---
title: "Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4"
description: New blog on EO14028 Section 3 - Modernizing Federal Government Cybersecurity. Plus a new web Timeline tool to help prep for deadlines and deliverables.
image: https://blog.adolus.com/hubfs/Timeline-webpage-thumbnail-new.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[ICS/IoT Upgrade Management](https://blog.adolus.com/tag/upgrades) [vulnerability disclosure](https://blog.adolus.com/tag/vulnerability-disclosure) [Regulatory Requirements](https://blog.adolus.com/tag/regulatory-requirements) [Vulnerability Tracking](https://blog.adolus.com/tag/vulnerability-tracking) [Supply Chain Management](https://blog.adolus.com/tag/supply-chain) [SBOM](https://blog.adolus.com/tag/sbom) [EO14028](https://blog.adolus.com/tag/eo14028)

# Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May, 26 2021

[Back](https://blog.adolus.com)

Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4> <http://www.facebook.com/share.php?u=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4> [mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-webpage-thumbnail-new.png](mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-webpage-thumbnail-new.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4> <http://www.facebook.com/share.php?u=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4> [mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-webpage-thumbnail-new.png](mailto:?subject=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4%20&body=Check%20out%20https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-4&media=https://f.hubspotusercontent40.net/hubfs/6687498/Timeline-webpage-thumbnail-new.png)

### Section 3 - Less Fog, More Cloud

*Section 3: Modernizing Federal Government Cybersecurity* of the Executive Order is all about government agencies moving to the cloud and doing it right. If you are someone who believes that the cloud has absolutely no place in the industrial control systems (ICS) world, you are going to hate this section.

| The aDolus team has converted our previous EO Timeline to a web page that more easily handles all the sections and associated dates & deadlines. **Bookmark it and stay on top of the EO!** | [![Handy EO14028 Timeline](https://no-cache.hubspot.com/cta/default/6687498/4925167f-be1b-4098-bd88-a93cbcecb668.png)](https://cta-redirect.hubspot.com/cta/redirect/6687498/4925167f-be1b-4098-bd88-a93cbcecb668) |
| --- | --- |

The section starts with a preamble;

> The Federal Government must take decisive steps to modernize its approach to cybersecurity.

Then the section goes on to say that the government will accelerate movement to cloud technologies and there will be a single coordinated approach for cloud security strategies and service purchases by government agencies. 

The government’s cloud service security strategy has needed modernization for a while now. It has been over a decade since the US Government started moving its data storage away from agency-owned data centers and towards using cloud-based services. Unfortunately, despite good intentions, the government's requirements for cloud security have been rather “foggy” to say the least. For example, the Office of Management and Budget released its [Cloud Smart Strategy](https://cloud.cio.gov/strategy) in 2019 to help agencies securely migrate to the cloud. While security was one of the three pillars of that report, the guidance was largely a collection of security truisms like

> This requires that agencies place an emphasis on… transitioning to a multi-layer defense strategy, otherwise known as defense-in-depth. 

Use defence-in-depth… wow, what a radical idea. 

The EO aims to modernize the US government’s cloud security posture in four ways. The first directs CISA to develop secure cloud adoption practices and guidelines, offer incident response services to government cloud users, and set policy on how agencies should work with partners like CISA and the FBI in responding to cloud incidents. The timeline to develop these complex policies is tight, 90 days or less in each case.

The second set of clauses is a requirement for all agencies to implement a Zero Trust Architecture for all cloud computing services. If you are not familiar with Zero Trust Architecture (and frankly it isn't often discussed in the OT world), you need to jump ahead to *Sec. 10. Definitions.*  The EO’s definition begins: 

> a security model… based on an acknowledgement that threats exist both inside and outside traditional network boundaries.

In other words, you assume the bad guys are already inside your network and now you need to manage them. 

Zero Trust (sometimes called perimeterless security) has been discussed in the IT world since the 1990s. My good friend [Paul Dorey](http://personal.rhul.ac.uk/vsai/149/), tried to bring it to the OT world in the early 2000’s when he was the CSO at BP. Unfortunately the concept of Zero Trust was and still is an anathema to many in the OT world. For the past 30 years the design of industrial control systems has been based on the dubious assumption that everything connected to the ICS network is friendly. As Dale Peterson says, that traditional OT security strategy should be called Insecure-by-Design. Frankly, I agree.

PaloAlto Networks has a [good, quick summary](https://www.paloaltonetworks.com/cyberpedia/what-is-a-zero-trust-architecture) of the Zero Trust philosophy  if you want more details. But it’s the next sentence in the EO definition that stood out to me: 

> The Zero Trust security model eliminates implicit trust in any one element, node, or service and instead requires continuous verification of the operational picture via real-time information from multiple sources to determine access and other system responses.

“Continuous” verification is no trivial task. Anyone who has tried to determine if their ICS software contains vulnerabilities will know that new vulnerabilities are found all the time, and they can be hidden in components you don’t even know you’ve got. Also, monitoring “real-time information from multiple sources” isn’t the kind of job that humans excel at.  Satisfying this requirement in the EO is going to require automation of trust validation.

