Transparency
Methodology
This page explains which sources IACS Radar uses, how often information is updated, how relevance is determined, and where the limitations of this platform lie.
Sources used
CISA KEV, NVD, CISA ICS advisories, the vendor advisories (Siemens, ABB) and EPSS scores (FIRST.org) are retrieved live. This happens server-side. No API key is mandatory for NVD and EPSS (see below).
The exposure map uses a live Shodan integration. It supplies the total number of observations and the protocol distribution per country, via the credit-free `/host/count` endpoint. No active scans are performed and no individual host data is retrieved.
Critical-vulnerability and KEV estimates per country, top vendors and the 30-day trend remain an illustrative estimate. Shodan offers no CVE or vendor correlation at count level.
CISA Known Exploited Vulnerabilities
actiefRetrieved live from the public CISA KEV catalogue (JSON feed, no API key needed).
NVD CVE API 2.0
actiefRetrieved live via the NVD CVE API 2.0 with a configured API key.
CISA ICS advisories
actiefRetrieved live from the official CSAF 2.0 advisories published by CISA (cisagov/CSAF), with a configured GitHub token.
Leveranciersadvisories
actiefRetrieved live from the own CSAF advisory feeds of Siemens ProductCERT and ABB PSIRT. Hitachi Energy advisories currently come in only via the CISA ICS Advisories integration.
EPSS (Exploit Prediction Scoring System)
actiefDaily updated exploitation probability per CVE, retrieved live from FIRST.org (no API key needed).
Shodan
actiefPublicly observable industrial exposure (host/count, credit-free), accessed exclusively server-side.
How the vulnerability list is compiled
- IACS Radar does not search NVD broadly by vendor or keyword. Candidate CVEs come from only three sources: the 60 most recent CISA ICS-CERT advisories, the own CSAF advisory feeds of Siemens ProductCERT and ABB PSIRT, and the CISA KEV catalogue with confirmed active exploitation. These sources are merged into a maximum of 1000 CVEs.
- NVD is then used only to enrich these CVEs, with CVSS, CWE and a description. NVD is not used to search for new CVEs.
- A vendor without a recent CISA advisory, own advisory or KEV entry can end up with 0 CVEs here. That also applies if that same vendor has dozens or hundreds of CVEs in the full NVD history. A tool such as OpenCVE does show that full history.
- This is a deliberate choice for a smaller scope. The focus is on recent and officially reported vulnerabilities. This is not a full CVE inventory per vendor.
- Hitachi Energy, Fortinet, Welotec and Westermo are known vendors in the catalogue, but have (as yet) no own, directly linkable CSAF feed. Their advisories therefore only come in when CISA publishes about them.
- Microsoft Windows is in the catalogue as a vendor because substations increasingly use Windows thin clients and workstations as a gateway to an HMI or other OT device. Only the operating system variants are followed (no Office, Exchange, .NET and other applications), and only vulnerabilities in core OS components that are in the CISA KEV catalogue (i.e. confirmed actively exploited) — not the full Microsoft CVE inflow.
- Each candidate CVE is then enriched with NVD data and an EPSS score from FIRST.org. Together with the industrial relevance score, both form the IACS Radar priority score.
1. Bronnen
Public source data, retrieved server-side.
2. Verzamelen & normaliseren
- Retrieve and merge sources
- Deduplicate CVE IDs
- Enrich metadata (CVSS, CWE, description)
- Caching and periodic synchronisation
3. Verrijken & prioriteren
- Industrial relevance score
- Include KEV status and EPSS
- Internet exposure as extra context
- IACS Radar priority score (0–100)
KEV ×1.4 and internet exposure ×1.1 as extra uplift.
4. Publiceren & duiden
- Dashboard, Intelligence and Vulnerabilities
- IEC 62443 context and knowledge base
- IACS Radar assessment separate from source data
- Last update visible per source
Key principles
Limitations
No full CVE history per vendor. The focus is on recent, officially reported advisories, KEV entries and enriched OT relevance.
