Version history
Release notes
What has changed on IACS Radar, from the first release until now. Version numbering has been assigned retroactively to the existing development history.
v2.8.1
Current version
- v2.8.1Verbetering23 September 2026
Automatic language selection on first visit
- Visitors with a German browser language now open IACS Radar in German, and visitors with any other non-Dutch browser language in English; Dutch browsers stay on Dutch.
- As soon as you choose a language yourself via the flag, that choice is remembered in a functional cookie and the automatic selection no longer intervenes. Search engines are not redirected.
- v2.8.0Nieuwe functie21 September 2026
English and German, and light mode by default
- IACS Radar is now available in Dutch, English and German. Choose your language via the flag at the top right; Dutch remains the default language and has no language prefix in the URL (/en/… and /de/… for the other languages).
- All interface texts, data descriptions, dates and numbers follow the chosen language; if a translation is missing somewhere, Dutch is shown instead of a blank.
- All knowledge base and blog articles are now also available in English and German.
- Search engines get hreflang references to all language variants per page, including in the sitemap.
- The site now opens in light mode by default; use the sun/moon button to switch to dark and your choice is remembered.
- v2.7.0Nieuwe functie9 September 2026
Asset Matcher: firmware-version-aware matching
- Asset Matcher now assesses whether your specifically installed firmware/software version actually falls within a known vulnerable range, instead of only reporting that a product has vulnerabilities — with a concrete recommended action (e.g. "upgrade to V9.80 or newer") where the source indicates one.
- With insufficient or unclear version information, Asset Matcher always shows an explicit intermediate status ("Possibly vulnerable", "Firmware version needed") — never a reassuring "safe" based on uncertain data.
- Assets can now be edited inline (vendor, product, version, zone, criticality) instead of deleting and re-adding them.
- Better automatic recognition of vendor names, including with deviating legal forms ("Siemens AG", "Mitsubishi Electric Corporation").
- Zone and criticality now count towards the Asset Priority, alongside the existing IACS Radar Score.
- CSV import now shows a preview of recognised/ignored columns before final import, and supports new columns (model, zone, criticality, asset name).
- v2.6.6Nieuwe functie3 September 2026
Illustrations per blog category
- Every blog article now has a banner illustration (blog list and article page), in its own colour and motif per category — not a photo (no royalty-free source available), but a custom-made illustration in the same style as the homepage hero.
- v2.6.5Verbetering3 September 2026
- My Radar: "Follow a vendor, product or CVE" now sits directly below the export/import buttons, before the "Nothing to follow yet" message.
- v2.6.4Verbetering2 September 2026
Website links for automatically recognised vendors
- Vendors recognised only via a live CISA/NVD integration (not from the manual list) never had a website link — 28 of them now have a verified official address; the rest get a clearly labelled search link instead of nothing.
- v2.6.3Verbetering2 September 2026
WAGO added, non-industrial CISA advisories filtered
- WAGO added as a vendor (PFC200 series).
- CISA ICS advisories outside OT-relevant critical infrastructure sectors (e.g. consumer vehicle security) no longer appear as a vendor/vulnerability — CISA publishes those under the same advisory feed as real OT/energy-sector advisories.
- v2.6.2Verbetering2 September 2026
Terms of use and attribution
- New Terms of use page (via the About menu or the footer) with the mandatory NVD attribution notice and attribution for CISA, Siemens, ABB, FIRST.org (EPSS) and Shodan.
- New, valid NVD API key activated — the previous one was rejected by NVD, which silently dropped NVD enrichment (including all Microsoft Windows CVEs).
- v2.6.1Verbetering2 September 2026
More reliable vulnerability data refresh
- The site could temporarily hang for minutes when refreshing vulnerability data (NVD/EPSS) — batches are now fetched in parallel instead of one after another, and the result is cached reliably so visitors never again wait for a full recalculation.
- Full Microsoft Windows CVE coverage restored, after a temporary restriction yesterday because of this same performance problem.
- v2.6.0Nieuwe functie1 September 2026
Help page with a short guide per section
- New Help page (via the About menu or the footer) with a short explanation per section: dashboard, My Radar, Intelligence, vendors/products, Asset Matcher, prioritisation and preferences.
- Release notes is now also in the main menu under "About", no longer only in the footer.
- v2.5.0Nieuwe functie1 September 2026
Microsoft Windows added as a vendor
- Microsoft Windows added to the vendor/product catalogue (Windows XP, 7, 10, 11 and Server) — relevant because substations increasingly use Windows thin clients and workstations as a gateway to an HMI.
- Vulnerabilities only come in for core operating system components that are in the CISA KEV catalogue (confirmed actively exploited), not for Microsoft applications or the full CVE inflow.
- v2.4.0Nieuwe functie1 September 2026
Take your watchlist to another browser
- My Radar: the watchlist can now be exported/imported as a file, or shared via a link — handy on another browser, device, or after clearing cache/cookies.
- v2.3.0Nieuwe functie26 August 2026
Simulated attack patterns on the exposure map
- New, optional visualisation on the exposure map that shows illustrative attack patterns (clearly labelled as a simulation, no live threat data) — enabled by default.
- Hero and header reduced in size so the exposure map is immediately in view on a first visit.
- Dark mode made a few shades lighter.
- v2.2.1Verbetering25 August 2026
Vendor fixes
- The link to the official source on vendor advisories now points to the readable page instead of a raw JSON file.
- Fortinet, Welotec and Westermo added to the vendor and product catalogue.
- Vendors without a current vulnerability were wrongly missing from the vendor overview — fixed, with sort options (alphabetical / number of vulnerabilities) added.
- v2.2.0Nieuwe functie24 August 2026
Redesigned zones & conduits, dark mode as default
- The interactive "zones and conduits" visualisation redesigned in a professional OT architecture style, with explanation.
- Dark mode is now the default view.
- Main menu restructured: Asset Matcher directly in the main menu, Vulnerabilities and ICS Advisories moved to Intelligence.
- My Radar, Intelligence and the CVE detail page aligned to the same width as the rest of the site.
- v2.1.2Verbetering23 August 2026
- Contact options (LinkedIn, email) added to the About page.
- v2.1.1Verbetering20 August 2026
- Explanation "How the vulnerability list is compiled" simplified and the accompanying diagram rebuilt as a clear 4-step infographic.
- Two findings from the OWASP security assessment resolved.
- My Radar now shows the full product catalogue, instead of only products with a current vulnerability.
- v2.1.0Nieuwe functie17 August 2026
Vendor and product pages, Asset Matcher
- Own pages per vendor and product added.
- Asset Matcher introduced: match your own equipment locally in the browser against the vulnerability catalogue.
- Abbreviations page added.
- Various texts on the methodology page clarified and findings from an external website scan resolved.
- v2.0.0Grote release16 August 2026
My Radar, EPSS and live vendor feeds
- "My Radar" introduced: follow vendors, products or CVEs and see in one overview what has changed since your last visit.
- EPSS (Exploit Prediction Scoring System) added to the OT priority score.
- Live vendor advisories from Siemens ProductCERT and ABB PSIRT added.
- Filter options added to ICS advisories, as with Vulnerabilities.
- CVE detail page restructured and a data consistency error between dashboard and detail pages resolved.
- New knowledge base article on the Cybersecurity Act and IEC 62443.
- v1.3.2Verbetering9 August 2026
- 404 error fixed when clicking through from intelligence feed items on the dashboard.
- Default period filter on the dashboard extended from 30 to 90 days.
- Text alignment on the homepage improved.
- v1.3.1Verbetering1 August 2026
- Browser tab title fixed (showed "Dashboard" instead of "IACS Radar").
- Payoff text aligned pixel-perfectly with the logo in the header.
- v1.3.0Nieuwe functie31 July 2026
- Visual explanation of the CVE compilation methodology added to the Methodology page.
- New logo (header and favicon) and USP text on the homepage.
- Explanation added of what makes IACS Radar different, on the About page.
- v1.2.2Verbetering30 July 2026
- Site verification added for Bing Webmaster Tools.
- More contrast between the exposure map and the page background in light mode.
- v1.2.1Verbetering29 July 2026
- robots.txt and sitemap.xml added for better discoverability in search engines.
- v1.2.0Nieuwe functie27 July 2026
New look
- Completely new, NCSC-inspired design: institutional header, hero and dashboard layout.
- The IACS Radar logo added to the header.
- The search function now also searches the knowledge base, blog and IEC 62443 content.
- v1.1.1Verbetering26 July 2026
- Subtle heartbeat animation added on the selected country circle of the exposure map.
- v1.1.0Nieuwe functie25 July 2026
Dashboard redesign
- Dashboard rebuilt: map-first layout with sidebar navigation, KPI sparklines and clearer status messages.
- Netherlands as the default country and light mode as the default theme.
- Security tightened (Content-Security-Policy without inline scripts).
- Various data bugs fixed: exposure figures per country, a Shodan error that kept most countries at 0, and time zone handling.
- v1.0.0Grote release24 July 2026
First release
- IACS Radar live: dashboard with exposure map, vulnerabilities, KEV matches, ICS advisories and methodology.
- Production environment set up on a TransIP VPS.