Complexity and software supply chain security: 5 key survey takeaways
ID: fc9b4a09-d860-52bc-ab1a-19e4a8763216
STIX ID: report--fc9b4a09-d860-52bc-ab1a-19e4a8763216
Feed Name: ReversingLabs Blog
Date Published: 2024-02-15
Date Updated: 2026-04-29
Author: [email protected] (John P. Mello Jr.)
An ESG study of 368 security, IT, and development professionals reports that 91% of organizations experienced software supply chain incidents in the past year—most often zero-day exploits in third-party code, misconfigured cloud services, open-source component exploits, stolen secrets from repositories, and API breaches. Despite many claiming “robust” capabilities, respondents struggle with continuous discovery, accurate inventories of third-party APIs and cloud services, and especially creating and maintaining SBOMs (only 22% use SBOM tools, and most find them challenging). The report recommends optimizing DevSec efficiency, empowering developers to shift security left, and investing in OSS/library scanning, API inspection, runtime/production scanning, and complex binary analysis aligned with frameworks like NIST SSDF and NSA/CISA guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
