams can play a part in the vulnerability assessment.
OROCHIFY is a framework for setting up, executing and managing third-party scanners including OSS and our proprietary scripts. Furthermore, OROCHIFY supports conformance checks for vulnerability assessment requirements under JC-STAR, a labeling scheme based on Japan's Cybersecurity Technical Assessment Requirements for IoT products, which was launched this year. In this session, we will share the experience achieved through trial and error during 6 years of OROCHIFY development, the features and demonstrations of the tools we have developed. In addition, we will explain why the tool's concept aligns well with JC-STAR.
---
Mr. Yuki Osawa is a member of Panasonic PSIRT and leads some R&D projects in IoT security. He started his career as a software engineer for the telecom network at NTT Comware Corporation. He worked for Hyogo prefectural government from 2005 to 2017 as an administrator of information systems. He was a member of CSIRT in Hyogo government. He received a master's degree in Information Technology - Information Security from Carnegie Mellon CyLab Japan in 2009. After joining Panasonic in 2017, he has focused on improving security for IoT, including Product security training for developers, IoT Threat intelligence and CTFs. He led Panasonic product security activities in the APAC region until 2022.
Chih-Hsiang Chang is the Technical lead at Panasonic Cyber Security Lab. He was a software engineer and transitioned into cybersecurity due to his passion for cybersecurity. After joining Panasonic, he focused on threat hunting and penetration testing. Chih-Hsiang Chang has a strong interest in the various attack techniques used in cybersecurity. He has obtained the OSCP certification and is constantly expanding his knowledge in the field. With his skills and expertise, Chih-Hsiang Chang is dedicated to ensuring that Panasonic's products remain secure and protected from potential threats.
OROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find Vulnerabilities at Earlier Phases of Product Lifecycle
Yuki Osawa (Panasonic Holdings Corporation, JP), Chih-Hsiang Chang (Panasonic Cyber Security Lab, TW)
The concept of Shift Left for security testing at earlier phases of development, by enabling vulnerability assessments to be conducted by development teams, is one of the keys for product security management. We have developed a basic tool set for vulnerability assessments against an IoT device, designed for product development teams in Panasonic group. It aims for a ""pre-test, or a simple security assessment, at earlier phases of development"" to supplement the comprehensive assessments by the Product Security Center, the security team that conducts vulnerability assessments before product shipment groupwide. We designed the tool with the goal of enabling uniform testing quality no matter who uses it, so that development, test and quality assurance teams can play a part in the vulnerability assessment.
OROCHIFY is a framework for setting up, executing and managing third-party scanners including OSS and our proprietary scripts. Furthermore, OROCHIFY supports conformance checks for vulnerability assessment requirements under JC-STAR, a labeling scheme based on Japan's Cybersecurity Technical Assessment Requirements for IoT products, which was launched this year. In this session, we will share the experience achieved through trial and error during 6 years of OROCHIFY development, the features and demonstrations of the tools we have developed. In addition, we will explain why the tool's concept aligns well with JC-STAR.
---
Mr. Yuki Osawa is a member of Panasonic PSIRT and leads some R&D projects in IoT security. He started his career as a software engineer for the telecom network at NTT Comware Corporation. He worked for Hyogo prefectural government from 2005 to 2017 as an administrator of information systems. He was a member of CSIRT in Hyogo government. He received a master's degree in Information Technology - Information Security from Carnegie Mellon CyLab Japan in 2009. After joining Panasonic in 2017, he has focused on improving security for IoT, including Product security training for developers, IoT Threat intelligence and CTFs. He led Panasonic product security activities in the APAC region until 2022.
Chih-Hsiang Chang is the Technical lead at Panasonic Cyber Security Lab. He was a software engineer and transitioned into cybersecurity due to his passion for cybersecurity. After joining Panasonic, he focused on threat hunting and penetration testing. Chih-Hsiang Chang has a strong interest in the various attack techniques used in cybersecurity. He has obtained the OSCP certification and is constantly expanding his knowledge in the field. With his skills and expertise, Chih-Hsiang Chang is dedicated to ensuring that Panasonic's products remain secure and protected from potential threats.










