logo

What SolarWinds Tells Us About Securing the Software Development Supply Chain

ID: a3061074-92e5-5fe7-bc64-32b5b8a18a6c

STIX ID: report--a3061074-92e5-5fe7-bc64-32b5b8a18a6c

Feed Name: Security Ledger

Date Published: 2021-06-07

Date Updated: 2026-04-26

Author: Brian Trzupek

...
...

This sponsored article uses the SolarWinds supply-chain breach as a cautionary example to urge organizations to modernize code signing practices. It recommends centralized and automated code-signing management (including code-signing-as-a-service), permission-based access controls, separating signing keys per team, shorter certificate lifetimes and rotation, offline/virtual HSM storage for keys, and integrating signing into CI/CD pipelines to reduce the risk of compromised updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.