logo

Complexity and software supply chain security: 5 key survey takeaways

ID: fc9b4a09-d860-52bc-ab1a-19e4a8763216

STIX ID: report--fc9b4a09-d860-52bc-ab1a-19e4a8763216

Feed Name: ReversingLabs Blog

Date Published: 2024-02-15

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

An ESG study of 368 security, IT, and development professionals reports that 91% of organizations experienced software supply chain incidents in the past year—most often zero-day exploits in third-party code, misconfigured cloud services, open-source component exploits, stolen secrets from repositories, and API breaches. Despite many claiming “robust” capabilities, respondents struggle with continuous discovery, accurate inventories of third-party APIs and cloud services, and especially creating and maintaining SBOMs (only 22% use SBOM tools, and most find them challenging). The report recommends optimizing DevSec efficiency, empowering developers to shift security left, and investing in OSS/library scanning, API inspection, runtime/production scanning, and complex binary analysis aligned with frameworks like NIST SSDF and NSA/CISA guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.