ICS Vendor Security Posture
Independent risk grades for 169 major ICS vendors, calculated from CISA advisory history.
How Grades Are Calculated
Each vendor is scored based on publicly available CISA ICS advisory data. A lower score = better security posture. This measures public vulnerability disclosure history — not a vendor's internal security investment.
A
Minimal History
Score 0–24
B
Below Average
Score 25–39
C
Average
Score 40–54
D
Elevated Risk
Score 55–69
F
High Risk
Score 70+
Score formula: advisory volume (40pts max) + critical ratio (25pts) + KEV count (20pts max) + avg CVSS (10pts) + recent activity (5pts). Higher advisory counts can reflect larger product portfolios, not just poor security practices.
Vendor Rankings
| Vendor ↕ | Grade ↕ | Risk Score ↕ | Advisories ↕ | Critical ↕ | KEV ↕ | Avg CVSS ↕ | Last Advisory |
|---|---|---|---|---|---|---|---|
| Hitachi Energy | F | 78.4 | 112 | 26 | 5 | 7.6 | 2026-05-21 |
| Schneider Electric | F | 77.9 | 142 | 31 | 5 | 7.5 | 2026-06-02 |
| Siemens | F | 75.9 | 2007 | 258 | 45 | 7.7 | 2026-06-02 |
| Rockwell Automation | F | 74.0 | 234 | 56 | 13 | 8.0 | 2026-03-20 |
| Open Source | F | 70.6 | 328 | 31 | 4 | 7.3 | 2026-06-01 |
| Advantech | D | 62.9 | 78 | 36 | 1 | 8.4 | 2025-12-18 |
| ABB | D | 62.4 | 81 | 18 | 1 | 7.9 | 2026-05-28 |
| Mitsubishi Electric | D | 62.4 | 108 | 25 | 1 | 7.6 | 2026-05-28 |
| Delta Electronics | D | 60.4 | 95 | 17 | 2 | 7.9 | 2026-04-16 |
| Schneider Electric Software, LLC | D | 59.2 | 84 | 24 | 1 | 8.0 | 2022-12-13 |
| SUSE | C | 53.2 | 60 | 9 | 3 | 7.4 | 2026-04-27 |
| Microsoft | C | 52.5 | 47 | 8 | 3 | 7.7 | 2026-05-26 |
| Red Hat | C | 45.4 | 58 | 9 | 0 | 7.5 | 2026-05-14 |
| Moxa | C | 44.2 | 49 | 22 | 0 | 8.5 | 2026-04-26 |
| Debian | C | 41.0 | 30 | 7 | 3 | 8.1 | 2026-04-29 |
| Sensormatic Electronics, LLC, Johnson Controls Inc. | C | 40.4 | 14 | 3 | 5 | 8.0 | 2022-08-30 |
| FESTO | C | 40.3 | 3 | 3 | 1 | 9.8 | 2026-03-17 |
| B | 36.6 | 17 | 5 | 3 | 8.7 | 2026-04-28 | |
| Optigo Networks | B | 36.3 | 3 | 3 | 0 | 9.8 | 2025-05-06 |
| Honeywell | B | 36.2 | 35 | 15 | 0 | 8.0 | 2026-03-26 |
| Dover Fueling Solutions | B | 36.1 | 3 | 3 | 0 | 9.6 | 2025-09-18 |
| Automated Logic | B | 36.0 | 3 | 3 | 0 | 9.5 | 2026-03-19 |
