---
title: "Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1"
description: President Biden has signed an Executive Order on Cybersecurity. This blog outlines its implications and provides a detailed Timeline with key dates.
image: https://blog.adolus.com/hubfs/Timeline-thumbnail.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[ICS/IoT Upgrade Management](https://blog.adolus.com/tag/upgrades) [vulnerability disclosure](https://blog.adolus.com/tag/vulnerability-disclosure) [Regulatory Requirements](https://blog.adolus.com/tag/regulatory-requirements) [Vulnerability Tracking](https://blog.adolus.com/tag/vulnerability-tracking) [Supply Chain Management](https://blog.adolus.com/tag/supply-chain) [SBOM](https://blog.adolus.com/tag/sbom) [EO14028](https://blog.adolus.com/tag/eo14028)

# Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May, 14 2021

[Back](https://blog.adolus.com)

Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1> <http://www.facebook.com/share.php?u=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1> [mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-thumbnail.png](mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-thumbnail.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1> <http://www.facebook.com/share.php?u=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1> [mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-thumbnail.png](mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-thumbnail.png)

 

Late Wednesday night President Biden signed the [Executive Order on Improving the Nation’s Cybersecurity](https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/).  

Compared to any Executive Order (EO) I’ve seen, this is a massive and complex policy document: the average length of an EO has been under 3½ pages; most are just 1 or 2 pages. This EO weighs in at 18 pages with 74 actionable directives. Forty-five of those directives have defined *due dates*, many linked to the completion of other directives. Add in the soup of acronyms and abbreviations common to the cybersecurity world and you have a document that is going to take months to fully decipher.

Unfortunately, companies don’t have months to understand how this EO will impact them. This is especially true for companies that supply *Critical Software* to the U.S. government (more on this in a bit). So let me provide a quick summary of the key takeaways (more in-depth analysis will follow in the days to come — be sure to click Subscribe when you've read to the end to get notified of updates).

I’ll start with the observation that securing the software supply chain is arguably the major focus of this EO. Almost 1/3 of the document’s policy statements are in the **Enhancing Software Supply Chain Security** section. This is no surprise after the [SolarWinds](https://blog.adolus.com/blog/three-things-the-solarwinds-supply-chain-attack-can-teach-us) attack in December infiltrated all five branches of the U.S. Military, the Pentagon, the State Department, the National Security Agency, the White House, and a whole lot of other significant targets. That kind of widespread havoc was certain to set the tone for this EO. (I’ve seen media stories suggesting this EO is a response to the Colonial Pipeline attack, but this document clearly wasn’t written over the weekend. Its scope is much further reaching and broader than ransomware attacks.) 

The goals of this major initiative to secure the software supply chain aren’t obvious on first reading of the EO. But head to the accompanying [EO Fact Sheet](https://www.whitehouse.gov/briefing-room/statements-releases/2021/05/12/fact-sheet-president-signs-executive-order-charting-new-course-to-improve-the-nations-cybersecurity-and-protect-federal-government-networks/) and four objectives stand out. I’ve quoted these directly from the Fact Sheet:

> 1. The Executive Order will improve the security of software by establishing baseline security standards for development of software sold to the government... 
> 2. requiring developers to maintain greater visibility into their software and making security data publicly available....
> 3. It stands up a concurrent public-private process to develop new and innovative approaches to secure software development and uses the power of Federal procurement to incentivize the market...
> 4. it creates a pilot program to create an “energy star” type of label so the government – and the public at large – can quickly determine whether software was developed securely.

How exactly the EO plans to achieve the above objectives is something I will lay out in my next blog post. That said, [Software Bill of Materials (SBOMs)](https://www.ntia.gov/SBOM) is a core concept with no less than 14 mentions. Two key directives include:

> ***4 (e) (vii)*** *providing a purchaser a Software Bill of Materials (SBOM) for each product directly or by publishing it on a public website;*
> 
> ***4 (f)*** *Within 60 days of the date of this order, the Secretary of Commerce, in coordination with the Assistant Secretary for Communications and Information and the Administrator of the National Telecommunications and Information Administration, shall publish minimum elements for an SBOM.*

As a point of interest, the aDolus team has been actively involved with the National Telecommunications and Information Administration (NTIA) in defining and testing these elements.