Next, the order requires all agencies to adopt multi-factor authentication (MFA) and encryption for all data at rest and in transit. Note the phrase *data at rest.* Just deploying your PLC’s communications over SSL isn’t going to cut it.

If you are selling to the Feds (or to companies that will expect the same commitment to cybersecurity that the Feds are demanding) your software must implement MFA and data encryption. This isn’t a quick and simple retrofit for ICS; you’ll need to start early as you’ve only got 180 days to come up with a solution. And you’ll want to build this in from the get go for new software in the future. Of course there is an escape clause - agencies using products that are unable to comply must provide a written report explaining why they are unable to comply. That should be a fun pile of paperwork to fill out.

Finally, the Administrator of General Services is tasked with a significant set of actions to modernize FedRAMP (the federal government’s main security authorization program for cloud services) by July 11. There is significant emphasis here on more-automated, more-rapid and less-duplicative reviews of new cloud services:

> improving communication with CSPs (Cloud Service Providers) through automation and standardization of messages at each stage of authorization.  These communications may include status updates, requirements to complete a vendor’s current stage, next steps, and points of contact for questions

It is encouraging to see acknowledgement that automation will be necessary. 

So what has any of this cloud stuff got to do with OT you ask? Well, every one of the major automation vendors is now promoting a significant cloud services solution for tasks like asset management, process optimization, and security response coordination. Sure you don’t have to use those cloud services, but customers soon find that they lose some very useful capabilities when they do that. So while closed-loop control over the cloud might be a ways off yet, control system communication to the cloud is here now.

**To Close...**

It is clear that cloud technology is going to be a big area of attention for this administration. Companies with secure and robust cloud security solutions will be the beneficiaries. On the other hand, if your company supplies a product that doesn’t support multi-factor authentication and encryption of data both in transit and at rest, you and your government clients may have a lot of paperwork to do in the next 180 days.

As always, if you want to be notified of the next report on EO14028, click Subscribe (down to the right).

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2-0) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/hubfs/Timeline-thumbnail.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 4 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 14, 2021

Late Wednesday night President Biden signed the Executive Order on Improving the Nation’s Cybersecurity. Compared to...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 3](https://blog.adolus.com/hubfs/chains-stock-photo.jpg)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2-0)

 3 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 3](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2-0)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 21, 2021

So you don’t sell to the Feds… Today’s blog is going to take a break from analyzing a specific section of the Executive...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2-0)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/hubfs/Timeline-thumbnail2.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 3 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 18, 2021

Removing Barriers to Sharing Threat Information On Friday we dissected Section 4: Enhancing Software Supply Chain...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

[![Three Quick Takeaways from Biden’s National Cybersecurity Strategy](https://blog.adolus.com/hubfs/National%20Cybersecurity%20Strategy%20Carrot%20and%20Stick.png)](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

 2 min read

##### [Three Quick Takeaways from Biden’s National Cybersecurity Strategy](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on March 2, 2023

NOTE: We were going to publish our second blog of the S4x23 SBOM Challenge today. However, the new National...

[Continue Reading](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

[![3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/hubfs/Imported_Blog_Media/NERC-CIPC-Training-Session-1024x451.jpeg)](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 3 min read

##### [3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on April 21, 2020

Earlier this month, as the coronavirus accelerated its alarming sprint across North America, NERC requested that...

[Continue Reading](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

[![How Russia Might Come After the West](https://blog.adolus.com/hubfs/russian-gas-pump-cyberattack-900x525.png)](https://blog.adolus.com/how-russia-might-come-after-the-west)

 2 min read

##### [How Russia Might Come After the West](https://blog.adolus.com/how-russia-might-come-after-the-west)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on February 25, 2022

The DDoS attack surge that began last week against Ukrainian government agencies and banks was a bad sign. I was...

[Continue Reading](https://blog.adolus.com/how-russia-might-come-after-the-west)

[![Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 3 min read

##### [Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 26, 2019

Earlier this year I attended the Public Safety Canada Industrial Control System Security symposium in Charlottetown,...

[Continue Reading](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 4 min read

##### [The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 11, 2023

This blog is a follow-up to our first post on the 2023 Microsoft Digital Defense Report where I described our...

[Continue Reading](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/hubfs/Mark-Weatherford-Appointment.png)](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 2 min read

##### [aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 23, 2021

Cybersecurity veteran tapped to accelerate growth of ICS supply chain security leader VICTORIA, BC, CANADA, June 23 -- ...

[Continue Reading](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

[![A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/hubfs/Regulatory%20Action.png)](https://blog.adolus.com/a-flurry-of-regulatory-action)

 5 min read

##### [A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/a-flurry-of-regulatory-action)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a...

[Continue Reading](https://blog.adolus.com/a-flurry-of-regulatory-action)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)