---
title: Kaseya Supply Chain Attack on SMBs
description: Observations on Kaseya supply chain attack from Eric Byres and his recommendations on protecting your company from future attacks.
image: https://blog.adolus.com/hubfs/Dominoes2-1.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[#supplychainsecurity](https://blog.adolus.com/tag/supplychainsecurity)

# Kaseya Supply Chain Attack on SMBs

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on July, 6 2021

[Back](https://blog.adolus.com)

Kaseya Supply Chain Attack on SMBs

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs> <http://www.facebook.com/share.php?u=https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs> [mailto:?subject=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs%20&body=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs&media=https://f.hubspotusercontent40.net/hubfs/6687498/Dominoes2-1.png](mailto:?subject=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs%20&body=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs&media=https://f.hubspotusercontent40.net/hubfs/6687498/Dominoes2-1.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs> <http://www.facebook.com/share.php?u=https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs> [mailto:?subject=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs%20&body=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs&media=https://f.hubspotusercontent40.net/hubfs/6687498/Dominoes2-1.png](mailto:?subject=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs%20&body=Check%20out%20https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs&media=https://f.hubspotusercontent40.net/hubfs/6687498/Dominoes2-1.png)

Last week I participated in a panel discussion on the Executive Order’s Impact On Embedded Device Security hosted by [ISSSource.com](http://www.ISSSource.com). I signed off with a comment about my biggest worry: **someone will combine professional ransomware with a software supply chain attack to create a truly massive ransomware attack.**

Then, being a holiday here in Canada, I set off on a good long bike ride, unaware how prescient my remarks were. For that’s exactly what happened over the weekend, courtesy of the Russia-based hacking group REvil, which attacked the Florida-based software company Kaseya Ltd.

If you are not familiar with Kaseya, they provide network and security management services for small to medium-sized businesses (SMBs), not unlike what SolarWinds offers for large businesses. So this is yet another attack taking advantage of poor software security at companies that provide security management products and services. “Quis custodiet ipsos custodes?”[\*](https://blog.adolus.com/kaseya-supply-chain-attack-on-smbs#Latin-quote) 

I don't expect many major OT operators, like the big oil & gas companies, will be impacted. Similarly, US government agencies will probably be okay, unlike in the December [SolarWinds supply chain attack](https://blog.adolus.com/blog/three-things-the-solarwinds-supply-chain-attack-can-teach-us). However, this could be a real mess for the industries with lots of smaller operations, such as water utilities, smaller power utilities (like Munis), or the food and beverage industry.

In my experience, industrial SMBs often have a very decentralized security management strategy; that is, it’s every plant for itself when it comes to security. For example, just before the pandemic struck, I met with an OT security manager at a Fortune 500 food and beverage company and asked him what the software approval process was for OT systems at their company. The answer:

> "Each engineer or technician downloads the software they need for the PLCs they manage directly from the PLC vendors' websites. They then make their own decisions on whether they should install that software. There is no company-wide strategy to validate the safety or security of that software."

This approach is going to make Kaseya an issue for industrial SMBs for two reasons: 

1. SMBs often have very weak separation between IT and OT. In many cases, there is zero separation as the security team is simply too small to afford dedicated staff and services for OT. So any Kaseya problems in IT quickly become OT problems. 
2. The Kaseya product is really popular with managed service providers (MSPs) who use it to manage multiple clients' systems. Industrial SMBs often outsource their security (again, because building a full security team is too costly). These companies don't even know what software is being installed in their facility!  

As a result, the fan-out from this attack is going to be nasty and the true impact will trickle out in the weeks and months ahead. I saw the following statement from the cybersecurity firm Sophos:

> “At this time, our evidence shows that more than 70 managed service providers were impacted, resulting in more than 350 further impacted organizations,” CSO Ross McKerchar said in a statement. “We expect the full scope of victim organizations to be higher than what’s being reported by any individual security company.”

This “attack once, affect many” result is exactly why software supply chain attacks are on the rise. The ROI is just too attractive. And tracking down all the victims is difficult because it’s hard to tell how many branches there are in the tree.

Another complicating factor is that the victims were using Kaseya products as part of their cybersecurity toolkit. I read a great quote from a [Washington Post article](https://www.washingtonpost.com/business/on-small-business/mass-ransomware-hack-used-it-software-flaws-researchers-say/2021/07/04/70d87c44-dd3a-11eb-a27f-8b294930e95b_story.html) on Kaseya:

> “From a criminal standpoint it’s a brilliant supply-chain target to take away the tool that’s needed to recover from the threat,” Murray added. “They’re not only encrypting the systems but they’re also taking the recovery tool out of the equation.”

This is going to doubly affect industrial SMBs as many operators are unlikely to have the well-defined, well-tested recovery systems common in more high risk industries.

So what is a small or medium-sized enterprise to do to protect themselves against these supply chain attacks? The answer is simple: Don’t blindly have staff install patches and updates just because they are available.

Industry has become obsessed with deploying security patches rapidly and widely, but a well managed rollout strategy is a better idea. 

As far back as the mid-2000s, pharmaceutical companies published papers on how to use a staged rollout strategy to reduce the risk of patches on operational reliability. The figure below is an example from the pharmaceutical company AstraZeneca and shows the patch cycle for their systems. Note that none of the patching is performed in a rush – there is always a process to collect feedback from one stage before embarking on the next stage. You’ll also note that patches are initially trialed in isolated test environments *before* they are widely deployed across the facility or company.

![Astra-Zeneca Typical Active Patching Cycle](https://blog.adolus.com/hs-fs/hubfs/Astra-Zeneca_small_V1.png?width=520&name=Astra-Zeneca_small_V1.png)

*Source: Joakim Moby, AstraZeneca, ISA Expo 2006*

Of course, back in 2006 (or even 2016) the threat of supply chain attacks wasn’t on the security radar screen, so a critical stage is missing from many patch processes: the need to validate that the patch is both legitimate and current. Tools like FACT were designed specifically to make that initial step easy for all companies.

If you’d like to arrange a call for an overview of how FACT can help protect your company from a supply chain attack, click below and we'll set it up.

[![Arrange a Call](https://no-cache.hubspot.com/cta/default/6687498/66311c45-d683-4a80-9f7b-1cf4b01e7d7c.png)](https://cta-redirect.hubspot.com/cta/redirect/6687498/66311c45-d683-4a80-9f7b-1cf4b01e7d7c)

 

\* “Quis custodiet ipsos custodes?” is the question attributed to first century Roman satirist and poet Juvenal. “Who will guard the guards themselves” is the rough translation of the Latin phrase.

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/hubfs/Unsolicited-Response-Eric-and-Dale.png)](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 2 min read

##### [Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 7, 2021

Wrapping up my year on December 31, I was delighted to join ICS cybersecurity luminary Dale Peterson for his December:...

[Continue Reading](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 4 min read

##### [Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 18, 2020

Just in case you missed it, a software supply chain attack on the US government and industries is consuming the waking...

[Continue Reading](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 2 min read

##### [Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 15, 2021

Seasoned financial and advisory executive to drive growth VICTORIA, BC, CANADA, June 15, 2021 /EINPresswire.com/ -- ...

[Continue Reading](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![S4x23 SBOM Challenge — Part 3: VEX Document Ingestion](https://blog.adolus.com/hubfs/INL%20Presentation.png)](https://blog.adolus.com/s4x23-sbom-challenge-part-3)

 7 min read

##### [S4x23 SBOM Challenge — Part 3: VEX Document Ingestion](https://blog.adolus.com/s4x23-sbom-challenge-part-3)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on March 16, 2023

Three weeks ago I reported on the first part of the S4x23 SBOM Challenge run by Idaho National Laboratory (INL), which...

[Continue Reading](https://blog.adolus.com/s4x23-sbom-challenge-part-3)

[![Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/hubfs/Bayshore-aDolus.png)](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 3 min read

##### [Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on July 23, 2020

The aDolus FACT™ platform provides independent software update validation to ensure safe upgrades and a more secure...

[Continue Reading](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

[![Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/hubfs/Imported_Blog_Media/monsterUSB-e1536780548901.png)](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 3 min read

##### [Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 12, 2018

On 24 August 2018 Schneider Electric issued a security notification alerting users that the Communications and...

[Continue Reading](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

[![aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/hubfs/newventuresbc_social-media-banner-1.png)](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 2 min read

##### [aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on December 1, 2020

aDolus Technology Inc. bested 240 of BC’s most innovative tech startups, winning the New Ventures contest in Canada’s...

[Continue Reading](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

[![S4x23 SBOM Challenge — Part 1](https://blog.adolus.com/hubfs/SBOM%20Pavilion.png)](https://blog.adolus.com/s4x23-sbom-challenge-part-1)

 10 min read

##### [S4x23 SBOM Challenge — Part 1](https://blog.adolus.com/s4x23-sbom-challenge-part-1)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on February 24, 2023

The aDolus Team has just returned from participating in the SBOM Challenge at the S4x23 cybersecurity conference in...

[Continue Reading](https://blog.adolus.com/s4x23-sbom-challenge-part-1)

[![Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/hubfs/Verve-aDolus.png)](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 3 min read

##### [Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on February 4, 2021

Verve embeds aDolus’ ability to generate SBOMs and validate components aDolus Technology Inc., a global authority on...

[Continue Reading](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

[![Industrial Defender and aDolus Partner to Improve ICS Supply Chain Security](https://blog.adolus.com/hubfs/IndustrialDefender-aDolus-partnership.png)](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

 2 min read

##### [Industrial Defender and aDolus Partner to Improve ICS Supply Chain Security](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 19, 2021

Industrial Defender’s integration with the aDolus FACT™ platform ensures updates are valid, tamper-free, and safe to...

[Continue Reading](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)