‘Good, fast, cheap... Pick two’: Software quality dilemma forces risky decisions
ID: 77472ee7-76fc-559c-b0bd-f0e940f05fd0
STIX ID: report--77472ee7-76fc-559c-b0bd-f0e940f05fd0
Feed Name: ReversingLabs Blog
Date Published: 2024-09-26
Date Updated: 2026-04-29
Author: [email protected] (Ericka Chickowski)
This article analyzes how the software development "iron triangle" (good, fast, cheap) shapes security outcomes in commercial software, highlighting vendor opacity and the need for organizations to continuously validate third‑party risk using contextual, risk-based testing such as SBOMs and binary analysis. It urges embedding these results into vendor management to drive accountability and applying mitigating controls when vendors cannot or will not remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
