Microsoft acquired ReFirm Labs Wednesday in a bid to bolster its operational technology security offerings.ReFirm provides drag-and-drop automated firmware analysis, which Microsoft hopes will provide security insight for industrial IoT products, where security personnel often struggle to look inside built-in hardware."I run vulnerability and pen testing for the operating system group at Microsoft, and the quality of reports that were coming out the ReFirm automated system was starting to rival the things that I would pay a highly-skilled professional to generate," said David Weston, Microsoft director of enterprise and OS security in Azure Edge and platform.Microsoft's ReFirm acquisition follows June's acquisition of CyberX, an agentless OT network defense system. Weston hopes that the products will synergistically bolster the defenses of industrial systems. And while much of Microsoft's announced focus has been on industrial IoT, he sees worthy uses for anything with firmware, including desktops.Department of Homeland Security named "vulnerabilities below the operating system" a key focus of future cybersecurity efforts. Thomas Ruoff and Boyden Rohner, methodology branch chief and associate director of CISA respectively, announced an agency campaign at the RSA Conference last month to increase firmware security.The Cybersecurity and Infrastructure Security Agency announcement specifically mentions automated code analysis as a key component, a goal Weston backs."Firmware is kind of the software that we politely ignore today," he said. "Mostly we don't have capabilities around it."
ReFirm was founded in 2017 as an offshoot of the popular open-source Binwalk product. Weston said he anticipated work on Binwalk would continue unabated.The ReFirm announcement comes less than a month after the Security Architecture, Cloud Security, Endpoint/Device Security, IoT, Governance, Risk and Compliance, Critical Infrastructure Security, ICS/SCADA, Endpoint/Device Security, Endpoint/Device Security, Endpoint/Device Security
Microsoft acquires firmware analysis company ReFirm, eying edge IoT security

Microsoft acquired ReFirm Labs Wednesday in a bid to bolster its operational technology security offerings. (Photo by Drew Angerer/Getty Images)
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds