logo

Software supply chain security risks addressed in new Gartner® report

ID: 850d0624-bf43-5941-9b73-ba4c4f5bec9d

STIX ID: report--850d0624-bf43-5941-9b73-ba4c4f5bec9d

Feed Name: ReversingLabs Blog

Date Published: 2024-01-01

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

This article reviews Gartner’s October 2023 guidance on mitigating enterprise software supply chain risks, emphasizing third-party risk management based on secure development attestations (e.g., NIST SSDF), mandatory SBOMs for transparency, and adoption of automated tools to detect malware and tampering across first-, second-, and third-party code; it highlights the limitations of traditional AppSec tools, warns that vendors unwilling to provide SBOMs or secure development attestations pose disqualifying risk, cites incidents such as SolarWinds and 3CX as context, and notes ReversingLabs among vendors supporting automated code and binary analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.