| InduSoft | B | 35.9 | 5 | 4 | 1 | 9.4 | 2025-06-18 |
| IBM | B | 34.5 | 34 | 7 | 0 | 7.4 | 2026-05-17 |
| Fedora | B | 34.3 | 28 | 5 | 2 | 7.9 | 2026-05-03 |
| ICONICS | B | 33.8 | 7 | 6 | 0 | 8.9 | 2025-06-09 |
| Emerson | B | 32.9 | 34 | 11 | 0 | 7.8 | 2025-11-20 |
| Apache | B | 32.4 | 26 | 3 | 1 | 7.5 | 2026-05-31 |
| General Electric (GE) | B | 31.7 | 27 | 7 | 1 | 7.7 | 2022-11-22 |
| GE | B | 31.5 | 24 | 11 | 0 | 8.0 | 2025-06-18 |
| Philips | B | 31.3 | 39 | 3 | 1 | 5.9 | 2026-03-26 |
| PTC | B | 31.2 | 15 | 9 | 0 | 8.7 | 2026-03-26 |
| WAGO | B | 29.8 | 11 | 7 | 0 | 8.4 | 2026-03-26 |
| 7-Technologies | B | 29.7 | 4 | 3 | 0 | 9.0 | 2025-06-09 |
| AVEVA Software, LLC | B | 29.7 | 21 | 9 | 0 | 8.5 | 2023-04-03 |
| Oracle | B | 29.5 | 26 | 4 | 0 | 7.6 | 2026-05-21 |
| Fuji Electric | B | 29.3 | 30 | 2 | 0 | 7.7 | 2026-05-12 |
| Johnson Controls Inc. | B | 29.2 | 17 | 5 | 0 | 8.4 | 2026-05-05 |
| Weintek | B | 28.8 | 6 | 4 | 0 | 9.1 | 2026-01-22 |
| Phoenix Contact | B | 28.3 | 14 | 7 | 0 | 8.8 | 2026-03-17 |
| 3S-Smart Software Solutions GmbH | B | 28.0 | 11 | 6 | 0 | 8.9 | 2020-05-14 |
| Sierra Wireless | B | 27.8 | 6 | 3 | 1 | 8.2 | 2025-06-06 |
| Korenix | B | 27.7 | 3 | 2 | 0 | 9.5 | 2025-06-06 |
| Baxter | B | 27.6 | 10 | 4 | 1 | 8.6 | 2025-06-06 |
| Elcomplus LLC | B | 27.6 | 3 | 2 | 0 | 9.5 | 2022-06-23 |
| GE Healthcare | B | 27.5 | 3 | 2 | 0 | 9.3 | 2024-05-16 |
| mySCADA | B | 27.5 | 9 | 5 | 0 | 9.1 | 2025-02-13 |
| Sielco | B | 27.4 | 3 | 2 | 0 | 9.2 | 2025-06-09 |
| WellinTech | B | 27.3 | 11 | 6 | 0 | 8.1 | 2025-06-09 |
| Unitronics | B | 27.0 | 4 | 2 | 1 | 8.5 | 2025-06-09 |
| Hospira | B | 26.8 | 7 | 4 | 0 | 9.1 | 2025-06-09 |
| Rockwell Automation | B | 26.8 | 7 | 4 | 0 | 9.0 | 2023-11-14 |
| Sielco Sistemi | B | 26.8 | 3 | 2 | 0 | 8.6 | 2025-06-09 |
| Wind River | B | 26.6 | 3 | 2 | 0 | 8.5 | 2025-06-18 |
| Rockwell | B | 26.5 | 3 | 2 | 0 | 8.4 | 2025-08-14 |
| Westermo | B | 26.4 | 5 | 3 | 0 | 8.9 | 2025-06-05 |
| Festo | B | 26.3 | 10 | 5 | 0 | 8.8 | 2026-01-14 |
| Geutebrück | B | 26.3 | 5 | 3 | 0 | 8.8 | 2021-07-27 |
| Yokogawa | B | 26.3 | 30 | 5 | 0 | 7.1 | 2026-04-02 |
| Cisco | B | 26.2 | 17 | 4 | 1 | 7.8 | 2026-04-06 |
| CODESYS | B | 25.9 | 4 | 1 | 1 | 8.6 | 2026-05-25 |
| Emerson Process Management | B | 25.5 | 3 | 2 | 0 | 7.4 | 2025-06-06 |
| Exacq Technologies, Johnson Controls Inc. | B | 25.0 | 9 | 2 | 2 | 7.0 | 2021-12-23 |
| Invensys | A | 24.8 | 11 | 5 | 0 | 8.0 | 2025-06-17 |
| Amazon | A | 24.3 | 16 | 3 | 1 | 7.6 | 2026-04-29 |
| AutomationDirect | A | 24.3 | 9 | 4 | 0 | 8.7 | 2026-01-22 |
| IGEL | A | 24.3 | 6 | 2 | 1 | 9.0 | 2026-04-29 |
| Medtronic | A | 24.3 | 14 | 3 | 0 | 7.0 | 2026-05-07 |
| Red Lion, AutomationDirect | A | 24.2 | 6 | 3 | 0 | 8.7 | 2022-11-17 |
| Samsung | A | 23.9 | 6 | 2 | 1 | 8.6 | 2026-04-06 |
| PHOENIX CONTACT, Innominate Security Technologies | A | 23.5 | 10 | 4 | 0 | 8.5 | 2019-01-24 |
| Mitsubishi Electric Corporation | A | 23.4 | 13 | 5 | 0 | 7.3 | 2025-09-09 |
| Softing | A | 23.3 | 4 | 2 | 0 | 8.8 | 2024-03-14 |
| cPanel | A | 23.3 | 4 | 2 | 0 | 8.8 | 2026-04-28 |
| Ecava | A | 23.2 | 10 | 4 | 0 | 8.2 | 2025-06-09 |
| Omron | A | 23.2 | 28 | 2 | 0 | 7.4 | 2023-09-19 |
| CODESYS, GmbH | A | 23.0 | 6 | 3 | 0 | 7.5 | 2023-08-24 |
| Automation Direct | A | 22.7 | 7 | 3 | 0 | 8.4 | 2022-07-21 |
| Aruba | A | 22.4 | 3 | 1 | 0 | 7.6 | 2026-05-12 |
| Citrix Systems | A | 22.4 | 3 | 1 | 1 | 8.6 | 2026-04-28 |
| RESF | A | 22.3 | 23 | 3 | 0 | 7.5 | 2026-04-29 |
| n8n | A | 22.3 | 4 | 1 | 0 | 9.1 | 2026-05-12 |
| Apple | A | 22.1 | 7 | 2 | 1 | 7.5 | 2026-04-22 |
| ARC Informatique | A | 22.0 | 4 | 2 | 0 | 7.5 | 2025-06-09 |
| Hitachi | A | 21.9 | 4 | 1 | 0 | 8.6 | 2026-05-25 |
| B&R | A | 21.4 | 4 | 1 | 0 | 8.1 | 2026-05-26 |
| Mozilla | A | 21.2 | 5 | 1 | 0 | 8.7 | 2026-05-25 |
| Ubuntu | A | 21.2 | 23 | 2 | 0 | 7.5 | 2026-04-07 |
| VISAM | A | 21.1 | 3 | 1 | 1 | 7.3 | 2023-04-03 |
| AVEVA | A | 20.8 | 18 | 3 | 0 | 7.7 | 2026-04-16 |
| Lantronix | A | 20.5 | 5 | 2 | 0 | 8.0 | 2026-03-10 |
| Becton, Dickinson and Company (BD) | A | 20.3 | 22 | 2 | 0 | 7.0 | 2025-01-28 |
| Synology | A | 19.6 | 3 | 1 | 0 | 9.8 | 2026-04-23 |
| OSIsoft LLC | A | 19.3 | 18 | 2 | 0 | 7.5 | 2021-11-09 |
| Horner Automation | A | 19.1 | 16 | 2 | 0 | 8.0 | 2026-04-16 |
| Cognex | A | 19.0 | 3 | 1 | 0 | 9.1 | 2025-09-18 |
| Fortinet | A | 18.9 | 11 | 1 | 1 | 7.1 | 2026-04-14 |
| HCL | A | 18.8 | 3 | 1 | 0 | 9.0 | 2026-04-20 |
