Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence

Version history

Release notes

What has changed on IACS Radar, from the first release until now. Version numbering has been assigned retroactively to the existing development history.

v2.8.1

Current version

  1. v2.8.1Verbetering23 September 2026

    Automatic language selection on first visit

    • Visitors with a German browser language now open IACS Radar in German, and visitors with any other non-Dutch browser language in English; Dutch browsers stay on Dutch.
    • As soon as you choose a language yourself via the flag, that choice is remembered in a functional cookie and the automatic selection no longer intervenes. Search engines are not redirected.
  2. v2.8.0Nieuwe functie21 September 2026

    English and German, and light mode by default

    • IACS Radar is now available in Dutch, English and German. Choose your language via the flag at the top right; Dutch remains the default language and has no language prefix in the URL (/en/… and /de/… for the other languages).
    • All interface texts, data descriptions, dates and numbers follow the chosen language; if a translation is missing somewhere, Dutch is shown instead of a blank.
    • All knowledge base and blog articles are now also available in English and German.
    • Search engines get hreflang references to all language variants per page, including in the sitemap.
    • The site now opens in light mode by default; use the sun/moon button to switch to dark and your choice is remembered.
  3. v2.7.0Nieuwe functie9 September 2026

    Asset Matcher: firmware-version-aware matching

    • Asset Matcher now assesses whether your specifically installed firmware/software version actually falls within a known vulnerable range, instead of only reporting that a product has vulnerabilities — with a concrete recommended action (e.g. "upgrade to V9.80 or newer") where the source indicates one.
    • With insufficient or unclear version information, Asset Matcher always shows an explicit intermediate status ("Possibly vulnerable", "Firmware version needed") — never a reassuring "safe" based on uncertain data.
    • Assets can now be edited inline (vendor, product, version, zone, criticality) instead of deleting and re-adding them.
    • Better automatic recognition of vendor names, including with deviating legal forms ("Siemens AG", "Mitsubishi Electric Corporation").
    • Zone and criticality now count towards the Asset Priority, alongside the existing IACS Radar Score.
    • CSV import now shows a preview of recognised/ignored columns before final import, and supports new columns (model, zone, criticality, asset name).
  4. v2.6.6Nieuwe functie3 September 2026

    Illustrations per blog category

    • Every blog article now has a banner illustration (blog list and article page), in its own colour and motif per category — not a photo (no royalty-free source available), but a custom-made illustration in the same style as the homepage hero.
  5. v2.6.5Verbetering3 September 2026
    • My Radar: "Follow a vendor, product or CVE" now sits directly below the export/import buttons, before the "Nothing to follow yet" message.
  6. v2.6.4Verbetering2 September 2026

    Website links for automatically recognised vendors

    • Vendors recognised only via a live CISA/NVD integration (not from the manual list) never had a website link — 28 of them now have a verified official address; the rest get a clearly labelled search link instead of nothing.
  7. v2.6.3Verbetering2 September 2026

    WAGO added, non-industrial CISA advisories filtered

    • WAGO added as a vendor (PFC200 series).
    • CISA ICS advisories outside OT-relevant critical infrastructure sectors (e.g. consumer vehicle security) no longer appear as a vendor/vulnerability — CISA publishes those under the same advisory feed as real OT/energy-sector advisories.
  8. v2.6.2Verbetering2 September 2026

    Terms of use and attribution

    • New Terms of use page (via the About menu or the footer) with the mandatory NVD attribution notice and attribution for CISA, Siemens, ABB, FIRST.org (EPSS) and Shodan.
    • New, valid NVD API key activated — the previous one was rejected by NVD, which silently dropped NVD enrichment (including all Microsoft Windows CVEs).
  9. v2.6.1Verbetering2 September 2026

    More reliable vulnerability data refresh

    • The site could temporarily hang for minutes when refreshing vulnerability data (NVD/EPSS) — batches are now fetched in parallel instead of one after another, and the result is cached reliably so visitors never again wait for a full recalculation.
    • Full Microsoft Windows CVE coverage restored, after a temporary restriction yesterday because of this same performance problem.
  10. v2.6.0Nieuwe functie1 September 2026

    Help page with a short guide per section

    • New Help page (via the About menu or the footer) with a short explanation per section: dashboard, My Radar, Intelligence, vendors/products, Asset Matcher, prioritisation and preferences.
    • Release notes is now also in the main menu under "About", no longer only in the footer.
  11. v2.5.0Nieuwe functie1 September 2026

    Microsoft Windows added as a vendor

    • Microsoft Windows added to the vendor/product catalogue (Windows XP, 7, 10, 11 and Server) — relevant because substations increasingly use Windows thin clients and workstations as a gateway to an HMI.
    • Vulnerabilities only come in for core operating system components that are in the CISA KEV catalogue (confirmed actively exploited), not for Microsoft applications or the full CVE inflow.
  12. v2.4.0Nieuwe functie1 September 2026

