
Build secure embedded products you can justify and maintain
Learn how to build and harden an embedded Linux system, manage vulnerabilities and SBOMs, assess security risks, and audit a running system using the Yocto Project.
Five days of hands-on training for engineers working on real embedded products.
Currently open sessions:
October 12-23, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
November 2-6, 2026 – online, intensive session (5 days), in English. Ideal for participants around the CET time zone (Europe/Africa)
November 23-December 4, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
Price: 1350 EUR excluding VAT
Enrollment closes 7 days before the session start.
Embedded security is no longer just about fixing CVEs
If you maintain an embedded Linux product for years, you need to make security decisions throughout its lifetime.
- Which packages should be in your production image?
- Which services really need to run as root?
- Which vulnerabilities actually affect your product?
- What exactly is in your SBOM?
- How do you protect the boot chain?
- And can you explain and justify those decisions when someone asks?
The Cyber Resilience Act makes some of these questions increasingly important for products sold in Europe. But they are also simply part of building and maintaining secure embedded products.
This course gives embedded engineers the practical knowledge and tools to answer them.
What you will be able to do after the course
You will work on practical exercises using the latest Yocto Project LTS release, not just discuss security concepts in slides.
By the end of the course, you will be able to:
- audit an embedded Linux image and identify unnecessary packages, services and privileges;
- apply Linux hardening mechanisms appropriate to an embedded product;
- generate and investigate SBOMs and understand what they do and do not tell you about your system;
- investigate CVEs and determine whether reported vulnerabilities actually affect your product;
- perform a security risk assessment and use it to prioritize engineering work;
- understand and design a secure boot chain, from the bootloader to the operating system;
- connect technical security work with CRA requirements without turning engineering into a compliance exercise.
Is This Course Right For You?
This training is perfect for embedded developers, system architects, and project managers who want to transform. To make sure you’ll get the most value from this course, let’s have a look at what you’ll need:
Required Experience
Yocto Project Basics
- Building and customizing images
- Working with .bbappend files to modify recipes
- Running images using QEMU
- Basic layer management
Basic Unix/Linux Skills
- Perform basic file operations (modify, copy, move)
- Access remote systems using SSH
- Handle basic system troubleshooting
- Navigate the command line efficiently
Programming Basics
- Python (recommended)
- Shell scripting
- Other YP-supported languages
Required Equipment:
- A computer with Internet access allowing SSH and video conferencing (Jitsi)
- A camera (recommended) and a microphone for video conferences
Accessibility & Support:
We believe everyone should have the opportunity to join our course. If you have any disabilities or need special accommodations, please contact us before registration to discuss possible adaption of the course.
Currently open sessions:
October 12-23, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
November 2-6, 2026 – online, intensive session (5 days), in English. Ideal for participants around the CET time zone (Europe/Africa)
November 23-December 4, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
Enrollment closes 7 days before the session start.
How The Course Works
- 100% Online
The whole course runs online through SSH access. You can learn from home, office, or anywhere with the internet. Just log in and you’re ready to go.
- Course Cohorts
Our participants start all at the same day. You follow the path together using a shared chat (over Matrix) and daily video-conferences
- Your Dedicated Virtual Machine
We provide you with a dedicated remote virtual machine that’s yours throughout the course, so you’ll have a consistent, reliable workspace where your progress is saved and accessible 24/7.
- No Need to Set up Your Machine
Skip the tedious setup process. Your environment comes pre-configured with all the tools, software, and resources you’ll need. The moment you log in, you’re ready to start learning and practicing.
- Live Expert-Led Sessions
Join video calls 2 times each day where your instructor walks you through new topics. We’ll show you exactly how things work and share tips from our experience.
- Daily Live Q&A Sessions
Got stuck? Need help? Every day we’ll do a live Q&A session where you can ask any of your burning questions. We’re here to make sure you understand everything clearly.
- Project-Based Approach
You’ll work on real exercises, not just read or watch videos. Then you’ll practice what you learn right away so it really sticks and gives you confidence to immediately use it in your project.
- Support & Discussion Channels
Use our chat channels to talk with your teachers and other students. Share ideas, ask questions, or help others out. It’s like having a whole team supporting you as you learn.
Course Schedule (over 5 or 10 days)
Module 1: We’ll start the course by building your own custom image. You’ll learn how to configure specific image features, create your distribution, and set up security features from scratch. We’ll end the day by running Lynis to check your system’s security baseline and understand what it flags.
Module 2: The next day focuses on security maintenance. You’ll scan your distribution for CVEs, implement fixes, and learn how to handle security patches efficiently. We’ll also cover the critical process of updating distributions between LTS releases without breaking existing security measures.
Module 3: Next, we’ll show you how to generate an SBOM and find information inside. You’ll learn to parse and query SBOM data to track dependencies and potential vulnerabilities. Then we’ll strengthen your build process by tweaking compiler security flags for better protection.
