---
title: Three Things the SolarWinds Supply Chain Attack Can Teach Us
description: "Eric Byres on lessons learned from the the SolarWinds Supply Chain Attack: limitations and advantages of SBOMs, digital signing, and network monitoring"
image: https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[hacking](https://blog.adolus.com/tag/hacking) [ICS](https://blog.adolus.com/tag/ics) [Supply Chain Management](https://blog.adolus.com/tag/supply-chain) [SBOM](https://blog.adolus.com/tag/sbom)

# Three Things the SolarWinds Supply Chain Attack Can Teach Us

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December, 18 2020

[Back](https://blog.adolus.com)

Three Things the SolarWinds Supply Chain Attack Can Teach Us

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us> <http://www.facebook.com/share.php?u=https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us> [mailto:?subject=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us%20&body=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us&media=https://f.hubspotusercontent40.net/hubfs/6687498/SolarWinds%20Attack%20Infographic.png](mailto:?subject=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us%20&body=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us&media=https://f.hubspotusercontent40.net/hubfs/6687498/SolarWinds%20Attack%20Infographic.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us> <http://www.facebook.com/share.php?u=https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us> [mailto:?subject=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us%20&body=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us&media=https://f.hubspotusercontent40.net/hubfs/6687498/SolarWinds%20Attack%20Infographic.png](mailto:?subject=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us%20&body=Check%20out%20https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us&media=https://f.hubspotusercontent40.net/hubfs/6687498/SolarWinds%20Attack%20Infographic.png)

 Just in case you missed it, a [software supply chain attack](https://us-cert.cisa.gov/ncas/alerts/aa20-352a) on the US government and industries is consuming the waking hours of everyone involved in cyber security this week. The attack involved the insertion of a compromised DLL infected with the [SUNBURST](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html) malware directly into the DevOps environment of SolarWinds’ Orion network monitoring and management software. It was a cunning and subtle infiltration: the package was signed with a valid certificate, it checked that its process name hash was set to a specific value, and it waited around two weeks before calling home. 

Maybe there is some security tool out there that could have detected SUNBURST, but the reality is that 99.9% of the available tools won’t. If they could have detected it, SUNBURST would have been discovered and exposed long ago, not nine months after it was unleashed by the attackers. 

This blog is not going to tell you that there is a silver bullet out there. There isn’t. Supply chain attacks are very difficult to detect. But the lack of an easy solution doesn't mean we can't learn from the attack (and make life much more challenging for the next attacker). So in this blog I will highlight what we can learn from this incident and what we should consider as we go forward to reduce the risk to software supply chains.

First, this attack is not an isolated incident. In 2014, we saw a similar supply chain attack against the energy and pharmaceutical industries in Europe. These attacks, known as the [Dragonfly attacks](https://blog.adolus.com/blog/2018/05/10/building-or-losing-trust-in-our-software-supply-chain), allowed the attackers (who very likely are associated with the SUNBURST attackers, if not the same people) to gain a foothold into hundreds of industrial plants by modifying the software being released by three European ICS product vendors. Just last month we saw [trojanized security software](https://thehackernews.com/2020/11/trojanized-security-software-hits-south.html) hit South Korea users in a supply chain attack that, like SUNBURST, also involved signed code. And if we go way back to the grand-daddy of ICS cyber attacks, [Stuxnet](https://isssource.com/stuxnet-report-a-system-attack/) was (in part) a supply chain attack using stolen code signing certificates. All of this is just the tip of the iceberg: according to the report [*2020 State of the Software Supply Chain*](https://www.sonatype.com/2020ssc), supply chain attacks have surged this year, up 430% in the past 12 months.

Clearly supply chain exploits are now a core tool in the cyber-weapons toolbox, especially if the attacker is from or sponsored by a nation state. In the words of the researchers at the internet security company [ESET](https://www.welivesecurity.com/2020/11/16/lazarus-supply-chain-attack-south-korea/)***,*** *"Attackers are particularly interested in supply-chain attacks, because they allow them to covertly deploy malware on many computers at the same time*.” We observed the same high "attacker return-on-investment" for the Dragonfly perpetrators — by successfully penetrating one mid-tier ICS product supplier, they got deep access into an estimated 280 industrial facilities.

The second takeaway is that [software code signing](https://www.youtube.com/watch?v=EulV9sCL0FY) alone is poor defence against supply chain attacks. In all but the Dragonfly attacks, the attackers signed the malicious code with a valid signing certificate. In the SUNBURST and Stuxnet cases, the attackers likely penetrated the supplier’s development operations and stole the signing keys, but in the Korean attacks, the bad guys created dummy companies (one a US branch of a Korean company) and signed the code with those companys’ keys. This second technique is a lot easier to pull off and sadly almost as effective, because most systems don’t check the quality of the signer; the simple fact that the software is signed by someone is enough. It’s like airport security accepting your passport for Disneyland as being as valid as a passport issued by the government.  

On a related note, I’m worried that some of the promoters of Software Bill of Materials (SBOMs) are overstating what vendor-generated SBOMs would have done to prevent this train wreck. IMHO if the actors can modify a software release to both include their "special features” and have it signed with a valid certificate, then modifying the produced SBOM is a piece of cake. I wouldn’t rely on an SBOM from SolarWinds right now if you paid me. 

The third lesson is that if it’s poorly managed, the solution can be the problem. Remember, SolarWinds is a network monitoring product used for security purposes at many companies. If you look at the list of [TCP ports](https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/core-solarwinds-port-requirements.htm#Ports) that are required for SolarWinds products to operate, you’ll see that it numbers in the hundreds. Every one of those TCP connections increases the attack surface. In this case, the attackers didn’t use that multitude of communications services to get into their victims' systems, but they sure exploited them to call home. The SolarWinds product might do a good job of network monitoring, but its chaotic design exposes its customers to a lot of unnecessary risks. 

To be 100% clear, I am not saying that code signing, SBOMs, or network monitoring are bad. I’m a big proponent of all three as critical tools in our cyber-defence toolbox. My company even [generates SBOMs for ICS software companies](https://youtu.be/yZfCxvxrRYg). But SBOMs or code signing or the tool "du jour" are limited when used on their own. 

What we need is a way to coordinate the information about the software we use in our critical systems. For example, if you are using an SBOM to determine the components in a software package, you also want to be checking the signing of those components. If you deploy a traffic analysis service on your networks and it detects a software package being transferred, you want to understand the risk that software might introduce into your system. And you’d want to know immediately if the reputation of that software changes for any reason.

This isn’t something that we can do as individual companies. We need cooperation on software threats and vulnerabilities across companies and sectors. We need coordination between vendors, users, and consultants. And we need that cooperation to be in real time, not after the fact. 

To put it another way, we need to get more eyes on the problem. And we need to have those eyes working as a team on a 24/7 basis. I believe that can happen only within a vendor-agnostic ecosystem for software information sharing — [an ecosystem like FACT](http://fact.adolus.com).

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![Building (or Losing) Trust in our Software Supply Chain](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain)

 3 min read

##### [Building (or Losing) Trust in our Software Supply Chain](https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 10, 2018

Back in 2014, when I was managing Tofino Security, I became very interested in the Dragonfly attacks against industrial...

[Continue Reading](https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 2 min read

##### [Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 15, 2021

Seasoned financial and advisory executive to drive growth VICTORIA, BC, CANADA, June 15, 2021 /EINPresswire.com/ -- ...

[Continue Reading](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/hubfs/newventuresbc_social-media-banner-1.png)](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 2 min read

##### [aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on December 1, 2020

aDolus Technology Inc. bested 240 of BC’s most innovative tech startups, winning the New Ventures contest in Canada’s...

[Continue Reading](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

[![Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/hubfs/Imported_Blog_Media/monsterUSB-e1536780548901.png)](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 3 min read

##### [Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 12, 2018

On 24 August 2018 Schneider Electric issued a security notification alerting users that the Communications and...

[Continue Reading](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

[![Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness](https://blog.adolus.com/hubfs/Imported_Blog_Media/windows10-CVE-820x1024-1.png)](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness)

 3 min read

##### [Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 17, 2020

The announcement Tuesday from the NSA about the new cryptographic vulnerability in the Microsoft Windows operating...

[Continue Reading](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness)

[![Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/hubfs/Unsolicited-Response-Eric-and-Dale.png)](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 2 min read

##### [Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 7, 2021

Wrapping up my year on December 31, I was delighted to join ICS cybersecurity luminary Dale Peterson for his December:...

[Continue Reading](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

[![ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/hubfs/Refirm-aDolus.png)](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 2 min read

##### [ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 3, 2020

aDolus Technology Inc., a global authority on software intelligence for critical infrastructure, and ReFirm Labs, a...

[Continue Reading](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

[![aDolus Technology Selected as One of 2020’s Top 10 Startups](https://blog.adolus.com/hubfs/NVBC-Top10-small.png)](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

 2 min read

##### [aDolus Technology Selected as One of 2020’s Top 10 Startups](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on August 28, 2020

NANAIMO, BC, CANADA, August 27, 2020: aDolus Technology Inc., a global authority on software intelligence for critical...

[Continue Reading](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

[![Industrial Defender and aDolus Partner to Improve ICS Supply Chain Security](https://blog.adolus.com/hubfs/IndustrialDefender-aDolus-partnership.png)](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

 2 min read

##### [Industrial Defender and aDolus Partner to Improve ICS Supply Chain Security](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 19, 2021

Industrial Defender’s integration with the aDolus FACT™ platform ensures updates are valid, tamper-free, and safe to...

[Continue Reading](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

[![Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/hubfs/Bayshore-aDolus.png)](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 3 min read

##### [Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on July 23, 2020

The aDolus FACT™ platform provides independent software update validation to ensure safe upgrades and a more secure...

[Continue Reading](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)