| Schneider Electric | A | 18.5 | 3 | 1 | 0 | 8.7 | 2023-10-17 |
| Johnson Controls | A | 18.3 | 10 | 2 | 0 | 8.3 | 2026-03-05 |
| B. Braun Medical | A | 18.2 | 3 | 1 | 0 | 8.4 | 2021-10-21 |
| MOXA | A | 18.2 | 3 | 1 | 0 | 8.4 | 2025-06-06 |
| Mitsubishi Electric Iconics Digital Solutions | A | 18.2 | 8 | 2 | 0 | 7.9 | 2026-04-07 |
| Open Automation Software | A | 17.9 | 3 | 1 | 0 | 8.1 | 2025-06-09 |
| Dingtian | A | 17.6 | 3 | 1 | 0 | 7.7 | 2025-09-25 |
| Inductive Automation | A | 17.6 | 8 | 2 | 0 | 7.3 | 2026-03-13 |
| XZERES | A | 17.6 | 3 | 1 | 0 | 7.8 | 2025-06-06 |
| Grafana | A | 17.5 | 3 | 1 | 0 | 7.7 | 2026-03-29 |
| Beckhoff | A | 17.1 | 3 | 1 | 0 | 7.3 | 2025-06-09 |
| Johnson Controls, Inc. | A | 16.7 | 10 | 2 | 0 | 6.7 | 2026-02-26 |
| Subnet Solutions Inc. | A | 16.7 | 8 | 0 | 0 | 7.7 | 2026-05-12 |
| Motorola Solutions | A | 16.6 | 4 | 1 | 0 | 8.4 | 2024-06-13 |
| FATEK Automation | A | 16.3 | 13 | 1 | 0 | 7.9 | 2025-06-05 |
| Devolutions | A | 16.2 | 4 | 1 | 0 | 8.0 | 2026-04-28 |
| GE Digital | A | 16.2 | 4 | 1 | 0 | 8.0 | 2023-08-31 |
| Intel | A | 16.1 | 6 | 0 | 0 | 8.1 | 2026-05-25 |
| Cogent Real-Time Systems | A | 16.0 | 4 | 1 | 0 | 7.8 | 2025-06-09 |
| Triangle MicroWorks | A | 15.6 | 4 | 1 | 0 | 7.4 | 2025-06-09 |
| AzeoTech | A | 15.5 | 5 | 1 | 0 | 8.0 | 2026-01-12 |
| Opto 22 | A | 15.5 | 5 | 1 | 0 | 8.0 | 2025-11-25 |
| Progea | A | 15.5 | 4 | 1 | 0 | 7.2 | 2025-06-12 |
| Johnson Controls Inc | A | 15.4 | 16 | 0 | 0 | 7.4 | 2022-10-04 |
| B&R Industrial Automation | A | 15.3 | 5 | 1 | 0 | 7.8 | 2023-03-29 |
| WECON | A | 15.3 | 16 | 0 | 0 | 7.3 | 2025-06-25 |
| VMware Tanzu | A | 15.1 | 6 | 1 | 0 | 7.9 | 2026-04-23 |
| MatrikonOPC | A | 14.6 | 5 | 1 | 0 | 7.1 | 2025-06-06 |
| Trane | A | 14.5 | 6 | 1 | 0 | 7.3 | 2026-03-12 |
| Ashlar-Vellum | A | 14.3 | 3 | 0 | 0 | 7.8 | 2026-05-12 |
| Checkmk | A | 14.2 | 8 | 1 | 0 | 7.1 | 2026-04-09 |
| TYPO3 | A | 14.2 | 3 | 0 | 0 | 7.7 | 2026-05-18 |
| Golang | A | 14.0 | 3 | 0 | 0 | 7.5 | 2026-05-25 |
| Dell | A | 13.9 | 8 | 1 | 0 | 6.7 | 2026-04-28 |
| HMS Networks | A | 13.9 | 5 | 1 | 0 | 6.4 | 2025-01-23 |
| Tridium | A | 13.8 | 6 | 1 | 0 | 6.6 | 2025-06-18 |
| Mattermost | A | 13.6 | 6 | 0 | 0 | 5.6 | 2026-05-17 |
