---
title: The Wretched State of OT Firmware Patching
description: Insights into the OT vulnerability research aDolus provided to the 2023 Microsoft Digital Defense Report.
image: https://blog.adolus.com/hubfs/negelct.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[Vulnerability Tracking](https://blog.adolus.com/tag/vulnerability-tracking)

# The Wretched State of OT Firmware Patching

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October, 11 2023

[Back](https://blog.adolus.com)

The Wretched State of OT Firmware Patching

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching> <http://www.facebook.com/share.php?u=https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching> [mailto:?subject=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching%20&body=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/negelct.png](mailto:?subject=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching%20&body=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/negelct.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching> <http://www.facebook.com/share.php?u=https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching> [mailto:?subject=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching%20&body=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/negelct.png](mailto:?subject=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching%20&body=Check%20out%20https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/negelct.png)

*This blog is a follow-up to our [first post on the 2023 Microsoft Digital Defense Report](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)where I described our collaboration with Microsoft on identified exploitable OT vulnerabilities.*

There is a saying in the IT world: patch early, patch often. It refers to the best practice of ensuring software is always running the latest version with the least number of bugs and vulnerabilities. 

It’s good advice in the IT world, but for OT it is often impossible. PLCs cannot just be turned off and patched when tons of logs are racing through a sawmill, dependent on those PLCs safely guiding their journey. Nor can the PLCs controlling the painting process be stopped while an automobile assembly line is still running. They’re not like executive laptops that can be rebooted at midnight when they need the latest Windows update. 

The need to ensure that an update will have no accidental impact on safety or production inevitably delays patching. Most guidelines for OT patch management suggest that companies push down patches to machines on a priority basis. This takes time: the pharmaceutical company AstraZeneca estimated back in 2006 that safe patching of OT systems requires [34 working days](https://www.tofinosecurity.com/blog/making-patching-work-scada-and-ics-security) from when the patch is first released to when the most mission-critical OT device is patched.

## Is that Patch Safety-Certified?

Another consideration that can limit timely updates are certifications. For example, a SIL Safety Certification is often required in situations where a PLC is controlling a hazardous process. Obtaining certifications is expensive so equipment manufacturers often don’t pursue certifications for every firmware version. Asset owners may thus need to skip some patches until the next certified version is available.

In reality, the patch cycle for OT devices can be years long for processes where high availability is critical. The costs involved in stopping are significant, so typically these patches are scheduled on an annual or biannual basis as part of a normal maintenance cycle.

Or at least they should be. 

## That Excuse Expired

What we discovered while digging into the distribution of firmware versions across Microsoft customers’ PLCs shocked me. Across various models of PLCs, **60% were running ancient firmware versions with 8 or more exploitable CVEs**. And even more astonishing, **updates have been available for over 10 years**!

Yes, there are more patching constraints in OT than in IT. But that excuse eventually expires.

## The Risk of Exploitable Vulnerabilities

[![MDDR Graph-1](https://blog.adolus.com/hs-fs/hubfs/MDDR%20Graph-1.png?width=397&height=396&name=MDDR%20Graph-1.png)](https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023)

Old firmware invariably means more CVEs, and the data bears that out. For example, firmware versions prior to 2012 had roughly 11 CVEs. But in 2012 a new version was released reducing the number of CVEs to around 2. Clearly the manufacturer invested the time and energy to eliminate vulnerabilities and improve the quality of their product. But that significantly lower-risk firmware was often never installed by the asset owners, even though it has been available since we all started dancing Gangnam Style.

Running firmware with 11 exploitable vulnerabilities introduces an unacceptable (and unnecessary) degree of risk. Yes, many old PLCs use inherently weak communications protocols (as Dale Peterson says, “Insecure By Design” protocols), but that has improved significantly over the past decade. Now most PLCs offer a secure communication option, but that is available only if you install the current firmware version. 

## The Reasons for Delinquent Patch Management

So why are control engineers not updating their firmware? It seems to be more of a people problem than a technical problem given the availability of the patches. I think these are the most likely culprits:

- An “if it ain't broke, don’t fix it” philosophy
- Lack of awareness
- Procrastination

## The Low-Hanging Fruit

The upside to our findings is that many asset owners can realize a significant reduction in risk by patching their devices.

