OEM News

Study Finds Software Bill of Materials is Not an Industry Standard

A German survey found less than a quarter of industrial organizations have a complete SBoM.

Photo: PeopleImages.com - Yuri A./Shutterstock.

A Software Bill Of Materials (SBoM) is an exception in German industry rather than standard, despite its role as an effective tool for thwarting cyberattacks, a new study concludes.

SBoM—a parts list of all software components in a networked device—is considered an indispensable prerequisite for effective protection against cyberattacks, according to the new “OT+ IoT Cybersecurity Report 2024” from Duesseldorf-based cybersecurity company ONEKEY. The study on the cyber resilience of industrial control systems (ICS) and Internet of Things (IoT) devices is based on a survey of 300 industry executives. Respondents included CEOs, chief information officers, chief information security officers, chief technology officers, and IT managers.

Outdated Software as a Gateway for Attackers

According to the survey, less than a quarter (24%) of industrial organizations have a complete SBoM. While computer and network software is usually recorded, there is often no overview of the embedded software in countless devices with network access, such as machines and systems of all kinds, ONEKEY CEO Jan Wendenburg noted.

“This is fatal because outdated software in industrial control systems is an increasingly popular gateway for hackers,” he said, citing manufacturing robots, CNC machines, conveyor belts, packaging machines, production systems, building automation systems, heating and air conditioning systems as typical examples. “All of these systems are connected to the corporate network and there is software in almost every single component.” The study found a majority of companies (51%) either have no software or, at best, an incomplete SBoM.

Software BOMs with Many Gaps and Uncertainties

“In many companies, there are many gaps and uncertainties in the SBoM for networked devices,” Wendenburg stated. “A single outdated program in a machine can be enough to give hackers access to the company network.” It is particularly alarming that nearly a quarter of companies surveyed are unaware whether an SBoM exists, the survey indicated.

“It’s like driving on the motorway at night without lights,” the ONEKEY CEO said. “With an average of more than 2,000 software vulnerabilities discovered each month, the question for a company that does not automatically monitor and update its software is not if it will fall victim to a cyber attack, but when and with what consequences.”

Suppliers and Subcontractors Barely Checked

According to the ONEKEY report, the lack of visibility into software components in machinery and equipment is attributable to the fact that very few industrial companies carry out a comprehensive review of the embedded software of their equipment suppliers and third-party vendors. Just over a third (34%) use questionnaires from industry associations to assess suppliers’ cybersecurity measures. Thirty-one percent rely on standardized assessments and certifications, and 11% have no systematic process in place to ensure the equipment, machinery, and systems they buy for operational use are adequately protected against cyberattacks.

“We advise every industrial company to use a Software Bill Of Materials to get an overview of the cyber risks from production to logistics and building automation. In this way, the security gaps that are uncovered can be effectively assessed and neutralised before they are discovered and exploited by hackers,” Wendenburg explained. “A modern analysis platform creates a Software Bill Of Materials automatically and with comparatively little effort. However, it can be very expensive if hackers gain access to the company network via the shop floor because outdated software is being used.”

EU Cyber Resilience Act to Take Effect in 2027

In 2027, the EU’s Cyber Resilience Act (CRA) will legally require manufacturers of equipment, machinery, and systems to protect their control systems against cyberattacks with updated software. “Manufacturers who continue to supply systems with known programming vulnerabilities, or who do not immediately provide an update for newly discovered vulnerabilities, will be liable for the consequences if hackers use their outdated software to break in and cause damage,” Wendenburg warned.

A third of the companies surveyed update their software as soon as a patch is available to fix the vulnerability, and 28% automatically check for vulnerabilities in devices already shipped to customers. Thirty percent are satisfied with occasional manual checks, while 31% do not patch at all and wait for the next scheduled release to ward off hackers. “A delay that can prove fatal, because it is precisely this window of opportunity between detection and remediation that cyber criminals naturally exploit,” Wendenburg noted.

Companies have their work cut out for them: 16% of survey respondents no longer check their devices for security vulnerabilities after delivery. Ten percent no longer provide updates or security patches, and 26% do not know the update policy for their industrial equipment.

ONEKEY is a European specialist in product cybersecurity and compliance management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). Critical vulnerabilities and compliance violations in device firmware are automatically identified in binary code by artificial intelligence-based technology in minutes without source code, device, or network access.

Keep Up With Our Content. Subscribe To Medical Product Outsourcing Newsletters