---
title: Building (or Losing) Trust in our Software Supply Chain
description: Building (or Losing) Trust in our Software Supply Chain
image: https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[Dragonfly](https://blog.adolus.com/tag/dragonfly) [chain of trust](https://blog.adolus.com/tag/chain-of-trust) [ICS](https://blog.adolus.com/tag/ics) [malware](https://blog.adolus.com/tag/malware) [pharmaceutical](https://blog.adolus.com/tag/pharmaceutical) [Havex](https://blog.adolus.com/tag/havex) [industrial control system](https://blog.adolus.com/tag/industrial-control-system) [Trojan](https://blog.adolus.com/tag/trojan) [energy](https://blog.adolus.com/tag/energy) [Supply Chain Management](https://blog.adolus.com/tag/supply-chain)

# Building (or Losing) Trust in our Software Supply Chain

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May, 10 2018

[Back](https://blog.adolus.com)

Building (or Losing) Trust in our Software Supply Chain

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain> <http://www.facebook.com/share.php?u=https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain> [mailto:?subject=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain%20&body=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png](mailto:?subject=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain%20&body=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain> <http://www.facebook.com/share.php?u=https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain> [mailto:?subject=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain%20&body=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png](mailto:?subject=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain%20&body=Check%20out%20https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)

Back in 2014, when I was managing [Tofino Security](http://www.tofinosecurity.com/), I became very interested in the Dragonfly attacks against industrial control systems (ICS). I was particularly fascinated with the ways that the attackers exploited the trust between ICS suppliers and their customers. Frankly, this scared me because, as I will explain, I knew that all the firewalls, antivirus, whitelisting, and patching in the world would do little to protect us from this threat.

If you are not familiar with the [Dragonfly attacks](http://www.belden.com/blog/industrial-security/how-dragonfly-hackers-and-rat-malware-threaten-ics-security), they were launched against the pharmaceutical industry (and likely the energy industry) in 2013 and 2014. The attacks actually started in early 2013 with a spear phishing campaign against company executives. But the part that concerned me began later, starting in June 2013 and ending in April 2014.

During that period, the Dragonfly attackers penetrated the websites of three ICS vendors: vendors who supply hardware and software to the industrial market. Once the bad guys controlled these websites, they replaced the vendors’ legitimate software/firmware packages with new packages that had Trojan malware called[Havex](http://www.netresec.com/?page=Blog&month=2014-10&post=Full-Disclosure-of-Havex-Trojans) embedded in them (Attack Stage #1).

When the vendors’ customers went to these websites they would see that there was a new version of software for their ICS products. They would then download these infected packages, believing them to be valid updates (Attack Stage #2). And because one of the messages we give in the security world is to “keep your systems patched,” these users pushed out the evil updates to the control systems in their plants (Attack Stage #3).

Once these systems were infected, the Havex malware would call back to the hacker’s command and control center, informing the attackers that they had penetrated deep into a control system. The attackers then downloaded tools for ICS reconnaissance and manipulation into the infected ICS hardware (Attack Stage #4). These new attack tools focused on the protocols we all know well in the ICS world, such as Modbus, OPC, and Ethernet/IP.

As far as we know, the attackers were most interested in stealing industrial intellectual property — not destroying equipment or endangering lives. However, there was nothing that would have restricted the attackers to just information theft. Their tool sets were extremely flexible and could have easily included software that would manipulate or destroy a process.

The Dragonfly attacks were particularly insidious because they took advantage of the trust between suppliers and end users. The engineers and technicians in industrial plants inherently trust their suppliers to provide safe, secure, and reliable software. By downloading software and installing it, the Dragonfly victims were doing what they had been told would improve their plant’s security. In effect, these users were unwittingly helping the attackers bypass all the firewalls, circumvent any whitelisting or malware detection, and go directly to the critical control systems.

This is what I call “Exploiting the Supplier-User Trust Chain” — and I think it is one of the most serious security risks facing our world today. It is not only a problem for ICS-focused industries like energy or manufacturing, but also for any person or company that uses “smart “ devices... which is pretty well all of us. Aircraft, automobiles, and medical devices are all susceptible to this sort of attack.

