

A survey of 400 platform and security engineers in the U.S and United Kingdom (UK), finds nearly three quarters (73%) are either only moderately confident (58%) or not confident (15%) in the ability of their existing tools for managing software artifacts to prevent attacks against their organization’s software supply chain.
Conducted by Cloudsmith, a provider of a platform for managing software artifacts, the survey also finds nearly half of respondents (48%) can identify an intrusion in their software supply chain but need to rely on manual efforts to enforce some type of quarantine or resolve the issue. Only 37% said they can automatically identify, block, and trace an intrusion within minutes.
As a result, nearly two thirds (65%) are either investigating a different approach to compliance (45%) or are evaluating some type of security framework (25%), the survey finds.
Cloudsmith CEO Glenn Weinstein said that as it becomes more apparent in the AI era that changes will be made to how software supply chains will need to be secured, there will be more focus on securing binaries after applications are deployed. Cybercriminals will increasingly target those binaries using cyberattacks that will be launched at machine speed. As such, more resources will need to be allocated to automating DevSecOps workflows within a curated repository that limits the number of potential vulnerabilities that might find their way into a software supply chain, noted Weinstein.
The challenge is that securing binaries is a much more complicated challenge than simply trying to fix issues at the source code level, he added.
Overall, the top three concerns are attacks exploiting AI-generated code to introduce malicious dependencies, followed by supply chain attacks blending into normal DevOps activities and automated systems modifying software at scale.
More challenging still, only 27% said they are very confident their organization could pass an unexpected audit of their software supply chain. On the plus side, however, 61% are at least moderately confident that AI coding tools are not introducing additional vulnerabilities into their software supply chains. However, only 32% said they are scanning the AI models they employ for specialized threats, compared to 41% that are scanning for basic integrity to, for example, verify checksums/provenance. Another 22% are relying on general security tools such as runtime monitoring. Half of respondents (50%) are relying on provenance or attestation data to validate software builds.
Additionally, a full 95% said they generate software bill of materials (SBOM) data but only 25% integrate and automate SBOM verification into security gatekeeping. Instead, three quarters (75%) said they use that data for ad hoc compliance only.
Finally, nearly half (49%) of respondents said their organizations will occasionally skip implementing a new security/developer feature, compared to 28% that admitted they do so regularly.
Ultimately, it’s not clear which teams have responsibility for securing software supply chains. More than three quarters of respondents said security is the function most concerned with dependency-led attacks. However, when asked where the decision to trust an open-source dependency should sit, nearly two in five (39%) put it with a centralized security, platform, or governance team. Another 37% said it is a shared responsibility with developers.
Regardless of who is ultimately held accountable for securing the software supply chain, the one thing that is certain is more cybercriminals than ever are discovering just how soft the underbelly of organizations that build and deploy software really is.