    Take your watchlist to another browser

    • My Radar: the watchlist can now be exported/imported as a file, or shared via a link — handy on another browser, device, or after clearing cache/cookies.
  13. v2.3.0Nieuwe functie26 August 2026

    Simulated attack patterns on the exposure map

    • New, optional visualisation on the exposure map that shows illustrative attack patterns (clearly labelled as a simulation, no live threat data) — enabled by default.
    • Hero and header reduced in size so the exposure map is immediately in view on a first visit.
    • Dark mode made a few shades lighter.
  14. v2.2.1Verbetering25 August 2026

    Vendor fixes

    • The link to the official source on vendor advisories now points to the readable page instead of a raw JSON file.
    • Fortinet, Welotec and Westermo added to the vendor and product catalogue.
    • Vendors without a current vulnerability were wrongly missing from the vendor overview — fixed, with sort options (alphabetical / number of vulnerabilities) added.
  15. v2.2.0Nieuwe functie24 August 2026

    Redesigned zones & conduits, dark mode as default

    • The interactive "zones and conduits" visualisation redesigned in a professional OT architecture style, with explanation.
    • Dark mode is now the default view.
    • Main menu restructured: Asset Matcher directly in the main menu, Vulnerabilities and ICS Advisories moved to Intelligence.
    • My Radar, Intelligence and the CVE detail page aligned to the same width as the rest of the site.
  16. v2.1.2Verbetering23 August 2026
    • Contact options (LinkedIn, email) added to the About page.
  17. v2.1.1Verbetering20 August 2026
    • Explanation "How the vulnerability list is compiled" simplified and the accompanying diagram rebuilt as a clear 4-step infographic.
    • Two findings from the OWASP security assessment resolved.
    • My Radar now shows the full product catalogue, instead of only products with a current vulnerability.
  18. v2.1.0Nieuwe functie17 August 2026

    Vendor and product pages, Asset Matcher

    • Own pages per vendor and product added.
    • Asset Matcher introduced: match your own equipment locally in the browser against the vulnerability catalogue.
    • Abbreviations page added.
    • Various texts on the methodology page clarified and findings from an external website scan resolved.
  19. v2.0.0Grote release16 August 2026

    My Radar, EPSS and live vendor feeds

    • "My Radar" introduced: follow vendors, products or CVEs and see in one overview what has changed since your last visit.
    • EPSS (Exploit Prediction Scoring System) added to the OT priority score.
    • Live vendor advisories from Siemens ProductCERT and ABB PSIRT added.
    • Filter options added to ICS advisories, as with Vulnerabilities.
    • CVE detail page restructured and a data consistency error between dashboard and detail pages resolved.
    • New knowledge base article on the Cybersecurity Act and IEC 62443.
  20. v1.3.2Verbetering9 August 2026
    • 404 error fixed when clicking through from intelligence feed items on the dashboard.
    • Default period filter on the dashboard extended from 30 to 90 days.
    • Text alignment on the homepage improved.
  21. v1.3.1Verbetering1 August 2026
    • Browser tab title fixed (showed "Dashboard" instead of "IACS Radar").
    • Payoff text aligned pixel-perfectly with the logo in the header.
  22. v1.3.0Nieuwe functie31 July 2026
    • Visual explanation of the CVE compilation methodology added to the Methodology page.
    • New logo (header and favicon) and USP text on the homepage.
    • Explanation added of what makes IACS Radar different, on the About page.
  23. v1.2.2Verbetering30 July 2026
    • Site verification added for Bing Webmaster Tools.
    • More contrast between the exposure map and the page background in light mode.
  24. v1.2.1Verbetering29 July 2026
    • robots.txt and sitemap.xml added for better discoverability in search engines.
  25. v1.2.0Nieuwe functie27 July 2026

    New look

    • Completely new, NCSC-inspired design: institutional header, hero and dashboard layout.
    • The IACS Radar logo added to the header.
    • The search function now also searches the knowledge base, blog and IEC 62443 content.
  26. v1.1.1Verbetering26 July 2026
    • Subtle heartbeat animation added on the selected country circle of the exposure map.
  27. v1.1.0Nieuwe functie25 July 2026

    Dashboard redesign

    • Dashboard rebuilt: map-first layout with sidebar navigation, KPI sparklines and clearer status messages.
    • Netherlands as the default country and light mode as the default theme.
    • Security tightened (Content-Security-Policy without inline scripts).
    • Various data bugs fixed: exposure figures per country, a Shodan error that kept most countries at 0, and time zone handling.
  28. v1.0.0Grote release24 July 2026

    First release

    • IACS Radar live: dashboard with exposure map, vulnerabilities, KEV matches, ICS advisories and methodology.
    • Production environment set up on a TransIP VPS.