---
title: "Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates"
description: "Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates"
image: https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[Code Signing](https://blog.adolus.com/tag/code-signing) [Software Validation](https://blog.adolus.com/tag/sw-validation) [malware](https://blog.adolus.com/tag/malware)

# Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October, 8 2019

[Back](https://blog.adolus.com)

Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates> <http://www.facebook.com/share.php?u=https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates> [mailto:?subject=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates%20&body=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png](mailto:?subject=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates%20&body=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates> <http://www.facebook.com/share.php?u=https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates> [mailto:?subject=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates%20&body=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png](mailto:?subject=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates%20&body=Check%20out%20https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)

Eric Byres in Morocco

I’m writing this blog from Marrakech, a city in the western foothills of Morocco’s High Atlas Mountains. Marrakech has been a trading city since it was established by a clan of Berber warriors (the Almoravids) in the 11th century. The heart of the city (where Joann and I are staying) is the medina, a densely packed, walled medieval city with over 9000 maze-like alleys full of noisy, chaotic souks (marketplaces) that sell everything from traditional textiles, pottery, and jewelry to food and spices to motorcycle parts. There is probably nothing you can’t buy, either legal or illegal, in the Marrakech medina.

![Fakes and counterfeit handbags](https://blog.adolus.com/hs-fs/hubfs/Imported_Blog_Media/Fake-bags-225x300.png?width=225&name=Fake-bags-225x300.png)Like all unregulated marketplaces, the Marrakech medina has its share of fakes and counterfeits. Some are very obvious (Armani bags for $50), some are highly amusing (need an official Louis Vuitton football anyone?), and some are subtle. But the one fake that really interested me was counterfeit saffron.

If you aren’t familiar with [saffron](https://en.wikipedia.org/wiki/Saffron), it is a vivid crimson spice created by collecting the stigma and styles from crocus flowers. According to Wikipedia, saffron is the world's most costly spice by weight. I won’t disagree: the saffron we ended up buying in the medina cost $6 USD per gram, but we heard of some higher quality stuff selling for over 4 times that price.

Now, at those sorts of prices, it isn’t surprising that some crooked merchants might start making fake product to swindle the unsuspecting consumer. Joann and I wanted to learn a bit about both the real and the fake saffron, so we spoke to a reputable spice merchant in the souk. He showed us both the real and fake product and what he looks for when buying wholesale.

![Spices](https://blog.adolus.com/hs-fs/hubfs/Imported_Blog_Media/Joann-checking-out-spices-in-market-225x300.png?width=225&name=Joann-checking-out-spices-in-market-225x300.png)I won’t go into the details of selecting good authentic saffron in this blog, but the fake stuff fascinated me. While there are some good fakes that require pretty [sophisticated testing](https://youtu.be/LM_v4-QW4Lw), many fakes are easily spotted impostors. These are made by simply dying corn silk with either red food colouring or paprika. The tests to spot them are simple,[as this Youtube video shows.](https://youtu.be/inWOEPrMDDk)

This got me wondering: how can it be profitable to make and sell such poor quality fakes? After all, if one can detect them so easily after a few minutes of education, wouldn’t anyone selling these fakes be immediately discovered and never make a sale? (Or much worse: in Middle Ages, those found selling adulterated saffron were executed under the [Safranschou code](https://www.azafran.com/history.html).)

Sadly, there must be a large enough cohort of people (aka tourists?) that buy saffron without knowing the first thing about it. Or, to put it another way, clearly counterfeit saffron doesn’t need to be a quality imitation to be an effective scam, it just needs to be good enough to fool a person that lacks either the knowledge, time or incentive to perform the simple tests (such as a tourist in a rush to get back to a tour bus).

Later that night I realized that the cybersecurity world has been seeing this same situation playing out in the area of digital signatures for executable files (aka code signing). In 2017, Doowon Kim, Bum Jun Kwon, and Tudor Dumitraș at the University of Maryland published a paper investigating malware that carried digital signatures.

Some of the malware they investigated had been digitally signed with keys stolen from legitimate companies: [Stuxnet](https://en.wikipedia.org/wiki/Stuxnet) being the most famous example of this sort of trickery. In other cases, malware was signed using certificates that had been mistakenly issued to malicious actors impersonating legitimate companies. For example, in 2001 [VeriSign issued two code signing certificates with the common name of “Microsoft Corporation"](https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-017) to an adversary who claimed to be a Microsoft employee. Both of these types of exploits require a considerable amount of expertise and effort to carry out.

However, the authors discovered a third unbelievably simple exploit that accounted for almost one-third of the signed malware in the wild. In the words of the authors:

> *We find that simply copying an Authenticode signature from a legitimate file to a known malware sample may cause anti-virus products to stop detecting it, even though the signature is invalid, as it does not match the file digest. 34 anti-virus products are affected, and this type of abuse accounts for 31.1% of malware signatures in the wild.*

This is the digital equivalent of the border officer that lets you pass simply because you have a passport in your hand. Not taking the time to see if the passport actually belongs to you completely invalidates the integrity of the passport system.

Now, in all my travels, I’ve never actually seen a border officer do this. They are trained to follow the approved validation processes that ensure all but the most skillfully constructed fake passport is detected.

But, like saffron purchasers, much of the IT and OT world has been assuming that the mere existence of a digital signature is proof of that software being trustworthy. This is a terrible assumption that allows malicious actors an easy attack path. Unless we start to properly test software signatures, the bad guys will penetrate our systems just as quickly as the scam artist in the medina separates tourists and their money.

**For More Information:**

Doowon Kim, Bum Jun Kwon, and Tudor Dumitraș [Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKI](https://users.umiacs.umd.edu/~tdumitra/papers/CCS-2017.pdf), CCS '17 Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Pages 1435-1448, October 2017

**Watch how FACT handles code signing/certificate checking:**

[http://www.youtube.com/watch?v=EulV9sCL0FY](http://www.youtube.com/watch?v=EulV9sCL0FY)

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 3 min read

##### [Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 26, 2019

Earlier this year I attended the Public Safety Canada Industrial Control System Security symposium in Charlottetown,...

[Continue Reading](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

[![How Russia Might Come After the West](https://blog.adolus.com/hubfs/russian-gas-pump-cyberattack-900x525.png)](https://blog.adolus.com/how-russia-might-come-after-the-west)

 2 min read

##### [How Russia Might Come After the West](https://blog.adolus.com/how-russia-might-come-after-the-west)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on February 25, 2022

The DDoS attack surge that began last week against Ukrainian government agencies and banks was a bad sign. I was...

[Continue Reading](https://blog.adolus.com/how-russia-might-come-after-the-west)

[![3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/hubfs/Imported_Blog_Media/NERC-CIPC-Training-Session-1024x451.jpeg)](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 3 min read

##### [3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on April 21, 2020

Earlier this month, as the coronavirus accelerated its alarming sprint across North America, NERC requested that...

[Continue Reading](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 4 min read

##### [The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 11, 2023

This blog is a follow-up to our first post on the 2023 Microsoft Digital Defense Report where I described our...

[Continue Reading](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

 6 min read

##### [Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

 By [Marcello Delcaro](https://blog.adolus.com/author/marcello-delcaro) on May 1, 2024

In the cybersecurity world, anticipation and rapid response are crucial in safeguarding against emerging threats....

[Continue Reading](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/hubfs/Mark-Weatherford-Appointment.png)](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 2 min read

##### [aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 23, 2021

Cybersecurity veteran tapped to accelerate growth of ICS supply chain security leader VICTORIA, BC, CANADA, June 23 -- ...

[Continue Reading](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/hubfs/Timeline-thumbnail.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 4 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 14, 2021

Late Wednesday night President Biden signed the Executive Order on Improving the Nation’s Cybersecurity. Compared to...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 5 min read

##### [EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 8, 2023

On December 3rd, the EU's new Cyber Resilience Act (CRA) got a big step closer to being adopted when the European...

[Continue Reading](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/hubfs/Regulatory%20Action.png)](https://blog.adolus.com/a-flurry-of-regulatory-action)

 5 min read

##### [A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/a-flurry-of-regulatory-action)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a...

[Continue Reading](https://blog.adolus.com/a-flurry-of-regulatory-action)

[![Three Quick Takeaways from Biden’s National Cybersecurity Strategy](https://blog.adolus.com/hubfs/National%20Cybersecurity%20Strategy%20Carrot%20and%20Stick.png)](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

 2 min read

##### [Three Quick Takeaways from Biden’s National Cybersecurity Strategy](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on March 2, 2023

NOTE: We were going to publish our second blog of the S4x23 SBOM Challenge today. However, the new National...

[Continue Reading](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)