I’ll also point out that the EO repeatedly calls out Operational Technology (OT) in both the introduction of the EO and the EO Fact Sheet. Then the EO switches focus to a more general term, *Critical Software*, as it spells out the list of requirements and directives that will be required for all software sold to the U.S. Government. After last week's Colonial Pipeline incident, you can be pretty confident that OT software is included as Critical Software. We won’t have to wait too long to find out for sure: the Director of CISA is tasked with providing a list of software categories meeting the definition of Critical Software by July 26.

The bottom line? If you are a supplier of ICS/OT products to the government (or a supplier to a company that supplies to the government), the security information you must share with your clients is going to change in the next 365 days. It takes a lot of digging to understand the exact days, so my team has created a timeline of the due dates for the various supply chain directives, highlighting those that most impact software suppliers:

| [![Timeline-thumbnail](https://blog.adolus.com/hs-fs/hubfs/Timeline-thumbnail.png?width=173&name=Timeline-thumbnail.png)](https://blog.adolus.com/hubfs/Documents/EO-14028-Timeline-Section-4.pdf) | [Timeline of Executive Order 14028: Improving the Nation’s Cybersecurity Enhancing Software Supply Chain Security (V1)](https://blog.adolus.com/hubfs/Documents/EO-14028-Timeline-Section-4.pdf) |
| --- | --- |

We’ll be providing additional analysis of the EO over the next two weeks, focusing specifically on the software supply chain requirements and how they will impact the OT market (subscribe to this blog down below to be notified of the next report). In the meantime, if you are looking for guidance on creating SBOMs or enriching SBOM data, or on software supply chain security in general, please reach out. We’ve been researching and creating SBOMs for the OT market since 2017 and we are happy to help you.

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/hubfs/Timeline-thumbnail2.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 3 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 18, 2021

Removing Barriers to Sharing Threat Information On Friday we dissected Section 4: Enhancing Software Supply Chain...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 3](https://blog.adolus.com/hubfs/chains-stock-photo.jpg)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2-0)

 3 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 3](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2-0)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 21, 2021

So you don’t sell to the Feds… Today’s blog is going to take a break from analyzing a specific section of the Executive...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2-0)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4](https://blog.adolus.com/hubfs/Timeline-webpage-thumbnail-new.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4)

 5 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 26, 2021

Section 3 - Less Fog, More Cloud Section 3: Modernizing Federal Government Cybersecurity of the Executive Order is all...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4)

[![Three Quick Takeaways from Biden’s National Cybersecurity Strategy](https://blog.adolus.com/hubfs/National%20Cybersecurity%20Strategy%20Carrot%20and%20Stick.png)](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

 2 min read

##### [Three Quick Takeaways from Biden’s National Cybersecurity Strategy](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on March 2, 2023

NOTE: We were going to publish our second blog of the S4x23 SBOM Challenge today. However, the new National...

[Continue Reading](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

[![NTIA Publishes Minimum Components of an SBOM](https://blog.adolus.com/hubfs/Main-SBOM-image.png)](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

 4 min read

##### [NTIA Publishes Minimum Components of an SBOM](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on July 15, 2021

In today’s blog post I’d like to recognize all the hard work done by NTIA (National Telecommunications and Information...

[Continue Reading](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

[![A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/hubfs/Regulatory%20Action.png)](https://blog.adolus.com/a-flurry-of-regulatory-action)

 5 min read

##### [A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/a-flurry-of-regulatory-action)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a...

[Continue Reading](https://blog.adolus.com/a-flurry-of-regulatory-action)

[![How Russia Might Come After the West](https://blog.adolus.com/hubfs/russian-gas-pump-cyberattack-900x525.png)](https://blog.adolus.com/how-russia-might-come-after-the-west)

 2 min read

##### [How Russia Might Come After the West](https://blog.adolus.com/how-russia-might-come-after-the-west)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on February 25, 2022

The DDoS attack surge that began last week against Ukrainian government agencies and banks was a bad sign. I was...

[Continue Reading](https://blog.adolus.com/how-russia-might-come-after-the-west)

[![Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 3 min read

##### [Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 26, 2019

Earlier this year I attended the Public Safety Canada Industrial Control System Security symposium in Charlottetown,...

[Continue Reading](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 4 min read

##### [The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 11, 2023

This blog is a follow-up to our first post on the 2023 Microsoft Digital Defense Report where I described our...

[Continue Reading](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 5 min read

##### [EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 8, 2023

On December 3rd, the EU's new Cyber Resilience Act (CRA) got a big step closer to being adopted when the European...

[Continue Reading](https://blog.adolus.com/eu-cra-clears-penultimate-step)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)