ICS Vendor Security Posture
Independent risk grades for 157 major ICS vendors, calculated from CISA advisory history.
How Grades Are Calculated
Each vendor is scored based on publicly available CISA ICS advisory data. A lower score = better security posture. This measures public vulnerability disclosure history — not a vendor's internal security investment.
A
Minimal History
Score 0–24
B
Below Average
Score 25–39
C
Average
Score 40–54
D
Elevated Risk
Score 55–69
F
High Risk
Score 70+
Score formula: advisory volume (40pts max) + critical ratio (25pts) + KEV count (20pts max) + avg CVSS (10pts) + recent activity (5pts). Higher advisory counts can reflect larger product portfolios, not just poor security practices.
Vendor Rankings
| Vendor ↕ | Grade ↕ | Risk Score ↕ | Advisories ↕ | Critical ↕ | KEV ↕ | Avg CVSS ↕ | Last Advisory |
|---|---|---|---|---|---|---|---|
| Rockwell Automation | F | 79.0 | 234 | 56 | 13 | 8.0 | 2026-03-20 |
| Hitachi Energy | F | 78.5 | 110 | 26 | 5 | 7.6 | 2026-04-02 |
| Schneider Electric | F | 78.0 | 140 | 31 | 5 | 7.5 | 2026-04-02 |
| Siemens | F | 75.8 | 1962 | 249 | 44 | 7.6 | 2026-04-14 |
| Delta Electronics | D | 65.4 | 95 | 17 | 2 | 7.9 | 2026-04-16 |
| Open Source | D | 63.4 | 224 | 28 | 2 | 7.3 | 2026-04-16 |
| Advantech | D | 62.9 | 78 | 36 | 1 | 8.4 | 2025-12-18 |
| Mitsubishi Electric | D | 62.4 | 108 | 25 | 1 | 7.6 | 2026-04-07 |
| Schneider Electric Software, LLC | D | 59.2 | 84 | 24 | 1 | 8.0 | 2022-12-13 |
| SUSE | D | 57.3 | 58 | 9 | 3 | 7.4 | 2026-04-14 |
| Microsoft | C | 48.6 | 39 | 7 | 3 | 7.6 | 2026-04-08 |
| ABB | C | 46.6 | 57 | 14 | 1 | 8.0 | 2025-11-06 |
| Debian | C | 45.7 | 29 | 7 | 3 | 8.2 | 2026-04-08 |
| Moxa | C | 44.0 | 48 | 22 | 0 | 8.5 | 2025-06-20 |
| C | 41.5 | 15 | 5 | 3 | 8.7 | 2026-04-08 | |
| Honeywell | C | 41.2 | 35 | 15 | 0 | 8.0 | 2026-03-26 |
| Sensormatic Electronics, LLC, Johnson Controls Inc. | C | 40.4 | 14 | 3 | 5 | 8.0 | 2022-08-30 |
| FESTO | C | 40.3 | 3 | 3 | 1 | 9.8 | 2026-03-17 |
| Fedora | B | 38.7 | 26 | 5 | 2 | 7.9 | 2026-04-14 |
| Red Hat | B | 38.1 | 43 | 7 | 0 | 7.5 | 2026-04-08 |
| Optigo Networks | B | 36.3 | 3 | 3 | 0 | 9.8 | 2025-05-06 |
| Philips | B | 36.3 | 39 | 3 | 1 | 5.9 | 2026-03-26 |
| PTC | B | 36.2 | 15 | 9 | 0 | 8.7 | 2026-03-26 |
| Dover Fueling Solutions | B | 36.1 | 3 | 3 | 0 | 9.6 | 2025-09-18 |
| Automated Logic | B | 36.0 | 3 | 3 | 0 | 9.5 | 2026-03-19 |
| InduSoft | B | 35.9 | 5 | 4 | 1 | 9.4 | 2025-06-18 |
| WAGO | B | 34.8 | 11 | 7 | 0 | 8.4 | 2026-03-26 |
| IBM | B | 34.2 | 33 | 7 | 0 | 7.4 | 2026-04-14 |
| ICONICS | B | 33.8 | 7 | 6 | 0 | 8.9 | 2025-06-09 |
| Emerson | B | 32.9 | 34 | 11 | 0 | 7.8 | 2025-11-20 |
| cPanel | B | 32.0 | 3 | 2 | 0 | 8.8 | 2026-03-31 |
| General Electric (GE) | B | 31.7 | 27 | 7 | 1 | 7.7 | 2022-11-22 |
| GE | B | 31.5 | 24 | 11 | 0 | 8.0 | 2025-06-18 |
| Yokogawa | B | 31.3 | 30 | 5 | 0 | 7.1 | 2026-04-02 |
| Cisco | B | 31.2 | 17 | 4 | 1 | 7.8 | 2026-04-06 |
| IGEL | B | 30.5 | 5 | 2 | 1 | 9.0 | 2026-04-01 |
| 7-Technologies | B | 29.7 | 4 | 3 | 0 | 9.0 | 2025-06-09 |
| AVEVA Software, LLC | B | 29.7 | 21 | 9 | 0 | 8.5 | 2023-04-03 |
| Amazon | B | 29.1 | 15 | 3 | 1 | 7.6 | 2026-03-31 |
| Weintek | B | 28.8 | 6 | 4 | 0 | 9.1 | 2026-01-22 |
| Phoenix Contact | B | 28.3 | 14 | 7 | 0 | 8.8 | 2026-03-17 |
| 3S-Smart Software Solutions GmbH | B | 28.0 | 11 | 6 | 0 | 8.9 | 2020-05-14 |
| Apple | B | 28.0 | 6 | 2 | 1 | 7.7 | 2026-03-24 |
| Sierra Wireless | B | 27.8 | 6 | 3 | 1 | 8.2 | 2025-06-06 |
| Korenix | B | 27.7 | 3 | 2 | 0 | 9.5 | 2025-06-06 |
| Baxter | B | 27.6 | 10 | 4 | 1 | 8.6 | 2025-06-06 |
| Elcomplus LLC | B | 27.6 | 3 | 2 | 0 | 9.5 | 2022-06-23 |
| CODESYS | B | 27.5 | 3 | 1 | 1 | 8.6 | 2026-03-23 |
| GE Healthcare | B | 27.5 | 3 | 2 | 0 | 9.3 | 2024-05-16 |
| mySCADA | B | 27.5 | 9 | 5 | 0 | 9.1 | 2025-02-13 |
| Sielco | B | 27.4 | 3 | 2 | 0 | 9.2 | 2025-06-09 |
| Oracle | B | 27.3 | 23 | 3 | 0 | 7.5 | 2026-04-06 |
| WellinTech | B | 27.3 | 11 | 6 | 0 | 8.1 | 2025-06-09 |
| Unitronics | B | 27.0 | 4 | 2 | 1 | 8.5 | 2025-06-09 |
| Hospira | B | 26.8 | 7 | 4 | 0 | 9.1 | 2025-06-09 |
| Rockwell Automation | B | 26.8 | 7 | 4 | 0 | 9.0 | 2023-11-14 |
| Sielco Sistemi | B | 26.8 | 3 | 2 | 0 | 8.6 | 2025-06-09 |
| Wind River | B | 26.6 | 3 | 2 | 0 | 8.5 | 2025-06-18 |
| Rockwell | B | 26.5 | 3 | 2 | 0 | 8.4 | 2025-08-14 |
| Westermo | B | 26.4 | 5 | 3 | 0 | 8.9 | 2025-06-05 |
| Festo | B | 26.3 | 10 | 5 | 0 | 8.8 | 2026-01-14 |
| Geutebrück | B | 26.3 | 5 | 3 | 0 | 8.8 | 2021-07-27 |
| Ubuntu | B | 26.2 | 23 | 2 | 0 | 7.5 | 2026-04-07 |
| AVEVA | B | 25.8 | 18 | 3 | 0 | 7.7 | 2026-04-16 |
| Apache | B | 25.5 | 15 | 1 | 1 | 7.3 | 2026-04-16 |
| Emerson Process Management | B | 25.5 | 3 | 2 | 0 | 7.4 | 2025-06-06 |
| RESF | B | 25.2 | 21 | 2 | 0 | 7.4 | 2026-04-06 |
| Exacq Technologies, Johnson Controls Inc. | B | 25.0 | 9 | 2 | 2 | 7.0 | 2021-12-23 |
| Samsung | A | 24.9 | 6 | 2 | 0 | 8.6 | 2026-04-06 |
| Invensys | A | 24.8 | 11 | 5 | 0 | 8.0 | 2025-06-17 |
| AutomationDirect | A | 24.3 | 9 | 4 | 0 | 8.7 | 2026-01-22 |
| Red Lion, AutomationDirect | A | 24.2 | 6 | 3 | 0 | 8.7 | 2022-11-17 |
| Horner Automation | A | 24.1 | 16 | 2 | 0 | 8.0 | 2026-04-16 |
| Johnson Controls Inc. | A | 24.1 | 16 | 5 | 0 | 8.3 | 2026-03-05 |
