A Flurry of Regulatory Action and the Need for SBOMs
· Connected Industry

A Flurry of Regulatory Action and the Need for SBOMs

Executive Order 14028 on Improving the Nation’s Cybersecurity was issued in May of 2021 and provided a roadmap for a series of regulatory initiatives that government agencies (and anyone doing business with them) should prepare for. Recently we’ve seen the rollout of two important mandates: OMB Memorandum M-22-18 dated Sept. 14, 2022 establishes requirements for […]

Read more →
Cybersecurity Nightmare = Ransomware + Software Supply Chain Attack
· ICS Security

Cybersecurity Nightmare = Ransomware + Software Supply Chain Attack

Recently, the Russia-based hacking group REvil, attacked the Florida-based software company Kaseya Ltd. If you’re not familiar with Kaseya, they provide network and security management services for small to medium-sized businesses (SMBs), not unlike what SolarWinds offers for large businesses. So this is yet another attack taking advantage of poor software security at companies that […]

Read more →
Deciphering Executive Order 14028: Improving the Nation’s Cybersecurity
· Cybersecurity

Deciphering Executive Order 14028: Improving the Nation’s Cybersecurity

An Executive Order (EO) issued by a U.S. President is usually a pretty straightforward document. Most are just two or three pages long with a handful of directives. This is definitely not the case with President Biden’s latest EO, Executive Order on Improving the Nation’s Cybersecurity. This is a massive policy document weighing in at […]

Read more →
A SolarWinds-style Attack Has Happened Before-Cybersecurity Lessons Learned
· ICS Security

A SolarWinds-style Attack Has Happened Before-Cybersecurity Lessons Learned

A SolarWinds-style cyberattack happened back in in 2013-14 that affected big government agencies and thousands of companies. What should we have learned from the Dragonfly/HAVEX attack? Software Infiltration A cyberattack group called Dragonfly attacked power plants and industrial sites, employing a very similar tactic to SolarWinds. “The technique of injecting into a supply chain is […]

Read more →
Cybersecurity Tactics to Reduce ICS Software Supply Chain Risk
· Cybersecurity

Cybersecurity Tactics to Reduce ICS Software Supply Chain Risk

Supply chain attacks like the recent SolarWinds hack are now front-page news, and cybersecurity steps must be taken to reduce the risk these attacks pose to critical systems. A platform that enables end users to manage the security of their ICS/OT endpoints down to vulnerabilities in hidden subcomponents is a necessity given the increased capabilities […]

Read more →