Supply chain & software security
Trust is an undeniable, if undesirable, part of supply chains. Trust is second to verification, but the challenge of today is software development has become a complex set of dependencies. API integrations, cloud services, open-source libraries, machine-generated code, software-as-a-service connections, and automated software builds. Grasping it from start to finish is a struggle.
Many companies no longer develop software in a vacuum. A single software application can depend on dozens of third-party components developed by other people or entities in different countries. The consequence is that companies are losing control over how their software reaches the production environment, who has access to it, and the security risks involved in each iteration of the software update process.
The statistics speak for themselves, between 26% and 31% of businesses said they experienced a security breach that originated from their supply chain or third-party vendors over the past year.
One breach reaches thousands
Consider the SolarWinds incident, in which attackers planted backdoors in SolarWinds Orion software updates, resulting in malware being installed across 18,000 companies (give or take) that were unaware of the infection.
Then, ShinyHunters carried out a slew of CRM attacks, using voice phishing and malicious OAuth applications to hijack Salesforce environments and gain API access. Hundreds of companies were affected, including luxury brands, travel entities, and tech companies. Significant amounts of consumer information were leaked.
The trend of attacking software vendors, managed service providers, CI/CD systems, update processes, and developer tools is growing, as attacking just one trusted supplier enables bad actors to access thousands of customers at once. Often, the initial attack itself is not very advanced. What makes these attacks successful is the trust inherent in software development ecosystems.
Pressure proliferates problems
AI is adding more pressure. As development teams embrace AI-coding assistants and automation systems to speed up development, their tolerance (and time) for vulnerability checking is decreasing. AI-generated code can introduce vulnerabilities, like logic flaws and dependencies, that developers might not verify before deploying.
Meanwhile, the proliferation of machine identities related to automation pipelines, cloud workloads, and development environments is escalating.
Visibility becomes resilience
The defender’s challenge lies in understanding systemic exposure. There is a trend toward more attention on issues such as software provenance, dependency mapping, code-signing integrity, identity governance, and runtime visibility throughout the software development life cycle. An issue that once only affected developers is now a board-level concern.
This is impacting the idea of resilience, too. Companies realise prevention will not be enough in interconnected supply chains. Firms must be able to detect when their dependencies are compromised, isolate the systems, gauge the impact, and ensure operations continue despite supplier or software component failures.
Maintaining visibility into software ecosystems, understanding how trust flows between suppliers and systems, and allowing them to react swiftly when trust is compromised. This is the advantage.
Top trends
More code means a larger attack surface: When developers ship more code, they ship more endpoints, integrations, configuration paths, and dependencies. Each one is something a security team eventually has to account for, whether for a routine assessment, an audit, an incident response, or a board-level risk conversation.
Code generation via AI raises governance issues: Auditors only care about three things, regardless of how the code was written: can you prove a vulnerability existed, that it got fixed, and if the testing can be repeated. “An AI suggested it and the developer approved it” doesn’t answer any of that. Neither does “the CI build passed.” And neither does a raw scanner report.
Visibility during runtime is more important than ever: Enterprises are paying closer attention to which software components are running in production environments, rather than relying solely on pre-deployment security checks. Maintaining visibility into software ecosystems means using controls such as SBOMs, dependency mapping, and code-signing integrity to understand what is running in production.
Regulatory watch: EU Cyber Resilience Act (CRA)
The requirements for reporting under the CRA come into effect from 11 September 2026, with manufacturers obliged to provide an initial report of actively exploited vulnerabilities or significant incidents impacting products with digital components within 24 hours of becoming aware, followed by a more comprehensive notification within 72 hours.
In practice, security teams will need a better process for internal escalation, proper assessment of what constitutes an incident, and effective means to determine whether an issue with a product meets the reporting threshold.
CISO voice
“Supply chain attacks against software are successful due to the complex nature of modern trust relationships.
Where once organisations worried about their perimeter; they now defend an ecosystem of vendors, platforms, identities, and dependencies that is in constant flux.”
— Ejona Preci, Group CISO, LINDAL Groups
Innovation spotlight
One business gaining traction is Socket, an innovative startup that works to secure software supply chains by detecting malicious or compromised open-source packages before they are introduced into
development environments. Its approach mirrors a surging industry demand for better, deeper visibility and proactive package risk analysis.
Barcelona Cybersecurity Congress update
This year’s Barcelona Cybersecurity Congress will cover the difficult task of securing software supply chains and gaining visibility into digital ecosystems. Among the topics to be covered are software resilience, the risks of AI-driven development, software supply chain vulnerabilities, and the adaptation of security strategies to the highly connected world.
Barcelona Cybersecurity Congress 2026
Dates: 3–5 November
Location: Barcelona
Co-located with: Smart City Expo World Congress
CONNECTING EUROPE’S CYBERSECURITY ECOSYSTEM
Register here for Barcelona Cybersecurity Congress 2026!