| Mozilla | A | 24.1 | 3 | 1 | 0 | 9.3 | 2026-04-07 |
| Fortinet | A | 23.9 | 11 | 1 | 1 | 7.1 | 2026-04-14 |
| Fuji Electric | A | 23.9 | 29 | 2 | 0 | 7.7 | 2025-12-16 |
| Hitachi | A | 23.5 | 3 | 1 | 0 | 8.6 | 2026-03-26 |
| PHOENIX CONTACT, Innominate Security Technologies | A | 23.5 | 10 | 4 | 0 | 8.5 | 2019-01-24 |
| Mitsubishi Electric Corporation | A | 23.4 | 13 | 5 | 0 | 7.3 | 2025-09-09 |
| Softing | A | 23.3 | 4 | 2 | 0 | 8.8 | 2024-03-14 |
| Ecava | A | 23.2 | 10 | 4 | 0 | 8.2 | 2025-06-09 |
| Mitsubishi Electric Iconics Digital Solutions | A | 23.2 | 8 | 2 | 0 | 7.9 | 2026-04-07 |
| Omron | A | 23.2 | 28 | 2 | 0 | 7.4 | 2023-09-19 |
| CODESYS, GmbH | A | 23.0 | 6 | 3 | 0 | 7.5 | 2023-08-24 |
| Devolutions | A | 22.8 | 3 | 1 | 0 | 8.0 | 2026-04-01 |
| Automation Direct | A | 22.7 | 7 | 3 | 0 | 8.4 | 2022-07-21 |
| Grafana | A | 22.5 | 3 | 1 | 0 | 7.7 | 2026-03-29 |
| ARC Informatique | A | 22.0 | 4 | 2 | 0 | 7.5 | 2025-06-09 |
| VISAM | A | 21.1 | 3 | 1 | 1 | 7.3 | 2023-04-03 |
| Lantronix | A | 20.5 | 5 | 2 | 0 | 8.0 | 2026-03-10 |
| VMware Tanzu | A | 20.4 | 5 | 1 | 0 | 7.9 | 2026-04-09 |
| Becton, Dickinson and Company (BD) | A | 20.3 | 22 | 2 | 0 | 7.0 | 2025-01-28 |
| OSIsoft LLC | A | 19.3 | 18 | 2 | 0 | 7.5 | 2021-11-09 |
| Checkmk | A | 19.2 | 8 | 1 | 0 | 7.1 | 2026-04-09 |
| Medtronic | A | 19.2 | 14 | 3 | 0 | 6.8 | 2025-07-24 |
| Cognex | A | 19.0 | 3 | 1 | 0 | 9.1 | 2025-09-18 |
| Dell | A | 18.8 | 7 | 1 | 0 | 6.7 | 2026-04-09 |
| Johnson Controls | A | 18.3 | 10 | 2 | 0 | 8.3 | 2026-03-05 |
| B. Braun Medical | A | 18.2 | 3 | 1 | 0 | 8.4 | 2021-10-21 |
| MOXA | A | 18.2 | 3 | 1 | 0 | 8.4 | 2025-06-06 |
| Open Automation Software | A | 17.9 | 3 | 1 | 0 | 8.1 | 2025-06-09 |
| Dingtian | A | 17.6 | 3 | 1 | 0 | 7.7 | 2025-09-25 |
| Inductive Automation | A | 17.6 | 8 | 2 | 0 | 7.3 | 2026-03-13 |
| XZERES | A | 17.6 | 3 | 1 | 0 | 7.8 | 2025-06-06 |
| Beckhoff | A | 17.1 | 3 | 1 | 0 | 7.3 | 2025-06-09 |
| Schneider Electric | A | 16.8 | 4 | 1 | 0 | 8.6 | 2023-10-17 |
| Johnson Controls, Inc. | A | 16.7 | 10 | 2 | 0 | 6.7 | 2026-02-26 |
| Motorola Solutions | A | 16.6 | 4 | 1 | 0 | 8.4 | 2024-06-13 |
| FATEK Automation | A | 16.3 | 13 | 1 | 0 | 7.9 | 2025-06-05 |
| GE Digital | A | 16.2 | 4 | 1 | 0 | 8.0 | 2023-08-31 |
| Cogent Real-Time Systems | A | 16.0 | 4 | 1 | 0 | 7.8 | 2025-06-09 |
| Intel | A | 15.6 | 5 | 0 | 0 | 8.1 | 2026-04-08 |
| Triangle MicroWorks | A | 15.6 | 4 | 1 | 0 | 7.4 | 2025-06-09 |
| AzeoTech | A | 15.5 | 5 | 1 | 0 | 8.0 | 2026-01-12 |
| Opto 22 | A | 15.5 | 5 | 1 | 0 | 8.0 | 2025-11-25 |
| Progea | A | 15.5 | 4 | 1 | 0 | 7.2 | 2025-06-12 |
| Johnson Controls Inc | A | 15.4 | 16 | 0 | 0 | 7.4 | 2022-10-04 |
| B&R Industrial Automation | A | 15.3 | 5 | 1 | 0 | 7.8 | 2023-03-29 |
| WECON | A | 15.3 | 16 | 0 | 0 | 7.3 | 2025-06-25 |
| WatchGuard | A | 15.3 | 4 | 0 | 0 | 8.3 | 2026-04-01 |
| FasterXML | A | 15.2 | 3 | 0 | 0 | 8.7 | 2026-04-06 |
| Adobe | A | 15.1 | 5 | 0 | 0 | 7.6 | 2026-04-09 |
| MatrikonOPC | A | 14.6 | 5 | 1 | 0 | 7.1 | 2025-06-06 |
| Trane | A | 14.5 | 6 | 1 | 0 | 7.3 | 2026-03-12 |
| OpenBSD | A | 14.3 | 8 | 0 | 0 | 5.3 | 2026-04-14 |
| HMS Networks | A | 13.9 | 5 | 1 | 0 | 6.4 | 2025-01-23 |
| Tridium | A | 13.8 | 6 | 1 | 0 | 6.6 | 2025-06-18 |
| Eclipse | A | 13.6 | 4 | 0 | 0 | 6.6 | 2026-04-08 |
| MariaDB | A | 13.3 | 3 | 0 | 0 | 6.8 | 2026-04-06 |
| Eaton | A | 13.2 | 13 | 0 | 0 | 6.7 | 2025-06-09 |
| Innominate | A | 12.8 | 5 | 0 | 1 | 6.3 | 2025-06-06 |
| Palo Alto Networks | A | 12.2 | 3 | 0 | 0 | 5.7 | 2026-04-08 |
| National Instruments | A | 11.8 | 8 | 0 | 0 | 7.8 | 2025-12-18 |
| Santesoft | A | 11.3 | 7 | 0 | 0 | 7.8 | 2025-08-12 |
| Subnet Solutions Inc. | A | 11.1 | 7 | 0 | 0 | 7.6 | 2025-05-06 |
| MicroDicom | A | 10.5 | 5 | 0 | 0 | 8.0 | 2025-06-10 |
| OSIsoft | A | 10.2 | 7 | 0 | 0 | 6.7 | 2025-06-09 |
| Atlassian | A | 9.8 | 3 | 0 | 0 | 8.3 | 2026-03-19 |
| Measuresoft | A | 9.7 | 5 | 0 | 0 | 7.2 | 2025-06-05 |
| Ashlar-Vellum | A | 9.3 | 3 | 0 | 0 | 7.8 | 2025-11-25 |
| SpiderControl | A | 9.3 | 6 | 0 | 0 | 6.3 | 2023-06-23 |
| IOServer | A | 9.0 | 5 | 0 | 0 | 6.5 | 2025-06-19 |
| ICONICS, Mitsubishi Electric | A | 8.9 | 4 | 0 | 0 | 6.9 | 2023-08-17 |
| Panasonic | A | 8.9 | 5 | 0 | 0 | 6.4 | 2025-06-05 |
| LCDS - Leão Consultoria e Desenvolvimento de Sistemas Ltda ME | A | 8.7 | 4 | 0 | 0 | 6.7 | 2020-04-28 |
| PEPPERL+FUCHS | A | 8.6 | 5 | 0 | 0 | 6.1 | 2025-06-06 |
| JTEKT Corporation | A | 8.5 | 4 | 0 | 0 | 6.5 | 2022-06-21 |
| MICROSYS | A | 8.3 | 4 | 0 | 0 | 6.3 | 2025-06-09 |
| Automated Logic Corporation (ALC) | A | 8.2 | 3 | 0 | 0 | 6.7 | 2022-04-19 |
| Elipse | A | 7.8 | 3 | 0 | 0 | 6.3 | 2025-06-06 |
| HID Global | A | 7.7 | 3 | 0 | 0 | 6.2 | 2024-02-06 |
| Schweitzer Engineering Laboratories | A | 7.2 | 3 | 0 | 0 | 5.7 | 2025-06-06 |
| Mattermost | A | 7.1 | 3 | 0 | 0 | 5.6 | 2026-03-16 |
| Proxmox | A | 6.5 | 3 | 0 | 0 | 0 | 2026-04-08 |
| SmarterTools | A | 6.5 | 3 | 0 | 0 | 0 | 2026-03-26 |
| Codewrights | A | 4.1 | 4 | 0 | 0 | 2.1 | 2025-06-06 |
Monitor Your Vendors
Get alerts when your vendors release new advisories
Add vendors to your watchlist and receive filtered email alerts with CVSS scores, CVE details, and remediation steps.
Start Free Trial → See Pricing