Keywords: Industrial Cybersecurity, Provenance, Supply Chain Cybersecurity, HBOM, SBOM, Power Inverters, Large Power Transformers
Overview
If you’ve ever bought antiques, you’re probably familiar with the concept of provenance. I have relatives that own a dresser that was once owned by George Washington. How do we know this? Because of the authenticated documentation that came with the dresser proving its origin. This is provenance – proving and documenting where something came from, what it contains, and the path it took before it wound up in your possession.
Heavy assets in industrial automation are a lot more complex than antiques, and the stakes are a lot higher, as we saw recently with the story about cellular powered kill switches found in Chinese manufactured power inverters used in solar and wind farms. In addition to being used around the world for renewable power applications, these inverters are also used in batteries, heat pumps, EV chargers, and other assets.
It’s typical for these products to have remote access capabilities, but these connections are normally handled through firewalls. You may have read the story about Chinese manufactured cranes that have remote connectivity capabilities but are largely unsecured. Many end users were not even aware of these remote communication capabilities, or if they were, they were improperly secured. If your assets come with features and functions that present a potential cybersecurity risk to your enterprise and you don’t address it or are not aware of it even though it is documented, that’s ultimately your responsibility, not the vendor’s.
The Problem of Rogue Components
It’s not always obvious what all the components are in an asset, be they hardware or software. The more complex the asset, the more complicated the issue becomes. In the case of the power inverters, the communication devices were undocumented, and asset owners did not even know they were there. The devices were found by a US-based team of experts whose job was to strip these assets down and identify their components. According to a Reuters article the “rogue components provide additional, undocumented communication channels that could allow firewalls to be circumvented remotely, with potentially catastrophic consequences.”
What Is Provenance in Cybersecurity?
In the world of cybersecurity, provenance is more than just the source of origin. According to NIST, provenance is “The chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include personnel and processes used to interact with or make modifications to the system, component, or associated data.” So, it’s more than just where the product came from, it includes all the associated data about what the asset or “component” contains from both a hardware and software standpoint.

ARC Advisory Group clients can view the complete report at the ARC Client Portal.
Contact Us if you would like to speak with the author.
Obtain more ARC In-depth Research Market Analysis.