Update frequency
CISA KEV, CISA ICS advisories, the vendor advisories (Siemens, ABB) and NVD enrichment are retrieved server-side and re-synchronised at most every 30 minutes (the advisory files and KEV catalogue themselves are cached longer, up to several hours, to avoid loading the sources unnecessarily). The exposure map retrieves new counts from Shodan every 6 hours. Every page shows an explicit time of last retrieval; the word “live” is used only where it concerns a recently retrieved external source, never for the synthetic parts.
How industrial relevance is determined
Not every vulnerability with a high CVSS score is relevant to OT. IACS Radar calculates a configurable industrial relevance score based on: mention in a CISA ICS advisory, CPE match, vendor, product category (for example PLC, RTU, IED, protection relay), industrial protocols used, sector keywords and manual analyst classification. For every classification it is recorded why a vulnerability was marked as industrially relevant — visible on every CVE detail page under “IACS Radar assessment”.
How CVSS is interpreted
CVSS expresses the technical severity of a vulnerability — not the likelihood of exploitation. A score of 9.8 means that exploitation, if it occurs, is potentially very serious; it says nothing about whether this actually happens. IACS Radar therefore always combines CVSS with additional context: KEV status, internet exposure and industrial relevance.
How the IACS Radar priority score is calculated
Besides the individual CVSS, EPSS, KEV and relevance signals, every CVE detail page shows a combined IACS Radar priority score (0–100). Base weighting: CVSS 35% (technical severity), EPSS 30% (the estimate, updated daily by FIRST.org, of the likelihood of exploitation within 30 days) and industrial relevance score 35%. If no EPSS score is available yet (for example for a very recent CVE), that weight is distributed proportionally over CVSS and relevance — a missing score is therefore never interpreted as “0% likelihood”. A confirmed KEV entry and relevance to internet exposure then act as a multiplying uplift on that base, because confirmed exploitation and observable exposure disproportionately increase urgency. The priority score is a supplementary aid for triage, not a replacement for the individual scores — those remain separately visible everywhere.
Difference between CVE and KEV
A CVE is an identification number for a documented vulnerability. A KEV entry means that CISA has established that this vulnerability is actually being exploited. See also the knowledge base article KEV, CVE, CVSS and EPSS explained for a detailed explanation.
How geographic data is aggregated
To prevent traceability to specific installations, IACS Radar never shows exact IP addresses or GPS coordinates. Observations are aggregated at country or region level (province, federal state, broad region). IP addresses are shown masked (for example 145.***.***.24) and serve solely as illustration in this demo environment.
Limitations of exposure data
- An internet-reachable service is not automatically vulnerable.
- Location data based on IP addresses can be inaccurate, for example due to the use of VPNs, CDNs or shared infrastructure.
- Visibility via scanning-based sources is not complete: not every internet-reachable system is observed.
- An observation shows no evidence of misconfiguration, only that a service responds to a specific request.
Possible false positives and data quality
Automatic matching between products, CPEs and advisories can lead to incorrect links, for example due to inconsistent product names between sources. IACS Radar explicitly marks its own interpretation as “IACS Radar assessment” and distinguishes it from official source data. Users are advised to always verify critical decisions against the official source.
Analyst interpretation
Where automated matching offers insufficient certainty, an analyst supplements the classification manually. This is recorded including name or team, date and explanation, so that it is clear which information comes from an official source and which from own analysis.
Responsible disclosure
IACS Radar publishes only information that is already publicly available (CVEs, KEV entries, ICS advisories) and contains no exploit code, step-by-step exploitation instructions or unpublished vulnerabilities. To report new vulnerabilities we refer to the vendor concerned or to CISA's coordination process for responsible disclosure.
Privacy and ethical principles
This platform is intended solely for defensive security, risk assessment, knowledge sharing and vulnerability management. No functionality is offered for active scanning, exploitation, credential testing or unauthorised access. Personal data is not processed in the exposure datasets; the identifiers shown are anonymised, aggregated technical characteristics.