So with the help of [Billy Rios](https://www.linkedin.com/in/billyrios/), [Dr. Jonathan Butts](https://www.linkedin.com/in/jonathan-butts-ph-d-68407564/) , a great team of researchers, and the[DHS Silicon Valley Initiatives Program](https://www.dhs.gov/science-and-technology/svip), I’ve been working on finding a solution to the Chain-of-Trust challenge. aDolus and FACTTM (Framework for Analysis and Coordinated Trust) are the result of 1000s of hours of our systematic investigation into the problem and its possible solutions. Join me on this blog over the next few months as I share what we have learned and where we still have to go to ensure trust in our software.

For more on Dragonfly:

- How Dragonfly Hackers and RAT Malware Threaten ICS Security, Belden Inc., September 15, 2014
- [The Impact of Dragonfly Malware on Industrial Control Systems](https://www.sans.org/reading-room/whitepapers/ICS/impact-dragonfly-malware-industrial-control-systems-36672), SANS Institute Reading Room, January 18,  2016
- [Dragonfly (Security Response)](https://docs.broadcom.com/doc/dragonfly_threat_against_western_energy_suppliers) — Version 1.0 - published by Symantec June 30, 2014
- [Havex Hunts for ICS/SCADA Systems](http://www.f-secure.com/weblog/archives/00002718.html) — published by F-Secure June 23, 2014

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 2 min read

##### [Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 15, 2021

Seasoned financial and advisory executive to drive growth VICTORIA, BC, CANADA, June 15, 2021 /EINPresswire.com/ -- ...

[Continue Reading](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/hubfs/Unsolicited-Response-Eric-and-Dale.png)](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 2 min read

##### [Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 7, 2021

Wrapping up my year on December 31, I was delighted to join ICS cybersecurity luminary Dale Peterson for his December:...

[Continue Reading](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

[![aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/hubfs/newventuresbc_social-media-banner-1.png)](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 2 min read

##### [aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on December 1, 2020

aDolus Technology Inc. bested 240 of BC’s most innovative tech startups, winning the New Ventures contest in Canada’s...

[Continue Reading](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

[![aDolus Technology Selected as One of 2020’s Top 10 Startups](https://blog.adolus.com/hubfs/NVBC-Top10-small.png)](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

 2 min read

##### [aDolus Technology Selected as One of 2020’s Top 10 Startups](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on August 28, 2020

NANAIMO, BC, CANADA, August 27, 2020: aDolus Technology Inc., a global authority on software intelligence for critical...

[Continue Reading](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

[![Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/hubfs/Imported_Blog_Media/monsterUSB-e1536780548901.png)](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 3 min read

##### [Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 12, 2018

On 24 August 2018 Schneider Electric issued a security notification alerting users that the Communications and...

[Continue Reading](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 4 min read

##### [Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 18, 2020

Just in case you missed it, a software supply chain attack on the US government and industries is consuming the waking...

[Continue Reading](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness](https://blog.adolus.com/hubfs/Imported_Blog_Media/windows10-CVE-820x1024-1.png)](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness)

 3 min read

##### [Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 17, 2020

The announcement Tuesday from the NSA about the new cryptographic vulnerability in the Microsoft Windows operating...

[Continue Reading](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness)

[![ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/hubfs/Refirm-aDolus.png)](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 2 min read

##### [ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 3, 2020

aDolus Technology Inc., a global authority on software intelligence for critical infrastructure, and ReFirm Labs, a...

[Continue Reading](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

[![Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/hubfs/Verve-aDolus.png)](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 3 min read

##### [Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on February 4, 2021

Verve embeds aDolus’ ability to generate SBOMs and validate components aDolus Technology Inc., a global authority on...

[Continue Reading](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

[![Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/hubfs/Bayshore-aDolus.png)](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 3 min read

##### [Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on July 23, 2020

The aDolus FACT™ platform provides independent software update validation to ensure safe upgrades and a more secure...

[Continue Reading](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)