Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 26 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Companies Double Down on AI and Supply Chain Security, According to Black Duck’s BSIMM15 Report

by The Gurus
January 14, 2025
in Featured
cybersecurity
Share on FacebookShare on Twitter

Organisations worldwide are ramping up efforts to tackle emerging security risks in artificial intelligence (AI) and software supply chains, according to the newly released BSIMM15 report from Black Duck. The report, which examines software security practices across 121 companies, reveals a sharp increase in activities aimed at strengthening defenses against evolving threats.

Key findings from the BSIMM15 report highlight significant shifts in how organisations are addressing software security:

  • The number of companies conducting adversarial testing, such as abuse case scenarios, has doubled compared to last year.
  • Software composition analysis (SCA) on code repositories has surged by 67%, reflecting a growing focus on supply chain security.
  • A 30% rise in organisations employing research groups to explore new attack methods underscores the increasing complexity of security challenges.
  • Software bills of materials (SBOMs), now a critical tool for compliance and transparency, are generated by 22% more organisations for deployed software.

AI Adoption Brings New Risks

“Over the past year, AI has gone mainstream across organizations of all sizes, bringing both opportunities and new risks,” said Jason Schmitt, CEO of Black Duck. “Prioritising security in the face of emerging technologies—especially rapidly evolving fields like AI—has never been more critical or challenging. BSIMM15 offers valuable insights into how organisations are navigating these hurdles and can serve as a guide for others looking to innovate securely and build trust in their software.”

The BSIMM15 study captures data from diverse industries, including cloud computing, financial services, healthcare, IoT, and technology. Collectively, it represents the efforts of 11,100 security professionals supporting 270,000 developers and securing 96,000 applications.

Spotlight on Software Supply Chains

Supply chain security has taken centre stage, particularly as organisations respond to U.S. government requirements for software self-attestation. BSIMM15 data shows a sharp rise in activities supporting compliance, such as the increased use of SCA tools and SBOMs. These measures are vital for ensuring transparency and security in today’s complex software ecosystems.

Security Awareness Training Declines

While strides are being made in AI and supply chain security, the report notes a concerning decline in security awareness training. Only 51.2% of organisations now offer basic training, the lowest rate observed since the BSIMM initiative began in 2008.

About BSIMM

The Building Security In Maturity Model (BSIMM) has tracked the evolution of software security practices since its inception in 2008. Through comprehensive interviews and assessments, BSIMM collects and analyses anonymised data to identify key trends and guide organisations in planning, executing, and measuring their software security initiatives.

With AI reshaping the digital landscape and supply chain threats growing more sophisticated, BSIMM15 offers a detailed look at how leading companies are staying ahead of the curve.

ShareTweet
Previous Post

KnowBe4 Research Confirms Effective Security Awareness Training Significantly Reduces Data Breaches

Next Post

Open Banking Shortcomings Threaten UK Global Leadership Position Research Finds

Recent News

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

June 25, 2026
pqc

New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security

June 24, 2026
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

June 24, 2026
Security Training Needs Google Maps, Not Christopher Columbus

Security Training Needs Google Maps, Not Christopher Columbus

June 24, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol