Eric Byres

Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.
Eric Byres
Evolving Threats and Regulations in Software Supply Chain Security
13 min read
Evolving Threats and Regulations in Software Supply Chain Security
By Eric Byres on February 13, 2024

2023 is in the rearview mirror and 2024 is now well underway. I wanted to post my thoughts on some of the software supply chain trends we saw last year and how they will continue to shape...

Continue Reading
EU Cyber Resilience Act (CRA) Clears Penultimate Step
5 min read
EU Cyber Resilience Act (CRA) Clears Penultimate Step
By Eric Byres on December 8, 2023

On December 3rd, the EU's new Cyber Resilience Act (CRA) got a big step closer to being adopted when the European Parliament and the EU Council reached an agreement on the legislation. It...

Continue Reading
The Wretched State of OT Firmware Patching
4 min read
The Wretched State of OT Firmware Patching
By Eric Byres on October 11, 2023

This blog is a follow-up to our first post on the 2023 Microsoft Digital Defense Report where I described our collaboration with Microsoft on identified exploitable OT vulnerabilities.There...

Continue Reading
Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities
3 min read
Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities
By Eric Byres on October 5, 2023

Earlier this summer, aDolus collaborated with Microsoft on vulnerability analysis and contributed to their Microsoft Digital Defense Report 2023 (MDDR 2023). This report is a significant...

Continue Reading
Three Quick Takeaways from Biden’s National Cybersecurity Strategy
2 min read
Three Quick Takeaways from Biden’s National Cybersecurity Strategy
By Eric Byres on March 2, 2023

NOTE: We were going to publish our second blog of the S4x23 SBOM Challenge today. However, the new National Cybersecurity Strategy was released this morning, and we thought that...

Continue Reading
A Flurry of Regulatory Action and the Need for SBOMs
5 min read
A Flurry of Regulatory Action and the Need for SBOMs
By Eric Byres on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a series of regulatory initiatives that government agencies (and anyone...

Continue Reading
How Russia Might Come After the West
2 min read
How Russia Might Come After the West
By Eric Byres on February 25, 2022

The DDoS attack surge that began last week against Ukrainian government agencies and banks was a bad sign. I was actually preparing a post and wondering if it was appropriate to call out...

Continue Reading
Sorry Blackberry: You Are Part of the Supply Chain
2 min read
Sorry Blackberry: You Are Part of the Supply Chain
By Eric Byres on November 2, 2021

Today, reporters Betsy Woodruff Swan and Eric Geller at Politico published a story: “BlackBerry resisted announcing major flaw in software powering cars, hospital equipment.” They outline...

Continue Reading
Kaseya Supply Chain Attack on SMBs
4 min read
Kaseya Supply Chain Attack on SMBs
By Eric Byres on July 6, 2021

Last week I participated in a panel discussion on the Executive Order’s Impact On Embedded Device Security hosted by ISSSource.com. I signed off with a comment about my biggest worry: ...

Continue Reading
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4
5 min read
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4
By Eric Byres on May 26, 2021

Section 3 - Less Fog, More Cloud Section 3: Modernizing Federal Government Cybersecurity of the Executive Order is all about government agencies moving to the cloud and doing it right. If...

Continue Reading
Loading more posts
No more posts to load
1 2 3

Stay up to date