| Eaton | A | 13.2 | 13 | 0 | 0 | 6.7 | 2025-06-09 |
| Innominate | A | 12.8 | 5 | 0 | 1 | 6.3 | 2025-06-06 |
| Znuny | A | 12.6 | 3 | 0 | 0 | 6.1 | 2026-05-27 |
| National Instruments | A | 11.8 | 8 | 0 | 0 | 7.8 | 2025-12-18 |
| Santesoft | A | 11.3 | 7 | 0 | 0 | 7.8 | 2025-08-12 |
| MicroDicom | A | 10.5 | 5 | 0 | 0 | 8.0 | 2025-06-10 |
| Atlassian | A | 10.3 | 4 | 0 | 0 | 8.3 | 2026-04-21 |
| WatchGuard | A | 10.3 | 4 | 0 | 0 | 8.3 | 2026-04-01 |
| FasterXML | A | 10.2 | 3 | 0 | 0 | 8.7 | 2026-04-06 |
| OSIsoft | A | 10.2 | 7 | 0 | 0 | 6.7 | 2025-06-09 |
| SmarterTools | A | 10.2 | 4 | 0 | 0 | 8.2 | 2026-04-27 |
| Adobe | A | 10.1 | 5 | 0 | 0 | 7.6 | 2026-04-09 |
| Measuresoft | A | 9.7 | 5 | 0 | 0 | 7.2 | 2025-06-05 |
| OpenBSD | A | 9.3 | 8 | 0 | 0 | 5.3 | 2026-04-14 |
| SpiderControl | A | 9.3 | 6 | 0 | 0 | 6.3 | 2023-06-23 |
| IOServer | A | 9.0 | 5 | 0 | 0 | 6.5 | 2025-06-19 |
| ICONICS, Mitsubishi Electric | A | 8.9 | 4 | 0 | 0 | 6.9 | 2023-08-17 |
| Panasonic | A | 8.9 | 5 | 0 | 0 | 6.4 | 2025-06-05 |
| Octopus Deploy | A | 8.8 | 3 | 0 | 0 | 2.3 | 2026-06-02 |
| LCDS - Leão Consultoria e Desenvolvimento de Sistemas Ltda ME | A | 8.7 | 4 | 0 | 0 | 6.7 | 2020-04-28 |
| Eclipse | A | 8.6 | 4 | 0 | 0 | 6.6 | 2026-04-08 |
| PEPPERL+FUCHS | A | 8.6 | 5 | 0 | 0 | 6.1 | 2025-06-06 |
| JTEKT Corporation | A | 8.5 | 4 | 0 | 0 | 6.5 | 2022-06-21 |
| Docker | A | 8.3 | 3 | 0 | 0 | 6.8 | 2026-04-23 |
| MICROSYS | A | 8.3 | 4 | 0 | 0 | 6.3 | 2025-06-09 |
| MariaDB | A | 8.3 | 3 | 0 | 0 | 6.8 | 2026-04-06 |
| Automated Logic Corporation (ALC) | A | 8.2 | 3 | 0 | 0 | 6.7 | 2022-04-19 |
| SonicWall | A | 7.9 | 3 | 0 | 0 | 6.4 | 2026-04-29 |
| Elipse | A | 7.8 | 3 | 0 | 0 | 6.3 | 2025-06-06 |
| HID Global | A | 7.7 | 3 | 0 | 0 | 6.2 | 2024-02-06 |
| Palo Alto Networks | A | 7.2 | 3 | 0 | 0 | 5.7 | 2026-04-08 |
| Schweitzer Engineering Laboratories | A | 7.2 | 3 | 0 | 0 | 5.7 | 2025-06-06 |
| Codewrights | A | 4.1 | 4 | 0 | 0 | 2.1 | 2025-06-06 |
| Proxmox | A | 2.0 | 4 | 0 | 0 | 0 | 2026-04-23 |
Monitor Your Vendors
Get alerts when your vendors release new advisories
Add vendors to your watchlist and receive filtered email alerts with CVSS scores, CVE details, and remediation steps.
Start Free Trial → See Pricing