Module 4: This day focuses on hardening the Linux kernel and the whole system. You’ll learn how to set up proper device permissions and make your services more secure by running them with limited privileges. These changes will help protect against common attacks.
Module 5: Finally, on the last day, we’ll wrap it up with practical security decisions. You’ll learn to choose the right packages for security, debug, and production builds, and test your system’s security using Kali Linux. We’ll end the course by looking at upcoming security regulations you need to know about.
Module 6: During the whole course, we will be building a simple risk assessment for a realistic, but theoretical project. You can build one for your own project in parallel.
Module 7: Also in parallel to the course, you explore secure boot techniques. We show them in a way that is useful both if you want to additionally harden the boot process, or if you decide to implement a complete secure boot.
Final Quiz: At the end of last module, you’ll have a chance to test your new skills with our certification quiz. Get at least 60% right and you’ll walk away with a certificate that shows you know how to build secure embedded systems, something that’ll definitely catch the eye of employers and clients.
Get Your Certificate Of Completion Complete the course requirements and prove your expertise: – Pass the final assessment with 60% or higher – Submit 90% of course exercises with passing grades – Get your certificate to showcase your new skills | ![]() |
Your Investment
To benefit best, reserve time in your schedule, adapted to your time zone and occupation – with one (semi-intensive) or two (intensive) sessions per day with the instructor.
Price in euros : 1620 euros with VAT (TTC)/1350 EUR without VAT (HT)
Price in US dollars : 1920 USD with VAT /1600 USD without VAT
VAT must be charged for individuals paying the course on their own, French companies, or companies outside France without valid VAT information.
Currently open sessions:
October 12-23, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
November 2-6, 2026 – online, intensive session (5 days), in English. Ideal for participants around the CET time zone (Europe/Africa)
November 23-December 4, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
Enrollment closes 7 days before the session start.
Take The Next Step To Better Secure Your Products
With rising IoT threats and tougher regulations with the CRA (Cyber Resilience Act), the question isn’t if you need these skills—it’s how soon you can get them. Each session fills up quickly as companies prioritize security training for their embedded teams. So don’t miss out!
Language: Training materials are in English. The course can be delivered on-demand in English, French, and Polish.
Our prices exclude VAT. Email us for a special offer for individuals paying the course on their own. VAT must be charged for French companies, or companies outside France without valid VAT information.
Sign Up Today & Claim The Bonuses
Embedded security is a fast-changing field. Because of that, everyone enrolled in the Embedded Security course will be invited to two additional webinars designed to keep you at the cutting edge of security developments.
Bonus #1: Yocto Project Security After Scarthgap
Get insider knowledge on the biggest YP security updates:
- Learn the revamped CVE-checking tools before your peers
- Discover the new SBOM generation features
- Be among the first to implement the latest security tooling
- Stay ahead of new vulnerabilities with updated techniques
Bonus #2: The Current State Of The Cyber Resilience Act
Gain essential insights for every embedded system developer (up to date as of December 2025 – and a new edition soon):
- Get practical guidance on the final CRA version, with the latest information
- Learn what regulatory changes mean for your projects
- Learn how to read specification drafts and how to use them even if you aren’t in the important/critical category
Need On-Demand Training Sessions?
We can organize on-demand (online or on your site) sessions. Contact us for details at contact@ygreky.com
Who Teaches This?
| Marta Rybczynska has PhD in network security, and 20 years of experience in Open Source including 15 in embedded development. She has been working with embedded operating systems like Linux and various real-time ones, system libraries and frameworks up to user interfaces. Her specialties are architecture-specific parts of the Linux kernel. In the last years, she focuses on improving security of Open Source products. She is a member of the Security Team of the Yocto Project. In the past, Marta served as Vice-President and treasurer for KDE e.V. She is involved in various Open Source projects, and also contributing kernel-related guest articles for LWN.net. She has experience with presentations on both scientific and free software conferences, including LinuxCon, Open Source Summit, Embedded Linux Conference, Akademy and FOSDEM. | ![]() |
Ygreky is a registred training organization under French law, registration number 84380947138 at préfet de région Auvergne-Rhône-Alpes.
Déclaration d’activité enregistrée sous le numéro 84380947138 auprès du préfet de région Auvergne-Rhône-Alpes.
Yocto Project and all related marks and logos are trademarks of The Linux Foundation. This training is not, in any way, endorsed by the Yocto Project or The Linux Foundation.
Currently open sessions:
October 12-23, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
November 2-6, 2026 – online, intensive session (5 days), in English. Ideal for participants around the CET time zone (Europe/Africa)
November 23-December 4, 2026 – online, semi-intensive session (10 half-days of work), in English. Ideal for participants around the CET time zone (Europe/Africa) afternoon or after work, and Americas (morning)
Enrollment closes 7 days before the session start.
Or: learn about new sessions when they open for enrollment!
Any further questions? Contact us at contact@ygreky.com


