Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 16 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Most Companies Affected by Software Supply Chain Attacks in the Last Year, Struggling to Detect and React Effectively

by The Gurus
May 16, 2024
in News
secure-software-supply-chain-feature
Share on FacebookShare on Twitter

Over the past year, a significant portion of global organisations (54%) experienced software supply chain attacks, with many struggling to adapt to the escalating risk environment. These findings stem from ‘The State of Software Supply Chain Security Risk’ report, released today by Synopsys in collaboration with the Ponemon Institute. The report highlights that half of the organisations took more than a month to respond to such attacks, and one in five admit their detection and response capabilities are ineffective.

Furthermore, the report underscores the pervasive integration of AI across the software development lifecycle. A majority of security professionals (52%) report the use of AI tools within their development teams, including OpenAI Codex (50%), ChatGPT (45%), and GitHub Copilot (43%). However, despite the efficiency gains from AI-driven automation, concerns arise due to the lack of adequate safeguards. Only 32% of organisations have established procedures to evaluate AI-generated code for potential risks related to licensing, security, and quality.

Survey respondents also voiced concerns about the insufficient commitment from decision-makers in addressing these challenges. Only 39% indicate strong leadership commitment to mitigating malware risks in software supply chains, despite 45% noting an increase in investment following high-profile incidents like the SolarWinds breach. Moreover, only 38% consider the current resources allocated to supply chain security adequate.

“Supply chain attacks are becoming more prevalent across organisations globally, yet this report highlights the sustained weaknesses in existing software development processes and security standards,” said Jason Schmitt, general manager, Synopsys Software Integrity Group. “Attackers are getting more sophisticated and thus finding more weaknesses that allow them to explore a supply chain where they can steal sensitive data, plant malware, and control systems. Particularly with the rise of AI-generated code, security teams need to maintain visibility into applications, and continuously evaluate IP, security threats, and code quality to reduce risk.”  

Key findings from the report also highlight:

  • Limited adoption of Software Bills of Materials (SBOMs), critical for ensuring supply chain security, with only 35% of organisations producing them.
  • Open source vulnerabilities remain a significant concern, with 65% of respondents utilising open source software, yet less than half (47%) deem their security measures highly effective in securing it within the supply chain.

To learn more, download a copy of “The State of Software Supply Chain Security Risks” report, read the blog post or register for the May 23 webinar. 

ShareTweet
Previous Post

Advanced Cyber Defence Systems Joins Elite Group in Signing CISA’s Secure by Design Pledge

Next Post

Cato Networks Partners with e& Further Expanding Global SASE Platform with New UAE PoP

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol