Synopsys
State of Software Supply Chain Security Risks
Pages
42
Time to read
39 mins
Publication
Language
English
Pages
42
Time to read
39 mins
Publication
Language
English
This research report by Ponemon Institute aims to assess the preparedness of organizations in mitigating software security risks within the supply chain. Conducted with 1,278 IT and security practitioners, the study reveals that a significant percentage of organizations have experienced software supply chain attacks, with 59% reporting such incidents. The report highlights that unpatched open source vulnerabilities and zero-day vulnerabilities are common root causes of these attacks. Recommendations for reducing risks include maintaining visibility of application components, managing open source dependencies, and continuously monitoring for new vulnerabilities. The report also discusses the importance of Software Bill of Materials (SBOM) in securing the software supply chain and emphasizes the need for organizations to automate evaluations of security risks associated with AI-generated code. Key findings indicate a lack of commitment from leadership towards reducing malicious code risks, and many organizations struggle with adequate resources for securing their software supply chains.