Through our research with Microsoft, we determined that if operators updated their firmware to the latest version, the number of devices free of exploitable CVEs would increase from 4% to 40%. This is a significant improvement, but there’s still plenty of risk in the remaining vulnerable devices. To quote the sage philosopher Jon Bon Jovi, “Whoa, we're halfway there, Whoa oh, livin' on a prayer.”

Here’s another way to look at the impact of updating those PLCs to the latest version: asset owners could reduce the percentage of the devices with more than 8 exploitable CVEs down to only 18%. Again, that’s still a lot of vulnerable PLCs on the OT network, but the goal should be improvement rather than perfection.

If, for whatever reason, OT asset owners choose to remain using ancient firmware, they can at least look at hardening configuration settings or using compensating controls (I wrote about this a decade ago  - check out [Solving the ICS Security Patch Problem](https://scadahacker.com/library/Documents/White_Papers/Tofino%20-%20Solving%20the%20ICS%20Security%20Patch%20Problem.pdf)). Of course, perhaps the owners of those unpatched PLC had applied compensating controls to protect their systems from all those vulnerabilities, but I doubt it. In most cases deploying and maintaining compensating controls takes far more effort than installing patches. 

The research we did with Microsoft shows that far too many asset owners have leaned into the “we can’t patch this OT asset” excuse for far too long.

Microsoft’s key takeaway from the research was that *having visibility into OT assets, patch levels, vulnerabilities, and availability of updates is an important part of a comprehensive OT risk management program.*

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/eu-cra-clears-penultimate-step)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/hubfs/Imported_Blog_Media/NERC-CIPC-Training-Session-1024x451.jpeg)](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 3 min read

##### [3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on April 21, 2020

Earlier this month, as the coronavirus accelerated its alarming sprint across North America, NERC requested that...

[Continue Reading](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

[![Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 3 min read

##### [Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 26, 2019

Earlier this year I attended the Public Safety Canada Industrial Control System Security symposium in Charlottetown,...

[Continue Reading](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

[![How Russia Might Come After the West](https://blog.adolus.com/hubfs/russian-gas-pump-cyberattack-900x525.png)](https://blog.adolus.com/how-russia-might-come-after-the-west)

 2 min read

##### [How Russia Might Come After the West](https://blog.adolus.com/how-russia-might-come-after-the-west)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on February 25, 2022

The DDoS attack surge that began last week against Ukrainian government agencies and banks was a bad sign. I was...

[Continue Reading](https://blog.adolus.com/how-russia-might-come-after-the-west)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

 6 min read

##### [Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

 By [Marcello Delcaro](https://blog.adolus.com/author/marcello-delcaro) on May 1, 2024

In the cybersecurity world, anticipation and rapid response are crucial in safeguarding against emerging threats....

[Continue Reading](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/hubfs/Timeline-thumbnail.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 4 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 14, 2021

Late Wednesday night President Biden signed the Executive Order on Improving the Nation’s Cybersecurity. Compared to...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/hubfs/Timeline-thumbnail2.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 3 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 18, 2021

Removing Barriers to Sharing Threat Information On Friday we dissected Section 4: Enhancing Software Supply Chain...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

[![A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/hubfs/Regulatory%20Action.png)](https://blog.adolus.com/a-flurry-of-regulatory-action)

 5 min read

##### [A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/a-flurry-of-regulatory-action)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a...

[Continue Reading](https://blog.adolus.com/a-flurry-of-regulatory-action)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 5 min read

##### [EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 8, 2023

On December 3rd, the EU's new Cyber Resilience Act (CRA) got a big step closer to being adopted when the European...

[Continue Reading](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/hubfs/Mark-Weatherford-Appointment.png)](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 2 min read

##### [aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 23, 2021

Cybersecurity veteran tapped to accelerate growth of ICS supply chain security leader VICTORIA, BC, CANADA, June 23 -- ...

[Continue Reading](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

[![NTIA Publishes Minimum Components of an SBOM](https://blog.adolus.com/hubfs/Main-SBOM-image.png)](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

 4 min read

##### [NTIA Publishes Minimum Components of an SBOM](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on July 15, 2021

In today’s blog post I’d like to recognize all the hard work done by NTIA (National Telecommunications and Information...

[Continue Reading](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)